Privacy policy

Last updated: 16 September 2026

Workcraft is an AI-assisted hiring platform operated by WUQLA SOFTWARE CO. L.L.C, a company incorporated in Dubai, United Arab Emirates ("Workcraft", "we", "us"). This policy explains what personal data we collect, why, who we share it with, and what rights you have.

It applies to three groups of people:

  • Job candidates who apply for a role through a Workcraft job page, or whose resume is added to Workcraft by a hiring organization.
  • Users who sign in to Workcraft on behalf of a hiring organization.
  • Visitors to our website.

1. Who is responsible for your data

For candidate data, the hiring organization that posted the job or uploaded your resume is the data controller. Workcraft processes candidate data on that organization's behalf and under its instructions. Questions about why a particular organization holds your data, or how it will use it in its hiring decision, should go to that organization. We will still help you exercise your rights, and you can always contact us directly.

For user, organization and visitor data, Workcraft is the data controller.

2. What we collect

From candidates

When you apply through a job page:

  • Your name, email address and, optionally, phone number.
  • Your resume as a PDF.
  • Your answers to any screening questions the organization asked.

When a hiring organization uploads your resume on your behalf:

  • Your resume as a PDF.
  • Your name, email address and phone number, extracted from the resume by our AI system.

In both cases we then generate and store:

  • A structured profile extracted from your resume: work experience, education, skills, and achievements.
  • Scores for how your experience matches the role's stated competencies, with the AI system's reasoning.
  • Your application status, interview details, and any feedback interviewers record about you.

We do not ask for, and our systems do not deliberately extract, sensitive information such as health, religion, ethnicity or political opinions. If your resume contains such information it will be processed along with the rest of the document, so we recommend leaving it out.

From users

  • Your name, email address and profile picture, received from Google or Microsoft when you sign in.
  • Your job title and department, if you add them.
  • Your working hours and time zone, if you set them for interview scheduling.
  • A connection to your Google or Microsoft calendar, if you choose to connect one. We store a reference to that connection, your calendar email address and calendar identifier. We do not copy your calendar into Workcraft.
  • Billing details are collected and held by Stripe. We store only the transaction record and a link to the invoice.

From organizations

  • Company name, website, logo, headquarters location, industry, and descriptive text about the company, its culture, values and perks. Some of this is extracted automatically from your public website when you onboard.
  • Job postings, including screening questions and competency requirements.

From visitors

  • For each public job page, a count of views per day, per visitor country, and per referring website. No individual visitor record is kept.
  • If you consent to analytics cookies, product analytics about how you use our website and app. See section 9.
  • If you use the contact form, the name, email address and message you submit.
  • If you use the support chat, the messages you send and, if you are signed in, your name, email address and profile picture so we know who we are talking to.

3. How we use data

Candidate data is used to assess your application for the specific role you applied to or were added to. Our AI system extracts a structured profile from your resume and scores it against the competencies the hiring organization defined for the role. It also checks answers to screening questions against the organization's requirements.

The AI system does not make hiring decisions. It produces a score and a summary. Every change to your application status, including rejection, shortlisting and hiring, is made by a person at the hiring organization. You have the right to ask that organization for a human review of any decision.

We do not use candidate data, resumes or organization data to train AI models, and our AI providers are contractually prohibited from doing so.

User and organization data is used to provide the service: running your account, posting jobs, scheduling interviews, billing, and sending you transactional email about your account.

Visitor data is used to understand how our website and product are used, to answer your messages, and to show hiring organizations how many people viewed their job and from where.

4. Legal bases

Where the GDPR or UK GDPR applies, we rely on:

  • Steps prior to entering a contract for processing your application when you apply directly.
  • Legitimate interests of the hiring organization in recruiting, and ours in operating the platform, for candidates added by an organization, for aggregate analytics, and for security. You can object to this processing at any time.
  • Performance of a contract for user and organization data.
  • Consent for analytics cookies. You can withdraw it at any time using the cookie button on our website.
  • Legal obligation where we must retain records, for example for tax.

5. Who we share data with

We do not sell personal data. We share it with the service providers below, each of which processes data only on our instructions and under a data processing agreement.

