Privacy Policy
Reddy handles candidate data — some of the most sensitive information a person shares. This policy explains exactly what we collect, what we do with it, who else touches it, and how you get it back or get rid of it.
- We do not sell your personal information, and we do not share it for cross-context advertising.
- We do not track you across other apps or websites, and we run no ads.
- Your data is never used to train AI models — ours or our providers'.
- For candidate data, the recruiter or organizer is the controller. We process it on their instructions.
- You can export or delete everything from your privacy settings, at any time.
This summary is here to be useful, not to be binding. The full text below is what governs.
About this policy
What it covers and who it applies to.
Reddy ("Reddy", "we", "us") provides a career-fair and recruiting-event platform. This policy explains how we collect, use, share, and protect personal information across the Reddy web application, the iOS application, our websites, and the public pages a candidate can use without an account (together, the "Service").
It applies to everyone who uses the Service — students and candidates, recruiters, and event organizers. Where a section applies to only one of those groups, it says so.
This policy works alongside our Terms of Service.
Our role: when we are a controller, and when we are a processor
For your own account, we are the controller. For candidate data an employer collects, they are the controller and we act on their instructions.
This distinction determines who you go to about your data, so we put it near the top.
| Data | Our role | What that means |
|---|---|---|
| Your own account and profile | Controller | We decide why and how it is processed, and you exercise your rights directly with us. |
| Candidate data an employer or organizer collects through Reddy | Processor / service provider | The employer or organizer decides why and how. We process it only on their documented instructions, and we pass rights requests to them. |
| Service operation, security, and abuse prevention | Controller | We process limited data — logs, device and usage signals — to keep the Service running and safe. |
If you are a candidate and want data an employer collected about you corrected or deleted, contact that employer. Tell us at privacy@get-reddy.app and we will help you identify who holds it and support their response.
Information we collect
Three sources: what you give us, what we observe, and what others pass to us.
Information you give us
- Account information. Email address, name, and role (student, recruiter, or organizer). If you register through Google or Apple, we receive your name and email from them. If you use Sign in with Apple and choose to hide your email, we receive only Apple's private relay address.
- Profile information. Headline, company, phone number, website, graduation date, years of experience, industries, hiring preferences, and social handles you choose to add.
- Digital card. Card layout, colors, fonts, and the images you place on it.
- Images. Profile photos, headshots, and logos you upload. These are compressed and resized before storage.
- Skills and qualifications. Skills you list, used for matching, recommendations, and analytics.
- Resume data. If you upload or scan a resume, we extract education, experience, projects, skills, and contact details from it.
- Voice notes. Audio you record about a conversation. It is transcribed to text; the audio is discarded after transcription and only the text is kept.
- Notes and ratings. Notes, ratings, tags, and pipeline stages a recruiter records about a conversation.
- Candidate intake submissions. When you submit details through a recruiter's intake page, the name, contact details, optional resume, and the consent you gave.
- Support and correspondence. What you write to us, so we can answer.
Information collected automatically
- Usage data. Features used, screens viewed, and actions taken, so we can understand what works and fix what does not.
- Device information. Device type, operating system version, and app or browser version, for debugging and compatibility.
- Event interaction data. Booth visits, queue positions, wait times, check-ins, and exchanges during an event.
- Push tokens. If you enable notifications, the device token needed to deliver them.
- Log and security data. IP address, timestamps, and request metadata, retained briefly to detect abuse and diagnose incidents.
Information from other people
- Identity providers. Google and Apple pass us your name and email when you sign in with them.
- Event organizers. Event, booth, employer, and role information that is shown to attendees.
- Recruiters. Notes and ratings a recruiter records about a conversation with you, held on that recruiter's behalf.
- Public professional sources. Where a recruiter uses an enrichment feature, limited publicly available professional profile information about a candidate, retrieved through a third-party provider.
- Company logos. Employer logo images retrieved by domain from a logo provider, so booths and cards render correctly.
We do not collect biometric identifiers. Scanning a QR code or photographing a resume produces an image and text — no face template, fingerprint, or voiceprint is generated, stored, or compared.
How we use information
To run the service, make its features work, keep it safe, and improve it.
