DRAFT — pending legal review. This document is a first-pass working draft prepared for internal review only. It has not been reviewed or approved by a qualified lawyer and must not be published, linked from the live site, or relied upon as final until it has been. Bracketed placeholders mark facts (legal entity name, registered address, contact details) that could not be found in the codebase and must be supplied before publication. A separate "Notes for Legal & Engineering Review" section at the end of this document flags open questions that should be resolved, or explicitly accepted, before this policy goes live — it is not part of the published policy and should be removed before publication.
Privacy Policy
Last updated: 9 September 2026
This Privacy Policy explains how coffee-on.me ("coffee-on.me," "we," "us," or "the Company") collects, uses, shares, and protects personal data in connection with our platform for founder-led hiring (the "Service").
The Company is the operator of coffee-on.me. [The Company's registered legal name, company number, and registered address will be inserted here once confirmed.]
This policy is written for everyone whose personal data the Service processes — not only the founders and recruiters who sign up for an account, but also the candidates and clients they work with, and anyone who connects with a recruiter through a shared conversation link. Section 1 explains which of these you are likely to be, and Section 11 explains, concretely, how to exercise your rights over your own data.
1. Who this policy covers, and some terms we use
coffee-on.me is used in a few different ways, and we use a few product-specific terms throughout this policy:
- Workspace — the account a founder or recruiter (or their team) sets up to use coffee-on.me. A workspace has its own settings, such as a default timezone and country.
- Recruiter or workspace member — a person who signs in to a workspace to use the Service directly (typically a founder or a member of their hiring team).
- Candidate — a person a recruiter is recruiting for a role, whose relationship with that recruiter is tracked inside a workspace.
- Client — a company or hiring contact a recruiter works with, whose relationship is likewise tracked inside a workspace.
- Window — a private, shareable conversation link a recruiter can send to a candidate or client, so that person can connect and chat directly without first having a full account.
- Managed agent — the AI assistant that powers conversations inside the Service, built on Claude, a large language model provided by Anthropic. Different agents are configured for different situations (for example, one for recruiters, one for candidates responding via a Window).
- You — depending on context, this may mean a recruiter/workspace member, a candidate, a client, or a person who has connected via a Window. Where a section applies only to one of these, we say so.
If you are a candidate or client, your relationship with coffee-on.me generally arises because a recruiter who uses our Service is managing that relationship — either because you gave your details directly to that recruiter, or because you connected through a Window they shared with you. Section 2 explains how responsibility for your data is split between the recruiter and coffee-on.me.
2. Our role: who is responsible for your data
Where you are a recruiter or workspace member, coffee-on.me is the controller of your account data (Section 3.1) — we decide why and how it is processed, subject to this policy.
Where you are a candidate or client, your data is generally submitted to the Service by, or at the direction of, the recruiter you are working with. In that relationship, the recruiter's workspace is typically the controller of your data (they decide to recruit you, to record your details, to contact you), and coffee-on.me processes it as a processor on the recruiter's behalf, under the terms of our agreement with them. That said, coffee-on.me also builds and operates the systems that determine how your data can be used (for example, the consent gates described in Section 5, and the export/erasure tools described in Section 11), and provides those rights to you directly regardless of what the recruiter does. If you have a request about your data, you may raise it with either the recruiter or with us directly, using Section 11.
[Note for legal review: the controller/processor characterization in this section is a structural assumption typical of B2B recruiting software, not a conclusion drawn from the codebase research underlying this draft. It should be confirmed, and the wording adjusted if necessary, before publication — see the closing notes section.]
3. Information we collect
3.1 Recruiters and workspace members
When you create or join a workspace, we collect:
- Your display name, email address, and — optionally — a phone number (validated in international E.164 format) and the time it was verified.
- Your notification preferences, call-routing settings, and any personal override of your workspace's quiet hours.
- Whether you have opted to make the candidates you work with discoverable to other recruiter workspaces for matching purposes (see Section 5.4), and when you gave or withdrew that permission.
