Security & privacy

How CaesarHire protects your CV, your answers and your search.

You are trusting us with the story of your working life, including the parts you would not put on LinkedIn: what you earn, why you are leaving, what you are worried about. We treat it the way we would want ours treated.

  • Your profile, applications and documents are stored in the European Union, in Amsterdam, and backed up daily.
  • You sign in with a 6-digit code sent to your email, and a password is optional.
  • Your session is a signed cookie, so knowing somebody's account id is not enough to read their search.

What we store, and what we do not

Stored

  • Your CV, and the facts you confirm from it and from your interview.
  • Your search plan: target roles, pay expectations, locations and right to work.
  • The roles your agent found, the decisions you made on them, and your applications.
  • The CVs and cover letters written for you, and the interview briefs and debriefs.
  • Practice sessions, including the transcript of a video interview and your agent's debrief.
  • Recruiter emails you choose to forward to your CaesarHire address.

Not stored

  • Card details. CaesarHire is free while it is in beta and there is nothing to pay, so no payment details are collected at all.
  • Readable passwords. A password is optional, and if you set one only a bcrypt hash of it is stored.
  • Your browsing. The Chrome extension reads the one page you ask it about, never your history or your other tabs.
  • Video or audio of your practice interviews. Recording is switched off on every call we create.

Your account

  • Sign-in codes are six digits, kept only as a SHA-256 hash, valid for ten minutes, and usable once.
  • A code burns itself after five wrong attempts, and only one code is ever live for an email address.
  • Sign-in requests are rate limited per address and per email, so nobody can guess their way in.
  • A password is optional. If you set one it must be at least twelve characters with a mix of cases, a number and a symbol, and it is stored only as a bcrypt hash. The code flow doubles as the reset: prove the mailbox, choose a new one.
  • Your session cookie is signed with a key only the server holds, and the expiry is inside the signature, so it cannot be extended by editing the cookie.
  • The cookie is http-only and sent over HTTPS only. Every request is scoped to the account that cookie proves.
  • Traffic runs over TLS with strict transport security, and the site sets a content security policy, frame protection and no-sniff headers.

What your agent can and cannot do

Your agent works in your name, so the limits on it matter as much as the limits on your account.

  • Your agent never sends an application. It writes the pack; you send it from the employer's own site.
  • It never replies to a recruiter on its own. It reads what you forward and drafts a reply for you.
  • It only writes what you have confirmed is true, and flags anything in its own drafts it cannot support.
  • It never changes your search plan without asking you first, in plain words, with the evidence.
  • The browser extension does nothing on any page until you press start assistance, works on one tab at a time, and stops the moment you tell it to.

Data protection and GDPR

  • CaesarHire is a product of Friars Technologies Limited, registered as a data controller with the UK Information Commissioner's Office under reference ZC161465. You can verify that on the ICO's public register.
  • We handle personal data in line with UK and EU GDPR. Your data is stored and backed up in the EU.
  • You can access, export, correct or delete your data at any time, and withdraw consent where processing relies on it.
  • Writing your documents and reading job adverts uses AI providers in the United States, and the video practice interviewer is provided by a US company. We choose established providers and review them before they touch your information. We will share our full list of sub-processors on request.
  • Our AI requests are not kept for training. Every chat request we send to OpenAI carries the store: false flag, and neither OpenAI nor Anthropic trains their models on our API traffic.
  • If you believe we have handled your data wrongly, you can complain to the UK Information Commissioner's Office at ico.org.uk.

Your controls

  • Start over at any time: your CV, interview, confirmed facts, assessment and plan are cleared, and your account stays.
  • Delete your extension session history and saved answers separately, from Settings.
  • Turn off the daily email from Settings, or from any email your agent sends you.
  • Download everything we hold about you, and delete your account, from Settings.
  • Turn non-essential cookies off from cookie settings in the footer, and we stop setting them.

Found a vulnerability? Report it to [email protected]. We will not pursue action against anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.