DistillHire

Privacy Policy

Effective 21 August 2026 · Last updated 21 August 2026

DistillHire runs a human-panel interview loop for engineers and makes the resulting verified profiles searchable by hiring companies. Doing that means handling personal data — your name, your resume, how you performed in an interview. This page sets out exactly what we hold, who can see it, and what you can ask us to do with it.

The short version

  • Candidates give us a name, email, phone number and resume. Our ops team adds screening details, skill ratings and interview round scores.
  • Approved hiring companies can see your profile — but not your resume file or your phone number — and only during your 90-day visibility window.
  • Companies cannot contact you through the platform. Every introduction goes through our ops team.
  • We run no analytics, advertising or cross-site tracking. If you're not signed in, we set no cookies at all.
  • We don't sell your personal data, share it with advertisers, or use it to train machine-learning models.
  • You can ask us to show you, correct, or delete your data at any time — email hr@distillhire.com.

01Who this policy covers

This policy applies to everything at distillhire.com and covers three groups of people:

  • Candidates — engineers who apply through our application form, or whom our ops team adds after speaking to them directly.
  • Company users — the people who register a hiring company, sign in, and search for candidates.
  • Visitors — anyone who browses the site without applying or signing in.

DistillHire is based in Bangalore, India. Under India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”) we are the Data Fiduciary for this data, and you are a Data Principal — the person the data is about. Our Terms of Service covers the rest of the relationship.

02What we collect

If you're a candidate — what you give us

  • Required: your full name, email address, phone number, and your resume as a PDF or Word file (up to 10MB).
  • Optional at application: your role, seniority band, target pathway, and core stack. If you skip these, our ops team collects them on the screening call instead.

If you're a candidate — what our team records about you

Once you enter the interview loop, our ops team builds the rest of your profile:

  • Your assigned pathway (Startup, Product-based or Service-based) and where you are in it.
  • Skill ratings — named skills and frameworks, each scored out of 10, plus unrated tags for tooling you've worked with.
  • Interview round records — the round name, its status, when it was scheduled and completed, the interviewer's name, a score out of 10, and the interviewer's written notes.
  • Retake records — whether you've used your one retake for a round, and when.
  • A profile summary written by our ops team, your availability status, and the date your 90-day visibility window started.

If you register a company

  • Company name, your name, your work email address, and a password. The password is hashed and stored by our authentication provider — we never see or store it in readable form.
  • Your account's approval status, set by our team before search access is granted.
  • A log of each search you run — the role, experience level and filters you selected, and when — and each introduction you request.
  • Separately from this platform, we hold the contract and billing details for your company's commercial agreement with us — signatory and billing contact, and invoicing information. That sits in our business records, not in the product, and is used only to administer the agreement.

From everyone who visits

  • Standard server and hosting logs kept by our hosting provider — IP address, browser user-agent, the page requested and when.
  • Your IP address, used to rate-limit our public application and signup forms so they can't be flooded with junk submissions.

What we deliberately don't collect

No analytics or advertising trackers. No payment or bank details — the site takes no payments at all, and we never ask a candidate for payment details under any circumstances. No government identity numbers. No date of birth, gender, caste, religion, health data, or biometrics. Please don't include any of those in your resume either — we don't need them, and we'd rather not hold them.

03Cookies and local storage

We run no analytics, advertising, or cross-site tracking technology. There is no consent banner on this site because there is nothing non-essential to consent to. Specifically:

  • Session cookies are set only after you sign in as a company or admin user. They keep you signed in, and nothing else. Candidates never sign in, so applying sets no cookie.
  • Your light/dark theme choice is saved in your browser's local storage. It stays on your device and is never sent to our servers.

04Why we use your data

The DPDP Act requires us to tell you the specific purposes, not a vague catch-all. Here is the complete list:

  • To receive your application and contact you about it.
  • To run a screening call and record what we learn from it.
  • To assign you a pathway and schedule your interview rounds with a panel interviewer.
  • To record the outcome of each round — score and notes — and to enforce the one-retake and 30-day cooldown rules.
  • To build a verified profile that approved hiring companies can search.
  • To make that profile visible to approved companies for 90 days from the day we mark it ready.
  • To pass an introduction request from a company to you, and connect the two sides by email if you're interested.
  • To register, review, approve and administer company accounts.
  • To keep the platform working and secure — rate-limiting public forms, investigating abuse, and keeping operational logs.
  • To count searches and introductions in aggregate, so we know whether the service is working.

We do not use your data for any purpose beyond these without asking you first.

06Who can see your data

Our ops team

The small admin team that runs the interview loop can see your full record, including your resume file and phone number. This is the only group with access to everything.

The interview panel

Rounds are conducted by senior engineers we contract as panel interviewers. They don't have accounts on this platform. Ops shares only what an interviewer needs to run your round, and the interviewer relays the score and notes back to ops, who enter them. Panel interviewers are under a confidentiality obligation to us.