- If you add one, a profile photo. Unlike most files in the Service, your profile photo is stored in a location that is publicly accessible rather than access-controlled, because it has no other party that needs to be individually granted access to it, and because it may be composited into a preview image shown to someone you invite to a conversation via a Window before they connect.
- Your underlying sign-in credentials (e.g., email/password or equivalent) are held by our authentication provider, Supabase, as part of the same infrastructure described in Section 7.
- At the workspace level: the workspace's name, its default timezone (UK time by default), and its default country and phone region (Great Britain by default) — these are workspace settings, but they shape default behaviour like quiet hours that can affect when candidates and clients are contacted.
3.2 Candidates and clients
Recruiters use coffee-on.me to record and manage their relationships with the people and companies they work with. For a candidate, this can include: display name, email address, phone number, LinkedIn URL, a running "profile snapshot" summarising what the recruiter and our systems have learned about them, and where they stand in the recruiter's follow-up process. For a client (a company or hiring contact), this can include: company name, contact name, email address, phone number, and stated preferences.
This information may be entered directly by the recruiter, or built up automatically over time from documents you or the recruiter upload, from calls, and from chat conversations, as described below.
3.3 Documents
If you are a candidate, a recruiter may upload your CV or a snapshot of your LinkedIn profile; for a role, a recruiter may upload a job description. We accept PDF, Word (DOCX), and plain-text files, up to 25MB.
For every document uploaded, we generate a full-text extraction of its contents and use it to identify structured details relevant to the document type — for a CV, things like headline, current company and title, location, skills, work experience, and education; for a job description, things like title, company, location, compensation, and requirements. This extraction step sends the document's text to Anthropic (see Section 6). The structured facts it produces, together with facts learned from call transcripts, chat messages, or manual entry by a recruiter, accumulate over time to build a fuller picture of a candidate.
3.4 Conversations with our AI assistant
coffee-on.me's chat interface is used by recruiters, and by the candidates and clients they invite to converse with our AI assistant. We store the full text content of every message sent in a conversation, regardless of who is participating in it. These conversations are handled by a managed agent, built on Anthropic's Claude models — see Section 6 for what that means for where your conversation data goes.
3.5 Phone calls
coffee-on.me includes a feature that lets a recruiter bridge a live phone call with a candidate or client from inside the Service. As of the date of this policy, this feature is disabled by default and must be explicitly turned on for a given deployment of the Service.
Where it is enabled: calls are transcribed in real time, with the transcript broken into segments that record who spoke, what was said, and when. The call is also recorded as an audio file. We keep this audio for a limited period so the call can be reviewed shortly afterwards (see Section 9 for how long); with a separate, optional consent from the person we're calling, a copy of the recording may instead be retained for longer as part of a training data set (see Section 5.3 and Section 9). Both the recruiter's standing consent and a fresh consent from the person being called are required before a call can be connected at all — see Section 5.3.
3.6 People who connect through a shared conversation link (a "Window")
A recruiter can send you a private link to start a conversation without you first having an account. We do not create any record identifying you — no name, no readable email address or phone number — until you actually verify that address or number, by entering a one-time code we send to it. Before that point, if you've provided a destination for that code, it is held only in an encrypted form that isn't readable as your personal data; nothing about you is written to a person record yet.
Once you verify, we create a record for you containing: your display name (if you gave one), your locale and timezone, and your communication and notification preferences. We also keep a value derived from your verified email, phone number, or LinkedIn URL (rather than the raw value alone) so that we can recognise you if you connect again through another Window in future, together with the plain, normalised form of that contact detail and its verification status.
3.7 Information from public web pages
If you are a recruiter, the chat assistant you use can, at your direction, fetch and read the contents of a public web page — for example, if you paste a candidate's public LinkedIn profile URL into a conversation so the assistant can look at it. When this happens, only the URL you provided and the resulting public page content are sent to the rendering services described in Section 7; none of the other personal data we hold about you or your candidates is sent along with it.
