Privacy
What ReadyReq keeps, who sees it, and how to ask.
This page says, in plain words, what we store, what our AI provider sees, which companies process it for us, how long we keep it, and how to make a request. It describes what ReadyReq does today, not what we hope to build.
Last updated September 28, 2026
Who we are
ReadyReq is a prospecting and CRM tool for recruiting and staffing agencies, based in Calgary, Alberta, Canada, and currently in an invite-only pilot. ReadyReq's founder is the person accountable for how we handle personal information.
We write this policy against Canada's private-sector privacy laws: Alberta's Personal Information Protection Act (PIPA) and the federal Personal Information Protection and Electronic Documents Act (PIPEDA). To reach us about privacy, use the request form at the bottom of this page.
Whose information this covers
- People who use ReadyReq — agency staff with an access code, and the admins who add them.
- People an agency keeps in ReadyReq — contacts at the agency's prospects and clients, and candidates a rep attaches to a lead. The agency decides who is in its book and why; we store and process that information for the agency, on its instructions. If you're one of these people, the agency is the quickest route. If you write to us instead, we'll pass your request to the agency and help it act on it.
- Visitors to this website, including anyone who uses the chat or sends us a request.
What we store
Everything below is kept in our database, separated by agency (a “workspace”). Each item says how long it stays.
- Your workspace
- Your agency's name and settings: the mailing address used in email footers, the overnight-scan switch, the chance of a placement you set for each stage, the digest of the playbook you uploaded, the counts behind learned signal figures, your GST/HST and QST registration numbers and the provinces or states where you collect sales tax, and your Manatal API token if an admin connects Manatal. Kept: While the workspace exists.
- People on your team
- Each person's name, role (admin or member), access code, and desk profile: agency, niche, roles, territory, target titles, email signature and templates. Kept: Until an admin removes the person.
- Leads
- The companies your team works and what it records about them: hiring signals and their sources, contacts (names, titles, email addresses, phone numbers, notes and opt-out flags), calls, emails sent, notes, tasks, deals, placements and fees, the names and titles of any candidates a rep attaches, the company's live count of public job postings (with up to three job titles and the board's address), and — for a company someone watches — when it was last re-checked and what changed. Kept: While the workspace exists. The app can't delete a lead yet, so we delete leads on request.
- Inbox connections
- For a rep who connects Gmail or Outlook: the address, the refresh token the provider issues, the permissions the provider says it granted, and a count of today's sends (and how many of them were automatic follow-ups). Kept: Until she disconnects or is removed from the team.
- LinkedIn connections
- The export file a rep chooses to upload from her own LinkedIn account: each connection's name, company, position, profile link and date. It's used only to spot people she already knows at a company. Kept: Until she uploads a new file or clears it, or is removed from the team.
- Invoices and clients
- Invoice numbers, amounts, tax lines (with the province or state they were charged for and the registration numbers printed on them) and dates; client names, contacts, notes and where each client is billed. Kept: While the workspace exists (they're your financial records). Deleted on request.
- The opt-out list
- Email addresses someone asked your agency not to contact, with who recorded it and when. Kept: For good, on purpose: forgetting an address would let it be emailed again. An admin can lift an entry.
- Requests from our website
- Invite requests and privacy and security requests: name, email, agency, territory, team size, the message, the page it was sent from, and the IP address it came from (to stop floods). Kept: The newest 1,000; any one is deleted on request.
- Feedback
- Messages sent from the app (with the sender's name) or from the website chat (with its last six messages), and the page they came from. Kept: The newest 500.
- Coach questions
- Each question asked of the in-app coach, with the person's name and workspace, so we can see what the coach can't answer yet. Kept: The newest 1,000, across all workspaces.
- Daily usage counters
- A count per access code per day (per IP address for the website chat and forms), to enforce the daily caps; and, for a rep with the morning email on, a mark for each day it went out (so it goes once a day) and how many address-confirmation emails she asked for that day; and, for a rep who disconnects her inbox, how many emails it had sent that day (so connecting again doesn't restart her daily limit). Kept: Deleted after 60 days.
- Manatal radar
- If an admin connects Manatal: the names of your agency's Manatal organizations and the signal found for each. Kept: While the workspace exists.
- Inbox sign-in handoffs
- A one-time token that links a rep to her inbox while she signs in with Google or Microsoft. Kept: Used once, and never valid past 15 minutes.
- Scan receipts
- A record of each scan our server runs for a rep, one she started or her overnight scan: who it ran for, the focus and company size she chose, when it started and finished, and what it found and filed (company names and counts, never anyone's contact details). Kept: 30 days after the scan finishes.
