Opens in a new tab

CandorBrief Plugin Privacy Policy

For CandorBrief Free and CandorBrief Pro
Last updated: September 27, 2026

Who This Is For

This document explains what the CandorBrief WordPress plugin (Free and Pro) does with data once you install it on your own WordPress site. It is written for:

  • the site administrator/professional who installs CandorBrief and builds a profile with it, and
  • visitors to a public CandorBrief profile who submit a contact or access request.

If you are looking for how HighTechDad handles information collected through the candorbrief.com website itself (purchases, support emails, the Licensing Server), see the Site Privacy Policy instead. That is a different, separate document.

If you are a site administrator using CandorBrief, you are responsible for your own site’s privacy policy and data practices. CandorBrief stores customer-selected profile and visitor data within your WordPress installation, on hosting and systems you choose and control. You, not HighTechDad, determine how the plugin is configured, what information is published or collected, which other WordPress components operate on the site, and how privacy requests or security incidents are handled. HighTechDad does not host, access, monitor, administer, secure, or back up that customer-site data.

1. The Short Version

  • CandorBrief is AI-free: it never calls OpenAI, Claude, Gemini, or any other AI service from inside WordPress.
  • CandorBrief Free makes no background network calls to HighTechDad. It includes an optional, admin-initiated “Check for updates” action (see Section 6) that runs only when an administrator chooses it, and, for Pro only, the license activation/renewal check needed to keep Pro working runs on its own schedule.
  • All candidate profile data, Resume/CV content, and visitor contact/access requests are stored within your own WordPress installation. HighTechDad never receives, sees, or hosts this data.
  • CandorBrief Pro’s license check-in never sends candidate, Resume/CV, visitor, or contact data: only the minimum technical information needed to verify the license (see Section 7).

2. Data CandorBrief Stores on Your Site

CandorBrief stores data within your own WordPress installation. Depending on the feature, that can include CandorBrief database tables, WordPress options, WordPress pages or content that you configure, and the WordPress Media Library for profile photos. CandorBrief does not transmit this profile or visitor data to HighTechDad, except for the narrowly described Pro licensing and manual release-check requests in Sections 6 and 7.

Candidate/professional profile data

When you (the professional) build a CandorBrief profile, the plugin stores what you enter or import:

  • name, pronouns, contact details, and profile photo (the photo is stored via the standard WordPress Media Library)
  • structured Resume/CV sections you save or import: work history, education, skills, capabilities, and similar professional content
  • Professional Links you add (website, portfolio, LinkedIn, Indeed, YouTube, custom URLs)
  • your per-item and per-section visibility choices (public/private), which control what a site visitor can ever see

Resume/CV import records

When you use CandorBrief’s guided Resume/CV import flow, the JSON you paste or upload (which you generate yourself, outside WordPress, using a prompt CandorBrief gives you; CandorBrief does not parse or receive your original resume file) is stored in an import log so you can review what was imported. This log is retained in your database until you delete it or reset your profile; CandorBrief does not currently apply an automatic expiration to import logs.

Because you control what goes into that pasted JSON, avoid including personal data you don’t want retained in your site’s database. The plugin’s own import prompt is designed to help you scrub direct personal identifiers before that step, but the final content is your responsibility.

Visitor contact, access request, and invitation data

If you enable Contact & Access or Protected Brief invitations, CandorBrief may store the following within your WordPress installation:

  • a visitor’s name and verified email address
  • organization, role or job context, and optional message content that the visitor chooses to submit
  • request, verification, approval, decline, invitation, revocation, and access status and relevant timestamps
  • securely hashed invitation or access tokens. CandorBrief does not store raw reusable tokens.
  • one-way, IP-derived hash values and rate-limit records used to help detect repeated or abusive request attempts

CandorBrief can verify the visitor’s control of a submitted email address before notifying the profile owner. It can also use rate limits, invalid-attempt controls, and hashed tokens to help reduce spam and unauthorized access. These are reasonable operational safeguards, not a guarantee that spam, malicious traffic, email-delivery failure, unauthorized access, or a security incident will never occur.

This information is not sent to HighTechDad. It remains in your WordPress installation and may also be processed by hosting, email delivery, security tools, and other services you choose. CandorBrief does not add advertising trackers, retargeting pixels, or third-party identity-scoring to these flows.

WordPress core privacy tools. CandorBrief registers selected contact-request and Protected Brief data with WordPress’s built-in Tools → Export Personal Data and Tools → Erase Personal Data features. Depending on the record and feature, erasure may anonymize identifying information while retaining limited non-identifying operational history. The site administrator remains responsible for reviewing, responding to, and documenting privacy requests under the laws that apply to that site.

3. What CandorBrief Never Does

  • It never makes an AI API call from inside WordPress.
  • It never uploads, parses, or transmits your Resume/CV file: import happens by you pasting/uploading JSON you generated yourself, outside the plugin.
  • Free never sends candidate, Resume/CV, visitor, contact, or usage data to HighTechDad, under any circumstance.
  • It never sells or shares your data with advertisers.
  • It never infers or records protected characteristics (race, religion, disability, and similar) as part of its prompt or profile logic.
  • It never makes a final hiring recommendation; it only assembles prompts for a visitor to run in their own AI tool.

