Access follows the relationship
A coach cannot browse every client. Server checks tie protected data to the specific coach-client connection.
Client data safety, in plain English
HiringCoachAI uses clear access boundaries, client controls, protected infrastructure, and honest retention rules. No jargon, no claim of zero risk, and no hiding important limits.
The 30-second answer
A coach cannot browse every client. Server checks tie protected data to the specific coach-client connection.
After acceptance, clients can change any of the six categories, including core workspace access.
Coach-private notes use a different access boundary from the shared log and are excluded from the client's export.
Signed-in people can export a broad account archive. Coaches can export notes before choosing immediate, scheduled, or indefinite retention.
Who can see what
HiringCoachAI checks both identity and the coach-client relationship before protected data is returned. If a category is off, coach access to that category is rejected.
Owns their account and can manage supported career-content categories.
Names the client, the connected coach, the status, and the allowed sharing scope.
Sees the shared workspace and only the career categories the relationship allows.
Existing and default relationships begin with supported categories shared. In the scoped acceptance flow, the core coaching workspace starts on. After acceptance, the client can change any of the six categories, including workspace access.
Private notes and context
Private notes and the client context card are checked against the signed-in coach and the relationship on every read and write.
Private notes and context sit in a separate boundary from the shared log. The client's product access does not reach this data.
A private note is never emailed, never sent in a notification, and never included in the client's account export. The one exception is the coach's own retention export, described below.
People, care flags, key dates, and values sit behind the same access checks as private notes and are excluded from the client's export. A saved value can appear inside a check-in reminder the coach sends to themselves; it is never sent to the client.
A coach can keep full narrative notes, or switch to a minimal mode that stores only structured items and hides the narrative composer.
Ending an engagement lets the coach export notes first, then choose immediate deletion, a scheduled deletion window, or indefinite retention.
How the system protects data
HTTPS protects data moving between the browser and HiringCoachAI.
Google Cloud provides platform encryption at rest. Selected restricted fields receive additional application-side encryption.
Firestore denies anything not explicitly allowed, while most coach data is handled through authenticated server APIs.
The signed-in person, relationship role, relationship status, and content category are checked before access.
Error monitoring disables default personal-data collection and strips common secrets such as cookies and authorization headers.
The Trust Center publishes documented controls, policies, providers, limitations, and reporting paths.
The data lifecycle
A client accepts the relationship and sees the sharing choices available to that flow.
Coach and client use shared records, while private coach context stays in its separate boundary.
Account owners can request an authenticated archive. Coaches can export relationship notes before close-out.
End the relationship, revoke ordinary shares, choose note retention, or delete the account. Each is a distinct action.
Account deletion removes data from active product systems, but limited billing, audit, contract, legal, and backup-window records may remain under the published retention policy.
When another service is involved
Supported AI features send the context needed for that call. Session AI can include private coach notes; a transcript is included only after the coach confirms client consent. Standard provider retention can still apply.
See providers and triggersStripe captures card numbers and coach bank, identity, and tax-input details. HiringCoachAI stores identifiers, amounts, fees, payout status, refunds, disputes, and records needed to operate and document the workflow.
Open payments helpHiringCoachAI creates one marked folder. A dedicated service account is shared only on that folder, including files and folders placed directly beneath it. It does not receive access to the rest of the Drive.
See service providersWhat we will not claim
Questions coaches hear
The client and the coach connected to that specific relationship can access the shared workspace within their roles and permissions. Authorized HiringCoachAI personnel or providers may access limited data when needed for support, security, fraud, legal, or policy work.
Existing and default coach relationships begin with the supported content categories shared. During scoped acceptance, the core workspace starts on. After acceptance, the client can change any of the six categories, including workspace access.
No. Coach-private notes and private context are separated from shared records and are intentionally excluded from the client's account export. The coach can use the relationship close-out export before choosing a retention action.
Yes. When a coach starts Session AI, the request can include session content and private coach notes so the model can draft the requested output. A transcript is included only when the coach confirms client consent. This does not make the notes visible to the client.
Yes. HTTPS protects data while it moves between the browser and HiringCoachAI. Google Cloud encrypts stored data, and selected sensitive fields receive another layer of encryption before storage. HiringCoachAI does not describe the service as end-to-end encrypted.
HiringCoachAI uses email sign-in links or selected sign-in providers. A second security check through an authenticator app is available when the Account Security screen shows that it is enabled.
HiringCoachAI is based in the United States and stores data in the US by default. Connected providers may process data under their own documented locations and transfer safeguards.
A signed-in user can download a broad snapshot of their account data. Passwords and similar secrets are removed, and the user may need to sign in again or complete a second security check. Some restricted legal or signed-out transaction records require an identity-verified request to [email protected].
Yes. Self-service deletion requires recent reauthentication and typed confirmation. It removes the account from active product systems, while limited billing, audit, contract, legal, and backup-window records may remain under the published retention policy.
HiringCoachAI follows a documented process to investigate, contain affected access or services where possible, address the cause, restore service, and monitor for recurrence. Notifications are made when required by law or contract. Major service updates can appear on the status page, and a public-safe summary may be added to the Trust Center when appropriate.
No. HiringCoachAI does not currently claim its own SOC 2 attestation or a recent independent penetration test. Some infrastructure providers have their own attestations. Those vendor controls do not make HiringCoachAI itself SOC 2 certified.
Email [email protected] for a vulnerability or security concern. Email [email protected] for a privacy or data-rights request. Do not include sensitive client content in the first message unless the support team asks for a secure follow-up.
A client asks a question you cannot answer?
Security concerns go to [email protected]. Privacy and data-rights questions go to [email protected].