Privacy Policy
Effective: August 9, 2026
Hunt is operated by Eitan Divone, an individual based in Israel operating under the Kraitos brand. This policy explains how Hunt collects and uses personal information in the marketplace, verification, support, and Client Influx services. Contact support@kraitos.app for privacy questions or requests.
Who controls the information
Eitan Divone, operating under the Kraitos brand, controls account, marketplace, security, verification, support, and service-operation information. A user operating Client Influx determines which lawful markets, sources, and recipients to research or contact and is responsible for their own role as a controller or business under applicable privacy and marketing laws. Hunt processes that tenant's Client Influx records to provide the service and separately uses limited operational data for security and reliability.
Information we collect
- Account and profile: name, email, role, authentication provider, phone verification status, onboarding answers, availability, languages, capabilities, proof links, and profile choices.
- Marketplace activity: project briefs, privacy selections, offers, milestones, conversations, files, reviews, reports, disputes, system-access grants, notifications, and fee records.
- Verification: phone and email status, Didit session references and results, identity-match fingerprints, public proof, reviewer notes, and audit history. Hunt does not intentionally store raw identity documents returned by Didit.
- Security and support: revocable session identifiers, hashed network identifiers, device/browser information, authentication events, support conversations, and administrative actions.
- Client Influx: encrypted tenant API and mailbox credentials, search configuration, public-source candidates, evidence, contact details, qualification decisions, suppression records, outreach status, and conversion outcomes.
Sources
Information comes from users, Firebase/Google authentication, Firebase phone verification, Didit identity checks, marketplace participants, support staff, and public or user-configured Client Influx sources such as Google Places, Exa, Jina, Reddit where separately approved, public websites, and OpenStreetMap. Client Influx users must follow each source's terms and must not use gated or unlawfully obtained data.
Purposes and legal bases
- Perform our contract: create accounts, show profiles, manage projects and offers, provide messaging, verification, support, Client Influx, and account controls.
- Legitimate interests: prevent abuse, secure accounts, maintain audit trails, improve reliability, match projects, and operate a trustworthy marketplace, balanced against individual rights.
- Consent: where required for optional communications, source integrations, or marketing activity. Consent may be withdrawn without affecting earlier lawful processing.
- Legal obligations and claims: accounting, fraud response, regulatory requests, disputes, and enforcement of agreements.
Hunt does not sell personal information. Hunt does not use sensitive identity information for advertising.
Sharing and service providers
Information is shared only as needed with the relevant client, builder, administrator, or service provider. Current or optional providers may include VPS and database hosting, Firebase and Google authentication/phone services, Didit, SMTP/mailbox providers, NVIDIA or OpenAI model APIs selected by the user, Google Places, Exa, Jina, Reddit, OpenStreetMap, and a future payment provider only when checkout is visibly enabled. Providers receive only the information needed for their function and may process it in other countries under their own terms and available transfer safeguards.
Public and private visibility
Verified builders who enable a public profile may expose selected professional information and proof links. Project visibility follows the chosen project privacy level and server-enforced detail grants. Email, phone, identity documents, private details, and tenant API credentials are not public profile fields. Users should not place secrets or unnecessary personal data in public text.
Automated processing
Hunt uses deterministic project matching and AI-assisted Client Influx search and lead qualification. Matching explanations and lead evidence are shown to users. These tools may be wrong and do not make legal, employment, credit, or similarly significant decisions about individuals. Builder and client verification decisions remain subject to administrator review.
Retention and deletion
- Login sessions expire after seven days at most and after 24 hours of inactivity; OAuth handoffs expire after two minutes.
- Account, project, message, verification, and Client Influx records are kept while the service is used and afterward only where needed for security, disputes, legal duties, suppression, or legitimate business records.
- Deletion requests immediately restrict account use. After review, direct identifiers, profile text, user-authored messages, uploads, tenant credentials, and tenant Client Influx data are deleted or anonymized. Records required for fraud, disputes, fees, taxes, or legal claims may be retained with access limited.
- Deleted information may remain temporarily in protected backups until the backup retention cycle expires.
Your choices and rights
The account Settings page lets users download their data, manage active sessions, and request access, correction, restriction, objection, or deletion. Requests can also be sent to support@kraitos.app. We may verify identity and may retain information where law permits or requires. People covered by the GDPR may also withdraw consent, request portability, and complain to their supervisory authority. People in Israel may exercise applicable access and correction rights and contact the Israeli Privacy Protection Authority.
Commercial outreach and public leads
A public email address is not by itself consent to receive advertising. Client Influx users must establish a lawful basis and obtain any consent required by the recipient's location before sending. Hunt maintains bounce, opt-out, and suppression records to prevent repeat contact. To object to lead processing or stop Hunt-assisted outreach, email support@kraitos.app; include the address or business record to suppress.
Security and incidents
Hunt uses encrypted transport, host-only secure cookies, revocable sessions, administrator MFA, request-origin checks, encrypted tenant credentials, private database binding, and access controls. No system is perfectly secure. Suspected incidents should be reported promptly to support@kraitos.app. Hunt will investigate and notify affected people and regulators where required.
Children and changes
Hunt is for people aged 18 or older and is not directed to children. Material policy changes will be dated and users will be asked to accept a new version before continuing to use account features.