Policy
Can a Company Train Its AI on Your Application?
A company can train AI on your job application, and the clause permitting it has a standard shape once you know where to look. Purpose limitation, the core privacy principle in GDPR and echoed in California's rules, says data collected to evaluate you for a role can't be repurposed for something incompatible, like training a general model, unless the notice separately says so and a lawful basis backs it. Read for who's actually doing the processing, the employer or a vendor, and whether an opt-out is offered.
The takeRead the clause before assuming the worst. A privacy notice mentioning model improvement is usually about improving the specific tool that screens applicants, tuned on aggregate patterns across many resumes, not about your file becoming a named part of a general-purpose model anyone can prompt. That distinction matters for how worried to be and it rarely shows up in the sentence that scares people. The separate, more common thing worth worrying about is a rejection you can't get explained, and that has a different set of rights behind it entirely.
Where Olive fits
Open a role and see what the work shows
Olive produces no automated decision and no composite score at all: a person writes each of six findings, each carries the evidence excerpt it rests on, and the candidate is granted the same report as the employer on every tier.
Rank your shortlistWhat Does the Clause Actually Permit?
Start from the rule the clause is written against, not the clause itself. Purpose limitation, spelled out in Article 5(1)(b) of the GDPR, requires that personal data be collected for specified, explicit purposes and not further processed in a way that's incompatible with them 1.
Applied to a job application, that means data collected to evaluate you for a role can't quietly become training material for a general model unless the notice separately discloses that use and a lawful basis supports it. GDPR also gives an applicant a way to ask about the automated part of the process directly: where automated decision-making is involved, a subject access request under Article 15(1)(h) reaches its existence, meaningful information about the logic involved, and the significance and envisaged consequences of that processing for you 2.
California's framework works on a similar logic even without using the same words: at or before collection, a business has to tell you the purposes it collects data for and how long it intends to keep each category, or the criteria it uses to decide 6. A sentence buried in a privacy policy that says data may be used to 'improve our services' is usually broad enough to cover model tuning on aggregate patterns, which is not the same claim as your specific resume sitting inside a general-purpose model's training set. Both are worth distinguishing before deciding how alarmed to be.
Check Who's Actually Doing the Processing
The employer and the vendor running its screening tool are usually separate legal actors with different permissions, and the clause you're reading may describe either one. An employer typically has your data only to evaluate you for the specific role you applied to.
The vendor supplying the screening or scoring tool sometimes has a broader license from the employer to use aggregated applicant data to improve its own product across all its customers, which is a different and larger use than anything the employer itself is doing with your file on its own.
Asking which entity wrote the sentence you're worried about is a legitimate question to put to a recruiter or in an email to the privacy contact usually listed near the bottom of the notice. Which one made the promise matters, since only one of them is actually making the decision about your application.
Ask for What California Actually Gives You
Since the employment-related exemption expired on December 31, 2022, California applicants have carried the same core rights as any other consumer there from January 1, 2023 onward 3. That includes asking a business what personal information it holds and where it came from, and requesting deletion or correction, real levers even if the training-data question specifically is hard to prove either way.
A more targeted right lands from January 1, 2027: California's finalized automated-decisionmaking regulations require a business using such a tool to make a significant decision, hiring named explicitly, to answer an access request with a plain-language account of the purpose, the logic behind the output, and what role a human actually played 4. It's a right to note now and use once it's live.
The honest limit sits next to it: California's opt-out from automated decisionmaking carves out hiring specifically where the tool is used solely to assess your ability to do the job and doesn't discriminate on a protected characteristic, so declining the tool itself usually isn't on the table the way declining a marketing use might be 5. Notice and access, yes. An opt-out from the screening tool itself, usually not.
Don't Confuse This With Being Screened Out
The question people actually mean to ask is often a different one underneath the privacy-notice worry: did my resume ending up in some training set somewhere actually cause me to get rejected from this specific job at this specific company? Almost certainly not.
A rejection comes from the specific screening or scoring step run on your specific application in that specific process, not from whatever a vendor's model absorbed from millions of other resumes months or years earlier. Saying so plainly matters more than it sounds like it should, because the fear of a vague, distant cause is worse than the mundane, checkable one actually at work.
