Last updated 5 August 2026. This is the plain-English version, and it is the whole policy — there isn't a longer one hidden somewhere.
Who we are
FlowGT Talent, Christchurch, New Zealand. We're a recruitment agency for AI and engineering roles. Under the Privacy Act 2020 we're the "agency" responsible for your personal information.
For anything on this page, email gabriel.chen@flowgt.co.nz. A human replies, usually within a day.
What we collect, and why
If you paste a CV or a job description into AI Studio
- The full text of whatever you paste — up to about 12,000 characters. If that's a CV, it includes everything in it: your work history, education, and any contact details you left in the document. We store this text.
- The email address you type in, so we can send you the result.
- The AI's analysis — a suggested role, a score out of 100, and a short list of observations. We store this alongside your document.
- Whether you asked for a call back.
We use this to prepare your read, email it to you, and — if it's a fit — talk to you about a role or a hire.
If you fill in the contact form
- Your name, email address, company, and the message you write. We use these to reply to you.
If you create an account
- Your email address, and a temporary six-digit sign-in code. We store a one-way hash of the code, not the code itself, and it expires after 10 minutes.
- A session token in a cookie, so you stay signed in for 30 days. It's a random string — it holds no information about you.
- If you sign in with Google: your Google account ID, your email address, whether Google has confirmed you own that address, and the name on your profile. See "Signing in with Google" below.
- Your name, company, job title and phone number, if you choose to give them.
Automatically, whenever you use the free tools
- A shortened one-way hash of your IP address, plus the date and the type of request. We use it only to stop one person burning through the free daily limit, and we don't store your IP address itself. We should be straight with you though: a hash of an IP address is not perfectly anonymous — someone determined, holding our data, could work backwards to a range of addresses. So we treat it as personal information and delete it on the schedule below.
If we email you first
- Your name, job title and work email address, taken from a page your company published — usually a job advertisement or your own website. We record where we found it and when.
Because we collected that from somewhere other than you, privacy principle 3A (in force since 1 May 2026) says we have to tell you. So the first email we ever send you states exactly where we found your address, why we're writing, and links here. We don't use address-harvesting software, we don't buy lists, and we don't scrape LinkedIn.
We only ask for what's relevant to the role or the enquiry. We don't ask about your age, ethnicity, marital status, health, or anything else with no bearing on the work. If you'd rather not give us something that's fine — but we may not be able to run the analysis or reply.
How we use AI — please read this bit
When you paste a document into AI Studio, we send that text to a large language model called Qwen, running on Cloudflare's Workers AI service. The model reads it and returns a structured opinion: a best-fit role, a score out of 100, and two to four observations.
Three things you should know:
- It's an opinion generated by software, and it can be wrong. It is not a decision about you. Nobody at FlowGT rejects a candidate or drops a role on the strength of a model score — a human reads the document before we act on anything.
- We cache the results. If the exact same text has been analysed before, we return the stored answer instead of running the model again. That means two people who paste an identical document get an identical result, and the second one is seeing an analysis originally generated for the first. If that isn't what you want, email us and we'll delete the cached entry for your document.
- Your document is never used to train an AI model. Cloudflare runs the model for us as a service provider; it does not learn from what we send it.
Who sees it
The FlowGT team, and nobody else — with two exceptions:
- An employer, only after you say yes. We never send your CV or your name to a client without asking you first, every time. We ask per role, not once and forever.
- The companies that run our infrastructure. They store or transmit the data on our behalf and are contractually barred from using it for their own purposes.
We never sell your information.
Where your information goes — overseas processing
We're a New Zealand business, but the tools we run on are not all in New Zealand. Under the Privacy Act these companies act as our agents, which means we stay responsible for your information wherever it sits.
- Cloudflare, Inc. (United States) — hosts this website, our database, and the AI model that reads your document. Cloudflare operates a global network, so processing may happen at a data centre outside New Zealand.
- Resend (United States) — delivers the emails we send you, including your results and your sign-in codes. Your email address and the content of that message pass through their systems.
- Google LLC (United States) — only if you choose to sign in with Google. See below.
These countries do not all have privacy laws identical to New Zealand's. We rely on our contracts with these providers to keep the protection comparable. If you'd rather your CV weren't processed overseas, email us and we'll take your details another way.
How long we keep it — and when we delete it
These are the periods we're committing to. They're new as of this version — we're proposing them, not reporting a long-standing practice. If you think one is too long, tell us.
- CVs, job descriptions and contact-form messages: 24 months from the last time we heard from you, then deleted. If you're an active candidate we'll keep going, and we'll ask you again at 24 months.
- The AI's analysis of your document: deleted at the same time as the document.
- The shared AI cache: 90 days, then cleared.
- Usage records (the hashed IP address and date): 90 days.
- Your account record — email, name, company, title, phone: while your account is open, plus 24 months of inactivity. Any sign-in resets that clock. Before we delete anything, we email you 30 days ahead — one sign-in during those 30 days keeps the account; doing nothing lets the deletion go ahead. Afterwards we keep only a one-way hash of the address in our deletion ledger, so we can prove the deletion happened without keeping who you were.
- Sign-in codes: 10 minutes.
- Sign-in sessions: 30 days, or immediately when you sign out.
- Google sign-in details: deleted when your account is deleted.
- If you tell us to stop contacting you: we keep your email address on a suppression list indefinitely, and nothing else. That's the only way we can be certain we never write to you again.
You don't have to wait for any of these. Ask us to delete your information and we'll do it — no reason needed, no questions asked, and we'll confirm in writing once it's done.
Seeing and correcting what we hold
Privacy principles 6 and 7 give you two rights, and we'll honour both:
- Access. Ask for a copy of everything we hold about you and we'll send it — including our internal notes and any AI-generated assessment, not just the parts that flatter us.
- Correction. Tell us something is wrong and we'll fix it. If we disagree with your correction, we'll attach your version to the record so anyone reading it later sees both.
Email gabriel.chen@flowgt.co.nz. We'll respond within 20 working days, which is what the Act requires, and usually within one or two.
If you're not happy with how we've handled it, you can complain to the Office of the Privacy Commissioner — it's free, and you don't need a lawyer.
Signing in with Google
If you use "Continue with Google", Google tells us four things: your Google account ID, your email address, whether Google has confirmed you own that address, and the name on your profile. We store those to create your account and to recognise you next time.
- We ask Google for sign-in information only — nothing from your Gmail, Drive, Calendar or Contacts. We can't see them and we've never requested access.
- We don't store your Google profile picture.
- Google doesn't stay signed in on our behalf. Once you've arrived we issue our own session, and Google is out of the loop.
- We don't share your Google information with anyone, and we never use it for advertising.
- Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
- You can disconnect FlowGT at any time from your Google account permissions page. To delete what we hold, email us.
Keeping it safe
Your data sits in Cloudflare's database, reachable only through our own code. Access is limited to the FlowGT team, sign-in has no passwords to steal, and the admin view is credential-protected and blocked from search engines.
We're a small team and we won't pretend to be a bank. What we will do: if we ever have a privacy breach that could cause you serious harm, we'll tell you and the Privacy Commissioner, as Part 6 of the Act requires.
Candidates never pay
We charge employers, never candidates. Charging someone a fee for getting them work is illegal in New Zealand (Wages Protection Act 1983, s 12A). If anyone claiming to be us asks you for money, it isn't us — please tell us.
Changes to this policy
If we change it we'll update the date at the top. If a change affects how we use information we already hold, we'll email you before it takes effect. We won't quietly start using your information for something you didn't agree to.