HiringCoach.ai

Privacy policy

Last reviewed 2026-08-10

This policy describes how HiringCoachAI collects, uses, shares, protects, and retains Personal Data when you use the service or apply to or participate in an internship or employment opportunity with us.


1. Who we are

Elite Ad Operations, LLC d/b/a JumpYield ("HiringCoachAI", "we", "us") operates the HiringCoachAI platform. Our contact for privacy questions is [email protected].

2. What this policy covers

This policy covers Personal Data we collect about you when you use HiringCoachAI through our website, and Personal Data we collect about you when you apply to or participate in an internship or employment opportunity with us.

3. Personal Data we collect

CategoryExamplesPurposeLawful basis (GDPR)
AccountEmail, name, profile photo, authentication identifiersProvide the service; authenticate youContract (Art. 6(1)(b))
ContentResumes, cover letters, job-application notes, contacts you add, questions you ask, public and private coach profiles, directory listings, applications, bookings, service information, reviews, testimonials, files, attachments, coaching materials, links, images, recordings, and content you create or adopt with AI toolsDeliver the service; make content available to the people or public audience you select; trust, safety, and policy enforcementContract; legitimate interest (service integrity and abuse prevention)
Voice & audioRecordings of your spoken responses (interview coaching). Audio is sent to our transcription provider for transient processing and is not retained as audio by HiringCoachAI after the transcript is produced; transcripts and any generated audio outputs you save (e.g., text-to-speech playback) are retained per the data retention policy until account deletion. No biometric voiceprint is created or storedTranscription and feedback: processed transientlyContract
PaymentStripe customer and transaction references, subscription status, amount/currency, receipt email, and refund/dispute status. For a purchase made while signed out, we also retain the normalized purchaser email, the exact Terms/Guidelines/Privacy release and acknowledgment labels accepted, the provider-object binding, timestamp, stable operation ID, hashed IP and browser user agent, and tamper-evident evidence seal. No payment-card primary account number (PAN), card verification value (CVV), or card-track data reaches us: Stripe handles card captureBilling, receipts, fulfillment, refund/dispute handling, and proof of purchase assentContract; legal obligation where applicable; legitimate interest in transaction integrity and legal claims
Calendar permissions and scheduling metadataFor Google Calendar: coaching-account email, provider account IDs, calendar IDs, and event-sync metadata. For Microsoft Outlook Calendar: delegated Calendars.ReadWrite permission and standard OAuth connection state; calendar IDs, names, and editability used to present calendar choices; selected calendar IDs; and limited event-sync metadata. For either provider: booking links and consent/connection stateCalendar booking, availability checks, event synchronization for booked coaching sessions, and auditability of scheduling consent stateContract; legitimate interest in service delivery and fraud prevention
Coach-selected automation metadataWhen a coach enables a Zapier or custom webhook connection: opaque client, relationship, purchase, engagement, appointment, and series IDs; offer/version and amount/currency; appointment start/end timestamps and status; connection URL; delivery state and bounded error evidence. Payloads exclude names, email addresses, notes, intake responses, session content, and payment credentialsDeliver and troubleshoot the workflow automation the coach configuredContract; legitimate interest in reliable user-requested integrations and service integrity
Coaching contracts and e-signature evidenceAgreement terms and pricing, typed or drawn signature image, verified signer identity, consent disclosure, timestamps, IP address, browser user agent, document/event hashes, and completion certificate. We do not collect biometric handwriting dynamicsCreate, sign, verify, and provide both parties' coaching agreement recordContract; legitimate interest in record integrity and legal claims
Public-booking verification and assentDuring email verification, the claimed email, name, note, timezone, booking-link and hold references, and a sealed but not-yet-attributed legal acknowledgment. Only after the visitor proves control of the claimed email do we create durable evidence containing the verified email, exact Terms/Guidelines/Privacy release and acknowledgment labels, booking binding, timestamps, hashed IP and browser user agent, and a tamper-evident platform sealComplete the requested booking, prevent abuse, attribute assent to a verified email, and preserve reliable booking-formation evidenceContract; legitimate interest in service integrity and legal claims
Device & usageIP address, browser type, pages visited, clicks, session IDsSecurity, product analytics, fraud detectionLegitimate interest (security, essential product analytics); consent (browser analytics and marketing tracking)
Session recordingDOM events, clicks, scrolls, mouse movement, recorded during sessions where you have granted analytics consent; password and payment fields are masked per vendor defaultProduct debugging and UX improvementConsent (analytics)
Institution or sponsor programPilot membership, cohort or subgroup labels, activation status, and engagement or usage metrics for participants in a sponsored programAdminister sponsored programs, report authorized engagement metrics to program administrators, and support participantsContract, legitimate interest, institution authorization where applicable
CommunicationsInbox messages, real-time chats, comments, replies, mentions, support threads, platform-generated or platform-relayed email, non-promotional coaching text-message content, U.S./Canadian mobile number and timezone while opted in, message drafts and templates, consent/revocation evidence, and related delivery metadata and previewsDeliver and route communications; honor and prove opt-in/opt-out choices; customer service; prevent fraud and abuse; investigate reports; enforce the Terms and Community GuidelinesContract, consent for text messages, legitimate interest
Applicant and internResume, work samples (links or attached files), written application materials (growth theses, why-this-role responses), email correspondence with hiring contacts, scheduling information, interview notes, accommodation requests submitted to [email protected]Evaluate candidates for internship and employment opportunities; schedule and conduct interviews; comply with EEO and California FEHA recordkeeping; respond to accommodation requestsLegitimate interest (Art. 6(1)(f), recruiting and selection); legal obligation (Art. 6(1)(c), EEO and FEHA recordkeeping); consent (Art. 6(1)(a), accommodation requests)
Marketing preferencesEmail subscriptions, cookie preferencesDeliver what you asked forConsent

