Privacy policy
What we collect, and what we do with it
Written to be understood rather than to be defensible. Where something is unwelcome — a record that outlives your account, a permission the Android app declares — it is stated plainly, with the reason, in the section where you would look for it.
- 18 August 2026
- Last updated
- 2.0 — rebuild
- Version
- Web and Android
- Applies to
- 13 clauses
- Length
The short version
For orientation only. The numbered clauses below are the policy; where the two appear to differ, the clauses are what apply.
We do not sell your data
No advertising networks, no data brokers. The only promotions here are for the developer’s own other apps. Clause 05
Clause 05Your resume is private until you publish it
A resume gets a public link only when you create one, and the link can be switched off again. Clause 03
Clause 03You can delete everything, yourself
One page, no email ticket, no waiting period. Two categories survive, and both are named. Clause 07
Clause 07The Android app declares five permissions
Each listed with what it does. Camera, microphone, location and photo-library access are actively removed. Clause 06
Clause 0601 · What this policy covers
The ClearHire website at clearhire.aoneahsan.com and the ClearHire Android app. There is no iOS app and no browser extension, so nothing here refers to one.
02 · What we collect
Only what a feature needs. The right-hand column is the honest test: remove the feature and the data stops being collected.
| Category | Examples | Why it exists |
|---|---|---|
| Account | Name, email address and profile picture from your Google account | Sign-in. Google is the only sign-in method, so there is no password to store. |
| Profile and career history | Roles, dates, education, skills, projects, awards | Building resumes, and claiming employment for verification. |
| Documents you upload | Resume files, portfolio files, profile photos | Stored so you can reuse them. Held by FilesHub — clause 05. |
| Identity verification | Identity document images and the verification outcome | Only if you choose to verify your identity. It is optional and the app works without it. |
| Applications and job activity | Roles you tracked, stage changes, notes, contacts you recorded | The application tracker. Visible to you alone. |
| Community content | Forum posts, comments, messages, reviews you write | The community features. Posts and comments are public by nature. |
| Technical | Device type, app version, the IP address of a request, error reports | Keeping the service working and diagnosing crashes. |
What we do not collect
We do not collect your contacts, your location, microphone or camera input, or the contents of your photo library. Clause 06 explains how that is enforced on Android rather than merely promised.
03 · What is public, and when
Nothing about you is public by default. Four things can become public, each by an action you take, and each reversible:
- A published resume — only once you create a public link. Turning the link off makes it private again.
- Your public profile — only if you create one, and you choose what appears on it.
- Countersigned employment records — only confirmed ones. A pending, declined, expired or disputed record is never published; a decline stays between you, the company and us.
- Forum posts and comments — public when written, which is the nature of a forum.
04 · Why we are allowed to
For readers in the UK, EU and other jurisdictions with an equivalent regime, the legal bases are:
- Contract — your account, resumes and applications. The service cannot be provided without them.
- Consent — identity verification, employment verification requests, and publishing anything. Withdrawable at any time.
- Legitimate interests — keeping the service secure, preventing fraud and abuse, fixing crashes.
- Legal obligation — where a law requires us to keep or produce something.
Free accounts and product improvement
Free accounts and product improvement. We may use content from free accounts to improve and train the features we build. Content in a paid plan is not used this way without your explicit consent. This is what lets the free plan stay free, and it is stated in clause 7 of the terms as well. You can ask us to stop at any time under your rights, and moving to a paid plan stops it too.
05 · Who else processes it
We do not sell personal information, and there are no advertising networks in this product. Data reaches other parties in exactly three ways: a company you ask to confirm an employment claim, an employer you apply to, and the service providers below.
| Provider | Handles | Role |
|---|---|---|
| Google Sign-In | Authentication. We receive your name, email and profile picture; we never see your password. | Independent controller for your Google account |
| Supabase | The database, and the authentication session behind it. | Processor |
| FilesHub | Files you upload, and outbound email such as verification requests. | Processor |
| Firebase Hosting | Serving the website. Receives the IP address of each request, as any web host does. | Processor |
| OneSignal | Push notifications, if you turn them on. Nothing is sent before you allow them. | Processor |
| Google Play | Distribution and updating of the Android app. | Independent controller |
| Sentry | Crash and error reporting, so a failure is fixed rather than guessed at. | Processor |
| Amplitude | Product analytics — which features are used, and where a flow is abandoned. | Processor |
| Microsoft Clarity | Session replay and heatmaps, used to find where a screen is confusing. | Independent controller |
| Google Analytics 4 | Aggregate traffic — which pages are reached, from where, and on what device. | Independent controller |
Clarity is listed as a controller, and the distinction matters
Sentry and Amplitude process data on our instructions and for our purposes only. Microsoft Clarity and Google Analytics each decide some of their own, which makes them independent controllers rather than processors — so those are sharing relationships, and they are named as such here and in the store’s data-safety disclosure. This paragraph previously described Firebase Analytics as dropped in the rebuild, and Firebase as serving hosting alone. That was wrong. Google Analytics 4 and Firebase Analytics are one product, and it has been loading on every page since the analytics layer was built. It is named in the table above, and what it stores is in cookies clause 10.