- Personal settings
- Choices each rep makes for herself, each off until she turns it on: whether the overnight scan also looks for her, with the focus and company size she picks; whether she gets the morning email, with the address it goes to, when she said yes or stopped it, and the private link that stops it; her time zone, so “today” in that email is her day; and whether she allows automatic follow-ups from her inbox. Kept: Until she changes them or is removed from the team.
- Scheduled follow-ups
- Only where your agency has switched automatic follow-ups on and a rep sets them up on a lead: each follow-up email exactly as she approved it (who it goes to, the address of the inbox it was approved to go from, the subject and the text), the day it is due, which entries the lead's timeline already held when she set it up (anything logged later stops the follow-ups), and whether it was sent or stopped, and why. Kept: 90 days after it is sent or stopped. One still waiting is stopped by the first daily run after its day is more than 7 days past — in every agency, including one where automatic follow-ups were switched off — so none waits for ever.
On your own device, the app keeps your access code and working copies of your leads in the browser's local storage, so a dropped connection doesn't lose your work. ReadyReq sets no cookies and runs no analytics, advertising or tracking scripts.
What the AI sees
ReadyReq's AI features run on Anthropic's Claude models through Anthropic's API. Each request carries what that feature needs, and no more:
- Scans
- Your desk profile (agency, niche, roles, territory, target titles) and the names of companies to skip — your book and your clients.
- Research on one company
- The company's name and website, your desk profile and the titles you want to reach.
- Finding people
- The company's name and website, the roles you fill and the titles you want to reach.
- Talent scans
- Your niche, territory and roles, and the names of companies you already hold as talent records.
- Look deeper, during a call
- The company's name and website and its top signal.
- Drafts
- The lead's stage, the last call's outcome with up to 160 characters of its note, the next step, its signals and whether each was found on its cited page, the contact's name and title, your agency, niche and roles, your templates, and your first name.
- The coach
- Your question, the lead you have open (its name, website, stage and score, top two signals, up to three contacts' names and titles, the last call, the next step, the number of touches, the deal value and the first 280 characters of its notes), a summary of the list on your screen, and your agency's playbook digest.
- Playbook upload
- The text an admin pastes, once. We store only the digest (up to 3,000 characters), what it covers and its gaps.
- The website chat
- Your messages and the page you're on, plus the niche, territory and lead counts saved in the same browser if you've used the app there.
- The Manatal check
- The names of your agency's Manatal organizations.
Answers from the AI are checked for anything that looks like a secret (keys, database addresses) before they reach a screen. The AI never sends anything itself: a person reviews what it drafts.
Companies that process it for us
These companies handle information on our behalf, each for one job:
- Vercel
- Hosts this website and the app, runs our server code and the overnight scan schedule. Receives: Every request to readyreq.com (and to our earlier address, openreq.vercel.app): the IP address it came from, browser details and the request itself. Vercel keeps request logs for a period it sets.
- Neon
- Our Postgres database: everything listed under “What we store” lives there. Receives: Everything we store. Neon states that it encrypts stored data; that is its commitment, not something our code does.
- Anthropic
- The Claude AI models behind scans, research, drafts, the coach, the website chat and the Manatal check. For scans and research the model also searches the public web itself, on Anthropic's side. Receives: What each feature sends, listed under “What the AI sees”. Anthropic's commercial terms, which cover our API use, say it doesn't train its models on that content — its commitment, not something our code controls.
- Google (Gmail)
- Sends email from a rep's own Gmail when she connects it and presses Send. Receives: The email being sent (recipient, subject, body), and the sign-in that connects the inbox. See “Email” below for exactly what we ask Google for.
- Microsoft (Outlook)
- Sends email from a rep's own Outlook or Microsoft 365 inbox when she connects it and presses Send. Receives: The email being sent (recipient, subject, body), and the sign-in that connects the inbox.
- Kickbox
- Checks whether an email address can receive mail, before a rep sends to it. Receives: The email addresses being checked, and nothing else about the person.
- Manatal
- The agency's own applicant-tracking system, only when an admin connects it with the agency's API token. Receives: When a rep pushes a lead: the company's name and website, its signals, and its decision-makers' names, titles and email addresses (anyone who opted out goes as “opted out, do not contact”, never with an address), plus calls logged on a linked lead. ReadyReq reads back the agency's own Manatal organizations and candidate matches.
- Resend
- Emails us when someone asks for an invite, sends a privacy or security request, or leaves feedback — only once we've switched these alerts on. It sends nothing to reps: their morning email is switched off here, and a rep can only read it inside the app. Receives: The contents of that request or feedback (name, email, agency and message), sent to our own inbox.
- Google Fonts
- Serves the typefaces this website and the app use. Receives: Your browser fetches the fonts straight from Google when a page loads, so Google receives your IP address and browser details. No ReadyReq data goes with it.
Public sources we read
For company-level facts, our server reads these public sources. None of them receives anything about you or your prospects.
