FairHire Privacy Policy
Last updated June 23, 2026.
This Privacy Policy describes how FairHire, a Luminid product, handles your information. We aim to collect only what we need, to be clear about how the text you submit is processed, and to give you real control over your data.
1. Who we are
FairHire is a product operated by Luminid, a sociedad de responsabilidad limitada organized under the laws of the Republic of Costa Rica, with Legal Entity ID (Cédula Jurídica) 3102-950-241 and its principal place of business in San José, Costa Rica ("FairHire," "Luminid," "we," "us," or "our"). FairHire is accessible at fairhire.luminid.org.
This Privacy Policy explains what information we collect when you use FairHire, how we use and share it, how long we keep it, and the choices and rights you have. It applies to the FairHire website, tools, and related services (the "Services"). It should be read together with our Terms of Service and our Legal Notice and Disclaimer.
2. Information we collect
Account information. When you create an account, we collect your email address and, if you provide it, your name. If you sign in with Google, we receive your basic profile information (name, email, and account identifier) from Google.
Audit content. When you use the Question Auditor, Job Post Auditor, or Job Description Builder, we collect the text you submit (for example, interview or application questions, a job posting, or job details) and the results we generate from it. For signed-in users, this content and its results are saved to your account history and any sets you choose to save, until you delete them or close your account.
No-login audits. If you run an audit without an account, we do not store the text you submit. To prevent abuse of this free, unauthenticated feature, we store only a one-way salted hash of your IP address and the type of audit run. We never store the raw IP address.
Reports you ask us to save or share. If you ask us to email you a copy of a no-login audit, or you create a shareable report link, we store that report so the link keeps working. A stored report contains the findings and the exact phrases quoted from the text you submitted (that is what the report is), not the full submitted text. Shared report pages are excluded from search engines and are reachable only by their unguessable link. Write to hello@luminid.org to have a report deleted.
Email addresses entered at an audit gate. Entering an email address to unlock the fixes sends you one report email. We add an address to our follow-up emails only after someone opens the link in that email, which confirms the address actually receives mail; every follow-up carries a one-click unsubscribe.
Payment information. When you subscribe or buy a single audit, payment is processed by our payment provider, ONVO Pay. We receive transaction metadata (such as a subscription or payment identifier, amount, currency, and status) and retain billing records, but we do not collect or store your full card number.
Usage and analytics. We record limited, privacy-preserving funnel events (for example, that an audit was run, a trial started, or a subscription began) together with minimal, non-sensitive metadata, to understand and improve the Services.
Business-contact information for outreach. For our business-to-business outreach (see Section 11), we process professional contact details (such as a work email address, name, company, and public job-posting information), which may be obtained from third-party business-data providers or public sources.
Device and log data. Like most online services, our infrastructure automatically receives technical data such as IP address, browser type, and request timestamps as part of normal operation and for security.
3. How we use your information
We use the information described above to: provide and operate the Services and generate audit results; save and display your audit history and saved sets; create and manage your account, trial, and subscription; process payments and issue legally required invoices; provide customer support; maintain the security, integrity, and reliability of the Services and prevent abuse; understand and improve the Services; conduct business-to-business outreach in line with Section 11; and comply with our legal, tax, and accounting obligations.
4. AI processing of your audit content
FairHire's tools use artificial intelligence to analyze the text you submit. To generate results, the text you enter is transmitted to and processed by our AI sub-processor, Anthropic, PBC (the provider of the Claude models), acting on our behalf.
Under Anthropic's commercial terms of service, inputs and outputs submitted through its commercial API are not used to train its models. We likewise do not use your audit content to train any artificial-intelligence model.
As explained in our Legal Notice and Disclaimer, automated analysis can be incorrect or incomplete; FairHire's results are informational signals, not legal advice or a legal conclusion.
5. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose information only as described here.
