Controller and scope
Provider: RIKHATH LLC, doing business as RaiseFeed
Registered address: 5900 Balcones Drive, Austin, Texas 78731, USA
Governing law: Texas, USA
Legal and privacy contact: imran.hassan@rikhath.com
RIKHATH LLC, doing business as RaiseFeed, controls the personal data described in this Notice. It covers raisefeed.com, professional workspaces, pilot requests, transactional email, billing reconciliation, and the separately gated candidate product. Public browsing requires no account. The Notice does not govern third-party employer, ATS, or source sites.
Information we process
Depending on the feature used, RaiseFeed processes: name and email; organization, membership, role, consent, and access status; pilot-request and business-objective details; workspace notes, saved desks, qualification state, alerts, exports, portfolio imports, and Evidence Packets; authentication challenge and hashed session identities; transactional email purpose, delivery state, and provider identity; billing-provider identifiers, subscription state, amounts, tax totals, and service periods; privacy-safe product events; and candidate information described below.
RaiseFeed also preserves public-source company, job, filing, and event evidence with source URL, observation time, provenance, and review state. Publicly filed names are not automatically relabeled as founders, buyers, or sales contacts, and RaiseFeed does not create scraped personal-contact lists.
Why we process information
We process account, workspace, candidate, and billing-reconciliation data to provide the requested service and perform the contract; request and optional-feature data when you ask us to take steps before a contract or give consent; security, fraud prevention, service reliability, source integrity, and limited product measurement for our legitimate interests where those interests are not overridden; and commercial, tax, legal, and incident records where needed for legal obligations or legal claims. You may withdraw consent for a consent-based feature without affecting earlier lawful processing.
Professional workspaces and authentication
One-time sign-in tokens are stored only as SHA-256 hashes. Session cookies are secure, HTTP-only, same-site cookies used for authentication—not advertising. RaiseFeed product data does not store IP addresses or user agents. Workspace data is organization-scoped and visible to authorized members of that organization according to their role.
Candidate private-data boundary
Candidate accounts may store exact searches, structured preferences, alerts, application tracking, profile fields, match feedback, optional Candidate Pro interest and price responses, and optional application materials. Interest responses contain fixed choices, no free text, and are not treated as purchases. They are included in self-export and deleted with the candidate account. Documents use envelope encryption and short-lived access URLs. Raw document uploads expire after 30 days. Profile fields, local vectors, matches, and application kits preserve source and version lineage and are removed through applicable profile, document, or account deletion cascades. Sensitive demographic, disability, veteran, work-authorization, clearance, compensation, criminal-history, and similar answers are never inferred, never derived from a document, and never used for matching, ranking, or filtering.
Candidate authentication supports a secure email link, an optional password, and Google sign-in. Passwords are stored only as salted, versioned scrypt hashes with an additional server-side secret; plaintext passwords are never stored. Password setup and reset links are hashed, expire after 15 minutes, and work once. When Google sign-in is enabled, RaiseFeed receives the candidate's verified email address, display name, and stable Google account identifier after the candidate chooses an account and approves the flow. RaiseFeed does not receive or store the Google password or OAuth access token. All methods resolve to the same private candidate account and HTTP-only session.
Candidate information is isolated from professional workspaces unless a candidate opts in to being found. Opting in is off by default, records its own consent, and is reversible at any moment with immediate effect. While it is on, a paying recruiting team can search only the headline, desired titles, skills, seniority, workplace and locations the candidate wrote themselves — never applications, tracker, saved searches, blocked companies, documents, or forwarded mail, none of which are part of that query. Every profile a recruiter opens is logged and shown back to the candidate by name and organization.
Optional browser helper
The separately distributed RaiseFeed Application Helper connects to a candidate account through an explicit, short-lived pairing approval. The browser stores a random device secret locally; RaiseFeed stores only its SHA-256 hash, the connection state, extension version, and connection/use timestamps. Once connected, the helper can recognize the exact active employer posting and, when the candidate chooses “Prepare this application,” create or reuse a grounded kit from that candidate's current profile and CV. The posting URL is normalized and hashed locally; RaiseFeed receives the hostname and opaque SHA-256 identity, not the URL path or query string. It fills only fields the candidate reviews and only after an explicit click. It requests local extension storage for the device secret, but no browsing-history, cookie, or clipboard permission. A candidate can disconnect the browser from the helper or candidate settings.