4. How we use personal data, and our legal basis for doing so
| We use personal data to… | Which mainly involves | Our legal basis (UK GDPR) |
|---|---|---|
| Provide the Service — accounts, workspaces, chat, document storage, calls | Recruiter account data; candidate/client relationship data | Performance of our contract with the recruiter/workspace (Art. 6(1)(b)); legitimate interests in operating the Service for candidate/client data processed at the recruiter's direction (Art. 6(1)(f)) |
| Power the AI assistant, extract structured facts from documents and calls, and help match candidates to roles | Chat content; document text; call transcripts | Necessary to perform the recruiting service the recruiter has engaged us to provide (Art. 6(1)(b)/(f)); see Section 6 for the specific AI processing involved |
| Re-contact a candidate or client about future opportunities after the original engagement ends | Contact details; follow-up status | Consent (the follow_up consent described in Section 5.3) |
| Share a candidate's profile with a specific client for a specific role | Candidate profile data | Consent (the profile_share consent described in Section 5.3) |
| Place and record a phone call | Phone numbers; call audio; transcript | Consent from both the recruiter and the person being called (the call_transcription consent described in Section 5.3) |
| Keep a call recording as part of a training data set, beyond its normal short retention window | Call audio; transcript | Separate, optional consent (the audio_training consent described in Section 5.3) |
| Consider a candidate for opportunities sourced by a different workspace than the one that originally captured their data | Candidate profile data | Consent-based eligibility gate described in Section 5.4 |
| Send notification emails and text messages (e.g., pre-alerts, callback requests, conversation summaries) | Contact details; a short message summary; a link to the relevant conversation | Legitimate interests in keeping participants informed (Art. 6(1)(f)); performance of contract where the recipient is a recruiter |
| Keep the Service secure, prevent abuse, and enforce our terms | Account and usage data | Legitimate interests (Art. 6(1)(f)) |
| Comply with our legal obligations | As required by law | Legal obligation (Art. 6(1)(c)) |
5. How consent works in this product
We treat consent as something to be recorded and checked in the system, not just a box ticked once and forgotten. This section explains, specifically, how that works.
5.1 We don't write anything about you until you're verified
As described in Section 3.6, if you connect with a recruiter through a shared Window, no identifying record is created until you complete a one-time-code verification. This was a deliberate fix to an earlier version of this flow, which could write an unverified contact's plaintext email or phone number, and a placeholder relationship, before any code had even been sent. Under the current design, the first time anything identifying is written about you is the moment your code is confirmed.
5.2 We keep a record of consent decisions
We maintain a dedicated log of consent decisions, separate from the underlying profile data it relates to. Each entry records who the decision relates to (a candidate, client, or recruiter), what it was for, whether it was a grant or a withdrawal, which version of our consent language was in effect at the time, supporting evidence of how the decision was captured, and when it happened.
5.3 The specific things we ask consent for
We currently track four distinct kinds of consent:
- Future contact (
follow_up). A candidate's or client's agreement to be contacted again about future opportunities once their current engagement has ended. We check for this consent before any automated follow-up is triggered, and before a candidate is recontacted through our matching process. - Sharing a profile with a client (
profile_share). A candidate's agreement to have their profile shared with a specific client, for a specific role. This isn't a simple checkbox — it is captured through a confirmation-token flow, and we check for it before a client-facing pitch about that candidate is put together. - Call recording and transcription (
call_transcription). Required from both the recruiter and the person being called before any call is connected. The recruiter's standing consent is checked first; the other person's consent is captured at the moment the call is requested. A call session cannot exist in our systems without a linked record of this consent. - Retention of a call recording for training (
audio_training). A separate, optional, opt-in consent — captured at the same time as call-transcription consent, but tracked independently — for us to keep a copy of that specific call recording beyond its normal short retention period, so it can be used as part of a training data set. We check for this consent before any such copy is made.
