Key privacy terms
Capitalized terms used in this Privacy Policy have the meanings set out below.
- Bash
- Bash AI Inc., a Delaware corporation, with its principal business office at 7688 Saint Patrick Way, Dublin, California 94568, USA ("Bash", "we", "us", or "our").
- Platform
- Bash's hosted software, including the recruiter workspace, Ask Bash analytics, Live Co-pilot, Advocacy, Assessments, the Lite hiring flow, ATS integrations, and associated APIs, bots, and mobile surfaces.
- Services
- The Platform together with related implementation, support, and professional services provided by Bash.
- Customer
- The organization that has contracted with Bash for the Services (the "tenant"). Where in-product notices say "your organization" or name the hiring company, they refer to the Customer.
- User
- Any individual who accesses the Platform: Staff Users, Candidates, and Third-Party Participants.
- Staff User
- An individual authorized by a Customer to use the Platform under a role-based account (administrator, co-administrator, hiring manager, recruiter, or interviewer), or an authorized Bash operator.
- Candidate
- An individual who participates in a Customer's hiring process through the Platform — for example through an Advocacy conversation, an Assessment, a Lite application, or a recorded interview. Candidates do not create accounts; they access the Platform through personal, time-limited links and codes.
- Verified Candidate
- A Candidate who has opted into the identity-verification flow described in this Privacy Policy.
- Third-Party Participant
- An individual who interacts with the Platform without an account and outside a Candidate flow: assessment collaborators invited by link, external recipients of shared reports, interviewers contributing to job-description enrichment, and participants in meetings that a Recording bot attends.
- Customer Data
- Data submitted to the Platform by or for a Customer, including job, pipeline, and organizational data, and including Candidate Data.
- Candidate Data
- Personal information about Candidates processed through the Platform on a Customer's behalf, as described in Privacy Policy §3.
- Usage Data
- Technical and operational data about use of the Platform (logs, metrics, diagnostics) that does not identify a Candidate except as needed for security and service integrity.
- Recording
- An audio, video, or transcript capture of an interview or meeting made through the Platform's meeting bots or voice features.
- Sub-processor
- A third-party service provider Bash uses to process Customer Data, Candidate Data, or other personal information to help provide, secure, support, or improve the Services.
§1 Who we are & scope
Bash AI Inc. ("Bash") provides a hiring-intelligence platform that employers use to run structured, evidence-based hiring: candidate pipelines and interview scheduling, AI-assisted interview kits and live interview support (Live Co-pilot), pre-interview candidate conversations (Advocacy), skills assessments with integrity monitoring (Assessments), analytics over hiring data (Ask Bash), a high-volume hiring flow (Lite), and integrations with customers' applicant tracking systems.
This Privacy Policy explains how Bash collects, uses, discloses, retains, and protects personal information through the Platform, our websites including bash.ai, online forms, communications, integrations, support channels, and related product experiences. Bash is headquartered in the United States and may process personal information of Customers, Staff Users, Candidates, business contacts, website visitors, and other individuals located in multiple countries. Where a Customer provides additional candidate-facing notices, those notices should be read together with this Privacy Policy.
§2 Our roles: service provider and business
Bash processes personal information in different legal roles depending on the context:
- For Candidate Data processed in connection with a Customer's hiring process, the Customer generally determines the purposes and means of processing and Bash acts as a service provider, processor, or equivalent role under applicable privacy laws. The Customer remains responsible for its hiring decisions, candidate notices, lawful basis, employment-law compliance, accessibility obligations, anti-discrimination obligations, and any consent or authorization required for the relevant hiring workflow.
- For website visitor information, Bash account administration data, Staff User account data, business contact information, support communications, security logs, and information used to operate and improve our own Services, Bash may act as a business, controller, or similar role under applicable privacy laws.
White-labeled experiences. Some Customers may present the Platform under their own brand. In that case, candidate-facing emails and screens may identify the Customer as the sender and Bash as the technology provider. The Customer remains responsible for the candidate relationship, while Bash processes the relevant data as the service provider or processor, as applicable.
