Hire Me — Privacy Policy

This policy describes what the Hire Me iOS application actually does with your data at version 1.

Last updated
22 August 2026

1 Who we are

Hire Me is operated by Ahmed Ramadan Khalifa as an individual developer. This policy explains what personal data the Hire Me iOS application collects, why, who it is shared with, and how you control it.

2 What we collect

What we collect, why, and where it comes from. Scroll sideways inside this box to see every column.
Category What exactly Why Source
Account identifier The unique subject identifier your sign-in provider issues for your account — Apple's when you use Sign in with Apple, Google's when you use Sign in with Google To create and recognise your account Sign in with Apple, or Sign in with Google
Email address Your email. With Sign in with Apple this may be an Apple private relay address if you chose to hide it; Google offers no equivalent, so Sign in with Google gives us the real address on your Google account Account recovery and service notices Sign in with Apple, or Sign in with Google
Name Optional: the name Apple offers to share when you first sign in with Apple, or the name on your Google account. There is no name field in the app, and it works without one To address you in the app and, if you choose, in a generated CV Sign in with Apple, or Sign in with Google
CV file and its contents The PDF or DOCX you upload, plus the text and structure extracted from it (work history, education, skills, contact details it contains) To score your CV, suggest improvements, and match you to jobs You
Job preferences Target country, target roles, seniority, remote preference, employment type, salary expectation, languages, excluded companies To find and rank relevant jobs You
Activity data Jobs shown, saved, dismissed; applications you record; CV versions created; quota usage To operate the service, enforce plan limits, and show your history Generated by your use
Subscription status Your plan, its status and renewal date, and the Apple transaction identifiers that prove it To grant paid features Apple
Technical logs Request timestamps, error codes, and coarse diagnostics Security, abuse prevention, and debugging Generated by your use

How you sign in. There are two ways in — Sign in with Apple and Sign in with Google — and each is handled by the provider you pick, so we never see or store an Apple or a Google password. Sign in with Google asks Google only for your basic profile and your email address: it gives the app no access to Gmail, Drive, contacts, or anything else in your Google account, and we keep no Google token once the sign-in is done. The first time you sign in with Google we refuse an address Google has not verified rather than store an unproven one. If the address Google gives us is one Google has verified and it already belongs to an account here, that sign-in opens the existing account instead of starting a second one, so both buttons then reach the same CVs and history.

We do not collect your precise location, your contacts, your photos beyond a file you deliberately pick, or advertising identifiers. We do not ask for your email password, and v1 of the app does not connect to your mailbox at all. We do not use your activity data for analytics or advertising profiles: it is there to run the service, hold you to your plan limits, and show you your own history.

Sensitive details inside your own CV. Hire Me never asks you for special-category data. There is no field anywhere in the app for your date of birth, nationality, photograph, religion, political opinions, trade-union membership, health or disability. But we do store the file you upload and the full text extracted from it, and CVs routinely carry some of that anyway — a date of birth, a nationality, a photograph, a union role, a political or religious affiliation, a health or disability disclosure. Whatever your own document contains is processed as part of that document: stored with it, shown back to you, used for scoring and matching, and, if you consent to AI improvement, included in the text sent to the AI provider. A photograph stays inside the stored file rather than in the extracted text, because extraction reads text only. You decide what to upload: you can take out anything you would rather we did not hold and upload the file again, delete that CV, or delete your whole account.

3 What we do not do

  • We do not sell your personal data, and we do not share it with advertisers or data brokers.
  • We do not send email to employers on your behalf in this version. When you apply, the app opens the employer's own official application page.
  • We do not send your CV to any employer automatically.
  • We do not invent facts in your CV. Improvement suggestions rephrase and reorganise what you already wrote; every change is shown to you and only applied if you accept it.

4 Artificial intelligence

Improving your CV uses an external AI provider. This happens only after you give separate, explicit consent, which is distinct from accepting these terms and can be withdrawn at any time.

