Privacy Policy
Last updated: September 2, 2026
PerfectLaunch.ai (“PerfectLaunch”, “we”, “us”), operated by BookGenius, Inc., provides AI-assisted interview scoring and hiring-workflow software (the “Service”). This policy explains what information we collect, how we use it, and the choices you have. Questions: privacy@perfectlaunch.ai.
Information we collect
- Account & workspace data — your name, email, organization, and the hiring data you enter (roles, candidates, interview scorecards, notes).
- Data from connected services you authorize — your email provider and your calendar (see “Google user data” below), and meeting recordings you ask us to make.
- Usage & device data — standard log data (IP, browser, actions taken) used to operate and secure the Service.
- Data you send from our browser extension, if you choose to install it (see “Browser extension” below).
Analytics & session replay
We use Microsoft Clarity to understand how people use the Service — through behavioral metrics, heatmaps, and session replay — so we can find usability problems and improve the product. Clarity records interactions such as pages visited, clicks, scrolling, and mouse movement, along with device and browser information, using first- and third-party cookies. Text you type into input fields is masked by Clarity before it leaves your browser.
Google user data is excluded from analytics and session replay. Screens that display data from a connected Google account — your candidate email log and your calendar meetings — are masked in the recording before it leaves your browser, so message content, subjects, participants, meeting titles and attendee addresses are never transmitted to Clarity or any other analytics provider. We do not use Google user data to measure, analyze, or improve the Service.
If you are signed in, we associate these recordings with your account (a hashed identifier derived from your email, your name, and your organization) so we can investigate issues you report and understand usage in context. We use this data for product improvement and security purposes — not for advertising. For more about how Microsoft handles this data, see the Microsoft Privacy Statement. To object to this processing, contact privacy@perfectlaunch.ai.
Google user data
If you connect a Google account, PerfectLaunch requests only the scopes needed to power the specific feature you turn on:
gmail.readonly— to read and display your email correspondence with a given candidate on that candidate’s profile, so your team has a shared record of communication.gmail.send— to send emails to candidates from your connected mailbox when you compose them in PerfectLaunch.calendar.events.readonly— to identify which meetings on your calendar are candidate interviews, so the notetaker can join and score them without you pasting a link before every call.userinfo.email— to show you which account you connected.
How we use it. We use this access solely to provide and improve the candidate-communication and interview-recording features described above. We search your mailbox only for messages exchanged with the specific candidate addresses in your workspace, store the resulting messages (subject, participants, timestamp, and body) against that candidate, and send messages you explicitly compose.
How we use calendar data. We read three fields from an event: its start and end time, its video-conferencing link, and its attendee email addresses. Attendee addresses are compared against the candidates already in your own workspace; when a candidate is on the invite, that meeting is treated as an interview and a notetaker is scheduled for it. Access is read-only — we never create, modify, or delete calendar entries. We do not store calendar content: titles, attendees and times are read when you view or when a meeting changes, and are discarded. The only value we retain is an opaque event identifier, used to link a recording to the right interview.
Who else processes it. Calendar synchronization and meeting recording are performed by our vendor Recall.ai, acting on our behalf under contract. To do this it holds the authorization token you granted and reads the calendar events described above. It is not permitted to use that data for any purpose other than providing the feature to you.
How we store it. OAuth refresh tokens are encrypted at rest (AES-256-GCM). Message data is stored in our database, access to which is restricted to members of your organization’s workspace.
What we do not do. We do not use Google user data for advertising, marketing, credit assessment, lending, or any purpose other than providing and improving the user-facing features you turned on. We do not sell it, and we do not use it to train generalized artificial-intelligence or machine-learning models. It is excluded from our analytics and session-replay tooling. Humans do not read it except where strictly necessary (to provide the feature at your direction, for security or abuse investigations, to comply with law, or with your explicit consent).
Limited Use disclosure
PerfectLaunch’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect your data
Security procedures are in place to protect the confidentiality of your data, including data we access through Google APIs. In particular:
- Encrypted in transit. The Service is served only over HTTPS/TLS, with HTTP Strict Transport Security enforced, so data moving between your browser, our servers, and Google’s APIs is encrypted.
- Encrypted at rest. Our database provider encrypts stored data at rest. OAuth refresh tokens — the credentials that grant access to your mailbox and calendar — are additionally encrypted by us with AES-256-GCM before they are written, and are never stored or logged in plaintext.