§3 Personal information we collect (notice at collection)
The table below summarizes the categories of personal information that may be collected or processed through the Platform and our websites. Not every product or Customer configuration involves every category.
| CCPA category | What this includes on the Platform | Where it arises |
|---|---|---|
| Identifiers | Name, email address, phone number, time zone; links a candidate chooses to share (LinkedIn, GitHub, portfolio); IP address; hashed device identifiers. | All products. Assessments deliberately hold only name and email. |
| Professional / employment information | Resumes and parsed resume content, cover letters imported from a Customer's ATS, application status and outcomes, recruiter notes, reference-check notes, interview evaluations, candidate summaries. | Core workspace; ATS integrations. |
| Audio, electronic, visual information | Interview Recordings and transcripts; Advocacy chat messages and voice notes with transcripts; assessment work product (code submissions, written answers, whiteboards, chats with the built-in AI assistant). | Live Co-pilot; Advocacy; Assessments. |
| Sensitive PI — biometric information | For Verified Candidates only: a verification selfie (portrait) and the result of a one-to-one comparison against a government ID performed by our identity-verification provider. See §7. | Optional identity verification. |
| Sensitive PI — precise geolocation | For Verified Candidate flows only: browser-reported location at defined checkpoints (advocacy gate, assessment start), stored with city-level context. | Optional verification checkpoints. |
| Internet / electronic activity | Assessment integrity signals (see §9); session and connection metadata (IP, user agent, device signals, VPN/proxy indicators where verification is enabled); derived, content-free typing-rhythm statistics; platform logs. | Assessments; verification flows; all products (logs). |
| Inferences | AI-generated summaries, interview kits, evidence packs, assessment scores and reports, integrity ratings, and optional work-style questionnaire results. | Ask Bash; Live Co-pilot; Assessments; Advocacy. |
What we deliberately do not collect
- No webcam, screen recording, or microphone capture during Assessments. Assessment monitoring is limited to the browser signals listed in §9.
- No raw ID document images. Identity verification stores only the verification selfie and a pass/fail result — never the ID document image.
- No date of birth, gender, or nationality from identity documents. Only the verified name is retained from the document.
- No keystroke content. Typing-rhythm signals are derived timing statistics; the Platform never records what was typed outside the answer a candidate submits.
- No protected-category evidence. The Advocacy AI is hard-blocked from asking about age, gender, race or ethnicity, religion, disability or health, marital or family status — and about salary history. If a candidate volunteers such information, it is acknowledged but not recorded as evidence and not followed up.
§4 Sources of personal information
- Directly from you — what you type, upload, or say in an Advocacy conversation, Assessment, interview, or form.
- From the Customer — candidate profiles, resumes, and application data entered by recruiters or imported from the Customer's applicant tracking system through our ATS integrations.
- From meeting platforms — when a Customer schedules a recorded interview, a meeting bot joins the video call and captures the Recording and transcript.
- From verification providers — for Verified Candidates, the identity-verification provider returns the verification decision, document type, and verified name; where fraud-prevention checks are enabled, a device-intelligence provider returns risk signals about the connection.
- From your browser and device — session metadata and, in Assessments, the integrity signals described in §9.
§5 How we use personal information; no sale or sharing
We use personal information to:
- provide the Services a Customer has configured — running conversations, assessments, interviews, reports, and analytics for that Customer's hiring process;
- verify identity and protect assessment integrity, where the Customer enables those features (always surfaced as evidence for human review — see §6);
- operate, secure, and troubleshoot the Platform (authentication, abuse prevention, logging, diagnostics);
- communicate transactionally — interview invitations, assessment links, verification codes, and status updates (we do not send marketing messages to Candidates);
- comply with law and enforce our agreements.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. If our practices change, we will update this Privacy Policy and provide any legally required opt-out mechanism. Where required by applicable law, we will recognize valid opt-out preference signals, including Global Privacy Control, for processing activities to which those signals apply.
Cookies and similar technologies. Our websites and Platform may use cookies, pixels, local storage, analytics tools, and similar technologies to operate the Services, secure sessions, remember preferences, understand site usage, and improve performance. Where required by law, we will obtain consent before using non-essential cookies or similar tracking technologies. If we use advertising or cross-context behavioral advertising tools in the future, we will update this Policy and provide any opt-out mechanism required by applicable law.
AI model training. Bash does not use Customer Data or Candidate Data to train generalized AI models shared across customers unless the Customer expressly agrees in writing and the use is permitted by applicable law. Bash may use de-identified, aggregated, or synthetic information to maintain, test, secure, and improve the Services, provided the information cannot reasonably be used to identify an individual or reveal a Customer's confidential hiring process. Where Bash uses third-party AI, transcription, verification, hosting, or analytics providers, Bash seeks contractual restrictions designed to prevent those providers from using Customer Data or Candidate Data for their own model training, advertising, or unrelated purposes.
