The principle
Keep it while it is useful for a permitted purpose, then destroy or de-identify it.
Australian Privacy Principle 11.2 requires us to destroy or de-identify personal information once it is no longer needed for a purpose we are permitted to use it for. This schedule is how we do that for Kwirl Connect, and the same approach applies to New Zealand and United States users unless a longer legal floor applies.
Retention schedule
Core product data lives with your account. Side signals and soft-deleted content have clocks.
- Account and profile: until you delete your account.
- Posts, comments, likes, active chats, and in-progress applications: while your account is open.
- Finished applications shown in hiring history: until you delete your account (so both sides keep an accurate record).
- Content you delete in the app (posts, comments, chats, Kira/Kwirl sessions, saved Kira library items): hidden immediately; permanently removed about 30 days after you delete it.
- Profile views: 90 days.
- Feed ranking signals: about 14 days.
- In-app notifications: 90 days.
- Activity signals used to personalise Kira (if you opt in): 90 days.
- Interview transcripts for a closed job: removed when the job is closed.
- Moderation / abuse reports: 24 months.
- Billing and tax records: as required by tax and company law (generally several years). We delete your Stripe customer record when you delete your account where we can.
- Trust and safety records for a closed or banned account: up to seven years, so a banned account cannot simply be recreated.
- Encrypted backups: typically roll off within about 30 days after production deletion.
- De-identified analytics: may be kept indefinitely, because it is no longer personal information.
What deletion does
Hidden immediately when you delete in-app; hard-removed on the schedule above.
Deleting an item in the product hides it from you and from feeds immediately. We keep a short soft-delete window (about 30 days) for restore and backup safety, then permanently remove it from live systems.
Deleting your account removes your profile, showcase, social content, chats, Kira sessions and related personal data from live systems on the account-deletion cascade, subject to the billing, trust-and-safety and backup windows above.
If you applied to a job and shared information with an employer, that employer may keep their own copy under their policies — contact them to request deletion of that copy. Material you have already sent in a message is likewise outside our full control once delivered.
Deletion you can run yourself
Export first, then delete.
Settings holds account export and delete-account flows. You can also delete individual posts, comments, chats, Kira sessions and library items in the product.
Employer records
Employers hold their own copies. We tell them the rules.
Employers using Kwirl are separate controllers of the application data they receive, and are required by our Terms to apply their own lawful retention period.
On request we delete an employer workspace and its Kwirl-held candidate records within 30 days, subject to the billing and trust-and-safety retention above.
Questions about this policy
Write to legal@kwirl.com.au for anything on this page, privacy@kwirl.com.au for a privacy request, or security@kwirl.com.au to report a vulnerability. Postal mail reaches us at Kwirl Australia Pty Ltd, Australia.