Moneko helps recruiting teams search their own resume databases with AI. Resumes are personal data, so we keep this policy specific: what we process, which providers touch it, where it is stored, and how to reach us.
1. Who we are and what this policy covers
Moneko (“Moneko”, “we”, “us”) provides an AI-assisted candidate search service available at https://moneko.app (the “Service”) and this website at https://moneko.ai. This policy explains what personal data we process, why, and what rights you have.
The Service is used by recruiters and hiring teams (“Customers”) to store and search resumes of job seekers (“Candidates”). Two situations are covered here:
- Data about you as a user of the Service or visitor of this website — we act as the controller.
- Candidate data uploaded by a Customer (resumes, contact details, tags, notes) — the Customer is the controller and Moneko acts as the processor on the Customer’s instructions. Section 4 describes this in detail.
2. Data we collect about users
When you create an account or use the Service we process:
- Account data — name, email address, profile picture (if provided), and authentication data managed by our identity provider (Clerk). We never see or store your password.
- Dataspace data — the dataspaces (team workspaces) you belong to, your role in them, and invitations you send or receive.
- Activity data — searches you create (query text, generated summary and requirements, results, pins and hidden candidates), candidates you create, edit, tag or delete, files you upload, and API keys you create. Changes to candidates are recorded in a per-candidate change log together with your name so your team can see who did what.
- Technical data — IP address, browser and device information, timestamps and error logs needed to operate and secure the Service.
- Correspondence — emails you send to hi@moneko.ai.
This website (https://moneko.ai) does not use analytics or advertising trackers. The contact form opens your own email client; nothing is submitted to our servers from this website.
3. How and why we use your data
- To provide the Service — authenticate you, run your dataspaces, parse and index resumes, execute searches and show results (performance of a contract).
- To keep the Service secure and reliable — rate limiting, abuse prevention, debugging, backups (legitimate interest).
- To improve the Service — aggregate, de-identified usage and cost statistics (for example, how long parsing takes or how many tokens a search uses). We do not use your content to train AI models (legitimate interest).
- To communicate with you — service announcements, answers to your requests, billing (contract / legitimate interest). We do not send marketing email without your consent.
- To comply with law — accounting, tax and responding to lawful requests.
4. Candidate data processed on behalf of Customers
When a Customer uploads resumes or sends candidate data through the API, Moneko processes that data only to deliver the features the Customer uses:
- storing the original files and extracted text, and converting Word documents to PDF for display;
- extracting structured fields with AI (job title, name, location, contact details, keywords, summary) and generating a numeric embedding of the resume for semantic search;
- ranking and assessing candidates against a Customer’s search query with AI;
- indexing candidates for keyword search within the Customer’s dataspace.
Candidate data is visible only to members of the Customer’s dataspace and to API keys the Customer creates. Moneko staff access it only to provide support at the Customer’s request or to investigate security incidents.
Customers are responsible for having a lawful basis to upload and process Candidate data, for informing Candidates as required by applicable law, and for handling Candidates’ requests. We assist Customers with access, correction and deletion requests; deleting a candidate in the Service removes the candidate record, files, extracted data and search index entries. Candidates who contact us directly will be pointed to the relevant Customer where we can identify them, and we will assist as required by law.
A data processing agreement (DPA) with the standard terms required by the GDPR is available on request at hi@moneko.ai.
5. AI processing
Moneko uses third-party large language models to read resumes and queries. Resume text (or the PDF itself), the Customer’s search query and the requirements derived from it are sent to the providers below via their APIs:
- OpenAI (GPT-5 family models) — resume parsing, keyword and contact extraction, summaries, requirement extraction, head-to-head candidate comparison and factor assessments. Requests are sent with storage disabled; OpenAI does not use API data to train its models.
- Google (Gemini Embedding API) — numeric embeddings of resumes and queries for semantic search. API data is not used to improve Google’s models.
AI output is assistive. Factor assessments and rankings are generated from the evidence in the resume and may be incomplete or wrong; Customers remain responsible for hiring decisions and for complying with anti-discrimination and employment law. We do not use AI to make automated decisions with legal or similarly significant effects on individuals.
6. Where data is stored and who helps us process it
We use the following service providers (subprocessors):
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Hosting of the application and this website | Global edge network; serverless functions in the EU/US |
| Clerk | Authentication, user accounts, organisations (dataspaces) | United States (EU data transfer safeguards in place) |
| MongoDB Atlas | Primary database (candidates, searches, logs, API keys) | Cloud-hosted cluster |
| Elastic Cloud | Keyword and vector search indices | AWS eu-central-1 (Frankfurt, Germany) |
| Amazon Web Services (S3, Lambda) | Resume file storage and Word-to-PDF conversion | eu-central-1 (Frankfurt, Germany) |
| Upstash | Short-lived locks and coordination (no personal content stored) | Cloud-hosted |
| OpenAI | AI parsing, ranking and assessment (see section 5) | United States |
| Embeddings for semantic search (see section 5) | United States / global | |
| Google Maps Platform | Location autocomplete when editing a candidate’s location | United States / global |
Where data leaves the European Economic Area we rely on the providers’ standard contractual clauses and, where applicable, the EU-US Data Privacy Framework. We will update this list when providers change; material changes are announced to Customers in advance.
7. Retention
- Candidate data is kept for as long as the Customer keeps it in the dataspace. Deleted candidates, files and searches are removed from the primary database and search indices promptly and from backups within 30 days.
- Account data is kept while your account exists. When a dataspace is deleted, its content is deleted; when you delete your account, your profile is removed from our identity provider.
- Technical logs are retained for up to 30 days unless needed for an ongoing security investigation.
- AI usage statistics (token counts, durations, cost) are retained without the underlying content.
8. Security
- All traffic is encrypted in transit (TLS); data at rest is encrypted by our hosting providers.
- Every record is scoped to a dataspace (tenant). Access is verified on each request against your dataspace membership and role.
- API keys are created per dataspace by admins, can be disabled or deleted at any time, and every change made through a key is attributed to it.
- Resume files are served through short-lived signed URLs and are never publicly accessible.
If you believe you have found a security issue, please email hi@moneko.ai. We will respond quickly and keep you informed.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise these rights, email hi@moneko.ai. If your request concerns data held in a Customer’s dataspace, we will involve that Customer as the controller.
11. Changes to this policy
We may update this policy as the Service evolves. The date at the top shows the latest revision. For material changes we will notify Customers by email or in the Service before they take effect.
12. Contact
Moneko — hi@moneko.ai