Other than applicant and intern accommodation requests submitted to [email protected], HiringCoachAI is not designed to request, and we do not intentionally solicit, government-issued ID numbers, Social Security numbers, driver's license numbers, health information (PHI), biometric identifiers, children's personal information, payment-card numbers, card verification values, card-track data, credentials, secrets, or third-party personal data submitted without appropriate rights or consent. Users must not submit those categories to the service. Because the product includes free-text career content, users may inadvertently include unexpected regulated information; if that happens, we treat it under our confidential-data safeguards and data-request/deletion processes rather than as an intended data category.

4. How we use your data

  • Operate the service (account, content, billing).
  • Authenticate you (via Google, LinkedIn, or Facebook if you choose; Google and LinkedIn are the primary options for institutional and professional users, and Facebook is retained as a consumer fallback).
  • Generate AI-assisted drafts (resumes, cover letters, coaching) using approved AI providers: see "AI" below.
  • Send transactional emails (signin links, receipts, security notices).
  • Send relationship-specific, non-promotional coaching texts only after the adult client opts in; apply local quiet hours and honor STOP or in-product opt-out.
  • Deliver and route profiles, messages, chats, comments, files, reviews, booking details, and other content to the recipients or public audience selected through the feature and settings you use.
  • Send marketing emails if you opted in (withdraw anytime).
  • Keep the service secure (rate limiting, abuse detection, audit logs).
  • Assess reports, enforce the Terms and Community Guidelines, and protect users, the service, and the integrity of professional relationships and transactions.
  • Improve the product (essential server-side analytics under legitimate interest; browser analytics consent-gated).
  • Administer institution- or sponsor-supported programs and provide authorized program administrators with participation and engagement reports when you participate in such a program.
  • Comply with legal obligations.

Connected calendar services

Calendar connections are optional and are enabled only after a coach chooses a provider and completes that provider's authorization flow.

  • Google Calendar permissions: The Google Calendar integration for booking workflows is blocked until the OAuth callback confirms that Google granted all required scopes listed in our provider integration (calendar.events, calendar.freebusy, calendar.calendarlist.readonly, calendar.app.created). Without the full scope grant, tokens are not activated and no scheduling connection is enabled.
  • Microsoft Outlook Calendar permissions and calendar list: The Outlook integration uses Microsoft's delegated Calendars.ReadWrite permission. HiringCoachAI lists calendar IDs, names, and editability so the coach can select calendars for conflict checks and new booking events.
  • Microsoft Outlook Calendar conflict checks and event creation: For conflict checks, HiringCoachAI reads only event start time, end time, and availability status. When event sync is enabled and a booking needs an Outlook event, HiringCoachAI sends the event title, start and end time, optional location, and the attendee email address only when attendee invitations are enabled.
  • Credential security and local removal: OAuth access and refresh credentials are encrypted at rest. On in-app disconnect, permanent authorization revocation, or HiringCoachAI account deletion, HiringCoachAI removes locally stored credentials and Microsoft-derived calendar selection metadata. After disconnect or permanent revocation, HiringCoachAI may retain only a sanitized connection-status record and bounded error code without credentials or calendar selections.
  • Disconnect, consent revocation, and provider-side events: Disconnect the integration in HiringCoachAI calendar settings. To revoke Microsoft consent, use Microsoft account consent management for a personal account or Microsoft My Apps for a work or school account. Disconnecting, permanent revocation, or deleting your HiringCoachAI account does not delete events already created in Outlook. Those events remain until you remove them in Outlook or through HiringCoachAI while the connection is active.
  • Restricted uses: HiringCoachAI does not use or transfer data received from Google Calendar or Microsoft APIs for advertising, marketing, creditworthiness or lending decisions, or generalized AI model training.
  • Google API Limited Use: HiringCoachAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide or improve the calendar features you enable.