- Greenhouse, Lever, Ashby and SmartRecruiters
- Their public job-board feeds, for a live count of a company's open postings. Receives: A request for one company's public board, named from the company's name or website.
- CanadaBuys
- The Government of Canada's open tender notices, for staffing requests for proposals. Receives: A download of the public notice file.
- SAM.gov
- US federal contract opportunities, for staffing requests for proposals — only when we've set it up with a key. Receives: Our key, a date range and the staffing industry codes.
- Indeed Hiring Lab (on GitHub)
- Indeed's openly published job-postings index, for the market trend line. Receives: A download of the public data file.
- Pages a signal cites
- When a signal links to a public web page, our server reads that page to check the signal's names and numbers are really on it: once when the signal is filed, and again while someone on your team watches that company — by our daily run, when it has time left after the overnight scans (at most once a day), and whenever someone re-checks the company by hand: Re-check now, Check now on its Jobs section, or opening it when its job count is missing or more than a week old. Receives: An ordinary page request from our server. Only public addresses are read, and never LinkedIn, Indeed, Glassdoor, ZipRecruiter, Facebook, Instagram or X (Twitter), their link shorteners included. On a watched company's re-check, a page that sends the reader on to another website is not followed.
Search links ReadyReq shows you — LinkedIn, Google and Indeed searches, and a company's own job board — open in your own browser when you click them. Our server never visits LinkedIn, Indeed, Glassdoor, ZipRecruiter, Facebook, Instagram or X (Twitter).
Where it lives
Our database is hosted by Neon and the app by Vercel. The region each one runs in is a setting in those accounts, not in our code; ask us and we'll tell you. AI requests go to Anthropic, a US company, and the other companies above may process information in the United States or elsewhere outside Canada. So your information may be stored or processed outside Canada, where the law of that country applies to it.
If you need your data kept in Canada, ask us before your agency joins. We can't promise that today.
How long we keep it
Each item under What we store says how long it stays. Three moments matter most:
- When a person leaves an agency. An admin removes them on the Team page. Their access code stops working at once (a workspace's first admin code, set up on our side, is changed by us on request), and their team profile, inbox connection and LinkedIn upload are deleted with them. The leads they worked stay with the agency, which owns them.
- When an agency leaves. It can export its lists as CSV and ask us to delete its workspace. We delete it from our live database within 30 days of the request and confirm when it's done. Our database provider keeps a short restore history that expires on its own schedule.
- Counters and logs. Daily usage counters are deleted after 60 days. Our hosting provider keeps request logs for a limited period it sets.
Some deletions are done by hand today rather than by a button: the app can't yet delete a lead or an invoice, so we do it in the database and tell you when it's done.
Email: send-only, and opt-outs that stick
Reps send email from their own Gmail or Outlook inbox, never from a shared ReadyReq address, and only when they press Send. When a rep connects Gmail, ReadyReq asks Google for exactly two permissions: send email as you (gmail.send) and see your email address (userinfo.email). When she connects Outlook, it asks Microsoft to send mail as you (Mail.Send), read your basic profile (User.Read), sign you in (openid), see your email address (email) and keep that permission until you disconnect (offline_access). That is send-only: none of these permissions lets ReadyReq read, search, move or delete anything in an inbox.
Every email carries a footer naming the sender and the agency, a line saying to reply “unsubscribe”, and the agency's mailing address once an admin has set it (until then, the app warns before each send). When someone opts out, any rep can mark it in one tap and the address goes on the agency's opt-out list. Every send is checked against that list before anything leaves, the list never expires, and only an admin can lift an entry.
In Canada, commercial email falls under Canada's anti-spam law (CASL). In short: you generally need the person's consent, express or implied — for example, a business address they published without saying they don't want unsolicited email, when your message is relevant to their role. You must identify yourself and your agency with a mailing address, and you must honour an unsubscribe within 10 business days. ReadyReq's footer and opt-out list are built for those rules, but the agency sending the email is responsible for having consent. This is product information, not legal advice.
Your rights, and how to make a request
You can ask us what information we hold about you and how it has been used, to correct it, to delete it (unless we're required to keep it), or to stop using it for outreach. An agency can ask us to export or delete its workspace. You can also withdraw your consent to how we handle your information; we'll explain what that means for anything that depends on it.
We answer within 30 days, and if we need longer we'll tell you why. We may ask you to confirm who you are before we act, so we never hand your information to someone else.
If you're not satisfied with our answer, you can complain to the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada.
It lands in our request inbox and a person reads it. We use what you send only to answer you.
Changes to this page
When we change this page, the date at the top changes too. If a change affects how we use information we already hold, we'll tell pilot agencies' admins directly before it takes effect. When ReadyReq changes what it asks an inbox for, this page changes in the same release.