In either delivery mode, the helper may request access to a specific applicant-tracking host, revocably and one host at a time, to reach an embedded form. It does not retain a loaded kit after the helper tab closes or submit applications.
Dynamic analysis starts only when the candidate selects “Analyze unanswered fields.” The extension then sends RaiseFeed the signed short-lived kit and an empty-form description: destination hostname, question labels and descriptions, field kinds, required state, employer option labels, exact field identifiers, and structural fingerprints. It never sends values already present on the employer page, checked or selected state, the full page URL, cookies, page text, CAPTCHA content, files, or file paths. The signed kit contains candidate values RaiseFeed previously generated or stored for that candidate; it is used as the application capability and is not newly retained from the extension request. Employer-page values, page contents, and submission results are not synced to the candidate account.
The extension uses information received from Chrome APIs only to provide this single local review-and-fill function. That use adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements: no unrelated use or transfer, advertising use, sale, or human access to extension-processed content.
Drafted answers to employer questions
RaiseFeed may draft an answer to an employer's own application question. A draft is composed only from what the candidate supplied — their stored autofill answers, their profile, and answers they wrote and saved themselves — together with the role's public description for context. Anything that cannot be traced back to those inputs is refused and the question is left for the candidate. Questions about a protected characteristic are refused outright and are never sent to a model at all.
Drafting runs on Google Cloud's Vertex AI within RaiseFeed's own Google Cloud project, under the terms listed for that processor. What is sent is the employer's question text and the candidate-supplied facts above. When an answer is drafted, documents, equal-opportunity answers, forwarded mail, and any information about other candidates are never sent. That is enforced by which service account holds which key: the identity that drafts answers cannot decrypt a stored document at all. Reading a CV is a separate, opt-in process described below, and it runs as a different identity. RaiseFeed does not use candidate content to train models, and its processor is contractually bound not to.
Every dynamically drafted answer is a suggestion. Direct candidate-entered facts start selected; generated narrative suggestions start unselected. The candidate may edit and must approve each generated suggestion before the helper fills it. RaiseFeed stores only operational metadata for this request (application identity, non-content hashes, counts, model/validator identity, token counts, timestamps and outcome), not the employer form or generated answer text.
Matching, generated explanations and drafted answers all support the candidate’s own review. RaiseFeed does not make a solely automated decision that produces a legal or similarly significant effect, and it never submits a job application without the candidate’s final action.
Reading a CV you upload
A candidate may ask RaiseFeed to read a CV they have uploaded and suggest fields for their profile. This is switched off unless the candidate turns it on, and consenting to store a document does not consent to reading one — they are separate choices, and either can be withdrawn without the other.
When it is on, the text of the uploaded document is sent to Google Cloud's Vertex AI inside RaiseFeed's own Google Cloud project, under the same processing terms already listed for hosting. This adds no new vendor. Only the document's own body text is read: headers and footers are not, so a phone number or postal address placed in one is not part of what is sent. The text is held only for the length of that single read and is never stored. Google does not use this content to train its models.
What comes back is a set of suggestions, one profile field at a time. A suggested value that does not actually appear in the document is discarded before the candidate ever sees it, and so is anything containing contact details or a sensitive-answer category. Nothing enters the profile until the candidate accepts it, field by field. A field accepted as suggested stays linked to the CV it came from: it is excluded from recruiter search, and it is deleted when that document expires. A field the candidate rewrites becomes their own, on the same footing as anything else they typed.
A scanned CV is not put through image recognition. RaiseFeed says it could not read the document rather than guessing at its contents. Withdrawing consent deletes every outstanding suggestion and every profile field that came from a document; fields the candidate entered themselves are unaffected.
Billing and payment data
When live billing is enabled, Stripe processes cards, billing addresses, supported tax IDs, subscriptions, invoices, refunds, and disputes under Stripe’s own notices and its data processing terms. RaiseFeed stores provider identities and the minimum amounts, periods, tax totals, and access state needed to reconcile service and accounting evidence. RaiseFeed does not retain raw Stripe webhook bodies, card numbers, full billing addresses, or tax IDs.
