coffee-on.mecoffee-on.me

DRAFT — pending legal review. This document is a first-pass working draft prepared for internal review only. It has not been reviewed or approved by a qualified lawyer and must not be published, linked from the live site, or relied upon as final until it has been. Bracketed placeholders mark facts (legal entity name, registered address, contact details) that could not be found in the codebase and must be supplied before publication. A separate "Notes for Legal & Engineering Review" section at the end of this document flags open questions that should be resolved, or explicitly accepted, before this policy goes live — it is not part of the published policy and should be removed before publication.

Privacy Policy

Last updated: 9 September 2026

This Privacy Policy explains how coffee-on.me ("coffee-on.me," "we," "us," or "the Company") collects, uses, shares, and protects personal data in connection with our platform for founder-led hiring (the "Service").

The Company is the operator of coffee-on.me. [The Company's registered legal name, company number, and registered address will be inserted here once confirmed.]

This policy is written for everyone whose personal data the Service processes — not only the founders and recruiters who sign up for an account, but also the candidates and clients they work with, and anyone who connects with a recruiter through a shared conversation link. Section 1 explains which of these you are likely to be, and Section 11 explains, concretely, how to exercise your rights over your own data.


1. Who this policy covers, and some terms we use

coffee-on.me is used in a few different ways, and we use a few product-specific terms throughout this policy:

If you are a candidate or client, your relationship with coffee-on.me generally arises because a recruiter who uses our Service is managing that relationship — either because you gave your details directly to that recruiter, or because you connected through a Window they shared with you. Section 2 explains how responsibility for your data is split between the recruiter and coffee-on.me.


2. Our role: who is responsible for your data

Where you are a recruiter or workspace member, coffee-on.me is the controller of your account data (Section 3.1) — we decide why and how it is processed, subject to this policy.

Where you are a candidate or client, your data is generally submitted to the Service by, or at the direction of, the recruiter you are working with. In that relationship, the recruiter's workspace is typically the controller of your data (they decide to recruit you, to record your details, to contact you), and coffee-on.me processes it as a processor on the recruiter's behalf, under the terms of our agreement with them. That said, coffee-on.me also builds and operates the systems that determine how your data can be used (for example, the consent gates described in Section 5, and the export/erasure tools described in Section 11), and provides those rights to you directly regardless of what the recruiter does. If you have a request about your data, you may raise it with either the recruiter or with us directly, using Section 11.

[Note for legal review: the controller/processor characterization in this section is a structural assumption typical of B2B recruiting software, not a conclusion drawn from the codebase research underlying this draft. It should be confirmed, and the wording adjusted if necessary, before publication — see the closing notes section.]


3. Information we collect

3.1 Recruiters and workspace members

When you create or join a workspace, we collect:

3.2 Candidates and clients

Recruiters use coffee-on.me to record and manage their relationships with the people and companies they work with. For a candidate, this can include: display name, email address, phone number, LinkedIn URL, a running "profile snapshot" summarising what the recruiter and our systems have learned about them, and where they stand in the recruiter's follow-up process. For a client (a company or hiring contact), this can include: company name, contact name, email address, phone number, and stated preferences.

This information may be entered directly by the recruiter, or built up automatically over time from documents you or the recruiter upload, from calls, and from chat conversations, as described below.

3.3 Documents

If you are a candidate, a recruiter may upload your CV or a snapshot of your LinkedIn profile; for a role, a recruiter may upload a job description. We accept PDF, Word (DOCX), and plain-text files, up to 25MB.

For every document uploaded, we generate a full-text extraction of its contents and use it to identify structured details relevant to the document type — for a CV, things like headline, current company and title, location, skills, work experience, and education; for a job description, things like title, company, location, compensation, and requirements. This extraction step sends the document's text to Anthropic (see Section 6). The structured facts it produces, together with facts learned from call transcripts, chat messages, or manual entry by a recruiter, accumulate over time to build a fuller picture of a candidate.

3.4 Conversations with our AI assistant

coffee-on.me's chat interface is used by recruiters, and by the candidates and clients they invite to converse with our AI assistant. We store the full text content of every message sent in a conversation, regardless of who is participating in it. These conversations are handled by a managed agent, built on Anthropic's Claude models — see Section 6 for what that means for where your conversation data goes.

3.5 Phone calls

coffee-on.me includes a feature that lets a recruiter bridge a live phone call with a candidate or client from inside the Service. As of the date of this policy, this feature is disabled by default and must be explicitly turned on for a given deployment of the Service.

