Last updated: September 16, 2026
This Privacy Policy explains how Hi Maya ("we", "us", "our") collects, uses, and discloses personal data in the course of providing our recruiting and interview-scheduling platform (the "Service").
"Personal Data" means any information relating to an identified or identifiable person that we process as described here. "Customer" means a recruiting team or organization that uses the Service. "Candidate" means a job applicant or interviewee whose data is handled through the Service.
For account, billing, website, and marketing data, we act as the data controller. When a Customer uses the Service to manage applications, message candidates, or schedule interviews, we act as a data processor on the Customer's behalf, and the Customer is the controller of that candidate data. Data is strictly isolated per tenant. If you are a candidate and want to exercise your rights over data an employer holds about you, please contact that employer directly.
Account data. When a Customer sets up an account we collect names, email addresses, and login credentials for each team member.
Billing data. Paid plans are arranged directly with us and invoiced outside the product. We do not collect payment card details through the Service; we store only your plan and contact details for billing correspondence.
Candidate data. Customers upload or receive candidate data (name, contact details, phone, CV, application answers, salary expectations, interview notes and evaluations, and any optional diversity information such as gender that a candidate chooses to provide) that candidates submit through careers pages, booking links, or apply-by-email. We process this data on the Customer's instructions. Customers can also define custom fields; Customers are responsible for not collecting special categories of data through them without a lawful basis.
Data from other sources. Customers may also add candidate and prospect data they obtained elsewhere: imports from a previous applicant-tracking system (such as Greenhouse or Comeet), manual entry, or profile information captured with our browser extension while a recruiter views a public professional profile (such as name, role, experience, education, and, where visible, contact details and photo). This can include information about people who have not applied to the Customer. The Customer is the controller of this data and is responsible for having a lawful basis and providing any required notices to those individuals.
Communications. If you contact us for support or feedback, we keep the content of those messages to respond and improve the Service.
Log and device data. When you use the Service we automatically record technical information such as IP address, browser type, device and operating system, referring pages, and timestamps.
Cookies and local storage. We and our service providers use cookies, local storage, and similar technologies to keep you signed in, remember preferences, and understand how the Service is used. On public booking and careers pages you can adjust non-essential cookies at any time through the "Cookie settings" link in the page footer. Where a Customer embeds its careers pages into its own website, the Customer's website is responsible for presenting cookie consent. Strictly necessary cookies are required to authenticate and operate the Service and cannot be turned off.
Usage data. We collect information about how the Service is used, such as which features are used and how often, to monitor, secure, and improve the product.
Product analytics. Within the signed-in product we use Microsoft Clarity to understand how the Service is used through session insights and heatmaps. Clarity may record general interactions such as clicks, scrolls, and navigation; sensitive input fields are masked. We identify sessions to Clarity with your account, including your user ID, name or email, role, and workspace, so we can review and support your use of the product. Clarity does not run on the public careers and booking pages. Clarity's use is also governed by Microsoft's privacy statement.
The Service includes AI-powered features: automatic CV parsing and summarization, semantic search over candidate profiles, AI-suggested match scores, drafting assistance, and the Maya assistant (in the product and, where a recruiter connects them, over Slack or WhatsApp). To provide these features, relevant data - including CV text, candidate profile information, job descriptions, and assistant conversation content - is processed by our AI model provider, Google (Gemini API), acting as a sub-processor. This data is used only to generate the requested output for the workspace; it is never sold and never used by us for advertising. We use Google's paid API tier, under which Google does not use submitted data to train its models.
AI outputs are assistive suggestions for recruiters. No hiring decision is made solely by automated means: decisions with legal or similarly significant effect on a candidate (such as rejection) require confirmation by a human recruiter, and AI-suggested scores and summaries are recommendations that recruiters review. Every action the assistant takes is logged and reversible by the workspace.