- Running the Service. Creating and managing accounts, rendering profiles and cards, connecting people who exchange details, running live booth queues, and moving records where you send them.
- AI features. Drafting follow-ups, parsing resumes and cards, transcribing voice notes, suggesting role matches, normalizing analytics values, and summarizing sessions. Detailed in AI features.
- Analytics and reporting. Giving recruiters pipeline views and organizers aggregate event reporting, and understanding product usage so we can improve it. Reporting shown to organizers is aggregated.
- Communication. Queue alerts, connection activity, event reminders, verification codes, security notices, and answers to your questions. We do not send marketing email to candidates.
- Safety and integrity. Detecting abuse, preventing fraud and unauthorized access, enforcing our Terms, and investigating reports.
- Legal compliance. Meeting obligations that apply to us, and responding to lawful requests.
We do not use your personal information to train machine-learning models, and we do not allow our providers to.
AI features and your data
What goes to which provider, why, and the guarantees attached. Nothing trains a model, and nothing decides anything about a person.
AI features send only the data needed for the specific task, and only when you use the feature.
| Feature | Provider | What is sent |
|---|---|---|
| Follow-up drafting, pitch assistance, candidate–role matching, analytics normalization, session summaries | OpenAI | Relevant professional context — role details, stated skills, conversation notes |
| Voice note transcription | OpenAI | The audio recording, discarded after transcription |
| Resume, business card, and image parsing | Google (Gemini) | The image or document you scanned |
| Booth and employer research | OpenAI | Public employer and role information |
The guarantees
- No training. Our integrations are configured so that data sent for processing is not used to train the provider's models.
- Transient processing. Data is processed to generate a response and is not retained by the provider afterwards.
- No automated decisions. No AI feature makes an employment decision. Output is a draft or a suggestion, reviewed by a person who decides. See Employment-related AI.
- Minimum necessary. We send the fields a feature needs, not your whole record.
These providers have their own privacy policies covering how they handle data in transit: OpenAI's Privacy Policy and Google's Privacy Policy.
Sub-processors
Every third party that can touch data, what they do, and where.
We keep this list current. If you want notice of changes before they take effect, ask at privacy@get-reddy.app.
| Provider | Purpose | Data involved | Region |
|---|---|---|---|
| Supabase | Database, authentication, file storage, realtime delivery, serverless functions | All stored account, profile, and candidate data | United States |
| Vercel | Web application hosting and delivery | Request data and web session traffic | United States |
| OpenAI | Text generation, transcription, matching, summarization | Professional context, notes, voice audio | United States |
| Google (Gemini) | Resume and image parsing | Scanned documents and images | United States |
| Google (Sheets API) | Optional export destination a customer connects | Candidate records the customer exports | United States |
| Firebase Cloud Messaging | Push notification delivery | Device tokens and notification content | United States |
| Resend | Transactional email — verification codes, service notices | Email address and message content | United States |
| PostHog | Product analytics | Usage events and device metadata | United States |
| logo.dev | Employer logo images by domain | Employer domain names only — no personal data | United States |
| RapidAPI | Optional professional profile enrichment a recruiter triggers | Public profile identifiers | United States |
| Apple / Google | Sign-in, and Apple Wallet passes where used | Authentication identifiers, pass content | United States |
Applicant tracking systems you connect yourself — Greenhouse, Lever, Ashby, Workable, SmartRecruiters, Teamtailor, Breezy HR — are not our sub-processors. They are your systems, receiving your data at your direction, under your agreement with them.
Security and breach notification
What protects your data, and what we commit to if something goes wrong.
- Row-level security. Access rules are enforced in the database itself, so a user can reach only their own data and data explicitly shared with them — not merely hidden in the interface.
- Encryption in transit. All traffic between your device and our infrastructure uses HTTPS/TLS.
- Encryption at rest. Stored data is encrypted at rest by our infrastructure provider. Integration credentials you supply are encrypted before storage.
- Private storage. Resumes and other sensitive files live in private buckets reachable only through short-lived signed links issued to authorized recipients.
- Public storage. Only the card and avatar images you explicitly publish are stored publicly, because sharing a card requires it.
