Legal

Privacy Policy

Effective date: June 27, 2026

This policy explains, in plain language, what we collect, why, how long we keep it, who we share it with, and the control you have. Twynit is built so that AI prepares the work and a human makes every decision — and the same principle governs your data: nothing important happens to it without a clear reason you can see.

1. Who we are

Twynit ("Twynit", "we", "us", or "our") is the Hiring Intelligence Platform that gives recruiting teams a Twin — a partner that prepares hiring work and remembers the decisions a recruiter makes. This policy applies to our marketing site at twynit.com and our product at app.twynit.com (together, the "Service").

For most candidate data we process, our customer — the company that uses Twynit to hire — is the data controller, and Twynit acts as the data processor on their behalf. For our own account, billing, and marketing data, Twynit is the controller.

2. Information we collect

Account information

When you create an account or are invited to a workspace, we collect your name, work email, password (stored only as a salted hash), company name, role, and the team and workspace you belong to. If you subscribe to a paid plan, our payment processors collect billing details; we never see or store full card numbers.

Recruiter & workspace data

As you use Twynit, we process the content you create: roles and job descriptions, your plain-English hiring criteria, screening questions, notes, decisions (shortlist, advance, reject), and messages you send through the Service. Your decisions and the reasoning behind them are stored so your Twin can remember how your team hires.

Candidate data

To evaluate candidates, we process information about them: name, contact details, work history, education, skills, and the structured data extracted from their applications. We process this on behalf of the hiring company. We do not buy candidate data, and we do not sell it.

Uploaded resumes & documents

When a resume or document is uploaded — by a recruiter, a candidate applying through a public job link, or a connected source — we store the original file and the structured data we extract from it. Files are stored encrypted, scoped to the workspace that uploaded them.

Usage, device & log data

We automatically collect standard technical data — IP address, browser and device type, pages viewed, and actions taken — to keep the Service secure, reliable, and improving.

3. How we use information

We use the information above only to:

  • Provide the Service — parse, evaluate, rank, and explain candidates against your criteria.
  • Let your Twin remember your decisions so recommendations become more accurate over time.
  • Secure the Service, prevent abuse, and meet legal and contractual obligations.
  • Communicate with you about your account, support requests, and material changes.
  • Improve the Service in aggregate. We do not use one customer's candidate data to train models that serve another customer.

4. AI processing

Twynit uses AI to prepare hiring work: reading resumes, extracting structured data, matching candidates to your criteria, generating screening questions, and explaining its reasoning. Two principles govern this:

  • AI proposes; a human decides. Our AI produces recommendations and evidence. It does not make hiring decisions. A recruiter reviews, can override, and makes the final call on every consequential action.
  • Your data stays yours. We use sub-processors (see Section 7) to run AI models. We do not permit them to train their foundation models on your candidate or recruiter data, and we do not use your data to train models that serve other customers.

AI-generated evaluations can be incomplete or wrong. They are decision support, not a determination, and should always be reviewed by a person before any action is taken.

5. Cookies

We use a small number of cookies and similar technologies: strictly necessary cookies that keep you signed in and the Service secure, and preference cookies that remember choices such as theme. We also use analytics cookies (Section 6) to understand product usage. When you first visit, we ask your permission before setting any non-essential (analytics) cookies, and you can change your choice at any time by clearing the cookie-consent preference in your browser. Strictly necessary cookies cannot be switched off, as disabling them would break core functionality.

6. Analytics

We use product analytics (PostHog) and Vercel Analytics to understand how the Service is used and where it can be better. These tools collect usage events tied to your account and approximate, IP-derived location. We do not sell analytics data, and we do not use it for cross-site advertising.

7. Third-party services (sub-processors)

We rely on a short list of trusted providers to deliver the Service. Each is bound by contract to protect data and use it only to provide their service to us:

  • Cloud hosting & storage — to run the Service and store files securely.
  • AI model providers — to power parsing, evaluation, and explanations, under terms that prohibit training on your data.
  • Payment processors — Stripe and Razorpay, to handle billing. We never store full card details.
  • Email & communications — to send account, support, and transactional messages.
  • Analytics — PostHog and Vercel Analytics, as described above.
  • Error monitoring & observability — Sentry, to detect, diagnose, and fix errors and performance issues. May capture technical context and, when an error occurs, a recording of the affected session.

A current list of sub-processors is available on request at [email protected].

8. How information is shared

We share data only as needed to run the Service: within your workspace among your authorized team members; with the sub-processors above; and where required by law or to protect rights and safety. If Twynit is involved in a merger or acquisition, data may transfer as part of that transaction, subject to this policy. We never sell personal data.

9. Data retention

We keep personal data only as long as it is needed for the purposes above or as required by law.

  • Account data — for the life of your account, and a short period afterward for legal and accounting needs.
  • Candidate data & uploaded documents — for as long as the hiring company keeps them in the workspace, subject to their retention settings and applicable law.
  • Decisions & memory — retained while the workspace is active, because they are the asset the company is building; deleted on verified request or account closure.
  • Logs & analytics — retained for a limited period for security and product purposes, then deleted or aggregated.

On account closure, we delete or irreversibly anonymize personal data within 90 days, except where law requires longer retention.

10. Data security

We encrypt data in transit and at rest, enforce strict workspace (tenant) isolation, restrict internal access on a need-to-know basis, and log access for audit. No system is perfectly secure, but we treat the trust placed in us as the foundation of the company. To report a vulnerability, write to [email protected].

11. International transfers

We may process data in countries other than your own. Where we do, we use appropriate safeguards — such as standard contractual clauses — to protect it in line with applicable law.

12. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact us at [email protected]; we respond within the timeframes required by law.

If you are a candidate whose data was added by a hiring company using Twynit, that company controls your data. We will refer your request to them and support them in honoring it.

13. Children

The Service is for professional use and is not directed to anyone under 16. We do not knowingly collect data from children.

14. Changes to this policy

We may update this policy as the Service evolves. If we make a material change, we will notify you through the Service or by email and update the effective date above.

15. Contact us

Questions about this policy or your data? Write to [email protected]. See also our Terms of Service and Security pages.