§6 AI and automated processing
Bash is an AI product, and we are specific about what the AI does and does not do:
- Evidence, not an employment decision. AI outputs may include interview summaries, suggested questions, evidence packs, skills signals, assessment reports, integrity indicators, and side-by-side comparisons. These outputs are intended to support the Customer's human reviewers and are not intended to automatically reject, select, rank out, or disqualify a Candidate without human review.
- Integrity signals are never auto-scored. Assessment monitoring signals (§9) are presented separately from scores and are never folded into a score. Activity-pattern telemetry is disabled entirely when a Customer grants a candidate accommodations.
- Work-style questionnaires never affect scores. Optional psychometric questionnaires are shared with the hiring team as context only, with an explicit notice that they were not used to rank the candidate; declining is recorded neutrally and is never presented as a red flag.
- Biometric verification is never used for automated hiring decisions. See §7.
- Fairness and audit support. Where available and configured, the Platform may generate de-identified exports or statistical summaries to help Customers or their independent auditors review assessment outcomes. Bash does not intentionally collect protected-category data about candidates, and Customers remain responsible for any demographic data collection, bias audit, adverse-impact analysis, and legal conclusions required under applicable law.
Customers remain responsible for their hiring decisions and for providing any applicant or employee notices, consents, impact assessments, bias audits, accessibility accommodations, human review, appeal rights, and recordkeeping required by applicable AI-in-hiring, employment, anti-discrimination, disability-access, workplace-monitoring, and privacy laws.
For individuals in the European Economic Area, United Kingdom, Switzerland, and other jurisdictions with automated-decision or profiling rights, Bash does not intend the Platform to make decisions based solely on automated processing that produce legal or similarly significant effects. Customers must ensure that any use of Bash outputs in hiring complies with their own legal obligations, including transparency, lawful basis, human review, contestability, and anti-discrimination requirements.
§7 Biometric information
Biometric processing occurs only in the optional Verified Candidate flow, and only with the candidate's separate, express consent:
- What is collected. Our identity-verification provider compares a live selfie against the photo on a government ID to confirm the candidate is the document holder. Bash stores the verification selfie (portrait) and the verification result; the raw ID document images are never stored by Bash, and no date of birth, gender, or nationality is retained from the document.
- Purpose limitation. Biometric data is used solely for one-to-one identity verification in the hiring process the candidate is participating in. It is never used for automated hiring decisions, never used to surveil, and never combined across Customers.
- No sale, lease, or trade. Bash does not and will not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
- Separate optional reuse consent. Showing the verified selfie to an interviewer for comparison at the interview is a separate opt-in, and declining it has no effect on the candidate's application.
- Retention and destruction. Biometric information is retained only for the period necessary to complete and support the verification process, comply with law, resolve disputes, enforce agreements, and protect the security and integrity of the Services. Bash will delete or de-identify biometric information when it is no longer needed for these purposes, when required by law, or when instructed by the Customer or requested by the individual where applicable.
§8 Interview and meeting recordings
When a Customer schedules a recorded interview, a meeting bot joins the video call, visibly identified in the participant list, and captures the Recording and a speaker-labeled transcript at the Customer's direction. Live Co-pilot processes the transcript in real time to surface suggestions to the Customer's interviewer. Recordings and transcripts are Customer Data: the Customer decides when recording is used, who may access it, and how long it is retained, subject to applicable law and this Privacy Policy.
The Customer is responsible for recording notice and consent. The Customer must notify all meeting participants that the meeting may be recorded, transcribed, and analyzed, and must obtain any consent required by applicable law — including all-party consent laws that may apply in certain U.S. states and similar rules in other jurisdictions — before enabling recording or transcription for a meeting.
§9 Assessment monitoring
To keep assessments fair, the assessment runtime records a defined set of browser signals while a candidate works, disclosed on the invitation screen before the candidate consents to proceed:
- paste, copy, and cut events in the assessment window, including pasted-span ranges in the code editor;
- tab focus, window blur, and visibility changes;
- idle periods and coarse typing-activity samples (counts per interval — never keystroke content);
- fullscreen exits and the number of connected displays;
- run and submit actions.
