Most recruiting tools ask you to move your candidate data onto their servers just to use the product. knowhash doesn't. Here's exactly where everything lives, and what protects the one thing that ever leaves your browser.
Not one policy trying to cover every case — three genuinely different situations, each handled the way that situation actually calls for.
Lives in your browser's own storage. Never sent anywhere, not even to us, for as long as you're using knowhash normally.
The only copy that ever leaves your browser on purpose, as a file. Encrypted — see below.
Sent when you decide to send them. Once shared, it's your document to manage — same as any attachment.
A local-only tool still needs a way to survive a lost laptop or a wiped profile. That's what backups are for — and it's the one moment we ask you to trust a file instead of just your browser, so it's the one moment we lock it properly.
We'd rather tell you this plainly than have you discover it and wonder what else we didn't mention.
Both exist because you chose to hand that data to someone, on purpose, for them to read. At that point it's a document like any other you've ever emailed — yours to manage, not ours to lock. Encrypting a file you're actively trying to share with someone would just mean building a second system to hand them the key, which defeats the point of never running a server in the first place.
Every recruiting platform that stores your candidates on its own servers is a standing liability that exists for as long as your account does — not a one-off risk, a permanent one.
Every name, contact detail, and CV sits on someone else's server, indefinitely, as long as you keep the subscription. One breach there exposes everyone you've ever added.
Nothing to breach on our end — there's no central database of your candidates to steal, because it was never collected in the first place.