5.4 Sharing a candidate's profile with a different workspace
coffee-on.me can, in principle, introduce a candidate's profile to a recruiter workspace other than the one that originally captured their data — for example, if that candidate would be a good fit for a role at a company a different recruiter on our platform is hiring for. This does not happen automatically: our system checks a number of independent conditions before it is allowed, and every one of them must be satisfied, including that the candidate has given verified permission to be introduced to new opportunities, and that we hold valid, un-withdrawn consent for the channel through which they would be contacted. A candidate's underlying permission for this kind of introduction is itself a distinct, tracked setting (separate from the consent log described above) that cannot be marked as granted without recorded verification and a timestamp.
If you are a candidate, this means your profile could be surfaced to a recruiter workspace other than the one you originally gave your details to, subject to the safeguards above.
6. How we use AI in the Service, and what that means for your data
AI is central to how coffee-on.me works, so we're describing it here specifically rather than only in the sub-processor table below. Our chat assistant, document analysis, and related features are built on Claude, a large language model provided by Anthropic.
- Conversations. Every chat conversation on the platform — whether you are a recruiter, a candidate, a client, or someone connecting through a Window — is handled by one of several purpose-configured AI agents running on Anthropic's infrastructure. These run as persistent, provider-side sessions: Anthropic keeps its own copy of the full conversation transcript on its infrastructure, separately from the copy we keep in our own database. Because of this, fully removing a conversation from Anthropic's side requires us to take a further, explicit deletion step — described in Section 11 — rather than simply deleting our own copy.
- Document extraction. When a CV or job description is uploaded, its extracted text (up to roughly 80,000 characters) is sent to Anthropic in a single request to identify the structured details described in Section 3.3.
- Call transcript analysis. Where voice calling is enabled (see Section 3.5), the full call transcript and a brief description of the call are sent to Anthropic to produce a summary, an outcome, next steps, and any new profile facts about the candidate.
- Reading images. If an image is part of a conversation (for example, a photo, a scanned page, or a frame from a video), it may be sent to Anthropic's vision capability to extract text or a summary from it.
- Reading a web page you point it to. As described in Section 3.7, a recruiter's assistant can, at the recruiter's direction, fetch and read a public web page.
We do not currently use any other third-party AI provider for these purposes.
7. Who we share information with
We use a small number of specialist providers ("sub-processors") to run the Service. Each is only given the data it needs to perform its function.
| Provider | What they do for us | What of yours reaches them |
|---|---|---|
| Anthropic | Powers our AI assistant, document extraction, call-transcript analysis, and image analysis (see Section 6 for detail) | Chat message content; extracted document text; call transcripts and summaries (where voice calling is enabled); images shared in conversations; the URL and public content of any page a recruiter's assistant is asked to read |
| Supabase (database) | Hosts our application database, in the UK (London, eu-west-2) | Account, workspace, candidate/client relationship, consent, and conversation records described throughout this policy |
| Supabase (file storage) | Hosts uploaded files and media, on a separate Supabase project, in Australia (Sydney, ap-southeast-2) | CVs, job descriptions, LinkedIn snapshots, call recordings, Window-shared media, and recruiter profile photos |
| SendGrid (a Twilio company) | Sends transactional emails (for example, pre-alerts to a recruiter, callback requests, or a conversation summary) | Recipient email address, recipient/recruiter display name, a short text summary of the relevant conversation or role, and a link to the private conversation thread |
| Telnyx | Sends SMS notifications, and — where voice calling is enabled — connects and records phone calls | SMS: recipient phone number, name, role title, a short text summary, and a thread link. Voice (where enabled): the phone numbers being bridged, live call transcription, and the recorded call audio |
| Deepgram (via Telnyx) | Performs the speech-to-text transcription behind Telnyx's call-transcription feature, where voice calling is enabled | Call audio, but only as part of Telnyx's own service — we do not hold a direct account or relationship with Deepgram |
| Vercel | Hosts the application and runs its scheduled background jobs (for example, the daily job that deletes expired call recordings) | All data passing through the application at runtime; all of our operational secrets, held as encrypted environment variables |
| Google Cloud (Cloud Run) | Renders a single web page when a recruiter's assistant needs to read one and a plain server-side request is blocked by bot detection, and — for pages protected by an active CAPTCHA-style challenge — solves that challenge to render the same page | The URL being read, and the resulting public page content only — not any of the personal data we otherwise hold |
We do not share personal data with any advertising, marketing, or data-broker company, and we do not sell personal data.