Those are two different mechanisms with two different sets of rights behind them. If what you actually want to know is why you were screened out, that's a distinct question with its own answer, covered by what an employer using an AI screen is expected to tell a candidate, and it's worth reading on its own rather than folding into a training-data worry that doesn't actually explain a specific rejection.
Decide What Goes in the Free-Text Boxes
The most practical lever you actually control sits earlier than any privacy request: what you type into an open-text field. A structured field like years of experience carries little beyond its own number. A free-text cover-letter box or a 'tell us anything else' prompt can carry far more discretionary detail than the form requires, and that's the field worth being deliberate about before you submit rather than after.
Where an opt-out from a specific secondary use is offered on the application itself, take it; where it isn't, a short email asking the same question in writing puts a date on the record even in a state with no specific statute behind the request. If the process also involves a separate AI-use agreement before an interview round, reading what that document actually asks you to sign is worth doing alongside this one, since the two documents often arrive close together and cover overlapping ground from different angles.
Common questions
Does 'improve our services' in a privacy notice mean my resume trains a model?
It can, but it more often means the specific screening tool gets tuned on aggregate patterns across many applicants rather than your file becoming part of a general-purpose model. The notice should say which, and asking the privacy contact directly is reasonable if it doesn't.
Can I opt out of my data being used to train anything?
Sometimes, where the application itself offers a toggle for a secondary use. There's no general opt-out from the hiring tool itself in California once it's used solely to assess your fitness for the role and doesn't discriminate unlawfully.
Is the employer or the vendor responsible for how my data gets used?
Often both, in different roles. The employer usually controls what happens for your specific application; the vendor supplying the tool may have a separate license to use aggregated data to improve its product across customers. Ask which one wrote the clause you're reading.
Could my resume already be inside a large AI model somewhere?
Possibly, if a general-purpose model's training data included public web content that touched your resume or LinkedIn profile at some point. That's a different and much broader question than whether a specific employer's application form fed a model, and it isn't something a single deletion request resolves.
Should this change what I write in a cover letter?
It's a reasonable prompt to be deliberate rather than to withhold information you'd otherwise want to include. A structured field carries little on its own; a free-text box carries whatever you choose to put in it, so decide that on purpose.
References
- 1. Regulation (EU) 2016/679 (General Data Protection Regulation), Article 5(1)(b) - Purpose Limitation gdpr-info.eu Supports purpose limitation as the underlying rule: data collected for a specified purpose can't be further processed in an incompatible way without separate permission.
- 2. Regulation (EU) 2016/679 (General Data Protection Regulation), Official Journal L 119, 4.5.2016 publications.europa.eu Supports that a subject access request under Article 15(1)(h) reaches meaningful information about the logic behind automated processing of an applicant's data, where automated decision-making is involved.
- 3. California Consumer Privacy Act (CCPA) - Frequently Asked Questions cppa.ca.gov Supports that the employment-related exemption in Civil Code section 1798.145(m)-(n) expired December 31, 2022, bringing applicant data into CCPA scope from January 1, 2023.
- 4. California Privacy Protection Agency, Text of Regulations (CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations), Article 11 - Automated Decisionmaking Technology cppa.ca.gov Supports the January 1, 2027 access right to a plain-language explanation of purpose, logic, and outcome for a significant decision, hiring included, made using automated decisionmaking technology.
- 5. California Privacy Protection Agency, Text of Regulations (CCPA Updates, Cyber, Risk, ADMT, and Insurance Regulations), Article 11 - Automated Decisionmaking Technology cppa.ca.gov Supports the carve-out from the opt-out right for a hiring tool used solely to assess ability to perform the job, honestly limiting what 'you can opt out' actually means here.
- 6. California Civil Code Section 1798.100 (CCPA, as amended by the CPRA) - General Duties of Businesses that Collect Personal Information leginfo.legislature.ca.gov Supports that a business must disclose, at or before the point of collection, the purposes for which categories of personal information are collected and the length of time it intends to retain each category, or the criteria used to determine that period.
6 sources, numbered by first appearance. How Olive sources claims
General guidance, not legal advice. Hiring rules differ by state and country and change often; check anything here against your own counsel before you act on it.
Olive assesses how a person works with AI. It does not detect AI-written documents, and it never produces a score, a ranking, or a match percentage for a person. Candidates read the same report the employer reads.