Service providers (sub-processors). We share information with vendors who process it on our behalf, under contracts that limit their use of it to providing services to us. Our current sub-processors are:
• Anthropic, PBC. AI analysis of audit content. • Supabase. Database, authentication, and file storage. • Vercel. Web application hosting and delivery. • ONVO Pay. Payment processing (Costa Rica). • FacturaTica. Electronic invoicing required by Costa Rican tax law. • Resend. Delivery of transactional and outreach email. • Apollo.io. Sourcing of professional business-contact information for outreach.
Legal and safety. We may disclose information if required by law, regulation, legal process, or governmental request, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or abuse.
Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
6. Legal bases for processing (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Services you request and manage your account and subscription); our legitimate interests (to secure, maintain, and improve the Services, and to conduct proportionate business-to-business outreach), provided these are not overridden by your rights; compliance with a legal obligation (such as tax and accounting requirements); and your consent, where we ask for it (which you may withdraw at any time).
7. Cookies and similar technologies
We use strictly necessary cookies and similar technologies to keep you signed in, maintain your session, and operate core features such as authentication and security. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings; disabling strictly necessary cookies may prevent parts of the Services from working.
8. International data transfers
Luminid is based in Costa Rica, and our sub-processors operate global infrastructure. As a result, your information may be stored and processed in countries other than your own, including the United States and the European Union. Where required, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) for transfers of personal data out of the EEA or the UK. By using the Services, you understand that your information may be transferred to and processed in these jurisdictions.
9. How long we keep information
We retain information for as long as needed to provide the Services and for the purposes described in this Policy.
• Account and audit content: kept while your account is active. You may delete saved audits and sets at any time, and you may delete your account, after which we delete or de-identify associated personal data within a reasonable period, except where we must retain it by law. • No-login audit hashes: retained for seven (7) days, which is sufficient to enforce rate limits, then deleted automatically. • Analytics identifiers: the salted hash attached to a usage event is removed after thirty (30) days; the anonymous event itself is kept as an aggregate count. • Saved and shared audit reports: kept until you ask us to delete them, so their links keep working. • Billing and financial records: retained for seven (7) years following the relevant fiscal year, as required by Costa Rican tax and accounting law. • Outreach suppression list: if you opt out of our outreach, we retain the minimum information needed (such as your email or domain) on a do-not-contact list indefinitely, so that we can continue to honor your opt-out.
10. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information; to opt out of the "sale" or "sharing" of personal information (note that we do not sell or share personal information for advertising); to object to or restrict certain processing; and to withdraw consent where processing is based on consent. Residents of California (under the CCPA/CPRA), the EEA, and the United Kingdom (under the GDPR/UK GDPR) have these and related rights, and we will not discriminate against you for exercising them.
To exercise any of these rights, email us at hello@luminid.org with the subject line "Data Subject Request." We may need to verify your identity before acting on your request. We will respond within the time required by applicable law (generally 30 days, extendable where permitted). If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
11. Marketing and business-to-business outreach
We may send you service-related messages (such as account, billing, and security notices), which are necessary to operate the Services.
We also conduct limited business-to-business outreach to professional contacts about FairHire. These messages identify FairHire as the sender, include our physical postal address, and provide a one-click unsubscribe and an opt-out mechanism in every message, consistent with the U.S. CAN-SPAM Act and comparable laws. If you opt out, we add you to a suppression list and stop contacting you. You can also opt out at any time by emailing hello@luminid.org.
12. Security
We use technical and organizational measures designed to protect personal information, including encryption in transit, access controls, row-level database security, and restricted use of administrative credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you discover a potential vulnerability, please report it to hello@luminid.org rather than disclosing it publicly.
13. Children
The Services are intended for adults aged 18 or older and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us at hello@luminid.org and we will take steps to delete it.
14. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy.
15. Contact us
If you have questions about this Policy or your personal information, contact us at:
Luminid (FairHire) San José, Costa Rica Legal Entity ID (Cédula Jurídica): 3102-950-241 Email: hello@luminid.org (Subject: "Privacy Inquiry" or "Data Subject Request").