Draft, not yet in force. AY Automate's legal details are still to be added, and the text needs a legal review before AyHire launches.
Privacy Policy
Effective [date]
AyHire is run by [company name], [registered address] (“we”). This page explains what we read, what we keep, who else handles it, and what you can ask us to do. It covers two groups of people: people who use AyHire, and developers whose public GitHub work AyHire reads.
If you use AyHire
What we keep
- Your email address, from signing in with an email link or with GitHub. There is no password.
- The searches you run: the words, the filters and how many results came back, linked to your account when you are signed in.
- What you save: shortlists and their notes, saved searches, and any webhook addresses you add.
- Your roles: each role's title and brief, the people added to it, and what you record about them there (your decision, notes, the date you contacted them, whether you watch them).
- Your activity feed: new matches for a role and changes in someone's availability, so Home can show what changed since you last looked.
- API keys, stored only as a one-way hash plus their first few characters. We cannot see your full key after it is shown to you once.
- Sign-ins from the command line: a short code and its status, which expire after ten minutes.
- Server logs: your account id, the page or tool used, and which GitHub username was looked up.
Your IP address is used only in memory, to stop one visitor from sending too many requests. It is not stored. The only cookies are the ones that keep you signed in; there are no analytics or advertising cookies.
If you are a developer AyHire has read
What AyHire reads
Only what GitHub shows to anyone, through GitHub's public API:
- your public profile (name, bio, location, company, blog, public email if you list one, and whether you have marked yourself available for hire);
- up to 100 of your public repositories, and the README of your five most-starred ones;
- up to 20 recent commit messages, your recent public activity, your public organisations, and pull requests you opened.
AyHire never reads private repositories or your source code.
What we keep
- your public profile details and repository details (names, languages, stars, topics, dates);
- short README excerpts (at most 500 characters each), never the full README;
- six scores out of 10 and a short written summary, made by an AI model from the details above;
- short pieces of that text turned into a search index, so people can find you by what you have built.
One of the six scores, “value”, weighs the quality of your work against the usual cost of hiring where you are based, using the location on your profile. Scores are estimates made automatically from public work. They can be wrong, and we ask everyone who uses AyHire not to treat them as the only basis for a hiring decision.
When someone checks if you are available
Only when a signed-in user asks, AyHire looks further: for your LinkedIn profile, your current and past companies, and a work email. Each fact is saved with where it came from and how sure it is, and a match made only by name and company is marked as a guess. These contact details are never shown in public lists or in our public API.
Who else handles the data
- Supabase: our database and sign-in.
- GitHub: the source of everything AyHire reads, and an optional way to sign in.
- An AI model provider (Anthropic, directly or through OpenRouter): receives profile details and excerpts to write the scores and summary.
- Voyage AI: turns profile text and search words into the search index.
- Looot: runs the deeper availability lookups (LinkedIn and work email) when a user asks for one.
- Webhook addresses that a user sets up receive a short summary (name, company, scores, GitHub link) of new developers who match that user's filters.
How long we keep it
An analysis or availability check is reused for 30 days, then refreshed the next time someone asks for that developer. Analyses are kept until they are refreshed or removed; there is no automatic deletion yet. If you delete your account, your shortlists, searches, saved searches, webhooks and API keys are deleted with it.
What you can ask us to do
You can ask to see what we hold about you, to correct it, or to delete it. Developers can also ask us to remove what we hold about them. Write to [contact email] and we will reply within one month. If you are in the EU or UK, you can also complain to your data protection authority.
Changes
If this policy changes, we will update this page and its date. See also the Terms of Use.