Privacy Policy
01Who we are
Dart Hit (“we”, “us”, or “the service”) is a workspace for job seekers, business developers, and hiring teams to research, personalise, and reach out to people from a single AI-assisted cockpit. This policy explains what data flows through the service, why, and what you can do about it.
Contact us at hello@darthit.com for any privacy question — we’re small, we read every message.
02Data we collect
We collect the minimum needed to run the workspace you signed up for. Three buckets:
- Account data
- Email address, name, hashed password, verification codes, session tokens, and OAuth tokens for mailboxes you connect (Gmail). Passwords are hashed with bcrypt; we never store or see the plaintext.
- Workspace data
- Everything you create inside the app — your Ideal Customer / Candidate Profile, resume text, campaign steps, notes, shortlist entries, and any contacts you save. This includes AI-generated drafts (email steps, cover letters, replies) attached to your workspace.
- Third-party research data
- When you launch a LinkedIn sourcing run through the built-in Apify actors, the returned profile data (name, current role, current company, public headline, skills, tenure, public photo URL) is stored in your workspace so you can score, shortlist, and reach out to those people. See §5 for the full third-party list.
- Usage + operational data
- Standard server-side telemetry — request paths, response times, error stack traces, and IP-derived country for debugging. Credit-event log entries record every metered action so you have a full billing audit trail.
03How we use your data
Only in service of running Dart Hit for you:
- Deliver the workspace you signed up for — dashboards, sourcing, AI drafts, sequences, inbox, billing.
- Send transactional email (verification codes, password resets, run-completion notifications). We do not send marketing email unless you opt in.
- Charge credits and — when we launch paid tiers — process subscription payments through Stripe.
- Ground AI prompts in your saved profile data (resume, blurb, ICP, IHP, proof points) so drafts feel like you wrote them.
- Detect abuse — rate limits, disposable-email blocking, unusual sending patterns.
- Improve the service — aggregated, non-identifying metrics only. We never train third-party models on your data (see §5).
04Legal basis (GDPR / equivalents)
We process personal data under the “contract necessity” basis — you signed up for a workspace, we run it. For research data returned by sourcing runs (which may include personal data of third parties), our lawful basis is “legitimate interest” provided the outreach is professional, non-spammy, and complies with local email/ anti-spam law. You are responsible for that compliance — see the Terms of Service.
05Third-party services we send data to
Running the workspace requires a handful of specialised vendors. We use only what’s needed and prefer providers with strong privacy postures:
- Anthropic + OpenAI
- AI model calls for drafting emails, cover letters, ICPs, and scoring. We send only the fields the specific prompt needs. Both vendors have zero-retention policies for API traffic and do not train on it.
- Apify
- Managed actor runs for LinkedIn profile / company / job sourcing. We pass the search parameters you configure and receive structured data back. Apify's own privacy policy applies to the run infrastructure.
- Google (Gmail OAuth)
- If you connect a Gmail mailbox, we store the OAuth refresh token needed to send/receive from that mailbox on your behalf. We never read messages that aren't sequence responses or their threads.
- Resend
- Transactional email (verification codes, run notifications). We send email address + short-lived code; nothing else.
- Railway
- Managed Postgres + application hosting. Data is encrypted at rest and in transit.
- Stripe (planned)
- When paid tiers launch, Stripe will process payment details. We never see your card number.
06How long we keep data
- Account data — retained while your account is active. Deleted within 30 days of account deletion.
- Workspace + research data — retained while your account is active. You can delete individual items (contacts, campaigns, runs) at any time; deletions are immediate and cascade.
- Credit event ledger — retained for the lifetime of the account for billing audit, then deleted 90 days after account deletion.
- Server logs — 30 days, then rotated.
07Your rights
You can exercise any of these at any time from within the app or by emailing hello@darthit.com:
- Access — every field is visible in the workspace UI. If you want a machine-readable export we’ll generate one within 30 days.
- Correction — edit any workspace field directly.
- Deletion — from /profile, the “Delete account” button removes your account and all owned rows within 30 days. Third-party research data (contacts you sourced) is deleted with your account.
- Data portability — CSV export is available for contacts, jobs, companies, and runs from /settings.
- Withdraw consent — disconnect any integration (Gmail, etc.) from /integrations.
09Security
- TLS 1.2+ everywhere — the site is served exclusively over HTTPS.
- Passwords hashed with bcrypt (never stored plaintext, never logged).
- Sessions are stateful JWTs with a per-user session version — logging out invalidates every existing session immediately.
- Email verification required on signup; disposable-email domains and plus-alias games are refused at the door.
- Postgres encrypted at rest by our hosting provider (Railway).
No system is unbreakable. If you spot a vulnerability, please email hello@darthit.com with details. We respond within 48 hours.
10Children
Dart Hit is a professional workspace and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe we’ve received data from a minor, email us and we will delete it.
11International transfers
Our infrastructure runs primarily in US-region data centres (Railway, Anthropic, OpenAI, Resend, Apify). If you access Dart Hit from another region your data will be transferred to and processed in the US. We rely on Standard Contractual Clauses and vendor certifications where applicable.
12Changes to this policy
If we make material changes we will notify signed-in users by in-app banner at least 14 days before the change takes effect, and we’ll update the “Last updated” date at the top of this page. Continued use after the effective date counts as acceptance; if you disagree, delete your account before then.
13Contact
Data controller: Dart Hit (darthit.com). Written notice: hello@darthit.com. We respond within five business days.
