How personal information is handled across cal.fyi and our other surfaces.
LAST UPDATED: Jul 29, 2026
PhynAI, Inc., a Delaware corporation doing business as Stitch ("Stitch," "we," "us," or "our"), runs an AI-powered recruiting platform spanning candidate sourcing, outreach, interview recording and insights, and applicant tracking.
This Privacy Policy ("Policy") describes the personal information Stitch handles, the reasons we handle it, who else sees it, and the choices available to you. It applies to our website at hirestitch.com (the "Site"), to the candidate-facing scheduling pages we operate on cal.fyi (the "Scheduling Pages"), and to information we collect about job candidates while operating our recruiting platform (together, the "Services").
The Policy does not cover information that we handle strictly on behalf of a customer (for example, data a customer uploads into its workspace, or activity by the customer's authorized users of the product). For that data we act as a service provider / processor, governed by our customer agreement and our Data Processing Agreement rather than this Policy.
A condensed Notice at Collection sits at the bottom of this page. If you want to file a privacy request, head to the Privacy Center.
If you have published professional information about yourself online, we and our data partners may collect that information so we can surface qualified candidates to our customers when they are hiring. Typical sources include resumes and CVs, professional profiles, code repositories and other open-source contribution platforms, patent filings, technical publications and conference materials, talks, podcasts, and other public video or audio content, awards and recognitions, personal websites and portfolios, and similar publicly accessible sources.
The candidate information we may hold includes:
We do not deliberately collect or infer special-category data (for example, health, political opinions, religion, race or ethnicity, sexual orientation, or trade union membership) from public sources.
From the professional information described above, our systems generate inferences such as seniority level, area of expertise, or estimated openness to a new role. These inferences are used inside the platform to support recruiting features such as candidate matching and scoring, outreach personalization, customer-facing review and shortlist surfaces (for example, quick review), and the AI-assisted features customers use to evaluate candidates throughout the recruiting workflow.
Candidate information reaches us through three routes: publicly accessible sources where you have made the information available, data and enrichment partners we work with, and customers who submit information about candidates they have already identified.
When you request a demo, contact sales or support, or create a Stitch account, you tell us things like:
When an authorized user of one of our customers signs in to the Services, we collect information necessary to operate the Services on the customer's behalf. That includes authentication credentials, communications sent through the Services, configuration data such as job descriptions and ideal candidate profiles, integration credentials for third-party services the customer authorizes us to access (typically their email and calendar accounts), and, where the customer enables interview recording, audio, video, and transcripts of interviews conducted through the Services along with the AI-generated summaries and insights derived from them.
Customers control whether to record interviews and are responsible for obtaining any consent or notice required from interview participants under applicable law, including state biometric and wiretap statutes such as the Illinois Biometric Information Privacy Act and the California Invasion of Privacy Act. The information described in this Section 1.c is processed under our customer agreements as a service provider/data processor, and is subject to those agreements rather than this Policy.
Stitch operates brand pages on third-party social platforms. If you follow, message, or otherwise engage with those pages, the platform may share information with us according to its own settings and terms.
To run our business-to-business sales and marketing, we and our partners collect limited professional information about people who work at companies that may be a fit for Stitch (or that already are). This typically includes name, employer, job title and seniority, business email and phone, networking profile, and other publicly available business-context information about that person's role.
Sources are similar in shape to those used for candidate sourcing in Section 1.a: publicly accessible professional sources, B2B data and enrichment vendors, marketing partners, and our own interactions with you (for example, when you visit the Site, request a demo, attend an event, or respond to our outreach).
We rely on the legitimate interests of Stitch and your employer in identifying relevant business opportunities. You can opt out of marketing or ask us to remove you from our records at any time through the Privacy Center.
Loading a page on the Site causes Stitch and a small number of necessary providers to receive standard request metadata, including:
We do not run third-party advertising or analytics cookies on the marketing website. The only cookies the Site sets are strictly necessary to render the page (for example, remembering whether you have dark mode on, or maintaining your session if you've signed in).
Once you are signed into the authenticated app, we use session cookies for authentication, plus product analytics (PostHog), error monitoring and session replay (Sentry, with replays mirrored to our Google Cloud Storage), and infrastructure logs to operate the Services and diagnose issues. None of this powers advertising and we do not share authenticated activity with ad networks.
So candidates can book a call or interview without first being routed through our main site, the Scheduling Pages are served on a separate, neutral domain (cal.fyi). When you book through a Scheduling Page, we receive the name and email address you provide, the time you select, any details you add to the booking, and the standard request metadata described in Section 1.f. We use this information to schedule and confirm the meeting, send reminders, and connect the booking to the customer recruiting campaign it relates to. Booking links we send on behalf of a customer are personalized: when you visit one, we recognize which candidate the link was created for and associate your visit — including the usage data, error reports, and session replays described in Section 1.f — with your candidate record. The underlying calendar and scheduling integration is handled through our infrastructure provider as described in Section 12, and whether we act as controller or processor for this activity follows the framework in Section 7.
