Privacy Policy

How Submio handles your data.

Last updated: June 28, 2026

Submio (“Submio,” “we,” “us”) is a candidate submission portal built and operated by RemoteBridge. This policy explains what data we collect, how we use it, how long we keep it, and the choices you have. Plain language, no fluff.

1. Who this applies to

This policy covers people who sign up for a Submio account at gosubmio.com (or any domain we operate Submio on), candidates whose information is processed in Submio by recruiters using the product, hiring managers who review candidate submissions via public review links, and visitors to our marketing site.

2. What we collect

2.1 Account information

When you sign up for Submio, we store:

  • Your email address and name
  • The password (hashed, never stored in plaintext) or, if you sign in with Google, the linked identity
  • Account metadata (when you signed up, what plan you're on, last activity)

2.2 Recruiting data you upload

Submio is built for recruiters submitting candidates to hiring managers. When you use the product, you create clients (the companies you recruit for), open roles under those clients, and submit candidates to those roles. The data you upload includes:

  • Candidate information — resume PDFs, video clips from screening calls, your notes, your scorecard ratings, the why-great-fit narrative
  • Client and hiring-manager information — company name, the HM's email address and display name so we can send them review links via Resend
  • Role context — title, scorecard requirements, salary band, and any other context you choose to attach

We store this data in your workspace and use it only to power the submission and review workflow you signed up for — building the candidate submission, generating the public review page for the hiring manager, and recording HM activity (sentiment, stage moves, questions, pass) back to your dashboard.

2.3 Screening-call recordings and transcripts

When you use the AI clip extraction feature, the Submio Notetaker joins the screening call on your behalf (via Recall.ai) and produces a recording and transcript. The Notetaker announces itself when it joins so the candidate knows the call is being recorded. The full recording, transcript, and any extracted clips are owned by your Submio account and stored on our infrastructure; they are deleted when you delete the associated submission or delete your account. Only the clip windows you explicitly approve are exposed to the hiring manager through the public review page.

2.4 Connected Google account (Calendar)

If you connect your Google account to Submio so the Notetaker can auto-join screening calls on your calendar, you grant us OAuth access to read your calendar events. We store:

  • The email address of the connected Google account
  • An OAuth refresh token, encrypted at rest using AES-256-GCM
  • The list of scopes you granted
  • A 14-day-forward window of calendar event metadata (title, attendees, start/end time, video conferencing URL) so we know which calls to dispatch the Notetaker to

We do not read your Gmail mailbox, your contacts, your Drive, or any other Google service. The scopes we request are listed explicitly in section 4 below.

2.5 Hiring-manager interactions on review pages

When you share a public review link with a hiring manager, the HM can react to the candidate without logging in — drop a sentiment, move the candidate to the next stage, pass, ask a question, or email the candidate directly from their own inbox via mailto:. We store the actions the HM takes (timestamp, action type, optional comment) so they appear in your dashboard activity feed. We do not store HM passwords because the review pages are tokenized, not authenticated.

2.6 Usage and diagnostics

We log basic usage information (which pages you visit, which actions you trigger) and error information (stack traces when something breaks). This helps us keep the product working and understand which features get used. We do not sell or rent this data.

3. Limited Use of Google Workspace data

Submio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We only request the Google scopes required to read your primary calendar so the Submio Notetaker can auto-join screening calls. We do not request Gmail mailbox access, Drive access, Contacts access, or any other Google service scope.
  • We do not use Google user data for serving advertisements, including personalized or retargeted ads.
  • We do not sell Google user data, transfer it for advertising, or transfer it to data brokers, information resellers, or any party that does not need access to provide Submio's services.
  • We do not allow humans to read your Google data unless (a) we have your specific consent for them to read specific events, (b) it is necessary for security purposes such as investigating abuse, (c) we are legally compelled to, or (d) the data has been aggregated and anonymized.
  • We do not use Google user data to train, refine, or improve generalized or non-personalized AI or ML models.