- Session security. Authentication uses short-lived signed tokens. On iOS, session credentials are held in the device Keychain.
- Least privilege. Administrative access is limited to the people who need it, and privileged surfaces fail closed in production.
If there is a breach
If we become aware of a personal data breach affecting you, we will notify you and, where we act as a processor, the relevant controller without undue delay and within 72 hours of becoming aware, together with what we know about the scope, likely consequences, and the steps we are taking. Report a suspected vulnerability or incident to security@get-reddy.app; we do not pursue good-faith security researchers.
No method of electronic storage or transmission is completely secure. We cannot guarantee absolute security, and we will not pretend otherwise.
How long we keep things
As long as your account is active, then a short, bounded wind-down.
| Data | Retention |
|---|---|
| Account, profile, card, connections | While your account is active |
| After you delete your account | Removed from active systems within 30 days |
| Encrypted backups | Up to 90 days, then permanently deleted |
| Voice recordings | Discarded immediately after transcription — only the text is kept |
| Log and security data | Up to 12 months |
| Aggregated, de-identified analytics | May be kept indefinitely; cannot be used to identify you |
| Records we must keep by law | For the period the law requires |
Candidate data held on behalf of an employer is retained according to that employer's instructions and their own retention policy.
Device permissions
Asked for only when the feature needs them, revocable at any time.
- Camera. Scanning QR codes and capturing resumes or cards. The camera feed is processed live and nothing is stored unless you deliberately capture an image.
- Microphone. Recording voice notes. Audio is transcribed, then discarded; only the text remains.
- Photo library. Choosing images for your card. We access only the images you select — we do not scan your library.
- Notifications. Queue changes, connection activity, event reminders, and service alerts. Categories can be turned off individually in settings.
Every permission is requested at the moment you first use the feature that needs it. You can revoke any of them in your device settings without affecting your account or stored data.
Tracking, cookies, and advertising
No ads, no ad IDs, no cross-app tracking, no data brokers.
Reddy does not serve advertisements, does not use advertising identifiers such as the IDFA, and does not track you across other apps or websites. We do not share data with advertising networks, data brokers, or information resellers, and we do not participate in any cross-app tracking program.
We use PostHog for product analytics — understanding which features are used, so we can improve them. That data is not shared for advertising.
Our websites use cookies that are strictly necessary for the Service to work: session and authentication cookies, and a cookie that remembers your language choice. The mobile app does not use cookies.
Because we do not sell or share personal information for targeted advertising, there is nothing to opt out of. We nevertheless honor Global Privacy Control signals where they apply.
Your rights and choices
Access, correct, export, delete, and control what is visible — mostly self-service.
- Access and export. Export a copy of your personal data from your privacy settings at any time.
- Correction. Update your profile information directly in the product.
- Deletion. Delete your account and its data from your privacy settings. Deletion is permanent.
- Visibility. Control what appears on your profile and card, and what is shared when you connect.
- Permissions. Grant or revoke camera, microphone, photo, and notification access in your device settings.
- Notifications. Turn notification categories on or off individually.
- Withdraw consent. Withdraw consent for optional processing at any time. Withdrawal does not affect processing that already lawfully happened.
- Cached data. Clear locally cached images and temporary files from your privacy settings.
If a self-service option does not cover what you need, write to privacy@get-reddy.app. We may need to verify your identity before acting, and we will not charge you or treat you differently for asking.
US state privacy rights
California, and every other state with a comprehensive privacy law. Same rights, one address, with an appeal if we get it wrong.
If you live in a US state with a comprehensive consumer privacy law — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, or Rhode Island — you have the rights below. We extend them to everyone regardless of where they live.
- Know and access. Learn what categories and specific pieces of personal information we hold about you, where it came from, why we collected it, and who we disclosed it to.
- Correct. Have inaccurate personal information fixed.
- Delete. Have your personal information deleted.
- Portability. Receive a copy in a portable, machine-readable format.
- Opt out of sale, sharing, and targeted advertising. We do none of these, so there is nothing to opt out of — but the right stands.