[Note for legal review — do not remove without reading: engineering has flagged a live, encrypted "ElevenLabs" credential present in our production environment with no corresponding reference anywhere in the application's code. It is not included in the table above because it cannot currently be confirmed as either an active integration or an unused, orphaned credential. This must be resolved with engineering — and the sub-processor list updated if needed — before this policy is published. See the closing notes section.]
8. International data transfers
Some of your personal data is transferred outside the UK/EEA as a normal part of running the Service. In particular:
- Our application database is hosted in the UK, but the separate storage system that holds uploaded files, call recordings, and shared media is hosted in Australia — meaning a candidate's file could, by design, be stored on a different continent from the record that describes them.
- Anthropic, SendGrid, and Telnyx are all providers whose processing may take place outside the UK/EEA.
Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards recognised under UK GDPR and (where applicable) the EU GDPR, such as the UK International Data Transfer Addendum or Standard Contractual Clauses incorporated into our agreements with these providers, or transfers to a jurisdiction covered by an applicable adequacy decision. [The specific transfer mechanism relied on for each provider will be confirmed and listed here once each vendor's current data processing agreement has been reviewed — see the closing notes section.]
9. How long we keep personal data
| Data | How long we keep it |
|---|---|
| Call recordings kept for short-term review | A limited number of days after the call (7 days by default, and never more than 30), after which the recording is automatically and permanently deleted, along with its storage file |
| Call recordings kept as part of a training data set, with the separate consent described in Section 5.3 | No automatic expiry — kept until you exercise your erasure rights (Section 11) or the relevant consent is otherwise acted on |
| CVs, job descriptions, and LinkedIn snapshots | No automatic expiry — retained until an erasure request is made (Section 11), at which point the file and its associated extracted text are deleted |
| Chat conversation content | No automatic expiry. If you exercise your erasure rights, the content of your messages is overwritten with a placeholder, but the surrounding record (that a message existed, when, and from whom) is kept to preserve the integrity of a conversation that may involve other participants — see Section 11 for detail |
| Signed links to shared media (photos, files shown via a Window) | 5 minutes per link — a fresh link is generated each time media is viewed, specifically so that access already revoked can't be regained by reusing an old link |
| Webhook event logs from our telephony provider | No automatic expiry currently in place |
| Short-lived records such as sign-in sessions, invitations, and verification codes | Deleted automatically once they expire (typically within a day for a verification code, unless still needed for an active conversation) |
[Note for legal review: the 7-day/30-day call-recording figure above reflects the software's configured default and hard-coded maximum. The exact value configured in our live production environment should be confirmed against this policy before publication — see the closing notes section.]
10. How we protect personal data
We use a combination of technical and organisational measures designed to protect personal data, including:
- Workspace-scoped access controls, so that a recruiter's access to candidate, client, and conversation data is limited to their own workspace.
- Short-lived access links for shared media, rather than permanent public URLs, so a disclosure can be effectively revoked (Section 9).
- Deferred identity creation for Window-based conversations, so an unverified contact detail is never stored as readable personal data before it has been confirmed (Section 5.1).
- Storing files and structured records in separately access-controlled systems, and routing all file access through a single, dedicated code path designed to prevent files from being addressed against the wrong storage location.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security. [A general statement about incident notification and any relevant security certifications will be added here once confirmed with the Company's security posture at the time of publication.]
11. Your rights, and how to actually exercise them
If UK or EU data protection law applies to you, you generally have the right to: access a copy of your personal data; rectify inaccurate data; erase your data; restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time where our processing relies on it (this doesn't affect the lawfulness of anything already done on the strength of that consent). You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
Unlike a policy that only says "contact us," coffee-on.me has built dedicated export and erasure functionality into the product itself, described below.