4. Why we collect each Google scope

ScopeWhy we need it
calendar.events.readonlyRead events on your primary calendar (next 14 days) so the Submio Notetaker can identify which screening calls to auto-join. Read-only — we cannot create, edit, or delete events.
userinfo.emailRead the email address of the connected Google account so we can show it back to you in the UI and confirm you have connected the account you intended.

5. Who we share data with

We share the minimum data necessary with the following service providers:

  • Supabase — primary database, authentication, file storage
  • Vercel — application hosting
  • Stripe — payment processing for Pro and Team subscriptions. Card numbers never touch our servers; Stripe is PCI-DSS Level 1 certified.
  • Resend — transactional email delivery (account verification, password resets, owner notifications on signup, hiring-manager review-link emails sent from noreply@gosubmio.com)
  • Google — when you connect your Google account so the Notetaker can read your primary calendar. Scopes and Limited Use commitments are described in sections 3 and 4 above.
  • Sentry — error monitoring
  • Inngest — background job orchestration (calendar sync, daily metrics digest, retention sweeps)
  • PostHog — product analytics. We use PostHog to understand which features get used and where users get stuck. We configure PostHog with IP address anonymization and we do not send personally identifying information (email, name) as event properties.
  • Recall.ai — when you send the Submio Notetaker to a screening call, Recall.ai joins the meeting on your behalf, captures the audio and video, and produces a transcript. The Notetaker announces itself when it joins; meeting participants know they are being recorded. The recording, transcript, and any extracted clips are owned by your Submio account and stored in our Supabase infrastructure; we delete them when you delete the associated submission. Recall.ai's privacy policy is at recall.ai/legal/privacy-policy.
  • Anthropic — Claude reads the transcript of your screening calls (when you use the AI clip extraction feature) against the role scorecard you defined, and proposes the most relevant candidate moments as short video clips. Submio data is not used to train Anthropic models — this is contractual under our enterprise agreement, not a courtesy. Anthropic's privacy policy is at anthropic.com/privacy.
  • Cloudflare — we use Cloudflare Turnstile, an invisible bot-mitigation service, on our sign-in and sign-up pages to protect against automated abuse. Turnstile collects limited session and device signals (browser characteristics, IP address, interaction patterns) to determine whether a request is from a human and does not use this data for advertising or for training machine-learning models unrelated to Turnstile. By using these pages you also agree to Cloudflare's Turnstile Privacy Addendum. You can read more about Turnstile in Cloudflare's general privacy policy.

We never sell or rent personal data to third parties.

6. Data retention

We retain account information and recruiting data for as long as your account is active. When you delete your account, we delete or anonymize your data within 30 days, except where we are required to retain it for legal or auditing purposes.

Connected Google account refresh tokens are deleted immediately when you disconnect the account, and we also call Google's revoke endpoint to invalidate the grant on Google's side.

Screening-call recordings and transcripts are retained according to your plan's retention window (60 days on Free, 180 days on Pro), unless you mark a specific recording “Keep” in which case it is retained beyond the standard window. Recordings tied to approved clips are also preserved so the clips never break.

7. Your choices

  • Disconnect your Google account. Open Submio → Your Calls → click Disconnect. We immediately delete the stored token and revoke our access at Google.
  • Revoke at Google directly. Visit myaccount.google.com/connections to revoke any third-party app at any time, including Submio.
  • Export or delete your account data. Email privacy@gosubmio.com and we will respond within 30 days.

8. Security

We use industry-standard practices: TLS in transit, AES-256-GCM encryption for OAuth refresh tokens at rest, scoped database access via row-level security, and least-privilege service accounts for our infrastructure. No system is perfectly secure, but we take this seriously.

9. Children

Submio is a tool for professional recruiters. It is not intended for and not directed at children under 16. We do not knowingly collect data from children.

10. Changes to this policy

We may update this policy as the product evolves. When we make material changes we will notify users via email and update the “Last updated” date at the top.

11. Contact

Questions about this policy or your data? Email privacy@gosubmio.com. We respond within a few business days.