Emails sent through the Service (for example application confirmations, interview invitations, and recruiter messages) are delivered by our email provider and include standard delivery, open, and click tracking (a tracking pixel and wrapped links). Engagement events are stored so recruiters can see whether their message arrived and was read. Replies sent to our reply addresses are processed to thread them into the correct application.
Customers can connect their own analytics to their public careers and booking pages. When a Customer configures Google Analytics (GA4) or the Meta (Facebook) Pixel, those third-party tools load on that Customer's public pages and collect usage data subject to the visitor's cookie choices. These tools are controlled by the Customer, and their use is also governed by Google's and Meta's own privacy terms. To opt out of Google Analytics, you can install the Google Analytics opt-out browser add-on.
Recruiters may connect their Google account to schedule interviews. When connected, we access Google Calendar with two scopes: calendar free/busy, to read only the busy time windows of the connecting recruiter's own calendar, used transiently to suggest interview times (busy windows are not stored); and calendar events, to create, update and delete the interview events the recruiter schedules through the platform (we store only the identifier of events we created, never the contents of other calendar events). We do not access Gmail, contacts, or any other Google data.
Google user data is never used for advertising, never sold, and never transferred to third parties except as required to provide the scheduling feature itself. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Workspace APIs are not used to develop, improve, or train non-personalized AI and/or ML models. Calendar data is used solely to provide the scheduling features described above.
A recruiter can disconnect Google at any time from the platform's Integrations page (which deletes the stored tokens) or revoke access at myaccount.google.com/permissions.
We use the information described above to:
We do not use candidate email addresses collected through booking or careers pages to send our own direct marketing.
Service providers and sub-processors. We use vetted sub-processors for cloud hosting, authentication, email delivery, search, AI processing, error monitoring, and product analytics. The current list is published on our sub-processor page. They may access personal data only to perform services for us and are bound to keep it secure.
Integration partners. Where a Customer or its members connect an integration (such as Google Calendar, Outlook, Zoom, Slack, WhatsApp, or LinkedIn), we exchange the data needed to make that integration work - for example interview events with attendee details in a connected calendar, or assistant conversations over a connected Slack workspace or WhatsApp number (which involves the recruiter's phone number and message content passing through that provider).
Legal and safety. We may disclose information where reasonably necessary to comply with the law or a legal request, to enforce our terms, or to protect the rights, property, or safety of any person.
Reorganization. If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy.
We retain personal data for as long as the Customer's workspace is active and as needed for legitimate business or legal purposes. Candidate data is retained on behalf of the Customer; Customers can delete individual candidate records at any time, and deletion is immediate and permanent. When a Customer deletes its workspace, all of the workspace's data - database records, uploaded files, and search index entries - is permanently deleted right away.
Data is stored in access-controlled infrastructure with tenant isolation enforced at the application and database layers. Data is encrypted in transit (TLS) and at rest, and OAuth tokens for connected accounts are encrypted before storage. We take reasonable technical and organizational measures to protect personal data, though no method of transmission or storage is completely secure. Keep your credentials private and unique.
We and our sub-processors may process data in countries other than your own. Where required, we rely on appropriate safeguards, such as standard contractual clauses, for international transfers.
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. Customers can review and update their account information in the platform at any time. Candidates should contact the relevant employer to exercise rights over data that employer controls; the platform gives Customers tools to correct, delete, and export candidate records, and we assist Customers with requests the tooling does not cover. You can also contact us at the address below and we will route your request appropriately.
For Customers and candidates in Israel, we process personal data in accordance with the Israeli Protection of Privacy Law, 5741-1981, as amended, and the Privacy Protection (Data Security) Regulations. Customers remain responsible for their own obligations under that law with respect to the candidate databases they control, including any registration or notification duties.
The Service is not directed to children, and we do not knowingly collect personal data from children. If we learn that we have, we will delete it.
We may update this Policy from time to time. If we make material changes we will update the date above and post the revised Policy on this page.
Questions about this Policy: [email protected]