ProviderPurposeDataLocation
SupabaseDatabase, sign-in, and file storage for resumes and imagesAll dataFrankfurt, Germany
VercelWeb hosting and routing of AI requestsAll data passing through the applicationFrankfurt, Germany, and USA for AI routing
AnthropicAI model that extracts and scores resumes and helps write job postingsResumes, screening answers, job and company descriptionsUSA
Trigger.devBackground job processingInternal record identifiers and processing metrics onlyFrankfurt, Germany
PostmarkSending transactional emailRecipient name and email, message contentUSA
StripePayments and invoicingBilling details, entered directly with StripeUSA
NylasCalendar connection for interview schedulingCalendar credentials, interview events including candidate name and emailEU
Google and MicrosoftSign-in, and calendar events when a calendar is connectedSign-in identity; interview eventsGlobal
PostHogProduct analytics, with consent where requiredUsage events, and for signed-in users their name, email and profile pictureFrankfurt, Germany
SentryError monitoringTechnical error reports, without user identityUSA
CrispSupport chatChat messages; name, email and profile picture of signed-in usersEU
UpstashRate limitingOrganization identifiers onlyUSA
FirecrawlExtracting company information from your public website during onboardingYour website addressUSA
FormspreeContact form on our websiteName, email and message you submitUSA

Hiring organizations can share a shortlist of candidates, including names, scores and the AI system's reasoning, with people outside Workcraft by email, for example with a hiring manager. Responsibility for that sharing lies with the organization.

We will also disclose data where required by law, or to protect the rights and safety of Workcraft, our users, or others.

6. International transfers

Workcraft is based in the United Arab Emirates. Our database and file storage are in Frankfurt, Germany. Some of the providers above are in the United States.

Where data about people in the European Economic Area, the United Kingdom or Switzerland is transferred outside those areas, including to Workcraft staff in the UAE and to US providers, we rely on the European Commission's Standard Contractual Clauses or the provider's certification under the EU-US Data Privacy Framework, together with additional safeguards where needed.

7. How long we keep data

  • Candidate data is kept for as long as the hiring organization keeps the job and your application on Workcraft, and until either they or you ask us to delete it. We are working on automatic deletion after a fixed period and will update this policy when it is in place.
  • User and organization data is kept while the account is active and deleted on request after closure, except for records we must keep for tax or legal reasons.
  • Aggregate job page statistics contain no personal data and are kept indefinitely.
  • Analytics data in PostHog is kept for 12 months.
  • Contact form and support chat messages are kept for as long as needed to handle your request.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent. You also have the right to lodge a complaint with your local data protection authority.

Candidates can see everything we hold about an application by signing in to the candidate portal using the link in any email we sent you, or by requesting a new link from the job page you applied to. To delete your data, reply to any email you received from us or write to hi@workcraft.ai. We will confirm deletion within 30 days. If you were added by a hiring organization and did not expect it, tell us and we will remove your data.

Users can edit their name, picture and preferences in the app, and can disconnect their calendar at any time. To close an account or delete an organization, write to hi@workcraft.ai.

We will answer any request within one month. We may ask you to confirm your identity before acting on it.

9. Cookies

We use these cookies:

  • Essential cookies that keep you signed in, remember your cookie choice, and protect the sign-in process. These are always on.
  • One analytics cookie, set by PostHog on the workcraft.ai domain, that lets us understand how visitors find Workcraft and move between our website and app. In the European Economic Area we set this cookie only if you accept it in the cookie banner. You can change your choice at any time using the cookie button in the corner of our website. Outside the EEA, you can block it in your browser settings.

Our support chat runs in a mode that does not set cookies or store data in your browser.

10. Security

Data is encrypted in transit and at rest. Resumes are stored privately and served only through short-lived signed links. API keys are stored hashed. Access to production data is limited to Workcraft staff who need it, and hiring organizations can only see candidates for their own jobs.

11. Data breaches

If a breach puts your data at risk, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires, and notify affected people without undue delay with what happened and what we are doing about it.

12. Children

Workcraft is not intended for anyone under 16, and we do not knowingly collect their data.

13. Changes

We will post changes here and update the date at the top. For material changes we will notify users by email.

14. Contact

hi@workcraft.ai

Google API disclosure

Workcraft's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar access only to check availability and create, update and cancel interview events on your behalf. We do not use Google Workspace APIs to develop, improve, or train generalized AI or machine learning models.