There is no webcam capture, no screen recording, and no audio capture. Everything recorded is evidence for a human reviewer; nothing disqualifies a candidate automatically. Activity-pattern telemetry is switched off when accommodations are granted. For Verified Candidates, a one-time location capture and device check may run before the assessment starts; both are used for integrity review only and are described to the candidate on the invitation screen.
§10 How we disclose personal information
We disclose personal information only as follows:
- To the Customer whose hiring process you are part of — that is the point of the Platform. Advocacy responses are shared with the hiring team only after the candidate consents to sharing.
- To Sub-processors that help us run the Platform, such as cloud hosting and storage providers, AI model providers, transcription providers, identity-verification providers, communications providers, analytics providers, support tools, security providers, and code-execution sandbox providers. Sub-processors are required to process personal information only for authorized purposes and under appropriate confidentiality, security, and data-protection obligations.
- For legal reasons — to comply with law, enforce agreements, or protect rights, safety, and the integrity of the Services.
- In a corporate transaction — in a merger, acquisition, or asset sale, subject to this policy's commitments.
§11 Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide and secure the Services, support the relevant Customer's hiring process, maintain audit and security records, comply with legal obligations, resolve disputes, enforce agreements, and exercise or defend legal claims. Candidate Data retention may depend on the Customer's configuration, instructions, and applicable hiring or employment-law obligations. When personal information is no longer needed, Bash deletes, de-identifies, or aggregates it in accordance with applicable law and internal retention procedures.
§12 Your privacy rights
Depending on where you live, you may have privacy rights under applicable law. These rights may include the right to know or confirm whether we process your personal information, access a copy of it, correct inaccurate information, delete information, restrict or object to processing, obtain portability, withdraw consent where processing is based on consent, opt out of certain disclosures or targeted advertising where applicable, limit certain uses of sensitive personal information, appeal a denied request, and lodge a complaint with a regulator. Bash will not discriminate against you for exercising privacy rights.
How to exercise your rights
- Email privacy@bash.ai. We will verify your identity using information reasonably available to us or the relevant Customer. We will respond within the period required by applicable law and may extend the response period where the law allows.
- Or go through the hiring company. For Candidate Data, the Customer is generally responsible for the candidate relationship and may be the controller or business under applicable law. When a Customer forwards a verified request, Bash will assist the Customer or process the request as required by law. Exercising these rights does not affect your application through Bash.
- Authorized agents may submit requests on your behalf with proof of authorization.
- If applicable law gives you an appeal right and we decline your request, you may appeal by replying to our decision at privacy@bash.ai. We will explain any further regulator or authority contact information where required by law.
§13 International compliance framework
Because Bash is a newly established U.S.-headquartered company that may support Customers, Candidates, Staff Users, website visitors, and business contacts in multiple jurisdictions, this section explains how Bash addresses international privacy and data-protection requirements where they apply. It is intended to be practical and proportionate: Bash does not claim that every law listed applies in every situation, but will apply the relevant requirements when legally triggered.
European Economic Area, United Kingdom, and Switzerland. Where the EU GDPR, UK GDPR, Swiss data-protection law, or similar laws apply, Bash processes personal information on an appropriate legal basis or under the Customer's documented instructions, depending on the context. For Candidate Data processed for a Customer, the Customer is generally responsible for determining the legal basis and providing required notices to Candidates, while Bash processes such data as processor, service provider, or equivalent role. Individuals may also have rights to object to processing, restrict processing, withdraw consent, request portability, and lodge a complaint with a competent supervisory authority.
California and other U.S. state privacy laws. Where U.S. state privacy laws apply, this Privacy Policy is intended to describe the categories of personal information Bash may collect, the sources of that information, the purposes of use, the categories of recipients, the general retention approach, sensitive personal information practices, and the rights request process. Bash does not sell personal information or share it for cross-context behavioral advertising. Sensitive personal information is used only for disclosed and permitted purposes such as identity verification, assessment integrity, security, fraud prevention, service delivery, and legal compliance.
Cross-border transfers. Personal information may be transferred to, stored in, or accessed from the United States and other countries that may not provide the same level of data protection as the country where the individual is located. Where required, Bash will use appropriate transfer safeguards, which may include standard contractual clauses, UK or Swiss transfer mechanisms, supplementary safeguards, transfer impact assessments, or equivalent mechanisms under applicable law.