06 · Android app permissions
The Android app declares five permissions. Each is listed with what it does.
| Permission | What it is for |
|---|---|
| INTERNET | Talking to the server. Nothing works without it. |
| ACCESS_NETWORK_STATE | Detecting that you are offline, so the app can say so instead of failing silently. |
| POST_NOTIFICATIONS | Showing notifications you asked for. Android prompts at the moment you enable them, never at launch, and declining leaves the rest of the app working. |
| VIBRATE | The short haptic that accompanies a notification. |
| AD_ID | The advertising identifier, read by the notification SDK. Declared because it is technically present, and reported in the Play Data Safety form as a device identifier. It is not used to target advertising, because there is no advertising. |
Five more are actively removed
These are actively removed from the app, so they cannot be requested even if a bundled library tries to add them: CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION, READ_MEDIA_IMAGES and WRITE_EXTERNAL_STORAGE.
File uploads still work. They go through the operating system’s own file picker, which hands the app the one file you chose and no access to anything else — which is why uploading a resume needs no storage permission at all.
07 · How long we keep it
While your account exists, your data exists. When you delete your account it is removed immediately — not queued, not soft-deleted behind a grace period.
| Data | Kept for |
|---|---|
| Profile, resumes, applications, uploads | Until you delete your account |
| Identity document images | Until you delete your account — deleted with everything else |
| Identity-verification disputes | Up to 2 years, and they survive account deletion |
| Abuse and message reports | Survive account deletion |
| Forum posts and comments | Kept, with your name removed — see below |
| Countersigned employment records | Deleted with your account. The company keeps its own record of what it confirmed. |
Two things outlive your account, and both are deliberate
A fraud dispute that could be erased by deleting the account that caused it would turn deletion into a tool for hiding fraud. An abuse report that vanished with the reported account would do the same for harassment.
Forum posts and comments are anonymised rather than deleted: the text stays, your name is replaced. Removing them outright would strand every conversation they were part of, leaving other people’s replies answering nothing. If you want a specific post gone rather than anonymised, delete it before deleting your account.
08 · Your rights
Under the UK GDPR, the EU GDPR and comparable regimes you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or have it handed to another service. You can withdraw consent at any time.
- Access and correction — most of it is editable directly in your profile.
- Deletion — the deletion page does it immediately, without asking us.
- Everything else — email aoneahsan@gmail.com. We aim to answer within 30 days.
If you are unhappy with how a request was handled you can complain to your local data protection authority. In the UK that is the Information Commissioner’s Office.
09 · Security
Data is encrypted in transit. Access to your records is enforced at the database level rather than only in the interface, so a bug in one screen cannot expose another person’s data. Sign-in is delegated to Google, which means we never hold a password.
We do not claim to be unbreachable, and a policy that did would be worth ignoring. If a breach affects you, we will tell you what happened and what was exposed.
10 · Age
ClearHire is for adults, 18 or over, and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, email us and it will be removed.
11 · Where the data lives
Our providers operate internationally, so your data may be processed outside your own country, including outside the UK and EEA. Where that happens we rely on the transfer mechanisms those providers offer, such as standard contractual clauses.
ap-southeast-1).The database is hosted in Singapore (ap-southeast-1). If you are in the UK or the EEA, your data is therefore processed outside it, and we rely on the standard contractual clauses our hosting provider offers for that transfer. If you are in Pakistan, where ClearHire is operated from, or elsewhere in the Asia-Pacific region, your data is processed closer to you than it would be on a European or American host.
12 · Changes to this policy
When this policy changes, the version and date at the top change with it. A change that materially affects you — a new category of data, a new provider, a longer retention period — is announced in the app before it takes effect, not only recorded here.
13 · Contact
Privacy questions, data requests, or a correction to this page:
| Channel | Detail |
|---|---|
| aoneahsan@gmail.com | |
| Phone | +92 304 6619706 |
| Post | Postal address (opens in a new tab) |
Written for people, and checked against what the software does. If a clause here does not match the product’s behaviour, one of the two is wrong — tell us which.