- Opt out of profiling. Object to profiling that produces legal or similarly significant effects. We do not conduct such profiling; see Employment-related AI.
- Limit sensitive information use. We use sensitive personal information only to provide the Service you asked for, never to infer characteristics about you.
- Non-discrimination. We will not deny service, charge a different price, or provide a lesser experience because you exercised a right.
How to exercise them
Use the in-product privacy settings, or write to privacy@get-reddy.app. We respond to verifiable requests within 45 days, and will tell you if we need a permitted extension. An authorized agent may submit a request on your behalf with proof of authorization.
If we decline your request, you may appeal by replying to our decision or writing to privacy@get-reddy.app with "Appeal" in the subject. We will respond to an appeal within 45 days and, if we still decline, tell you how to contact your state attorney general.
For candidate data an employer collected through Reddy, the employer is the business or controller. Send your request to them; we will help you identify the right contact and will support their response.
European, UK, and Swiss rights
Your GDPR rights, our legal bases, and how data moves across borders.
If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR and equivalent laws apply to our processing.
Our legal bases
| Processing | Legal basis |
|---|---|
| Providing the Service you signed up for | Performance of a contract |
| Optional features — AI assistance, voice notes, push notifications, enrichment | Consent |
| Security, abuse prevention, and product improvement | Legitimate interests |
| Meeting our legal obligations | Legal obligation |
| Candidate data processed for an employer | The employer's basis, on their instructions, with us as processor |
Your rights
You have the right to access, rectify, erase, restrict, and object to processing, the right to data portability, and the right to withdraw consent at any time. Where we rely on legitimate interests, you may object and we will stop unless we have compelling grounds that override your interests.
Write to privacy@get-reddy.app and we will respond within one month. You also have the right to complain to your local supervisory authority, or to the UK Information Commissioner's Office, and we would rather you told us first so we can fix it.
International transfers
Our infrastructure and providers are in the United States, so your data is transferred there. Those transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical measures including encryption in transit and at rest. A copy of the relevant transfer mechanism is available on request.
Employment-related AI and candidate rights
If you are a candidate: nothing in Reddy screens you out automatically, and you can ask what part AI played.
Recruiting technology is increasingly regulated — New York City Local Law 144, the Illinois AI Video Interview Act, Colorado's AI Act, and the EU AI Act all address automated tools used in hiring. Here is exactly where Reddy stands.
- Reddy does not screen candidates out. No feature automatically rejects, filters out, or advances a candidate. Match scores are ranked suggestions displayed to a recruiter, who decides.
- There is always a human. Every action that reaches a candidate — a follow-up message, a status change, an invitation — is taken by a person who reviewed it.
- No inference about protected characteristics. We do not infer or score race, gender, age, disability, national origin, or any other protected characteristic, and no such attribute is an input to matching.
- No biometric assessment. Reddy does not analyze faces, voices, or video to assess a candidate. Voice notes are transcribed to text and never scored.
- You can ask. Candidates may ask whether an AI feature was used in relation to them, what it considered, and request that a person review any outcome.
Employers using Reddy remain responsible for the notices, bias audits, and disclosures their own jurisdiction requires. We will supply the technical detail needed to complete them — write to privacy@get-reddy.app.
Children's privacy
Not for under-17s.
The Service is not directed to anyone under 17, and we do not knowingly collect personal information from them. If we learn we have, we delete it promptly. If you are a parent or guardian and believe a child under 17 has given us information, contact privacy@get-reddy.app and we will remove it.
Changes to this policy
Dated, and announced when material.
We may update this policy. We will update the "Last updated" date at the top, and for material changes we will give notice in the Service before they take effect — and where the law requires it, ask for your consent.
If you do not agree with a revised policy, you can export your data and delete your account.
Contact us
One address for privacy, monitored against the statutory clock.
For any question about this policy, our data practices, a rights request, or a data processing agreement, write to privacy@get-reddy.app. Security matters go to security@get-reddy.app.
Reddy is operated by Reddy. Our registered entity details and mailing address will be published here once incorporation is finalized.
Write to us and a person will answer. For privacy requests, use the privacy address so it reaches the queue with the statutory clock on it.