Compliance
Privacy tools
Subject-access export and irreversible anonymize for candidate personal data. Owners and admins only.
Where to find it
Open any candidate profile. In the right sidebar, Privacy tools appears when you have privacy.manage and candidates.delete (owners and admins by default). Settings → Workspace → Data & privacy links here too.
Export (subject access)
Download JSON or ZIP (JSON + README). The package includes profile fields, applications, notes you can see under RLS (team notes and your own private notes), email metadata (from/to/subject/timestamps — not full bodies), interviews, scorecards, a file list for resumes, talent pools, and recent activity.
Each download writes candidates.privacy_exported to the audit log. If the audit row cannot be written, the download fails (503) so you never export without a trail. Resume file bytes are not embedded — only the file list.
Delete / anonymize
Type DELETE to confirm. This cannot be undone. Otter scrubs personal fields, clears contacts used for duplicate matching, redacts notes and email content, clears resume parse text and filenames, and soft-deletes the candidate so they leave Candidates and search.
Kept: application rows (job, stage, status, applied/hired/rejected dates) and stage-history timestamps so Reports funnels stay accurate. Audit action: candidates.anonymized.
Files: the candidate's stored files — resumes, and the saved copy of any application email (with its attachments) — are permanently deleted from storage right away and their file records are removed. Audit action: candidates.files_purged (with the number of files removed). If storage is briefly unreachable, the files are kept on a waiting list and deleted on the next try; owners and admins see the count under Settings → Workspace → Data & privacy with a Retry now button.
Private notes authored by other teammates are not in the in-app export; email rohit@otter.diy if you need a service-role dump.