Stitch processes candidate information so customers can source, engage, interview, and hire people who may be a fit for their open roles. Under GDPR and equivalent laws, our lawful basis is the legitimate interests of Stitch and our customers in running an efficient recruiting platform that connects qualified professionals with relevant opportunities. We have weighed those interests against candidates' rights: we work only with information that has been published in a professional context, we do not deliberately collect or infer special-category data from public sources, and we honor the rights described in Section 4 (including the right to object) through our Privacy Center.
How customers themselves use the sourcing engine, the AI scoring features, the outreach tooling, and the rest of the product is governed by our Service Agreement with that customer.
Stitch uses artificial intelligence to score and recommend candidates for our customers' open roles. These scores and recommendations are decision-support tools intended to assist humans; they are not used to make decisions producing legal or similarly significant effects on candidates without human review. Customers remain responsible for any hiring decisions and for ensuring that any further automated decision-making they perform with our outputs complies with applicable law. If you are a job candidate and would like more information about how Stitch's AI evaluates candidates, or would like to object to such processing, please contact us through our Privacy Center.
For people who visit the Site, sign in to a Stitch account, or otherwise engage with us in a business context, we use personal information to:
These activities rely on our legitimate interests in running and growing the Services, on the contract we have with you, on your consent where applicable, or on a separate legal duty.
If you take part in the Stitch referral program, we process your account information (including your name and the email address on your Stitch account) to generate and operate your referral link, attribute the companies that sign up through it, calculate and pay any reward, and meet our tax, fraud-prevention, and compliance obligations. When a company signs up through your link, we record that attribution — including a snapshot of your email and the referred company's name at the time of signup — so the reward record stays accurate, and we show you limited status about your referrals (such as whether a referral is in progress and whether a reward has accrued or been sent). We do not share a referred company's confidential account or billing details with you. We rely on our legitimate interests in operating and growing the Services and on performance of the Referral Program Terms; tax reporting relies on our legal obligations. Participation is governed by the Referral Program Terms.
Several features of the Services are powered by third-party AI providers (for example, candidate evaluation, content generation, sourcing match-scoring, and interview summarization). Each of these vendors is contractually restricted to using the data we send them only to deliver the relevant feature, and is prohibited from training their underlying models on Stitch or customer data.
We may disclose personal information to:
Stitch does not exchange personal information with advertisers, brokers, or other parties for advertising revenue. However, candidate data is made available to customers through paid subscriptions to the Services, and laws like the California Consumer Privacy Act and equivalent state statutes treat that kind of disclosure as "selling" or "sharing." Candidates who would like us to remove them from the sourcing database (or stop displaying their information to customers) can request that through the Privacy Center.
Every marketing email we send carries an unsubscribe link; clicking it pulls you off the relevant list. We may still need to send you operational or transactional notices (billing, security, product changes); those are not optional while you are an active user.
Depending on where you live and how you have used the Services, you may be able to ask us to:
The fastest way to submit any of these is the Privacy Center. Email to privacy@hirestitch.com is also accepted, although we may redirect you to the form so we can verify and track the request properly. Statutory windows apply: 30 days under GDPR, 45 days under the CCPA. Before we act, we will ask for enough information to confirm you are the person whose data is at stake; we cannot fulfill a request we cannot verify.
Some laws let a third party submit a request on your behalf. If you would like to use an authorized agent, the agent should provide a signed authorization (or a power of attorney), and we will still confirm your identity directly before acting. Exercising any of these rights will not change the way we treat you.
People in the European Economic Area, the United Kingdom, and Switzerland may also file a complaint with a data protection authority in their country of residence, their place of work, or where they believe an infringement has occurred.
There are limits. We may not be able to act on a request that would compromise someone else's rights, prevent us from delivering a Service you have asked for, or conflict with a legal obligation we owe (a tax retention requirement, for example). If our response leaves you unsatisfied, please use the contact details below.
Stitch is based in the United States, and most of our infrastructure and service providers operate from the United States. Using the Services from outside the U.S. therefore involves transferring your personal information to, and processing it in, jurisdictions whose data protection laws may differ from those of your home country.
When EEA, UK, or Swiss personal data is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Modules 2 and 3) and the UK International Data Transfer Addendum. Both are built into our Data Processing Agreement and the agreements we maintain with each sub-processor.
If you want a closer look at how a particular transfer is safeguarded, email privacy@hirestitch.com.
We keep personal information only as long as we need it for the purposes set out in this Policy or as required by law.
How long we keep any given record depends on the type of information, how sensitive it is, the purpose it serves, whether that purpose can be met with less data, and any retention period we are legally required to observe.
Typical retention buckets:
Our role with respect to personal information depends on the activity:
If you are a job candidate and a customer of Stitch has contacted you using the Services, you may also have rights with respect to that customer in addition to your rights with respect to Stitch. Please contact the relevant customer directly for requests about how that customer is processing your personal information.
Stitch runs a layered security program built around encryption (in transit and at rest), role-based access controls, mandatory multi-factor authentication for personnel, vendor due diligence, and continuous logging and monitoring. The full set of technical and organizational measures we apply to customer data sits in Annex II of our Data Processing Agreement.