Where it is enabled: calls are transcribed in real time, with the transcript broken into segments that record who spoke, what was said, and when. The call is also recorded as an audio file. We keep this audio for a limited period so the call can be reviewed shortly afterwards (see Section 9 for how long); with a separate, optional consent from the person we're calling, a copy of the recording may instead be retained for longer as part of a training data set (see Section 5.3 and Section 9). Both the recruiter's standing consent and a fresh consent from the person being called are required before a call can be connected at all — see Section 5.3.

3.6 People who connect through a shared conversation link (a "Window")

A recruiter can send you a private link to start a conversation without you first having an account. We do not create any record identifying you — no name, no readable email address or phone number — until you actually verify that address or number, by entering a one-time code we send to it. Before that point, if you've provided a destination for that code, it is held only in an encrypted form that isn't readable as your personal data; nothing about you is written to a person record yet.

Once you verify, we create a record for you containing: your display name (if you gave one), your locale and timezone, and your communication and notification preferences. We also keep a value derived from your verified email, phone number, or LinkedIn URL (rather than the raw value alone) so that we can recognise you if you connect again through another Window in future, together with the plain, normalised form of that contact detail and its verification status.

3.7 Information from public web pages

If you are a recruiter, the chat assistant you use can, at your direction, fetch and read the contents of a public web page — for example, if you paste a candidate's public LinkedIn profile URL into a conversation so the assistant can look at it. When this happens, only the URL you provided and the resulting public page content are sent to the rendering services described in Section 7; none of the other personal data we hold about you or your candidates is sent along with it.


4. How we use personal data, and our legal basis for doing so

We use personal data to…Which mainly involvesOur legal basis (UK GDPR)
Provide the Service — accounts, workspaces, chat, document storage, callsRecruiter account data; candidate/client relationship dataPerformance of our contract with the recruiter/workspace (Art. 6(1)(b)); legitimate interests in operating the Service for candidate/client data processed at the recruiter's direction (Art. 6(1)(f))
Power the AI assistant, extract structured facts from documents and calls, and help match candidates to rolesChat content; document text; call transcriptsNecessary to perform the recruiting service the recruiter has engaged us to provide (Art. 6(1)(b)/(f)); see Section 6 for the specific AI processing involved
Re-contact a candidate or client about future opportunities after the original engagement endsContact details; follow-up statusConsent (the follow_up consent described in Section 5.3)
Share a candidate's profile with a specific client for a specific roleCandidate profile dataConsent (the profile_share consent described in Section 5.3)
Place and record a phone callPhone numbers; call audio; transcriptConsent from both the recruiter and the person being called (the call_transcription consent described in Section 5.3)
Keep a call recording as part of a training data set, beyond its normal short retention windowCall audio; transcriptSeparate, optional consent (the audio_training consent described in Section 5.3)
Consider a candidate for opportunities sourced by a different workspace than the one that originally captured their dataCandidate profile dataConsent-based eligibility gate described in Section 5.4
Send notification emails and text messages (e.g., pre-alerts, callback requests, conversation summaries)Contact details; a short message summary; a link to the relevant conversationLegitimate interests in keeping participants informed (Art. 6(1)(f)); performance of contract where the recipient is a recruiter
Keep the Service secure, prevent abuse, and enforce our termsAccount and usage dataLegitimate interests (Art. 6(1)(f))
Comply with our legal obligationsAs required by lawLegal obligation (Art. 6(1)(c))

5. How consent works in this product

We treat consent as something to be recorded and checked in the system, not just a box ticked once and forgotten. This section explains, specifically, how that works.

5.1 We don't write anything about you until you're verified

As described in Section 3.6, if you connect with a recruiter through a shared Window, no identifying record is created until you complete a one-time-code verification. This was a deliberate fix to an earlier version of this flow, which could write an unverified contact's plaintext email or phone number, and a placeholder relationship, before any code had even been sent. Under the current design, the first time anything identifying is written about you is the moment your code is confirmed.

5.2 We keep a record of consent decisions

We maintain a dedicated log of consent decisions, separate from the underlying profile data it relates to. Each entry records who the decision relates to (a candidate, client, or recruiter), what it was for, whether it was a grant or a withdrawal, which version of our consent language was in effect at the time, supporting evidence of how the decision was captured, and when it happened.

