Privacy Policy
Effective 21 August, 2026Reso is operated by Moonjoy Studios B.V., KVK 42136541 ("Reso", "we", "us"). This Privacy Policy explains how we collect, use, and protect personal data when you use joinreso.io and related services (the "Service").
What we collect
- Account data — email address, display name, profile photo, and authentication tokens needed to keep you signed in.
- Profile data — anything you choose to add: bio, specialization, phone, public booking handle.
- Workspace data — job briefs you claim, candidates you add, pipeline state, notes, scheduling records.
- Calendar and scheduling data — if you connect Google Calendar, we store an OAuth refresh token plus your Google email so we can read your free/busy windows, create calendar events, and show connected-calendar video calls in Reso. After a Google Meet ends, Reso may store attendance, duration, transcript text, links to recordings/transcripts/notes that Google makes available, and a generated summary, highlights, action items, and next steps. Reso does not operate or silently record the video call.
- Booking-page invitee data — when someone books a slot via a public booking page, we collect their name, email, and any optional fields configured by the booking owner.
- Candidate interest data — when you introduce yourself through a Reso talent-network intake, we collect the contact details, technical background, career preferences, profile links, and referral information you choose to provide.
- Technical data — standard server logs (IP, user agent, request path) retained on a short rolling window for security and debugging.
We do not sell personal data. We do not use third-party advertising or behavioural tracking SDKs.
Why we process your data
- To provide the Service you signed up for (account, scheduling, workspace).
- To secure the Service and prevent abuse.
- To send transactional emails about your account or activity.
- To contact interested candidates about relevant opportunities and, only with their approval, make an introduction to a specific employer.
- To improve the Service through aggregated, non-identifying analysis.
Google API services
Reso requests the following Google scopes when you connect a Google account. We use them only for the stated purpose, never for advertising or resale.
| Scope | Why we need it |
|---|---|
openid | Identify the user signing in. |
https://www.googleapis.com/auth/userinfo.email | Provision the account against the user's Google email. |
https://www.googleapis.com/auth/userinfo.profile | Populate the user's display name and avatar from their Google profile. |
https://www.googleapis.com/auth/calendar.events | Create, update, and remove calendar events when the user schedules interviews or accepts bookings via their public booking page. |
https://www.googleapis.com/auth/calendar.events.freebusy | Check whether a time is busy before showing it on a public booking page. Reso receives busy windows, not event titles or descriptions. |
https://www.googleapis.com/auth/meetings.space.readonly | Read conference attendance and available Google Meet artifacts after a connected-calendar call so Reso can build the recruiter's meeting record. Reso does not start or record the call. |
https://www.googleapis.com/auth/gmail.send | Send recruiter-authored candidate messages from inside Reso. Reso does not request permission to read the Gmail inbox. |
Reso's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies and analytics
Strictly necessary cookies and local storage keep you signed in and remember your UI preferences. These are required for the Service to work and are used whatever you choose below. We do not use cookies for advertising or cross-site tracking, and we never sell personal data.
We also use privacy-friendly product analytics (Vercel Web Analytics and Speed Insights) to see which pages are used and how fast they load. These are aggregate and cookieless: they set no cookie, store no identifier on your device, do not profile you, and do not follow you across other sites. Because they place nothing on your device, they run on the basis of our legitimate interest in understanding and improving the Service rather than on consent.
You can object at any time: choose Opt out on the notice shown on your first visit, or open Cookie preferences in the site footer. Opting out stops analytics immediately in that browser and leaves the Service fully usable.
Sharing
We share personal data only with vetted service providers that help us run the Service, including Supabase (database, authentication), Vercel (hosting), Google (calendar sync, OAuth sign-in and Meet artifacts), Anthropic (AI interpretation and meeting summaries), and Stripe (payments, where applicable). Each operates under a Data Processing Agreement.
Your rights
You have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Have your data erased
- Receive a portable export of your data
- Withdraw consent at any time
Authenticated users can request a portable data export and can delete their account from the Settings page. For either request, email hello@joinreso.io. We respond within 30 days.
Security
Personal data is encrypted in transit and at rest. Database access is gated by row-level security policies. OAuth tokens are stored encrypted.
Children
The Service is not directed at children under 16 and we do not knowingly collect personal data from them.
Changes
We may update this Privacy Policy from time to time. The "Effective" date at the top reflects the latest substantive update.
Contact
Questions or requests: hello@joinreso.io.
