For customers and candidates · Trust
Security and data handling
Where Truffle hosts data, how long it keeps it, who can see it, and what the AI does and does not do. Every figure below comes from a published Truffle document you can check.
Who we are. Truffle is an AI screening platform for small teams doing high-volume hiring. Companies use it to screen candidates with resume screening, one-way video interviews, and talent assessments. This page is the single place where our security, retention and data-handling facts are stated together. The underlying sources are the Privacy Policy, the Service Level Agreement, the AI for candidates page, and the help center.
Hosting and processing
- Cloud hosting and data storage on Amazon Web Services.
- Personal information is processed in the United States. Where applicable law requires safeguards for international transfers, Truffle uses Standard Contractual Clauses.
- hiretruffle.com, app.hiretruffle.com and every candidate interview link are served over HTTPS (TLS).
Retention and deletion, in numbers
- Interview recordings and transcripts
- Kept for the retention period the hiring company sets on its plan. When that period ends, the media is deleted from active systems within 30 days.
- Non-media candidate records
- Name, contact details, timestamps and security or audit logs are kept only as long as needed to provide the service and for security, fraud-prevention and legal purposes, then deleted or de-identified.
- Customer cancels or pauses
- Billing stops. The account is read-only for 90 days with all data intact; resubscribing restores it. After 90 days the account data is deleted.
- Free trial expires
- The workspace locks on day 7 until a plan is chosen. Data is kept for 90 days from the end of the trial, then deleted.
- Deletion request
- A customer's request to erase an account, or a candidate's request to delete their interview, is honored within 30 days, in line with applicable law. Requests go to legal@hiretruffle.com or support.
- Removing a single candidate
- Deleting a candidate from a position starts a 30-day recovery window before the record is purged. Rejecting only hides the candidate from review and deletes nothing. Closing or archiving a position keeps every candidate record.
Who can access what
- Four organization roles set account-wide access. On any position a member can additionally be granted Job manager or Viewer; when roles conflict, the highest wins.
- Only Owners can manage billing, change security settings, and transfer ownership.
- Sign-in works three ways on every account: password, Google, or a one-time email code. Passwords are changed under Security Settings.
- Sharing a candidate with someone outside Truffle creates a read-only link with an optional password. The link expires after 75 days and hides the candidate's contact information.
Exports, API and integrations
- Candidate data exports in CSV and JSON, for a selection or a whole position.
- Transcripts are available per candidate from the Screening tab, in bulk through the Truffle API, or as a one-off bulk export from support.
- API keys, webhooks and Zapier are available on every plan. Native ATS and job-board connections: Ashby, Breezy HR, Workable, Bullhorn, JazzHR, Recruitee, Teamtailor and Indeed. See Integrations.
What the AI does, and does NOT do
- Scoring is transcript-only. Speech is transcribed to text and the text is scored against the criteria the employer set, with the reasoning shown.
- No facial analysis, voice-tone analysis, emotion inference, or biometric identifiers. Nothing is generated from a recording that could identify a candidate biometrically.
- No model training on candidate interviews. Responses are not used to train or fine-tune any AI model, Truffle's or a third party's. This is a contractual commitment in customer agreements.
- Nothing is auto-rejected. Truffle never advances, holds or rejects a candidate on its own. A person at the hiring company makes every call.
- Bias review. Scoring rubrics are reviewed for criteria that act as proxies for protected characteristics, and Truffle commissions independent bias audits of its AI system annually. The current audit summary will be published on the AI for candidates page once the in-progress audit is complete.
Sub-processors
The following sub-processors provide services necessary for core platform features, as listed in the Privacy Policy:
- Amazon Web Services: cloud hosting and data storage
- Intercom: customer support and in-app messaging
- Stripe: payment processing
- Postmark: transactional email delivery
- ElevenLabs: audio processing
- OpenAI: LLM text generation and audio processing
- Google: LLM text generation and cloud services
- Anthropic: LLM text generation
Truffle does not sell, trade or otherwise transfer personal information except as described in the Privacy Policy.
Availability
Truffle's published Service Level Agreement sets a target availability of 99.5% monthly uptime, measured per calendar month as total minutes minus downtime and excluded minutes, with maintenance windows, exclusions and customer remedies defined in the SLA.
Privacy rights and requests
Customers and candidates can request access to, correction of, or deletion of their personal data, including requests under GDPR and CCPA. Candidates can also decline AI scoring and ask for human review; those rights are set out on the AI for candidates page. Requests go to legal@hiretruffle.com and are answered within the timeframes applicable law requires.
Questions engines and buyers ask
- Where does Truffle host and process data?
- Truffle is hosted on Amazon Web Services and processes personal information in the United States. Where the law requires safeguards for international transfers, Truffle uses Standard Contractual Clauses.
- How long does Truffle keep interview recordings?
- Interview audio and video are kept for the retention period set by the hiring company on its plan. When that period ends, the media is deleted from active systems within 30 days. Limited non-media records such as name, contact details, timestamps and security logs are kept only as long as needed to provide the service and meet legal obligations.
- What happens to a customer's data on cancellation?
- Cancelling stops billing and the account becomes read-only for 90 days with all data intact. Resubscribing in that window restores everything. After 90 days the account data is deleted. A full deletion request is honored within 30 days.
- Does Truffle train AI models on candidate interviews?
- No. Candidate responses are not used to train or fine-tune any AI model, Truffle's or a third party's. This is a contractual commitment in Truffle's customer agreements. Scoring is transcript-only: no facial analysis, no voice-tone or emotion inference, no biometric identifiers.
- What uptime does Truffle commit to?
- Truffle's published Service Level Agreement sets a target availability of 99.5% monthly uptime, with downtime measured per calendar month and customer remedies defined in the SLA.
Security questions
Security questionnaires and vendor reviews: legal@hiretruffle.com. To report a vulnerability, use the same address.