4. A Note on Copied Prompts and Third-Party AI

CandorBrief’s Ask feature lets an approved visitor copy a prompt (built from your public, professional-selected profile content) into an AI tool of their own choosing. Once a visitor copies that prompt outside of WordPress:

  • CandorBrief has no visibility into, or control over, what happens next. The visitor’s chosen AI tool processes that prompt under its own privacy policy, not CandorBrief’s or HighTechDad’s.
  • CandorBrief’s prompt guardrails (source-boundary and evidence-ledger instructions) are advisory text embedded in the prompt. They ask the external AI to behave a certain way; they cannot enforce, verify, or guarantee that any third-party AI actually complies.
  • If you make part of your profile public, you should assume that content may be copied into external AI tools by visitors you’ve granted access to. Your own visibility choices (private-by-default, per-item public toggles, and the access modes in Contact & Access) are the real control here, not a promise about what a third-party AI will or won’t do with copied text.

5. Retention and Deletion

  • Candidate/profile data and import logs are retained in your WordPress database for as long as you keep them. You can edit or delete profile content, sections, and Professional Links at any time from the CandorBrief admin screens.
  • Visitor contact, access-request, and invitation data is retained according to your site’s own policy and configuration. CandorBrief supports selected export and erasure requests through WordPress’s privacy tools. Depending on the feature, erasure may anonymize identifying information while retaining limited non-identifying operational history. You, as the site administrator, are responsible for deciding retention periods and handling requests under applicable law.
  • Uninstalling the plugin does not delete your data by default. CandorBrief’s uninstall routine checks a setting (retain_data_on_uninstall); unless you’ve explicitly turned that setting off before uninstalling, your CandorBrief tables and settings remain in your database after the plugin is removed, so you don’t lose data by accident. If you do turn that setting off, uninstalling permanently drops all CandorBrief database tables and options; this cannot be undone, so use it deliberately.

Optional Manual Update Checks (Free and Pro)

CandorBrief includes an optional, administrator-only Check for updates action in CandorBrief → Settings. It runs only when an administrator chooses it. It does not run automatically, in the background, on page load, or through WordPress cron.

When triggered, the release check sends CandorBrief’s release service the installed CandorBrief Free and Pro version numbers, WordPress version, PHP version, and site locale. It does not send your site URL, administrator identity, license data, activation token, profile content, or visitor data.

As with any network request, the release service and its infrastructure may receive normal technical request metadata, including the requesting server’s IP address and request time, for security and operational purposes. The service is described further in the Site Privacy Policy.

7. CandorBrief Pro: License Activation and Renewal

CandorBrief Pro requires an active license verified by the privately operated CandorBrief Licensing Server. This is separate from the optional manual update check in Section 6.

During activation, the installed Pro plugin sends the license key and activation email address entered by the administrator, the canonical site URL, and a request identifier to the Licensing Server. During renewal and deactivation, it sends an activation token, canonical site URL, and request identifier. The service and its infrastructure may also receive ordinary technical request metadata, including the requesting server’s IP address and request time.

The installed plugin does not transmit a separate environment field. The Licensing Server derives an environment classification, either local/development or production, from the canonical site URL it receives, and uses that classification to enforce the license’s production-site activation limit.

The Licensing Server does not receive candidate profile content, Resume/CV data, visitor contact or access-request data, prompt content, page views, administrator activity, or other product-usage analytics. A separately configured local-development endpoint may be used during development. That is endpoint selection, not additional data sent in the request.

If a renewal check fails, is revoked, or expires, CandorBrief Pro fails safe. Pro-only features can become unavailable, but existing Pro data remains on your WordPress site and is not deleted or rewritten by the Licensing Server. See the Site Privacy Policy for HighTechDad’s handling of licensing-service data.

8. Your Responsibilities as the Site Administrator

You control the WordPress environment in which CandorBrief operates. You are responsible for:

  • WordPress core, hosting, SSL and server configuration, themes, other plugins, administrator accounts, backups, and security monitoring
  • the accuracy, legality, consent basis, and public visibility of profile content and other information you publish
  • forms, email delivery, visitor notices, privacy policy, cookie choices, retention practices, and compliance with laws that apply to your use of the plugin
  • responding to data-subject requests, suspected spam, unauthorized access, breaches, and other security or privacy incidents involving your site

CandorBrief provides product controls and privacy-oriented features, but it cannot secure or control the hosting environment, configurations, third-party components, or people who operate your site. HighTechDad is not responsible for a customer site’s breach, compromise, misconfiguration, unauthorized disclosure, or failure to meet legal obligations, except to the extent required by applicable law.

9. Changes to This Policy

We may update this document as CandorBrief’s features change. Material changes (for example, a new feature that introduces a network call) will be reflected here and in the plugin’s changelog.

10. Contact

Questions about this document, or about CandorBrief’s data practices generally, can be sent to: legal@candorbrief.com

Questions about a specific CandorBrief site’s data (your candidate profile, or a request you submitted to a professional) should go to that site’s own administrator; HighTechDad does not have access to it.