5.3 The specific things we ask consent for

We currently track four distinct kinds of consent:

  1. Future contact (follow_up). A candidate's or client's agreement to be contacted again about future opportunities once their current engagement has ended. We check for this consent before any automated follow-up is triggered, and before a candidate is recontacted through our matching process.
  2. Sharing a profile with a client (profile_share). A candidate's agreement to have their profile shared with a specific client, for a specific role. This isn't a simple checkbox — it is captured through a confirmation-token flow, and we check for it before a client-facing pitch about that candidate is put together.
  3. Call recording and transcription (call_transcription). Required from both the recruiter and the person being called before any call is connected. The recruiter's standing consent is checked first; the other person's consent is captured at the moment the call is requested. A call session cannot exist in our systems without a linked record of this consent.
  4. Retention of a call recording for training (audio_training). A separate, optional, opt-in consent — captured at the same time as call-transcription consent, but tracked independently — for us to keep a copy of that specific call recording beyond its normal short retention period, so it can be used as part of a training data set. We check for this consent before any such copy is made.

5.4 Sharing a candidate's profile with a different workspace

coffee-on.me can, in principle, introduce a candidate's profile to a recruiter workspace other than the one that originally captured their data — for example, if that candidate would be a good fit for a role at a company a different recruiter on our platform is hiring for. This does not happen automatically: our system checks a number of independent conditions before it is allowed, and every one of them must be satisfied, including that the candidate has given verified permission to be introduced to new opportunities, and that we hold valid, un-withdrawn consent for the channel through which they would be contacted. A candidate's underlying permission for this kind of introduction is itself a distinct, tracked setting (separate from the consent log described above) that cannot be marked as granted without recorded verification and a timestamp.

If you are a candidate, this means your profile could be surfaced to a recruiter workspace other than the one you originally gave your details to, subject to the safeguards above.


6. How we use AI in the Service, and what that means for your data

AI is central to how coffee-on.me works, so we're describing it here specifically rather than only in the sub-processor table below. Our chat assistant, document analysis, and related features are built on Claude, a large language model provided by Anthropic.

We do not currently use any other third-party AI provider for these purposes.


7. Who we share information with

We use a small number of specialist providers ("sub-processors") to run the Service. Each is only given the data it needs to perform its function.

ProviderWhat they do for usWhat of yours reaches them
AnthropicPowers our AI assistant, document extraction, call-transcript analysis, and image analysis (see Section 6 for detail)Chat message content; extracted document text; call transcripts and summaries (where voice calling is enabled); images shared in conversations; the URL and public content of any page a recruiter's assistant is asked to read
Supabase (database)Hosts our application database, in the UK (London, eu-west-2)Account, workspace, candidate/client relationship, consent, and conversation records described throughout this policy
Supabase (file storage)Hosts uploaded files and media, on a separate Supabase project, in Australia (Sydney, ap-southeast-2)CVs, job descriptions, LinkedIn snapshots, call recordings, Window-shared media, and recruiter profile photos
SendGrid (a Twilio company)Sends transactional emails (for example, pre-alerts to a recruiter, callback requests, or a conversation summary)Recipient email address, recipient/recruiter display name, a short text summary of the relevant conversation or role, and a link to the private conversation thread
TelnyxSends SMS notifications, and — where voice calling is enabled — connects and records phone callsSMS: recipient phone number, name, role title, a short text summary, and a thread link. Voice (where enabled): the phone numbers being bridged, live call transcription, and the recorded call audio
Deepgram (via Telnyx)Performs the speech-to-text transcription behind Telnyx's call-transcription feature, where voice calling is enabledCall audio, but only as part of Telnyx's own service — we do not hold a direct account or relationship with Deepgram
VercelHosts the application and runs its scheduled background jobs (for example, the daily job that deletes expired call recordings)All data passing through the application at runtime; all of our operational secrets, held as encrypted environment variables
Google Cloud (Cloud Run)Renders a single web page when a recruiter's assistant needs to read one and a plain server-side request is blocked by bot detection, and — for pages protected by an active CAPTCHA-style challenge — solves that challenge to render the same pageThe URL being read, and the resulting public page content only — not any of the personal data we otherwise hold

We do not share personal data with any advertising, marketing, or data-broker company, and we do not sell personal data.

[Note for legal review — do not remove without reading: engineering has flagged a live, encrypted "ElevenLabs" credential present in our production environment with no corresponding reference anywhere in the application's code. It is not included in the table above because it cannot currently be confirmed as either an active integration or an unused, orphaned credential. This must be resolved with engineering — and the sub-processor list updated if needed — before this policy is published. See the closing notes section.]


8. International data transfers

Some of your personal data is transferred outside the UK/EEA as a normal part of running the Service. In particular:

Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards recognised under UK GDPR and (where applicable) the EU GDPR, such as the UK International Data Transfer Addendum or Standard Contractual Clauses incorporated into our agreements with these providers, or transfers to a jurisdiction covered by an applicable adequacy decision. [The specific transfer mechanism relied on for each provider will be confirmed and listed here once each vendor's current data processing agreement has been reviewed — see the closing notes section.]