11.1 If you are a candidate or client with a relationship in a recruiter's workspace
You (or the recruiter managing your relationship, on your behalf) can request:
- An export of everything we hold about that relationship — your relationship record, any role or introduction history, profile facts learned about you, your consent history, your full conversation transcripts, and a summary of any call sessions.
- Erasure, confirmed by an explicit "ERASE MY DATA" instruction (this exact phrase is required, so an erasure cannot happen by accident). When you do this, we will, in order: delete the audio, extracted text, and associated files for any calls tied to the relationship (removing a training-corpus copy too, even though you separately consented to it — that consent is not consent to survive a request to be erased); delete your CVs, LinkedIn snapshots, and any job description documents tied to the relationship; delete the individual facts we had learned about you and cancel any pending automated follow-up; overwrite the identifying fields on your relationship record (name, email, phone, LinkedIn URL, profile summary) and mark it as erased. The content of your chat messages is overwritten with a placeholder rather than the message rows being deleted outright — this is so that a conversation involving other participants keeps its structure and timing intact, even though your words in it no longer do. We also end any active AI conversation session and take a further step to delete the corresponding session held on our AI provider's own infrastructure (see Section 6), and we revoke any outstanding invitations or verification sessions tied to you.
11.2 If you connected through a shared conversation link (a "Window") and have your own identity across workspaces
You can request:
- An export of your person record, your verified contact details, your preferences, your conversation history, and the recruiter relationships associated with your identity.
- Erasure, using the same explicit confirmation phrase described above. This deletes records across the matching and introduction systems tied to you, removes or blanks anything you authored, cleans up any files (photos, CVs) you shared through a Window — including anything that was actually shown to someone else, or that failed our automatic classification but still exists in storage — redacts your chat message content in the same way described in 11.1, and permanently deletes your identity, preference, and verification records. Your session is also signed out as part of this process.
[Note for legal review — material gap to resolve before publication: the AI-provider session deletion step described in 11.1 is implemented for the candidate/client relationship erasure path, but does not currently appear to be implemented for the Window-identity erasure path described in 11.2. This asymmetry should be closed in the product, or reflected accurately in this section, before this policy is published — see the closing notes section.]
11.3 How to make a request
[The specific in-product location or support channel for making an export or erasure request — e.g., a settings page, a link in a conversation, or a request to the recruiter — will be confirmed and described here once finalised. Recruiters and workspace members wishing to exercise rights over their own account data, rather than a candidate or client relationship, should contact us using the details in Section 15.]
We will respond to a valid request within the time required by law (in general, one month, extendable in limited circumstances). We may need to verify your identity before actioning a request.
12. Cookies and tracking on our website
As of the date of this policy, our public marketing website and the public-facing pages of a shared conversation link (a "Window") set no cookies and load no analytics, advertising, or tracking scripts of any kind. Cookies are used only once you are signed in to the application, or once you have verified your identity to open a private conversation — and even then, only strictly necessary ones needed to keep that session working securely. Full detail is set out in our separate Cookie Policy, which should be read alongside this one.
13. Children's privacy
The Service is intended for use by working professionals — founders, recruiters, and the candidates and clients they engage with in a professional hiring context — and is not directed at, or intended for use by, anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have done so, we will take steps to delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time, for example as the Service changes or as required by law. Any update will be reflected by a new "Last updated" date at the top of this page. Where a change is material, we will provide a more prominent notice.
15. Contact us
If you have questions about this Privacy Policy, or wish to exercise any of the rights described in Section 11, please contact us at:
[Company privacy contact email to be added, e.g. privacy@coffee-on.me] [Company registered address to be added]
[If the Company is required to appoint a Data Protection Officer, or a UK/EU representative under Article 27, their contact details will be added here once confirmed.]
This Privacy Policy should be read together with coffee-on.me's Cookie Policy and Terms of Service (where published).