Privacy Policy
Effective June 14, 2026
Acuova ("Acuova," "we," "us," or "our") is a software-as-a-service recruiting CRM independently built, owned, and operated by Will Granchi. We provide recruiters with a workspace to manage candidates, pipelines, client communication, and the day-to-day operations of an executive search practice. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the choices available to you.
1. Who this policy covers
This policy covers personal information processed by Acuova in connection with the Acuova application available at acuova.com (and related subdomains), the Acuova LinkedIn Logger browser extension, and the Acuova integrations with RingCentral and Microsoft 365 (Outlook + Microsoft Graph).
Two data subject groups are involved:
- Recruiters and firm users — the people who sign into Acuova to do their jobs.
- Candidates and client contacts — the people whose information recruiters enter into Acuova as part of a search.
2. What we collect
From recruiters using Acuova:
- Account identifiers (email address, display name, role)
- OAuth access and refresh tokens for connected services (Microsoft 365, RingCentral). Tokens are encrypted at rest using symmetric-key encryption (pgp_sym_encrypt) before being written to our database.
- Application usage data (pages viewed, actions taken) used for telemetry and product analytics.
From connected RingCentral accounts (with the recruiter's explicit OAuth consent):
- Call metadata: phone numbers (caller and callee), call direction (inbound/outbound), duration, timestamp, recording URL (when available).
- Call notes the recruiter records inside RingCentral.
- Webhook subscription identifiers so we can subscribe to and unsubscribe from real-time call events.
We do notstore the audio content of recordings. When a recording URL is present, it is stored as a reference link only and accessed on-demand through the recruiter's RingCentral session.
From connected Microsoft 365 accounts:
- Outlook email metadata and message bodies that the recruiter has access to
- Calendar events and their attendees
- The recruiter's email signature
From candidates and client contacts:
- Name, email, phone number, LinkedIn URL
- Current and prior employers and titles (job history)
- Compensation, location, interview status, and other recruiting context entered by the recruiter
- Notes and call/email summaries the recruiter chooses to record
- Resume documents the recruiter uploads
3. How we use this data
- To operate the Acuova application for our recruiter customers.
- To synchronize phone calls, emails, and calendar events into the recruiter's candidate pipeline (so the recruiter has a single source of truth for every touchpoint).
- To generate AI-assisted drafts (outreach messages, candidate writeups, post-screen emails, summaries) using language models. AI requests include the relevant candidate, pipeline, or interaction context needed to produce the draft.
- To send service-related notifications.
- To detect and prevent abuse, fraud, security incidents, and policy violations.
- To comply with legal obligations, including responding to lawful requests from public authorities.
4. Sharing
We do not sell personal data. We share data only with sub-processors who provide infrastructure for Acuova to operate:
- Supabase — managed Postgres database hosting, authentication, and file storage.
- Vercel — application hosting and edge networking.
- Anthropic— Claude language model API used to generate AI-assisted drafts. Per Anthropic's API terms, inputs and outputs are not used to train its models.
- Microsoft — Microsoft Graph API for Outlook + calendar access (only when the recruiter connects their account).
- RingCentral — RingCentral REST API for phone call sync (only when the recruiter connects their account).
- Google — Gmail API for inbox integration (only when the recruiter connects a Google account).
- Slack — read-only Slack API access to channels the recruiter explicitly selects (only when they connect Slack).
- Sentry — error monitoring and uptime checks (error messages and stack traces; secrets are redacted).
- Cloudflare — off-site storage of encrypted backups (backups are encrypted before upload; Cloudflare cannot read their contents).
- GitHub — source code hosting and the automated jobs that produce encrypted backups (no customer data is stored on GitHub).
Each sub-processor receives only the data needed to perform its specific function. We may also disclose information when required by law, when necessary to protect our legal rights, or in connection with a corporate transaction (merger, acquisition, asset sale) — in which case we'll notify affected customers.
5. How long we keep data
We retain candidate, pipeline, and interaction data for as long as the firm using Acuova remains a customer plus a reasonable wind-down period. On written request from a firm administrator, we will delete the firm's data, and we aim to complete deletion within 30 days. A copy of the firm's data can also be provided on request.