  • The structural part of your CV score is computed on our own servers and involves no AI provider.
  • When you request improvement suggestions, only the CV text the request needs is sent: your headline, summary, job titles, employers, dates, bullet points, education, projects, skills, languages and certifications. Your name, email address, phone number and profile links are removed before the request leaves our server, in two passes. First, the contact details we read out of your CV's header are simply never part of the request. Second, every line that is sent is searched for the same details written inside your own sentences — a mobile number in a summary line, an address inside a bullet point, a profile URL in a skills list, your name in the opening line of a summary — and each one found is replaced with a neutral placeholder such as [phone removed].
  • Your name is removed in the spellings we can work out from your CV's header. That means the full name exactly as you wrote it there, your first name together with your surname, and your first name or your surname on its own. Three cases are deliberately left alone, because removing them would cut words out of your own sentences: a name word shorter than four characters, a middle name written by itself, and a name that is also an ordinary word — “Said”, “Nour”, “Malak”, “أمل”. And because this matches spellings rather than people, a name written one way in your header and a different way further down (“Khalifa” against “Khalifah”, “Mohamed” against “Muhammad”) is not recognised as the same name and is not removed.
  • That second pass is pattern matching, not understanding, and it is best-effort rather than complete. It leaves alone shapes it cannot tell apart from a figure you meant to state, such as a local phone number written with no country code and no leading zero. It also leaves alone a web address written with capital letters, no https:// and no path, because that is the same shape as a technology name like ASP.NET — unless we read that same address out of your header, in which case it is removed. Where a number could be either, it errs towards removing it, so a reference or badge number that begins with a zero may be replaced as though it were a mobile. It does not look for postal addresses, national ID or Iqama numbers, or dates of birth. Everything else you wrote is sent as you wrote it, so please do not rely on this to carry information you would not want the provider to see.
  • What the provider then does with that text is governed by the provider's own published terms, not by any agreement between them and us. We have no separately negotiated data-processing agreement with the provider, and we make no claim that your content is kept out of training their models.
  • If you decline AI consent, scoring and job matching still work; only the AI improvement feature is unavailable. Withdrawing consent stops any further request, but it cannot recall text that has already been sent.

Provider: DeepSeek (api.deepseek.com), an AI company based in China. Your CV text is processed on their servers, which means it leaves your country and is handled under Chinese law rather than the law of your own country. If you are not comfortable with that, decline AI consent — scoring and job matching work fully without it, and nothing is sent.

What that transfer rests on. If you are in the EEA, the UK or Switzerland, this is a transfer to a country with no adequacy decision. The only basis we rely on is your own explicit, separate and withdrawable consent to AI processing, given inside the app before anything is sent — the consent-based exception in Article 49(1)(a) of the GDPR and its UK equivalent. We do not have Standard Contractual Clauses or any other transfer safeguard in place with this provider, and we do not claim to. Consent is the stated basis precisely because the feature is optional: CV scoring and job matching work in full without it, and if you never consent, nothing is ever sent.

5 Job sources

To find jobs we query third-party job APIs and public employer job boards. We send them your search criteria — such as target country, role keywords, and remote preference — never your CV, your name, or your email. Job listings we retrieve are stored with a record of which source they came from and when.

These are not licensed feeds. Some are free or free-tier job APIs and some are employers' own published job boards, and we use each one within the terms that source publishes. Because permission to read a source does not extend to passing its listings on, the Terms of Use ask you not to redistribute listings you found through the app.

6 Who else processes your data

Every recipient of your data, what they do with it, and what they receive. Scroll sideways inside this box to see every column.
Recipient Purpose What they receive
Apple Sign in with Apple, subscriptions, and payments Your Apple account identity and purchase records; Apple's own privacy policy governs this
Google Sign in with Google, for the users who choose it That you are signing in to Hire Me and which Google account you picked; Google returns the account identifier, the email address and the name we then store. Google's own privacy policy governs this. No CV, job search or other app data is ever sent to Google
Our hosting provider Running our servers and database All data described above, stored on servers we control
AI provider CV improvement suggestions, with your consent The CV text the request needs, with your name, email, phone number and links removed — from the contact fields, and on a best-effort basis from your own sentences; what they do with it is governed by their own published terms, as described in section 4
Job source APIs Finding relevant jobs Search criteria only
Expo Delivering updates to the app's own code That a Hire Me iOS build is checking for an update, and which build it is: the platform, the build's version fingerprint, the release channel it follows, the identifiers of the update it is running and the one built into it, a random installation identifier that is not linked to your account, the identifiers of any updates that recently failed to start, and any value Expo itself set on an earlier reply for the app to quote back. Your IP address, as with any request. No account identifier, email address, name, CV or job search is ever sent to Expo

App updates, and the one check that happens before you sign in. Hire Me can deliver a small fix — a wording correction, a layout repair — without waiting for a new App Store release. To do that, the app asks Expo's update service whether newer code of its own is waiting. That check runs on every cold start, before you sign in and whether or not you ever create an account, which makes it the only request the app sends that does not follow from something you did.