AI in hiring and employment-related decisions. Bash provides AI-assisted evidence, summaries, assessments, interview intelligence, and workflow tools to support human hiring teams. Customers remain responsible for determining whether their use of the Platform is subject to laws governing automated employment decision tools, high-risk AI systems, profiling, workplace monitoring, anti-discrimination, accessibility, candidate notice, bias audits, human oversight, contestability, accommodations, and recordkeeping. Where required by law, Customers are responsible for providing pre-use notices, obtaining consents, conducting impact assessments or bias audits, maintaining meaningful human review, giving candidates a way to raise concerns, and avoiding use of Bash outputs as the sole basis for legally or similarly significant hiring decisions.
Regional privacy rights. Individuals in certain jurisdictions may have additional privacy rights depending on applicable law, including rights to access, correction, deletion, portability, restriction, objection, consent withdrawal, appeal, complaint to a regulator, and rights relating to automated decision-making or profiling. Bash will respond to such requests as required by law and, for Candidate Data controlled by a Customer, may refer the request to the Customer or act on the Customer's documented instructions.
Biometric, recording, and workplace monitoring laws. If a Customer enables identity verification, interview recording, transcription, assessment monitoring, device checks, location checks, or similar features, the Customer is responsible for confirming that those features are lawful for the relevant jurisdiction and hiring context. This may include obtaining express written consent, providing recording notices, offering reasonable accommodations, complying with all-party consent laws, avoiding prohibited workplace surveillance or emotion-recognition practices, and maintaining any biometric retention, destruction, and disclosure notices required by law.
Customer configuration and local compliance. Bash makes the Platform available as configurable software. Customers are responsible for configuring the Services in a manner consistent with their own legal obligations, sector rules, collective bargaining obligations, hiring policies, job-location requirements, and candidate-facing notices. Customers should not use the Platform to collect protected-category information, make discriminatory decisions, bypass accessibility obligations, or conduct monitoring that is unlawful in the relevant jurisdiction.
Other privacy regimes. Where laws such as India's Digital Personal Data Protection Act, Brazil's LGPD, Canada's privacy laws, Singapore's PDPA, Australia's Privacy Act, Japan's APPI, South Korea's PIPA, or similar laws apply, Bash will take reasonable steps to process personal information in line with applicable notice, consent, purpose limitation, data minimization, security, cross-border transfer, grievance, and individual-rights requirements. For Candidate Data, the Customer remains responsible for job-specific notices, lawful collection, and employment-related compliance in the jurisdiction where the hiring process is conducted.
§14 Children and minors
The Services are not directed to children under 13, and we do not knowingly collect personal information from them. The Platform is intended for hiring and recruitment workflows and should be used only for individuals who are legally permitted to participate in the relevant hiring process. If a Customer's hiring process includes minors, the Customer is responsible for confirming the applicable eligibility, parental consent, employment-law, and biometric-consent requirements before using the Platform for those individuals. If we learn that we have collected personal information from a child or minor without required authorization, we will delete it or process it as required by law.
§15 Security
We use reasonable technical and organizational measures designed to protect personal information, which may include encryption in transit, access controls, secure authentication practices, time-limited access links, logging and monitoring, and safeguards for assessment and verification workflows. Bash continues to develop and mature its security program as the company and Services grow.
No system is perfectly secure. If a security incident affects personal information, we will notify affected Customers, individuals, regulators, or other parties as required by applicable law and contractual obligations.
§16 Changes to this policy
We may update this Privacy Policy as our business, Services, technology, legal obligations, and international operations develop. The effective date at the top reflects the latest revision. If we make material changes, we will provide notice through an appropriate method, such as a website notice, in-product notice, or email to Customer administrators where feasible and required by law.
§17 Contact
Privacy questions and rights requests may be sent to privacy@bash.ai or by mail to: Bash AI Inc., 7688 Saint Patrick Way, Dublin, California 94568, USA. Where applicable law requires a data protection officer, EU/UK representative, grievance officer, or local representative, Bash will provide the relevant contact details through this Privacy Policy, the Platform, or an additional jurisdiction-specific notice.
This Privacy Policy is intended to provide a clear and transparent explanation of Bash's current privacy practices. It should be reviewed periodically as Bash launches new features, expands into new jurisdictions, appoints additional service providers, or materially changes how personal information is collected, used, disclosed, or retained.