OAuth tokens for connected RingCentral and Microsoft accounts are deleted from our systems immediately when the recruiter disconnects the integration, which ends Acuova's access. The authorization grant recorded on the provider's side remains until removed there — recruiters can additionally revoke it in their Microsoft account settings (“My Apps”) or RingCentral authorized-apps page.
Audit logs (records of who did what, when) are retained for at least one year for security and compliance purposes.
6. Your rights
Depending on where you live, you may have the following rights with respect to your personal data:
- Access to a copy of the data we hold about you.
- Correction of inaccurate or incomplete data.
- Deletion of your personal data (subject to legitimate business and legal exceptions).
- Portability of your data in a machine-readable format.
- Objection to certain processing activities.
Candidates and client contacts: The recruiter who entered your information into Acuova is the "controller" of that data. To exercise your rights, contact the recruiter directly. We can also forward your request to them on your behalf — write to wgranchi@directrecruiters.com.
7. Security
We use industry-standard measures to protect personal data, including:
- TLS encryption in transit.
- Row-level security (RLS) in our Postgres database — every row belongs to an owner and an organization, and reads are scoped accordingly.
- Symmetric encryption at rest for sensitive credentials (OAuth tokens).
- Multi-tenant isolation at the database level.
- Limited access to production data, audited via append-only audit logs.
No system is perfectly secure. If we discover a security incident affecting your data, we will notify affected customers without undue delay.
8. Cookies
We use a small number of essential first-party cookies to keep users signed in and to remember per-user preferences (e.g. dashboard scope, theme). We do not use third-party advertising cookies.
9. Acuova LinkedIn Logger (browser extension)
The Acuova LinkedIn Logger is a companion browser extension to this service, published on the Chrome Web Store and Microsoft Edge Add-ons. It runs locally in the user's browser and is governed by this Privacy Policy.
What it reads
The extension reads only the structured profile data rendered on the LinkedIn profile page (linkedin.com/in/*) the user is actively viewing and chooses to capture: name, headline, current title, current company, location, connection-degree badge, the About summary, skills, and the visible work-history blocks. It does NOT call any private LinkedIn API, and does NOT read, store, or transmit any LinkedIn data the user has not actively requested be captured.
Where data goes
Captured profile data is sent directly from the user's browser over HTTPS to their Acuova account's API. It is stored in that account's Supabase database, governed by the same access controls, retention, and deletion rules as the rest of the Acuova CRM (see sections above). No third party processes or stores the captured data.
Authentication
The extension authenticates against the user's existing Acuova session cookie. It does NOT store or transmit the user's LinkedIn credentials, the LinkedIn session cookie, or any password / API token.
Local storage
The extension uses the browser's extension storage to persist a small set of preferences: the API base URL of the user's Acuova deployment, an optional "my LinkedIn display name" safety net for users who browse from multiple LinkedIn accounts, and UI state (collapsed-section memory). No personal data is held in extension storage.
Telemetry
The extension does not use third-party analytics, telemetry, advertising libraries, crash reporters, or trackers. The only outbound network connections it makes are to the user's Acuova API URL.
Limited Use
Acuova LinkedIn Logger's use of information received from LinkedIn, and from any Google APIs, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Captured data is used only to provide the user-facing CRM features described above. It is never sold, never used for advertising or to build profiles for purposes unrelated to the extension, and never used to determine creditworthiness or for lending.
User control
Users may uninstall the extension at any time via their browser's extension management UI; doing so clears all extension-local storage. To delete captured profile data that was saved into the CRM, delete the candidate record in Acuova (or ask the recruiter who saved it), or use the options in the "Your rights" section above.
10. International users
Acuova is operated from the United States. If you access Acuova from outside the U.S., your information will be transferred to, stored in, and processed in the U.S.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Effective" date at the top of the page and, for material changes, notify customers via email or an in-app notice.
12. Contact
Questions about this policy or our handling of your data? Reach us at wgranchi@directrecruiters.com.