Skip to content

Privacy for employers

What we hold about you when you post a role, in plain language.

Who this is for

This covers the information Michi holds about you as an employer or recruiter. If you are looking for a job, the candidate privacy notice is the one that applies to you. What you may post and what you receive are in the terms for employers.

What we collect

What you give us when you create an account: your email address, your name, your company name, and a password. The password is stored only as a hash, so nobody at Michi can read it, including us.

What the system records as you use it: when the account was created, whether the email address has been verified, and when you last signed in. We use these to run the account and nothing else.

The postings you write, and the counts for them.

Why we use it

To let you sign in, to publish and review your postings, to match those postings against CVs, and to email you about your own account and your own roles. We do not send you marketing you did not ask for.

Who helps us process it

The same providers the rest of Michi runs on. Our database is hosted by Render in Frankfurt, the site itself by Vercel, and account emails such as verification and password resets are sent through Resend. Product analytics run through PostHog and Vercel, and both are cookieless.

The text of a posting is sent to OpenAI so we can extract the skills and tools it asks for, which is what makes it matchable. That is the posting you wrote for publication, not anything private to your account.

Signing in

We do not set a sign-in cookie for employers. Your session is a token kept in your browser's local storage on the device you signed in with, and it is removed when you sign out. Our analytics store nothing on your device and do not follow you across sites, and we do not use cookies for advertising.

How long we keep it

If you create an account and never verify the email address, we delete it automatically after 14 days. An unverified address is one nobody has proven they control, and it may not even be yours, so we do not keep it.

A verified account is kept until you ask us to remove it. We do not delete employer accounts for inactivity today, because doing so while your postings were live would strand roles that nobody could then manage.

Erasing your account

Email help@michi.ge from your account address and we will erase it. That removes your account and your sign-in tokens.

One thing worth saying plainly: postings you already published are unlinked from you rather than deleted. A published role has already been shown to candidates and is part of their match history, and deleting it would quietly rewrite what other people were shown. After erasure nothing on that posting connects it to you. If you want a role taken down, close it first, and then ask us to erase the account.

You are not given candidate data

This notice is about your data, but the other direction matters just as much. Michi does not hand you anyone's CV or contact details, and we do not sell candidate data to anyone. A candidate reaches you by choosing to apply through your own link, or by explicitly opting in to share their profile. What they send you then is covered by whatever law applies to you as its recipient, and by the terms.

Your control

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to erase it. Email help@michi.ge from your account address and we will act on it.

Changes to this notice

We may update this notice as the service grows. When we do, we will update the date below.

This notice is governed by the law of Georgia. Questions? Email help@michi.ge.

Effective date: 28 August 2026.