Referral and affiliate programs

If you take part in the referral program (see the Referral Program Terms) or the cash affiliate program (see the Affiliate Program Agreement), we process a limited record of each referral so we can credit it to the right person and detect abuse.

  • Attribution cookies: a referral link sets a first-party, httpOnly cookie named hc_ref; an affiliate link sets a first-party, httpOnly cookie named hc_aff. Each cookie lasts 90 days and contains only the referral or affiliate code, no personal information.
  • What we record when an attribution is claimed: an attribution record linking the referring or affiliate account to the referred account; sign-up context stored only as a salted, non-reversible hash, so your raw IP address and browser user agent are never stored against a referral; and, once a qualifying payment is made, payment references from Stripe, such as subscription, invoice, and payment identifiers, together with refund or dispute status.
  • What a referrer or affiliate can see: aggregate counts of referrals and their status. An affiliate's dashboard additionally shows per-conversion records limited to the date, the plan, and the amounts. A referrer or affiliate is never shown a referred user's name, email address, or other account details, and we do not sell this information.
  • Affiliate application and payouts (cash program only): to apply, an affiliate provides application information, including their website, audience, and promotion plan, and a US state of residence collected for sales-tax nexus visibility. Affiliate payouts are made through Stripe Connect. Stripe collects identity, bank, and tax information from the affiliate directly, and that information is held by Stripe under its own agreement with the affiliate, not by us.
  • Retention and legal basis: we process this data under contract, to operate the program you joined, and legitimate interest in fraud and abuse prevention; affiliate application, commission, and payout records also rest on legal obligation for tax reporting. Attribution records are retained while your account is active and for a limited additional period afterward to support fraud and abuse review. Affiliate commission and payout records are retained for the period required for tax and financial recordkeeping, consistent with the billing records described in Retention below. See the data retention policy for the full schedule.

5. AI

HiringCoachAI uses AI providers to generate draft content. Per our AI Use Disclosure at /ai-disclosure:

  • Providers we use: OpenAI, Perplexity, ElevenLabs, Deepgram, Google Cloud Text-to-Speech. The complete sub-processor inventory and routing detail is at /sub-processors.
  • Minimized provider retention and transcript exposure: we pass per-request controls where the provider supports them (for OpenAI, store: false; for Deepgram, redact=true to redact sensitive number-like entities from transcripts). We have not signed Zero Data Retention amendments with any AI provider; each provider's then-current standard API retention windows apply, and we do not have access to provider-side abuse-monitoring logs.
  • No training: we rely on each provider's then-current standard API terms. We also pass store: false on OpenAI Chat Completions and Responses API calls so generated responses are not stored as OpenAI application state for later retrieval. Our no-training posture is based on standard API terms rather than a separate enterprise no-training amendment.
  • Notice: AI processing is named in the cookie/privacy banner you saw on your first visit, described in this policy, and detailed on our AI Disclosure page (linked from the banner and the footer of every page). The disclosure page describes how we use AI in the product, the categories of data sent to AI providers, and whether calls are user-initiated or anticipatory (some flows pre-compute AI results in the background: e.g., entering job-description data triggers a Fit Analysis so it is ready when you open the job).
  • How to avoid AI processing: Generative AI runs when you use an AI-assisted feature. Automated moderation also applies when a coach uploads a profile photo or saves, reviews, or publishes a coach profile, as described below. You can avoid that profile-moderation processing by not using the coach-profile feature. Other manual product areas remain available without generative AI processing, and account deletion remains available.
  • User review and context: Resume, cover-letter, pitch, and similar drafting outputs are intended for you to review and edit before use. Other AI outputs, such as interview-practice scoring, transcription, task breakdowns, and value-proposition suggestions, are informational aids. AI outputs are never sent to third parties without your action.