It is a single request with no body attached, and here is everything in it: the platform (iOS), the version fingerprint of the build you have, the release channel that build follows, the identifiers of the update it is currently running and the one shipped inside it, an installation identifier, and — only when an update has recently failed to start on your device — the identifiers of those failed updates, so the service stops offering you the same broken one. The request also quotes back any value Expo attached to an earlier reply: the protocol lets Expo's service set a header of its own, which the app stores and returns on every later check. What goes into that value is Expo's to decide; nothing you do in the app puts anything into it. Alongside those the request carries fixed protocol headers — the update protocol and API version numbers, and the reply formats the app accepts — which are identical in every copy of the app and say nothing about you. The installation identifier is a random value the app makes up the first time it runs and keeps in its own settings. It is not your Apple ID, not your device's identifier, not an advertising identifier, and it is not joined to your Hire Me account — nothing sent with it says who you are, and deleting the app discards it. If the previous run ended in a crash, the text of that error message is attached once, then deleted from your device. And as with a request to any server, Expo sees the IP address you connect from.

Nothing you gave us travels with it — no account identifier, no email address, no name, nothing from your CV, none of your job searches. If an update is waiting, the app then downloads that code and its images from Expo's servers; if none is, the answer is that there is nothing to do. What Expo does with what it receives is governed by Expo's own published privacy policy, and we have no separately negotiated agreement with them. There is no switch inside the app that turns this check off.

7 Where data is stored and for how long

Your data is stored on servers we control. We keep:

  • your account, profile, CV files, the text extracted from them, your scores and your history for as long as your account exists — deleting your account deletes them, as described below;
  • job listings, which come from employers and job sources rather than from you, for the retention window recorded against each source: 7 days for the credentialed aggregator feeds (Adzuna, Jooble, Careerjet) and 30 days for the employer job boards (Greenhouse, Lever, Teamtailor, SmartRecruiters, Workable, Oracle Recruiting, Workday, Ashby). A scheduled fetch keeps them fresh; the automated sweep that deletes a listing once its window has passed is still being built, so until it ships a listing can stay in our database past its window;
  • technical logs on the server, which rotate by size — only the most recent files are kept — rather than after a fixed number of days. A specific log retention period has not been set yet, and it will be stated here once it is.

Payment records are retained where required for tax and accounting purposes. Those are the records Apple sends us about a subscription — the plan, its status, and transaction identifiers — never your CV or anything in it.

What deletion means, including for backups. Deleting your account removes the database rows and the stored files themselves from the live systems. What we deliberately keep afterwards is a dated deletion receipt recording that the deletion ran: it holds the internal account id and timestamps, and no CV content, no name and no email address. We do not rebuild a deleted account, and support cannot restore one. Where a copy of your data still exists in an operational backup or in a rotating server log at the moment you delete, that copy is not used to restore anything and passes out of use on that copy's own rotation cycle rather than being edited in place. If we begin keeping longer-term backups, we will state their retention period here before we do.

8 Your choices and rights

  • Access — you can view your profile, CV versions, scores and application history in the app. There is no automated export yet: if you need a copy of your data in a portable form, email us and we will put it together for you.
  • Correction — every field extracted from your CV is shown to you and can be corrected; extraction is never assumed to be right.
  • Deletion — you can delete your account from inside the app, in the Delete account section at the bottom of Settings. This deletes your profile, CVs, extracted content, scores, history and session tokens, and, if you signed in with Apple, revokes the Sign in with Apple token. Sign in with Google leaves the app no standing access to your Google account, so there is nothing there for us to revoke. It does not cancel your Apple subscription, which you manage in your Apple account settings.
  • Withdrawing consent — AI processing consent can be withdrawn at any time without losing access to the rest of the app.

Depending on where you live, you may have further rights under local data protection law. Contact us and we will respond — see Support for how to reach us.

9 Security

We protect your data with encrypted transport, access controls, private storage that is never publicly readable, and short-lived signed links for file access. Uploaded files are validated and held in a restricted area before they are processed. No system is perfectly secure, and we do not claim otherwise.

10 Age

Hire Me is a job-search product, not a product for children. You must be at least 16 to use it, the Terms of Use say the same thing, and the App Store listing is rated to match. We do not knowingly collect data from anyone under 16, and if we learn that an account belongs to someone under that age we delete it. If you believe a child has created an account, write to support@hireme-app.com.

11 Changes

If we change how we handle your data we will update this policy and, for material changes, ask for your consent again inside the app.