Privacy

How Otter handles candidate and customer data.

Otter processes recruiting data on behalf of customer workspaces. Each tenant is isolated with Postgres row-level security. Resumes and attachments are stored in Cloudflare R2 (or Supabase Storage as a fallback) under tenant-scoped keys.

Workspace owners and admins can fulfil subject-access requests in-product: download a JSON or ZIP package of a candidate's personal data from their profile, or permanently anonymize the profile (type DELETE to confirm). Both actions are audit-logged. Aggregate hiring metrics (application stage history) are kept so funnels stay accurate.

We do not sell personal data. Support impersonation (Super Admin only) is audit-logged and intended for customer support with care. Contact privacy@otter.diy for requests that need a service-role dump (for example notes marked private by another teammate).

This summary will be replaced by counsel-reviewed terms before general availability. Otter does not claim SOC 2 certification.