6. Trust, safety, and moderation

We may process content and communications available through the service using automated tools, authorized personnel, user reports, service providers, public information, and transaction, fraud, security, or abuse signals. Review may be triggered by a publication or delivery attempt, upload, user report, support request, abuse or security signal, suspected policy violation, or legal need. We use this information to prevent harm and fraud, investigate concerns, enforce the Terms and Community Guidelines, protect the service, and comply with law.

Our current routine external-AI content moderation is limited to the coach-profile workflow. Coach profile text and link fields are sent to OpenAI for review when a coach saves or attempts to publish the profile, and profile photos are sent to OpenAI for review when uploaded. We also use non-AI rules and availability checks for profile links and URLs. Other private inbox messages, real-time chats, and comments are not routinely sent to an external AI provider for content moderation. They may be accessed or reviewed by authorized personnel or service providers when a user reports them or when reasonably needed for support, safety, fraud prevention, security, legal compliance, or enforcement.

HiringCoachAI generally cannot access a direct external email, text message, phone call, video call, in-person interaction, or other off-platform communication unless a user submits or reports it, it is routed through the service, or applicable law otherwise permits access. We do not promise to monitor or review every user, profile, communication, coaching session, transaction, or external interaction. Automated tools and human reviewers can make mistakes.

7. Sharing

We share Personal Data with:

  • Service providers and processors identified at /sub-processors when they process Personal Data on our behalf. That page describes each provider's role and contractual-safeguard status. Inclusion there does not mean every listed provider is a HiringCoachAI sub-processor or is subject to a Data Processing Agreement with HiringCoachAI.
  • User-connected calendar providers, including Google Calendar and Microsoft Outlook Calendar, when you choose to connect them. Those providers supply services to the connected account owner, and their processing is governed by the account owner's agreement and consent with the provider rather than necessarily acting as a HiringCoachAI sub-processor.
  • Other users, recipients, and the public when you direct us to send or share content, use a communication or collaboration feature, publish a profile or review, or select a public visibility setting.
  • Coach-selected automation providers when a coach creates and enables a Zapier Catch Hook or custom HTTPS webhook. HiringCoachAI sends only the limited operational fields described above to the exact destination the coach configures. The coach is responsible for selecting and authorizing that provider; its processing is governed by the coach's agreement with it. The coach can pause or delete the connection at any time.
  • Institution or sponsor program administrators when you participate in a sponsored program, for authorized program administration, engagement reporting, and participant support. By default, sponsor administrators receive usage and engagement metadata only. Where the applicable program terms explicitly authorize advisor-level coaching access, limited advisor views may include the participant content identified in those terms, such as drafts, feedback, or AI-assisted fit analysis.
  • Law enforcement, regulators, safety organizations, and other authorized recipients when required or permitted by applicable law, legal process, an emergency, or a good-faith safety, fraud, security, or rights-protection need, with notice to you where law permits.
  • Business transfers if HiringCoachAI is acquired or merged (you'll be notified and offered choices per applicable law).

We do not sell your Personal Data, and we do not share it for cross-context behavioral advertising except where you have specifically consented via the cookie banner.

8. International transfers

HiringCoachAI is based in the United States. Data is stored in the US by default. If you're in the EU, UK, or another jurisdiction with transfer restrictions, we rely on:

  • 2021 EU Standard Contractual Clauses (Decision 2021/914)
  • UK International Data Transfer Addendum
  • Adequacy decisions where available

