Legal
Privacy Policy
How Verichi handles account and candidate information. Last updated: 1 March 2026.
1. Who this covers
This policy covers people who hold a Verichi account (customers) and candidates whose professional information a customer submits for verification.
Customers are responsible for having a lawful basis to submit candidate information and for informing candidates that verification tooling is used in their hiring process.
2. Information we process
Account information: name, email address, company and plan.
Candidate information supplied by customers: name, role title, CV file and extracted text, professional profile URL or profile text supplied by the customer, and a public GitHub profile URL.
Public technical evidence retrieved via the official GitHub API: public profile fields, public repository names, descriptions, languages, topics, stars and activity dates.
Generated output: the candidate consistency report and its score components.
3. What we never process
Verichi does not collect, infer or evaluate protected characteristics, including race, ethnicity, gender, age, nationality, religion, disability, sexual orientation, marital status, pregnancy or political opinion.
Verichi does not access private repositories, private messages, or any candidate account credentials.
Verichi does not scrape LinkedIn. Professional profile content enters the product only where a customer supplies it, or through an approved data provider where one is connected.
4. How information is used
Candidate information is used solely to produce the verification report requested by the customer who submitted it, and to make that report available to that customer.
Aggregate, non-identifying operational metrics may be used to maintain and improve service reliability.
Candidate information is not sold, and is not used to build cross-customer candidate profiles.
5. Storage and access
CV files are stored privately and are readable only by the account that uploaded them. Reports and candidate records are protected by row-level access rules scoped to the owning account.
Data is encrypted in transit and at rest by our infrastructure providers.
6. Retention and deletion
Customers may delete a candidate record, its CV file and its reports at any time from the dashboard. Deletion removes the record from active systems promptly and from backups within 30 days.
Account information is retained while the account is active and deleted on request following account closure.
7. Candidate rights
Candidates may request access to, correction of, or deletion of information held about them. Because Verichi processes candidate data on behalf of the customer, requests are routed to the customer who submitted the information; contact hello@verichi.app and we will assist.
8. Sub-processors
Verichi uses infrastructure providers for hosting, database, storage and model inference. Providers are bound by contractual confidentiality and data-protection obligations.
9. Changes and contact
Material changes to this policy will be communicated to account holders. Questions can be sent to hello@verichi.app.