Approved hiring companies

Once your profile is marked ready for visibility, approved companies can find it through search and open it. They can see:

  • Your name and email address.
  • Your role, seniority band, core stack, GenAI specialisation and availability status.
  • Your pathway, and the profile summary our team wrote.
  • Your skills and their ratings out of 10.
  • Each interview round: its name, status, score out of 10, and the interviewer's notes.

They cannot see your resume file, your phone number, or the internal notes our team keeps outside the round records. Access is enforced in the database itself, not just in the interface — a company account is structurally unable to read candidates outside an active visibility window.

Companies also cannot message you through the platform. When a company requests an introduction, it comes to our ops team, and we connect the two of you by email. What a company may then do with your data is restricted by our Terms of Service.

Nobody else

We don't sell your personal data, rent it, share it with advertisers or data brokers, or use it to train machine-learning models. The only other disclosures we'd make are to the service providers in the next section, or where we're legally compelled — a court order, or a lawful request from a government authority.

07Service providers

We keep our vendor list deliberately short. Only two providers process personal data on our behalf, under their own contractual and security obligations:

  • Supabase — hosts our database, handles sign-in for company and admin accounts, and stores resume files. Resumes live in a private storage bucket that only our ops team can read; the files are not reachable by a public URL.
  • Vercel — hosts and serves the website, and keeps short-lived request logs.

Both may store or process data on servers outside India. The DPDP Act permits such transfers except to countries the Central Government specifically restricts, and we'll change providers or regions if that ever affects us.

One further vendor, Sanity, stores the articles on our blog. It holds no personal data about you — only content we've written and published — and your browser never contacts it, because blog images are served through our own hosting rather than loaded from theirs. We list it here for completeness, not because it processes anything about you.

08How long we keep it

  • Your visibility window is 90 days, counted from the day our team marks your profile ready. When it lapses, your profile stops appearing in company search. Re-entering the pool requires a full re-interview of every round in your pathway.
  • Candidate records and resumes: kept for up to 12 months after your visibility window lapses, or after your last contact with us if you never reached that stage — so you can come back without starting from scratch. After that we delete the record and the resume file.
  • Company accounts: kept while the account is open, and for 12 months after you ask us to close it.
  • Search and introduction logs: kept up to 24 months as operational records and for aggregate reporting.
  • Rate-limiting records: IP-keyed counters that expire within hours.

You don't have to wait for any of these periods — ask us to delete your data at any time and we will, subject only to records we're legally required to retain.

09How we protect it

  • All traffic to the site is encrypted in transit over HTTPS.
  • Access rules are enforced at the database level with row-level security, so a company account can only read profiles inside an active visibility window and only its own searches and introduction requests. These boundaries are covered by automated tests.
  • Resume files sit in a private bucket readable only by our ops team — never by companies, and never through a public link.
  • Passwords are hashed by our authentication provider. We never see them.
  • Access to the admin console is limited to the ops team that runs the interview loop.

No system is perfectly secure, and we won't claim otherwise. If something goes wrong, the next section says what we'll do.

10Your rights

Under the DPDP Act you have the following rights over your personal data, and we'll honour them regardless of where you live:

  • Access — ask for a summary of the data we hold about you and who we've shared it with. For candidates that includes your skill ratings, round scores and the notes on your record.
  • Correction and completion — have anything inaccurate corrected, or anything incomplete filled in.
  • Erasure — have your data deleted, unless we're legally required to keep it.
  • Grievance redressal — complain to us directly, and get a substantive response.
  • Nomination — nominate another person to exercise these rights on your behalf if you die or become incapacitated.

To use any of these, email hr@distillhire.com from the address on your record. We may need to verify it's really you before acting, especially on a deletion request.

If you're unhappy with how we handle a grievance, you can escalate it to the Data Protection Board of India.

11Data breaches

If personal data we hold is breached, we will notify every affected person directly — describing what happened, what it means for you, what we've done about it, and what you should do — and we will report it to the Data Protection Board of India within the timeframe the law requires.

12Children

DistillHire is for working software engineers and is not directed at children. You must be 18 or older to apply as a candidate or to register a company. We don't knowingly collect data from anyone under 18; if we find that we have, we'll delete it. If you believe a child's data has been submitted to us, tell us at hr@distillhire.com and we'll remove it.

13Changes to this policy

As the platform grows, this policy will change. We'll update the effective date at the top whenever it does. If a change materially affects how we handle your data, we'll email candidates with an active visibility window and every registered company user before it takes effect, rather than relying on you to notice.

14Contact and grievances

For any question about this policy, any request to access, correct or delete your data, or any complaint about how we've handled it, contact our Grievance Officer:

DistillHire — Grievance Officer

hr@distillhire.com

Bangalore, India

We acknowledge complaints within 24 hours and aim to resolve them within 15 days. If you're not satisfied with the outcome, you may take the matter to the Data Protection Board of India.