Privacy Policy
Last updated: 19 August 2026
1. Introduction
This policy explains what personal data Tarantulah collects, why, on what legal basis, who it is shared with, and the rights you have over it.
Tarantulah is a permission broker for professional profiles. The design principle is that we hold as little about you as possible: our searchable pool contains no directly identifying information, and no company sees your identity or contact details unless you individually approve a specific request.
2. Who is responsible for your data
Data controller: Tarantulah. Contact: contact@tarantulah.com.
Two distinct relationships matter here:
We are the controller for your candidate profile, your pool entry, your consent records, and your account. We decide how that data is stored, matched, and protected.
A company becomes an independent controller of the data you release to it at the moment you approve a reveal request. From that point, that company's own privacy policy governs what it does with the information, and you should direct requests about its use of your data to that company. We record what was released, to whom, and when, and can tell you.
We are not a joint controller with recruiting companies for their own hiring decisions, and we do not participate in them.
3. Data we collect
3.1 If you are a candidate
In the searchable pool (no directly identifying data):
- a salted, one-way hash of your email address (we cannot reverse it to recover the address)
- skill, role, location and language tags
- a compensation band and currency
- years of experience
- your availability status and the date you were last active
In your private vault (identifying data, access-gated):
- name and email address
- headline, LinkedIn URL if you provide one
- CV text you paste, and the structured profile derived from it
- education and certifications
- compensation expectations
Records of activity: consent events, reveal requests and your decisions on them, company memberships, role match alerts, verification records, referral codes, and notification preferences.
3.2 If you are a recruiter or company user
Your name, work email address, the company derived from your email domain, sign in tokens, session records, and any ATS connection credentials you provide. Credentials are encrypted at rest and never displayed back to you.
3.3 If you receive marketing from us
Your name, work email address and company, obtained from publicly available professional sources or provided directly. If you click a link in our outreach we record the click, the time, your browser user agent and the referring page. We do this to understand whether our messages are relevant, and you can ask us to stop and to delete these records at any time.
3.4 Everyone
Your IP address, used to enforce rate limits that protect the service from abuse. It is stored only for the duration of the rate limit window. We use strictly necessary cookies for sign in sessions only. We do not use advertising or analytics cookies and we do not track you across other websites.
4. Why we process it, and on what basis
| What | Why | Legal basis |
|---|---|---|
| Creating your profile and pool entry | To let you be matched to roles | Consent (Art. 6(1)(a)) |
| Matching you to roles and ranking candidates | To surface relevant opportunities to recruiters | Consent |
| CV parsing | To save you filling in a form manually | Consent |
| Releasing your profile to a company | Because you individually approved that request | Consent |
| Match alerts and reveal notifications | To tell you about opportunities and requests | Consent, soft opt-in for email (ePrivacy Art. 13(2)) |
| Consent ledger | To prove what was consented to and when | Legal obligation (Art. 7(1)) and legitimate interests |
| Recruiter accounts and sessions | To operate the service for our customers | Contract (Art. 6(1)(b)) |
| Payment processing | To take payment for a paid plan | Contract |
| Rate limiting and security logging | To protect the service from abuse | Legitimate interests (Art. 6(1)(f)) |
| Business to business marketing email | To tell relevant professionals the product exists | Legitimate interests, with an unconditional right to object |
Where we rely on consent you may withdraw it at any time. Withdrawal does not affect processing that already took place, and you can withdraw it for one company without withdrawing it for others.
Where we rely on legitimate interests you have the right to object, and for direct marketing we will always stop on request without asking why.
6. Automated processing and artificial intelligence
We use AI in three narrow ways, and always as decision support with a human making the decision:
CV parsing turns CV text you paste into structured skills and experience. You review and edit every field before anything is saved. Extraction can miss or mislabel things, which is why nothing is stored without your review.
Matching scores how well a role fits your profile based on overlapping and related skills, and produces a score with stated reasons.
Ranking orders candidates for a recruiter across weighted criteria they set themselves, showing how each criterion contributed.
We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you within the meaning of Art. 22. A score only makes you visible to a recruiter. It triggers no contact, no rejection, and no hiring decision. The only route to contact is a request a human recruiter makes and that you personally approve.
You have the right to obtain human review of, and to contest, any AI output that affects you. Contact us and we will explain the reasoning and correct it.
In line with the EU AI Act we maintain an internal record of each AI component, its limitations and its human oversight, and we monitor aggregate scoring distributions to detect anomalies. This monitoring is an internal control and not a certified audit.
7. Who we share data with
We do not sell your data. We do not share it for advertising. Beyond the companies you personally approve, data reaches only the service providers below.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting | United States, with EU edge regions |
| Neon | Database hosting | AWS US East 1 (N. Virginia) |
| Resend | Transactional and notification email | United States |
| OpenRouter | AI CV parsing (CV text is sent) | United States |
| Paystack | Payment processing for paid plans | Nigeria and South Africa |
Some of these are outside the European Economic Area. Where that is the case we rely on Standard Contractual Clauses and, where required, supplementary measures. You can request a copy of the relevant safeguards by emailing us.
If you would prefer your CV not to be processed by an external AI provider, you can enter your skills and experience manually instead, and nothing is sent outside our own infrastructure.
8. How long we keep it
| Data | Retention |
|---|---|
| Candidate profile, vault and pool entry | Until you delete it |
| Reveal grants | Until they expire, then kept as a historical record until you delete your profile |
| Consent ledger | Until you delete your profile |
| Sign in tokens | Until used or expired, whichever is sooner |
| Sessions | Until expiry or sign out |
| Rate limit records | Minutes to hours |
| Outreach click records | 24 months, or until you ask us to delete them |
| Payment records | As long as tax and accounting law requires |
When you delete your profile, your vault, pool entry, memberships, alerts, requests, sessions and ledger are removed. This is immediate and irreversible.
9. Your rights
Under the GDPR and equivalent laws you have the right to:
- be informed about how your data is used, which is what this notice is for
- access a copy of the data we hold about you
- rectify anything inaccurate, directly in your wallet
- erase everything, in one action, from your wallet
- restrict processing while a dispute is resolved
- portability, receiving your data in a structured machine-readable format, available as a one click export
- object to processing based on legitimate interests, including an absolute right to object to direct marketing
- not be subject to solely automated decisions with significant effects, as described in §6
- withdraw consent at any time, per company or entirely
- complain to a data protection supervisory authority. You may complain to the authority in the country where you live or work, or where you believe the issue occurred
Most of these are self service in your wallet. For anything else, email contact@tarantulah.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.
Exercising these rights is free. We will not degrade your service for doing so.
10. Security
Identity in the searchable pool is protected by a salted one way hash. Third party credentials are encrypted using AES-256-GCM and are never returned to a browser or written to logs. Sign in is passwordless, session tokens are stored only as hashes, and session cookies are httpOnly. Access to identifying data is gated on an active, scoped, unexpired approval, checked on every read.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and tell you directly where the risk is high.
11. Children
Tarantulah is for professional use and not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
12. Changes
We will update this notice when our processing changes, and revise the date at the top. If a change materially affects your rights we will tell you by email before it takes effect, and where the change requires fresh consent we will ask for it rather than assume it.
13. Contact
Tarantulah — Email: contact@tarantulah.com