Privacy Policy
Last updated 2 October 2026
Mayur Srivastava, trading as HacknetAI, Dublin, Ireland, is the controller of the personal data described here. Contact: hacknetai@gmail.com.
What we collect
- Account: your name, email address, a securely hashed password (we can't read it), whether you've confirmed your email and, if you use two-step login, an encrypted authenticator secret and hashed recovery codes.
- Sign-ins: the browsers and apps signed in to your account (browser type, the device name an app reports, when it was last used).
- Plan and billing: your plan, its status and renewal date, currency and a Stripe customer reference. Card and UPI details go to Stripe/Link only; we never see them.
- Usage: what you use that counts against your plan (for example a CV, an ATS check or interview minutes) and, for each AI request, the model, the number of tokens, the time and whether it succeeded, so we can apply limits and keep costs in check. We don't store the content of AI requests.
- Support and waitlist: what you send us, and your email if you join a waitlist.
- Technical: IP addresses, used briefly to stop abuse (for example too many sign-in attempts) and kept in server logs for about 30 days.
What the apps do on your computer
Lumen turns speech into text on your own computer; audio isn't uploaded. Your CVs, documents and job data stay on your computer too. When you use an AI feature, only what that request needs is sent: for Lumen, the question and relevant text from your notes, plus a screenshot of your screen when you ask it to look; for jobEasy, the CV, job description and instructions for that task. Requests pass through our server, which forwards them to the AI provider and returns the answer without keeping the content.
Why we use it (legal basis)
- To provide the service you signed up for: your account, plan, apps and AI features (contract).
- To keep the service secure, prevent abuse and fix problems (our legitimate interests).
- To keep records the law requires (legal obligation).
We don't sell your data, show ads, or send marketing emails. We only email you about your account and the service.
Who processes it for us
- Microsoft Azure hosts the website and its database in the EU (North Europe, Ireland).
- Stripe and Link take payments as merchant of record and are responsible for the payment data they collect.
- Resend sends our emails (EU region).
- Anthropic, OpenAI and xAI (USA) process AI requests to produce answers. Under their API terms they don't use this data to train their models, and may keep requests for a limited time (typically up to 30 days) to detect abuse.
Where data goes outside the EU, as with the AI providers, it's protected by safeguards the law recognises, such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
How long we keep it
For as long as your account is open. When you delete your account, we erase your account, sign-ins, usage and support messages within 30 days (database backups roll over within 7 days after that). Stripe and Link keep payment records for as long as tax and financial law requires.
Your rights
You can ask to see, correct, export or delete your data, or object to or restrict how we use it, by emailing us. We'll reply within one month. You can also complain to the Data Protection Commission in Ireland (dataprotection.ie) or the authority where you live.
Security
Connections are encrypted (HTTPS), passwords are hashed, apps sign in with revocable tokens instead of your password, and you can turn on two-step login under Account.
Cookies
We use only essential cookies: to keep you signed in, to protect forms, for the code step of two-step login, and to remember the currency you picked. Your light/dark theme choice is saved in your browser. There are no advertising or tracking cookies, so there's no cookie banner.
Children
The service is for people aged 18 and over.
Changes
If we change this policy in a way that matters, we'll tell you by email before it takes effect.
Questions: hacknetai@gmail.com