9. How long we keep personal data

DataHow long we keep it
Call recordings kept for short-term reviewA limited number of days after the call (7 days by default, and never more than 30), after which the recording is automatically and permanently deleted, along with its storage file
Call recordings kept as part of a training data set, with the separate consent described in Section 5.3No automatic expiry — kept until you exercise your erasure rights (Section 11) or the relevant consent is otherwise acted on
CVs, job descriptions, and LinkedIn snapshotsNo automatic expiry — retained until an erasure request is made (Section 11), at which point the file and its associated extracted text are deleted
Chat conversation contentNo automatic expiry. If you exercise your erasure rights, the content of your messages is overwritten with a placeholder, but the surrounding record (that a message existed, when, and from whom) is kept to preserve the integrity of a conversation that may involve other participants — see Section 11 for detail
Signed links to shared media (photos, files shown via a Window)5 minutes per link — a fresh link is generated each time media is viewed, specifically so that access already revoked can't be regained by reusing an old link
Webhook event logs from our telephony providerNo automatic expiry currently in place
Short-lived records such as sign-in sessions, invitations, and verification codesDeleted automatically once they expire (typically within a day for a verification code, unless still needed for an active conversation)

[Note for legal review: the 7-day/30-day call-recording figure above reflects the software's configured default and hard-coded maximum. The exact value configured in our live production environment should be confirmed against this policy before publication — see the closing notes section.]


10. How we protect personal data

We use a combination of technical and organisational measures designed to protect personal data, including:

No method of storage or transmission is completely secure, and we cannot guarantee absolute security. [A general statement about incident notification and any relevant security certifications will be added here once confirmed with the Company's security posture at the time of publication.]


11. Your rights, and how to actually exercise them

If UK or EU data protection law applies to you, you generally have the right to: access a copy of your personal data; rectify inaccurate data; erase your data; restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time where our processing relies on it (this doesn't affect the lawfulness of anything already done on the strength of that consent). You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

Unlike a policy that only says "contact us," coffee-on.me has built dedicated export and erasure functionality into the product itself, described below.

11.1 If you are a candidate or client with a relationship in a recruiter's workspace

You (or the recruiter managing your relationship, on your behalf) can request:

11.2 If you connected through a shared conversation link (a "Window") and have your own identity across workspaces

You can request:

[Note for legal review — material gap to resolve before publication: the AI-provider session deletion step described in 11.1 is implemented for the candidate/client relationship erasure path, but does not currently appear to be implemented for the Window-identity erasure path described in 11.2. This asymmetry should be closed in the product, or reflected accurately in this section, before this policy is published — see the closing notes section.]

11.3 How to make a request

[The specific in-product location or support channel for making an export or erasure request — e.g., a settings page, a link in a conversation, or a request to the recruiter — will be confirmed and described here once finalised. Recruiters and workspace members wishing to exercise rights over their own account data, rather than a candidate or client relationship, should contact us using the details in Section 15.]

We will respond to a valid request within the time required by law (in general, one month, extendable in limited circumstances). We may need to verify your identity before actioning a request.


12. Cookies and tracking on our website

As of the date of this policy, our public marketing website and the public-facing pages of a shared conversation link (a "Window") set no cookies and load no analytics, advertising, or tracking scripts of any kind. Cookies are used only once you are signed in to the application, or once you have verified your identity to open a private conversation — and even then, only strictly necessary ones needed to keep that session working securely. Full detail is set out in our separate Cookie Policy, which should be read alongside this one.


13. Children's privacy

The Service is intended for use by working professionals — founders, recruiters, and the candidates and clients they engage with in a professional hiring context — and is not directed at, or intended for use by, anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have done so, we will take steps to delete it.


14. Changes to this policy

We may update this Privacy Policy from time to time, for example as the Service changes or as required by law. Any update will be reflected by a new "Last updated" date at the top of this page. Where a change is material, we will provide a more prominent notice.


15. Contact us

If you have questions about this Privacy Policy, or wish to exercise any of the rights described in Section 11, please contact us at:

[Company privacy contact email to be added, e.g. privacy@coffee-on.me] [Company registered address to be added]

[If the Company is required to appoint a Data Protection Officer, or a UK/EU representative under Article 27, their contact details will be added here once confirmed.]


This Privacy Policy should be read together with coffee-on.me's Cookie Policy and Terms of Service (where published).