Email and Founderr Pulse
Resend processes recipient address, message content, and delivery metadata for access, verification, invitation, alert, digest, reminder, security, and welcome messages. RaiseFeed does not enable or store provider open/click tracking. Permanent bounce and complaint suppressions are retained as necessary to prevent further delivery. RaiseFeed does not run a parallel newsletter list: newsletter links lead to the separately operated Founderr Pulse subscription flow and its applicable notice and unsubscribe controls.
Forwarded applicant-tracking mail
A candidate may create a private forwarding address and add a rule in their own mail app that sends RaiseFeed a copy of applicant-tracking messages. This is optional, requires its own consent, and can be revoked at any time; revoking stops mail to that address being accepted. RaiseFeed is never in the delivery path — the original message reaches the candidate’s inbox first, and RaiseFeed never receives mail from an employer directly.
Cloudflare Email Routing passes each forwarded copy to RaiseFeed, which reads it once to determine what it states — acknowledged, rejected, interview, offer, or unclassified — and then discards it. RaiseFeed retains only that outcome, the sender’s registrable domain, a subject line with address-shaped text removed, and the time of receipt. Message bodies, attachments, and recipient lists are not stored. Those outcomes update the candidate’s own tracker and contribute to an aggregate reply rate per employer, which is shown only above a minimum sample size. Deleting the candidate account deletes these records with it.
Product measurement and logs
Product analytics accepts only an allowlisted event name, route category, and optional public evidence ID. It does not store visitor IDs, emails, search text, workspace content, CV data, or arbitrary event properties. Application logs and traces are allowlisted and exclude names, email addresses, tokens, cookies, authorization headers, workspace notes, search contents, job descriptions, raw provider payloads, and candidate data.
Recipients and subprocessors
Personal data is disclosed only as needed to authorized organization members, service providers operating under contract, professional advisers, a successor in a legitimate corporate transaction, or authorities when legally required. The current service-provider roles are listed on the Subprocessors page. RaiseFeed does not sell personal data, share it for cross-context behavioral advertising, or use it for targeted advertising.
International processing
RaiseFeed is operated by a Texas company and its primary application database is in the United States. Information may therefore be processed in the United States and other places used by a listed provider. Where applicable law requires a transfer mechanism, RaiseFeed relies on the provider’s contractual data-processing and transfer terms, such as standard contractual clauses or another legally recognized safeguard. Contact us to request information about the safeguard applicable to your data.
Retention
- Unverified pilot requests expire after seven days.
- Rejected, withdrawn, or inactive pilot requests expire after 180 days.
- Onboarded request details are minimized 30 days after activation, leaving only required consent and organization linkage.
- Expired or abandoned checkout intents expire after seven days.
- Successfully provisioned checkout details are minimized after 30 days; required consent, provider, period, amount, tax, audit, and accounting evidence remains.
- Raw candidate document uploads expire after 30 days when document mode is enabled.
- Application logs are retained for 30 days under the production logging policy.
Account and workspace records remain while the account or organization is active and afterward only as needed for a requested workspace, security, dispute, legal claim, or applicable legal/accounting obligation. Candidate account data remains until the candidate deletes the relevant item or account, subject to narrowly required security/legal records. Deleted active data may remain temporarily in encrypted backups until the normal backup lifecycle expires.
Your choices and rights
Depending on your location, you may request access, a copy, correction, deletion, restriction, portability, or objection; withdraw consent; appeal a denied privacy request; and complain to an applicable privacy regulator. RaiseFeed will not discriminate against you for exercising an applicable right. Candidate accounts provide self-service export and deletion. Other requests may be sent to imran.hassan@rikhath.com with “Privacy Request” in the subject. We may verify the request and organization authority before acting. Authorized agents must provide evidence of authority.
Children
RaiseFeed is not directed to children and is not intended for anyone under 18. Do not submit information about a child through a workspace or candidate account.
Security, changes, and contact
We use technical and organizational safeguards described on the Security page, but no system can guarantee absolute security. We may update this Notice when the processing boundary changes. A new version and effective date will be published, and material changes will receive additional notice when required. Questions and privacy requests may be sent to imran.hassan@rikhath.com or mailed to the registered address above.