Who this covers
Two different groups, with different rights, and it matters which one you are in. Users are people who sign in and run searches. Candidates are people who appear in results — you never signed up for Cobb, and you can still have your record deleted. Jump to If you appeared in a search.
What we collect from users
- Account. The Google address you sign in with, which identifies your workspace. We receive your email address, name and profile picture from Google; we never receive your Google password. Your session is a signed, HttpOnly cookie that lasts up to a year; clearing cookies signs you out.
- Asking for access.If you leave your email on the sign-in page, or sign in with a Google account that isn't on the invite list yet, we keep that address (and the name Google gives us) so we can reply to you. Nothing else is done with it; write to support@hirecobb.com to have it removed.
- Your work in the product. Searches and filters, shortlists, projects, saved contacts, outreach sequences and templates, and the company URL and brief you give us so results can be tuned to your company.
- Usage counts. Number of searches, sequences and revealed contacts, used to show you your own spend estimates. There are no third-party analytics or advertising trackers on this site or in the app.
Google account data
Connecting Gmail is optional and only needed if you want Cobb to send outreach from your own address. When you connect it:
- We request exactly two scopes: gmail.send, which can send mail as you and nothing else, and openid email, to know which address is connected. Cobb cannot read, search, or delete your mail — the send-only scope does not permit it.
- We store your email address and a refresh token, encrypted at rest, so sending keeps working between sessions. We store the messages you send through Cobb, because they are your sequence.
- Cobb's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, which apply to gmail.send as a sensitive scope. Concretely: we use Google user data only to provide the outreach sending you can see in the product; we do not transfer or sell it, or use it for advertising; no human reads it except with your explicit permission, for security, or where the law requires it; and we do not use it to train generalized AI models.
- Disconnect any time from the app, or revoke Cobb at myaccount.google.com/permissions. Revoking stops sending immediately; ask us and we will delete the stored token too.
Candidate data, and where it comes from
To answer a search, Cobb retrieves professional profile records — name, headline, employer, role history, location, public profile URL, and public activity such as posts or repositories. These come from public professional sources, retrieved on our behalf by a data provider. When you reveal a contact, we ask email-lookup providers for a likely work address for that person.
We keep the records that land in a user's workspace so their shortlist still exists tomorrow. We do not build a general-purpose profile database to sell, and we do not sell candidate data to anyone.
If you appeared in a search: write to support@hirecobb.com with your name and profile URL. We will tell you what we hold, delete it on request, and keep it out of future results. You do not need an account, and there is no charge. Depending on where you live you may also have rights to access, correct, or object to this processing — the same address handles those.
Who else processes this data
- Anthropic — your search text and candidate profile snippets are sent to Claude models to interpret the query, rank results, and draft outreach.
- Bright Data — retrieves public professional profile records.
- Prospeo and Hunter — look up work email addresses when you reveal a contact.
- Google — sends the mail you send, if you connect Gmail.
- Netlify — hosting and stored workspace data.
Each receives only what it needs to do that job. We do not sell personal data or share it for cross-context behavioural advertising.
How long we keep it
Workspace data stays until you delete it or ask us to close the workspace, at which point we remove it within 30 days. Deletion requests from candidates are handled on receipt. Some records may persist briefly in backups or provider logs after deletion.
Security, stated plainly
Access is by Google sign-in against an invite list, plus a signed session cookie; data is stored with our hosting provider and the Gmail refresh token is encrypted at rest. Cobb is an early product run by a small team — it has not been through a third-party security audit, and we would rather say so than imply otherwise. Do not put data in Cobb that you could not tolerate being exposed.
Children
Cobb is a business tool and is not for anyone under 16.
Changes
If this page changes materially we will update the date above and, for anything that affects existing users, email you.
Contact
Privacy questions, access requests and deletions: support@hirecobb.com. Everything else: hello@hirecobb.com.