- Access is restricted. Reaching any of this data requires signing in. Every query is scoped to your own workspace, so members of one organization cannot read another’s. Uploaded files such as résumés and profile photos are held in private storage and served only through authenticated routes that re-check your session and workspace — never from public URLs. Confidential interview questions and their answers are redacted on the server for viewers without permission to see them, rather than merely hidden in the interface.
- The application is hardened. We serve an enforcing Content Security Policy along with standard protective response headers, and we keep dependencies patched against known vulnerabilities.
- Inbound data is authenticated. Webhooks from our meeting-recording vendor are cryptographically signature-verified before we act on them, so a third party cannot inject recordings or events into your workspace.
- Vendors are contractually limited. Service providers that process your data do so under confidentiality obligations and only to provide the feature you turned on. See “Sharing” below for who they are.
- You can withdraw access and have data deleted. See “How you can revoke access & delete data” below. Disconnecting a mailbox or calendar removes the stored credential immediately.
We review these safeguards as the Service changes. If you believe you have found a vulnerability, please report it to privacy@perfectlaunch.ai so we can address it.
Browser extension
We offer an optional Chrome extension, PerfectLaunch — Add candidate from LinkedIn, which you install separately. It exists to save you retyping: when you are viewing a public LinkedIn profile and click its “Add to PerfectLaunch” button, it reads that profile and opens your PerfectLaunch add-candidate form in a new tab with the details filled in. If you do not install it, nothing in this section applies to you.
What it accesses. Only pages on linkedin.com, and no other website. It runs across LinkedIn rather than on profile URLs alone for a technical reason: LinkedIn loads pages without a full browser navigation, so a script limited to profile addresses would never start and the button would never appear. What it does on those pages is add the button, and only on a profile. It reads page content only when you click that button, and it never browses, crawls, or opens pages on its own.
What it reads and transmits. From the profile page: the person’s name, job title, current employer, location, and the profile URL. These are passed to PerfectLaunch in the address of the new tab it opens, so they can be pre-filled on the form. They are stored only if you then save the candidate, at which point they become part of your workspace’s hiring data and are handled like any other candidate record you enter. Job title and employer are used to help you confirm you have the right person and are not stored.
What it stores on your device. Your own preferences only — whether candidates should arrive as “pending review”, and the app address — kept in Chrome’s extension storage and synced by Chrome across your browsers if you have Chrome sync enabled. The extension stores no passwords, API keys, or access tokens; the tab it opens is authenticated by the PerfectLaunch session you are already signed in to. Separately, the app remembers in your browser which role you last added a candidate to, so the form can pre-select it.
What it does not do. It does not read your browsing history, your other tabs, your LinkedIn feed, messages, or searches, or any page other than the profile you are viewing when you click. It contains no analytics, tracking, or advertising code, and loads no remote code. We do not sell data obtained through it, and we do not use it for any purpose beyond creating the candidate record you asked for.
Your role and ours. As with candidate information you type in directly, you (or your organization) decide what candidate data to add and are responsible for having a lawful basis to do so; we process it on your behalf to provide the Service.
Removing it. Uninstalling the extension from chrome://extensions immediately ends all of the access described above and deletes its stored settings. Candidate records you already saved remain in your workspace until you delete them.
How you can revoke access & delete data
- Disconnect a mailbox or a calendar anytime in Settings → Integrations; this removes the stored OAuth token, and disconnecting a calendar also deletes it from our recording vendor and cancels any notetaker it had scheduled.
- Revoke PerfectLaunch’s access directly at your Google Account permissions.
- Uninstall the browser extension at
chrome://extensions; this ends its access to LinkedIn pages and removes its stored settings. - Request deletion of your stored data by emailing privacy@perfectlaunch.ai.
Sharing
We share data only with service providers that help us run the Service (e.g., hosting, database, email-delivery, and analytics vendors) under confidentiality obligations, or where required by law. We do not sell personal information.
Google user data is narrower than that. It is shared only with the providers strictly necessary to operate and secure the feature you turned on — our hosting, database, and error-monitoring providers, and, for calendar auto-join, Recall.ai, which performs the calendar synchronization and meeting recording described above. It is not shared with analytics, session-replay, advertising, or marketing providers, and it is not used to train generalized artificial-intelligence or machine-learning models.
Data retention
We retain workspace and message data for as long as your account is active or as needed to provide the Service, then delete or anonymize it within a reasonable period, unless a longer period is required by law.
Changes
We may update this policy; material changes will be reflected by the “Last updated” date above.
Contact
BookGenius, Inc., 156 Hourglass Dr, Venice, FL 34293 — privacy@perfectlaunch.ai