Back to home

Privacy

Last updated 5 October 2026

RightSource reads job descriptions and ranks candidates against them. That means we hold two kinds of information that matter: the roles you are hiring for, and the people we match to them. This page says plainly what happens to both.

Your job descriptions

When you run a search we store the job description you pasted or uploaded, the requirements our system extracted from it, and the ranked list of candidates it produced. We store these so you can reopen a search later instead of paying to run it again.

Your job descriptions are not used to train AI models. We use Amazon Bedrock to read them. Bedrock does not use the text sent to it to train its models, and we do not use your job descriptions to train anything of our own.

We do not publish your roles. Searching on RightSource does not create a public job post, so the fact that you are hiring is not advertised to competitors, agencies or candidates.

Searching without an account

You can run a search without signing in. When you do, we set one cookie, named rs_guest, containing a random identifier and nothing else — no job description text, no results, no name or email. That identifier is the key that lets your browser see the searches it ran.

  • It lasts 30 days and is readable only by our servers, not by scripts on the page.
  • Searches it points at are deleted after 30 days if you never create an account.
  • If you do sign in, those searches are attached to your account and the cookie is cleared.

Clearing your browser cookies ends that link permanently. We have no other way to connect those searches back to you, so they are deleted on the schedule above.

Candidate information

Candidates in RightSource come from our own talent database, not from your systems. Résumés, work history and contact details belong to the people they describe.

Because of that, candidate names, employers, dates and contact details are masked by default. You see enough to judge fit — skills, seniority, the evidence behind each score — before you see who the person is. Revealing a candidate’s full details is a deliberate, recorded action.

Shared shortlists

You can share a shortlist by link. Anyone holding that link can open it without an account, so treat it like any other confidential document. Shared pages are excluded from search engines, we count how many times each link is opened, and a link can be given an expiry date or revoked.

Cookies we set

  • Session cookie — keeps you signed in. Essential.
  • rs_guest — the 30-day identifier described above, set only once you run a search while signed out.
  • Analytics — we use PostHog to understand which parts of the product are used and where people get stuck.

Who else processes your data

We use Amazon Web Services for hosting, storage and the AI models that read job descriptions, and PostHog for product analytics. We do not sell your data, and we do not share job descriptions or shortlists with anyone outside the service.

How long we keep things

  • Searches run while signed out: 30 days, unless you sign in and claim them.
  • Searches on an account: kept until you delete them or close the account.
  • Shared links: until they expire or you revoke them.

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Candidates can make the same requests about their own records. Write to hello@rightsource.ai and we will respond.

Contact

RightSource · Athena Works — hello@rightsource.ai. Our postal address is in the footer of every page.