Privacy policy

Last updated 26 August 2026

Opangle is applicant tracking and onboarding software. Companies use it to run hiring; candidates apply through it. This explains what we do with personal data on both sides, in plain terms.

Who is responsible for what

For the personal data of candidates, the hiring company is the data controller and Opangle is a processor: we hold and process that data on their instructions. If you applied for a job and want your data removed, ask the company you applied to — they can erase it, and we will act on their instruction.

For the personal data of our own customers — the people who sign in and use Opangle — we are the controller.

Candidate data

When someone applies through a careers page hosted by us, we collect:

  • Name, email address and, if given, phone number
  • The CV or documents attached to the application
  • Answers to any questions on the application form
  • Where the application came from, if a link carried that information

We do not collect or infer age, date of birth, gender, ethnicity, nationality, religion, disability, marital status or sexual orientation for any hiring purpose. Our AI schemas contain no field for any of them, so the model cannot record them even if a CV states them.

Where a company runs voluntary diversity monitoring, those answers are stored in a separate table that no recruiter can read. Only aggregate reports are produced, and any group of fewer than five people is suppressed.

How AI is used, and what it does not do

We use Google's Gemini API to read CVs into a structured profile, produce a summary, and score an application against the criteria the employer set — always with the evidence behind the score.

No decision about an application is made by AI. There is no configuration of Opangle in which a candidate is rejected, filtered out or ranked away automatically. A named person at the hiring company reviews and decides, and every AI-influenced decision is recorded with the material that was on screen at the time.

We use the paid tier of the Gemini API. Under Google's terms, paid-tier prompts and responses are not used to train Google's models. We do not train any model of our own on your data, and we do not sell personal data.

Google user data

If you connect a Google account, Opangle requests only these scopes:

  • calendar.eventsCreate, move and cancel the interviews you schedule in Opangle, so they appear in your calendar and the candidate's invitation.
  • calendar.readonlyRead your free/busy times so interview slots offered to a candidate are ones you are actually free for.
  • gmail.sendSend candidate email from your own address, so replies reach you and the thread appears in your Sent folder.
  • gmail.modifyRead replies on threads Opangle started with a candidate, so their answer appears against their application. Restricted to those threads — Opangle never reads the rest of your mailbox.

Opangle's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we do not:

  • Use Google user data to train any AI or machine-learning model
  • Transfer it to others except as needed to provide the feature you asked for, for security, or where the law requires
  • Use it for advertising of any kind
  • Allow humans to read it, except with your explicit consent, for a security investigation, to comply with the law, or on data that is aggregated and anonymised

Mail access is scoped to threads Opangle started with a candidate. We do not read, index or store the rest of your mailbox. You can disconnect at any time from workspace settings, or revoke access at your Google account permissions; we delete the stored tokens when you do.

How long we keep things

Candidate records are kept for as long as the hiring company keeps them, subject to the retention period they configure. Some jurisdictions require hiring records to be kept for a set period — four years under California's FEHA rules, for example — and a company may be obliged to retain data for that reason.

When a record is erased, we empty its personal fields rather than deleting the row, so that hiring statistics and audit history remain accurate without identifying anyone. Backups are overwritten on their own cycle within 30 days.

Where data is held

Data is held in the United States or the European Union depending on the region the customer chose. These are our sub-processors:

  • SupabaseDatabase, authentication and file storage (United States)
  • VercelApplication hosting (United States / global edge)
  • Google (Gemini API)AI processing of CVs and hiring records — paid tier, not used for model training (United States)
  • CloudflareScheduled background processing (Global edge)
  • ResendTransactional email delivery (United States)
  • PolarPayments and invoicing (merchant of record) (United States / EU)

Your rights

Depending on where you live you may have the right to access a copy of your data, correct it, delete it, object to processing, or receive it in a portable form. Under GDPR Article 22 you also have the right not to be subject to a decision based solely on automated processing — which is why Opangle does not make one.

If you are a candidate, the fastest route is the company you applied to. If they do not respond, write to privacy@opangle.com and we will help. If you are a customer, write to us directly.

Security

Data is encrypted in transit and at rest. Access between customers is separated at the database level rather than in application code, and every request runs under the identity of the person making it. More detail is on our security page.

Changes

If we change this policy in a way that materially affects you, we will tell you before it takes effect. The date at the top always reflects the current version.

Questions: privacy@opangle.com