If we ever discover a personal data breach affecting customer data, that is, data we handle as a processor on behalf of a customer, we are contractually obliged to alert affected customers without undue delay and, where the breach falls within Article 33 of the GDPR, within the 72-hour notification window. The full mechanics are set out in the Data Processing Agreement.
For personal data where Stitch is the controller, including the candidate sourcing database, information collected from website visitors, and information about customer representatives, we take on those notification obligations directly. If a breach is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the competent supervisory authority within 72 hours of becoming aware of it, in line with Article 33 of the GDPR (and equivalent obligations under the UK GDPR and other applicable laws). Where the breach is likely to result in a high risk to those rights and freedoms, we will also notify affected individuals without undue delay under Article 34, unless one of the exceptions in that Article applies (for example, where the data was rendered unintelligible by encryption, or where individual notice would involve disproportionate effort and a public communication is used instead).
No control surface is perfect. We cannot promise absolute security, and we encourage you to use a strong, unique password and to enable multi-factor authentication on your account.
The Services sometimes link to or embed third-party websites and tools. A link is not an endorsement or a representation of affiliation, and Stitch is not responsible for the content, security, or privacy practices of any external service. Their policies, not this one, apply when you use them.
The Services are intended for adult professionals. Stitch does not direct the Services at children, and we do not knowingly collect personal information from anyone under 16 without parental consent. If we discover that we have, we will delete the information promptly. If you believe a child's data has reached us, get in touch via the How to Contact Us section.
We update this Policy from time to time. When we make a material change, we update the "Last Updated" date at the top of the page and, where required by law, give advance notice via email or in-product before the change takes effect. We recommend checking back periodically.
When a user of one of our customers (for example, a recruiter) connects their Google Calendar to enable scheduling, Stitch, through our calendar and scheduling infrastructure provider, reads the connected user's own calendar events and free/busy information to calculate their availability for interviews, and creates, updates, and deletes events to manage interviews booked through Stitch. We store only the access grant and the booking and scheduling records needed to operate these features, not a copy of the user's full calendar. We handle it as a processor on behalf of the customer (see Sections 1.c and 7).
Stitch's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models. We do not allow humans to read this data except with the user's explicit consent (for example, to provide support they have requested), where the data has been aggregated and anonymized for internal operations, where necessary for security (such as investigating abuse), or to comply with applicable law. A connected user can disconnect at any time from their Stitch settings or revoke access from their Google Account permissions.
PhynAI, Inc., doing business as Stitch, is the legal entity that determines how personal information is processed under this Policy. Where applicable law uses the term "controller" (or "business"), it refers to us.
For questions about this Policy, requests to exercise privacy rights, or anything else: the Privacy Center is the fastest path, and email to privacy@hirestitch.com is also fine.
If neither is workable for you, the postal addresses below are an option.
United States & Global
PhynAI, Inc. 1522 Western Ave STE 24101 Seattle, WA 98101 United States
EU Representative
Osano International Compliance Services Limited ATTN: GXJU 25 North Wall Quay Dublin 1 D01 H104 Ireland
UK Representative
Osano UK Compliance LTD ATTN: GXJU 42-46 Fountain Street Belfast Antrim BT1 - 5EF United Kingdom
A condensed map of what we handle and why. The full picture is in the sections above.
| Data Categories Collected | How We Collect | Primary Purposes of Processing | Key Recipients / Disclosures | Can You Limit Sharing? |
|---|---|---|---|---|
| Identifiers (name, alias, postal address, account or unique personal identifier, online identifier, IP address, email address) | Directly from you, from our data partners, from publicly accessible sources, or if you apply for a job at Stitch | Operating the Services; product improvement and personalization; communicating with you; research; marketing; recruiting | Service providers; customers | Yes, for sharing with customers. See Privacy Center |
| Internet and network activity (browsing on the Site, activity inside the Services) | Captured automatically when you use the Site or product | Operating and improving the Services; security and fraud prevention | Service providers | No |
| Commercial information (records of subscriptions purchased, considered, or in use) | Captured during your use of the product | Delivering the Services; billing and account administration | Service providers | No |
| California Customer Records statute categories (such as name and contact details) | Directly from you, from publicly accessible sources, or if you apply for a job at Stitch | Operating the Services; communicating with you; recruiting | Service providers; customers | Yes, for sharing with customers |
| Professional or employment-related information | Publicly accessible professional sources, our data partners, or your job application | Operating, improving, and personalizing the Services; research; recruiting | Service providers; customers | Yes, for sharing with customers |
| Inferences (e.g., seniority level, area of expertise) | Generated by the Services from the categories above | Improving match quality and outreach relevance | Service providers; customers | Yes, for sharing with customers |
Stitch does not deliberately collect or infer special-category, sensitive, or biometric personal information, and does not knowingly collect data from anyone under 16.
Cookies on the Site are limited to those strictly necessary to render the page; cookies inside the authenticated app are limited to authentication, product analytics, and error monitoring. We run no advertising cookies, no cross-context behavioral advertising, and we do not share personal information with ad networks.