9. Retention

  • Active account: data retained while your account is active.
  • After deletion: removal or redaction across active product systems per the data retention policy. A deleted account's name and email remain visible only to restricted administrators for up to 30 days so we can identify the recent deletion and personally respond to optional deletion feedback. At day 30 those fields become unavailable in lookup and are queued for the daily redaction job. Shared conversations, comments, files, transaction records, or other records involving another user may remain where needed to preserve that user's records, complete a transaction, prevent fraud or abuse, comply with law, or establish, exercise, or defend legal claims; the departing user's identifiers and authored content are removed or redacted as applicable. For sponsored pilot programs, direct identifiers are removed from usage records so historical program reporting can continue without identifying the deleted account. Self-service account deletion is final in the product after required checks complete. Admin recovery snapshots used only for accidental internal deletion recovery may be retained for up to 30 days when that recovery path is used. Direct email correspondence is a separate business record and is not automatically removed by product-account deletion; it is retained only while reasonably needed for support, security, legal compliance, or legal claims, remains subject to applicable privacy rights, and is not used for marketing unless separately authorized.
  • Coaching agreements: unpublished templates and versions never delivered or signed are removed with the owning coach account. A delivered or signed agreement remains available to the surviving party if only one party deletes an account, then is removed after both parties delete their accounts unless a documented legal hold applies. Separate billing, tax, fraud, and security-audit records follow the schedules below.
  • Audit record of deletion: name and email up to 30 days; remaining confirmation and operational metadata 365 days. The record contains no copy of user-created product content.
  • Operational logs: Application audit log (security and account events, no user content) 2 years; AI call audit metadata (no prompts or completions) 1 year; deleted-account recovery snapshot up to 30 days. Full per-data-class schedule at /trust/docs/data-retention.
  • Coach profile review delivery records: notification and delivery-retry records, which may include the submitted profile snapshot, highlighted findings, automated analysis, and reviewer-routing metadata, expire after 30 days. Moderation status embedded in a coach profile remains with that profile until it is updated or deleted, subject to legal holds and the retention policy.
  • Coach automation delivery records: signed event payloads and delivery-attempt records expire after 90 days via Firestore TTL or are removed earlier on coach account deletion. Connection settings and encrypted signing secrets remain only while the connection or coach account exists.
  • Coaching text messages: HiringCoachAI message records expire 30 days after scheduled delivery or are removed earlier on account deletion. A raw mobile number is held only during active opt-in and is cleared on opt-out. Limited consent and revocation evidence without a raw number or message body is retained for six years under the current conservative policy, subject to Firestore TTL and qualified legal review. Twilio may separately retain limited-access compliance data under its terms.
  • Backups: production backup settings are managed in Google Cloud. Firestore PITR (7-day window) and managed daily Firestore backups are enabled, with backup-schedule retention of 98 days. Backup/export buckets use versioning, soft delete, and a retention policy. Account-deletion takes effect in active storage promptly and propagates to backups as the backup window rotates.
  • Billing records: retained up to 7 years per tax law.
  • Supplemental agreement PDFs: an independent coach may upload an optional PDF alongside a required baseline agreement. We store the signing package, restricted PDF custody, exact hash and generation evidence, and a bound view receipt when a signer opens the PDF. We do not draft, review, interpret, or guarantee coach-uploaded terms. Unattached upload drafts are removed on expiry or account deletion. Delivered or signed packages remain available to a surviving party for the agreement retention period, normally at least seven years, and legal holds extend that period. Account exports include safe document metadata and hashes for authorized participants, never internal storage, bucket, KMS, signed-upload, scanner, IP-address, or browser details. An authorized party can retrieve the exact PDF through the agreement record or an identity-verified request.
  • Purchase assent records: authenticated and signed-out purchase clickwrap evidence is retained for the applicable contract, financial, limitations, or claims period and any legal hold. Signed-out purchase evidence is available through a verified, assisted privacy request using the purchase email; it is not included in an unrelated signed-in account export. The founder-approved retention schedule governs this evidence; any material change requires explicit founder approval and matching updates to the retention policy and data map.
  • Public-booking verification and assent: a verification link is valid for eight minutes. After successful use, the service immediately attempts to clear the short-lived claimed personal and staged-assent fields; the TTL policy remains the fallback if that best-effort cleanup write fails. Unused expired verification records become eligible for Firestore TTL cleanup; Firestore explains that TTL deletion is not instantaneous and typically occurs within 24 hours after expiry, so eight minutes is the verification window rather than a guaranteed deletion deadline. Durable booking clickwrap evidence is created only after control of the claimed email is verified and is retained unchanged for the applicable contract, limitations, or claims period and any legal hold. It is available only through an identity-verified assisted privacy request using that email. The founder-approved retention schedule governs this evidence; any material change requires explicit founder approval and matching updates to the retention policy and data map.
  • Applicant and intern records: retained for a minimum of four years from the date of the application or the date of any related personnel action, as required by California Government Code §12946 and federal EEO recordkeeping rules (29 CFR §1602). Records subject to a litigation hold are retained until the hold is lifted. Accommodation requests received at [email protected] are stored separately from hiring decision records and are not used in hiring decisions.

