Privacy Policy
Effective date: 24 June 2026 · Last updated: 24 June 2026
1. Who we are
SignalTrust AI Limited (trading as SignalTrust) operates the SignalTrust platform at signaltrust.ai and its subdomain app.signaltrust.ai. We provide a Career & Hiring Intelligence service for candidates and recruiters.
For the purposes of the General Data Protection Regulation (GDPR) and Irish data protection law, SignalTrust is the data controller of your personal data.
2. What data we collect
2.1 Account data
When you sign in via Google OAuth we receive your:
- Google account email address
- Display name
- Profile picture URL
- Google user ID (used to link your account)
2.2 CV data
When you upload a CV we process:
- The PDF file (stored in Cloudflare R2 object storage)
- Extracted plain text from your CV (stored in Cloudflare D1)
- Structured fields parsed from the CV: employment history, education, skills, certifications, work authorisation indicators
2.3 Trust score and signal data
After processing your CV we generate and store:
- A Ready-to-Hire trust score (numeric, 0–100)
- A score bucket (green / yellow / red)
- A list of triggered trust signals with evidence — these are the individual findings that contribute to your score
- AI-generated explanations for your score, signals, and recommendations
2.4 Usage data
We log API requests for security and operational purposes. Logs include timestamps, endpoint paths, and HTTP status codes. We do not log request bodies beyond what is needed for error diagnostics.
3. How we use your data
- Providing the service — analysing your CV, generating your trust score, serving your dashboard
- AI features — generating CV improvement suggestions, visa guidance, salary benchmarking, and Q&A answers using your score and signal data as context
- Recruiter features — if a recruiter uploads your CV on your behalf, we produce a trust report visible to that recruiter and to you
- Security and fraud prevention — detecting abuse of the platform
- Service improvement — understanding how the product is used in aggregate (no individual-level profiling)
4. Legal basis for processing
Under GDPR, we rely on the following legal bases:
- Contract performance (Article 6(1)(b)) — processing your CV and generating a trust score is necessary to provide the service you requested
- Legitimate interests (Article 6(1)(f)) — security logging, fraud prevention, and aggregate service analytics
- Consent (Article 6(1)(a)) — where we rely on consent, you can withdraw it at any time by contacting us
5. AI and automated processing
Your CV text and trust signals are sent to third-party AI providers to generate explanations and recommendations:
- OpenAI — CV improvement suggestions, visa guidance, salary guidance, Q&A answers (gpt-4o-mini)
- Anthropic — used where indicated in specific features
These providers process your data as data processors under our instructions and are bound by data processing agreements. We do not use your data to train their models.
Trust scoring involves automated decision-making. Under GDPR Article 22, you have the right to request human review of a score that significantly affects you. To exercise this right, contact us at the address below.
6. Who we share data with
- Cloudflare — our infrastructure provider. CV files are stored in Cloudflare R2; structured data in Cloudflare D1; all traffic passes through Cloudflare Workers
- OpenAI / Anthropic — AI inference providers (see section 5)
- Google — OAuth authentication only; we receive the data described in section 2.1
- Recruiters — if a recruiter uses SignalTrust to score your CV, they can see your trust report. If you uploaded your own CV, your report is private to you unless you explicitly share it
We do not sell your data. We do not share your data with advertisers or data brokers.
7. Data retention
- Account data — retained while your account is active and for 90 days after deletion
- CV files — retained until you delete them or your account, whichever comes first
- Trust score and signal data — retained for 2 years or until you request deletion
- Security logs — retained for 90 days
8. Your rights
Under GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — ask us to restrict processing while a complaint is resolved
- Data portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Human review — request human review of automated decisions (see section 5)
Signed-in candidates can export or delete their data themselves at any time from your data & privacy page (export a portable JSON copy, or permanently delete your account). You can also contact us at privacy@signaltrust.ai to exercise any of these rights; we will respond within 30 days.
You also have the right to lodge a complaint with the Data Protection Commission (Ireland): dataprotection.ie.
9. Security
We implement the following security measures:
- All data in transit is encrypted using TLS 1.3
- CV files and database contents are encrypted at rest by Cloudflare
- Access to candidate data is isolated by user ID — no candidate can access another candidate's data
- Recruiter workspaces are isolated — recruiters can only see candidates they added
- Authentication is handled by Google OAuth — we do not store passwords
We will notify you and the relevant supervisory authority of any data breach that poses a risk to your rights within 72 hours of discovery, as required by GDPR Article 33.
10. Contact us
For privacy questions, data requests, or to exercise your GDPR rights, contact us at:
Email: privacy@signaltrust.ai
Subject line: "Privacy Request — [your request type]"
We aim to respond within 5 business days.