10. Your rights

Depending on where you live, you may have rights including:

  • Access: request a copy of your data. Built-in export at /account/export; restricted signed-out purchase and verified-booking assent evidence requires an assisted request and verification of the matching email.
  • Rectification: correct inaccurate data; edit in your account settings.
  • Erasure: delete your account and data: /account/delete.
  • Portability: receive your data in machine-readable form: same export.
  • Objection / restriction: contact [email protected].
  • Withdraw consent: for marketing and analytics cookies: manage via the cookie banner or in settings.
  • Avoid AI processing: Generative AI runs when you use an AI-assisted feature (resume optimization, cover letter generation, fit analysis, pitch studio, interview coaching, voice features, company intel, including features that pre-compute results in the background such as fit analysis from job-description data). Coach-profile uploads, saves, reviews, and publication attempts use the moderation processing described in Section 6. You can avoid that processing by not using the coach-profile feature. Other manual product areas remain available without generative AI processing.
  • Not subject to automated decisions: HiringCoachAI does not make decisions producing legal or similarly significant effects about you based solely on automated processing (GDPR Art. 22). AI-assisted outputs are drafts and informational aids; the user reviews them and makes the decision.
  • Non-discrimination (California): we will not discriminate against you for exercising your rights.
  • Complain: to your local supervisory authority (ICO for UK, Irish DPC for many EU users, your state AG in the US).

California-specific rights (CCPA/CPRA). If you are a California resident, you also have the right to (a) receive a Notice at Collection describing the categories of personal information we collect, the purposes, and the categories we share, summarized in this policy and the cookie policy; (b) request the specific pieces of personal information we have collected about you in the preceding 12 months; (c) request correction of inaccurate personal information; (d) limit the use and disclosure of any Sensitive Personal Information (SPI) to purposes permitted by Cal. Civ. Code §1798.121; (e) designate an authorized agent to submit a request on your behalf, subject to identity verification; and (f) have the service recognize a Global Privacy Control browser signal as a valid opt-out request under §1798.135(c). To exercise these rights, use the in-product tools above or contact [email protected].

Applicant and intern rights. If you submit an application to HiringCoachAI, the rights described above (access, correction, deletion, portability, and the California-specific rights under CCPA/CPRA) apply to your applicant data. To exercise these rights with respect to applicant data, email [email protected]. Requests for reasonable accommodations to participate in the application or selection process should be sent to [email protected]; these requests are kept confidential and are not used in hiring decisions. Exercising any of these rights will not be used against you in our evaluation of your application.

Response SLA: 30 days, extendable by 60 days for complex requests with notice.

11. Security

We follow a defense-in-depth program aligned with NIST CSF 2.0 and CIS Critical Controls v8 IG1. Details at /security. Highlights: TLS in transit, at-rest encryption, least-privilege access, TOTP-based application-level multi-factor authentication available as an opt-in user setting; current administrative accounts required by policy to use Google Account MFA; audit logging of security-sensitive actions, dependency scanning, and quarterly internal audits.

12. FERPA (educational institutions)

HiringCoachAI does not process "education records" as defined under 34 CFR §99.3 in its default scope; the service processes career content provided directly by individual end users (resumes, application drafts, interview practice content), which is not, by itself, an education record under §99.3.

If you are an educational institution subject to FERPA (20 U.S.C. § 1232g; 34 CFR Part 99) and wish to share education records with HiringCoachAI, or direct end users to share institution-controlled education records through the service, FERPA scope must be defined in a signed Data Processing Agreement before any such records are submitted. The applicable FERPA addendum designates HiringCoachAI as a school official with a legitimate educational interest under 34 CFR §99.31(a)(1)(i)(B), under the institution's direct control with respect to the use and maintenance of the education records, and governs re-disclosure under §99.33(a), directory-information handling, parental and eligible-student rights, deletion on institution request, and retention limits.

The DPA template is published at /trust/docs/dpa-template. For execution or a countersigned PDF, contact [email protected].

13. Children

HiringCoachAI is intended for adult users (18+) per the Terms of Service, and we do not knowingly collect Personal Data from people under 18. If you believe data from someone under 18 has been provided to us, email [email protected] and we'll delete it promptly.

14. Cookies and similar

See our Cookie Policy at /cookies. You control non-essential cookies via the banner and in your account settings.

15. Changes

We post changes here and aim to email registered users at least 30 days in advance of material changes, except where legal obligation or security risk requires shorter notice.

16. Contact

Privacy Officer / data protection contact Elite Ad Operations, LLC d/b/a JumpYield Email: [email protected]

For security concerns, see also /responsible-disclosure and [email protected].


← Back to the trust center

showUpgradeModal: false, modalType: migration, planName: