Where does my data actually live?
Start here, because every other answer depends on it. Most AI tools are cloud services. The moment you connect your email or upload a candidate file, a copy of your desk starts accumulating on someone else's infrastructure, governed by their retention rules and their security posture. That isn't automatically disqualifying, but the vendor has to say it plainly: which servers, which country, held for how long. If the answer takes a paragraph of qualifiers, you've learned something.
RecruiterClaw's answer is shorter. It installs on your machine, and that's where everything lives: memory, client profiles, conversation history, candidate files. RecruiterClaw operates no servers holding client data. Even document handling stays home. Drop a scanned resume or an iPhone photo of a signed agreement into Slack and the OCR runs on-device; nothing leaves the machine.
Who can see it?
Ask who on the vendor's side can access your data. Support engineers? Anyone with a database credential? And ask about your own side too: some cloud tools connect integrations once for a whole workspace, which quietly widens who can act through them. Your candidate notes and client fee structures are your competitive edge. You want to know exactly whose eyes can land on them, and you want the answer as a list of roles, not a link to a trust portal.
RecruiterClaw's answer follows from the first question: there is no vendor-side copy to look at. Your desk sits on your machine, and we hold none of it. The line we use is the policy: you own your data. We don't.
What trains on it?
Ask directly: does anything I type, upload, or connect feed model training? Is staying out of training the default, or a setting buried three menus deep? This is where a vendor's incentives show. Your data is valuable to them in exact proportion to how much of it they hold. A vendor that hesitates on this question is telling you something useful.
For RecruiterClaw the question is settled structurally. We operate no servers holding client data, so there is no stored pool of your candidate files, client notes, or conversations to train anything on. You can't train on what you don't hold.
What happens when I cancel?
The quiet horror scenario: you finally leave a tool, and years of notes, contacts, and history either export as a useless dump or don't export at all. So ask before you connect anything. What leaves with me, in what format? What do you retain after I'm gone, and for how long? Get the answer in writing while they still want your signature.
With RecruiterClaw there is nothing to export and no one to petition, because the files were on your machine the whole time. Stop the service and everything stays exactly where it always was. Nothing disappears, because nothing ever left.
How are credentials stored?
An AI chief of staff holds keys: your email, your calendar, your ATS. So ask where those tokens live. Sitting in a plain-text configuration file, they are a compromised laptop away from becoming everyone's problem. You want them in encrypted storage, and you want the vendor to know the answer cold, without checking with engineering.
RecruiterClaw keeps credentials in the machine's encrypted keychain. Not in a text file, and not on our servers, because there are no servers holding them.
How do you run this conversation?
Send the five questions ahead of the demo, in an email, so nobody has to improvise. Then listen for the shape of the answers. Policy answers sound like "we would never" and "our team is trained to." Structural answers sound like "that's impossible in our design," and each one can be explained in a sentence. Structural beats policy every time, because a policy needs enforcing and architecture doesn't.
The same lens applies once the AI is inside your systems and writing to them. If you're weighing what write access to your ATS should look like, we covered that safety model in its own guide: Is it safe to let AI write to your ATS? Between the two pages, you have the full interrogation kit. Use it on us first.
Where does RecruiterClaw store my recruiting data?
On your machine. Memory, client profiles, conversation history, and candidate files all live locally. RecruiterClaw operates no servers holding client data, and document OCR runs on-device, so scanned resumes and photos never leave the machine.
Does RecruiterClaw train AI models on my candidate data?
There is no vendor-held pool of your data to train on. Your desk lives on your machine, not on RecruiterClaw servers, so the training question is settled structurally rather than by policy.
What happens to my RecruiterClaw data if I cancel?
It stays on your machine, where it always lived. There is no export to request, no retention window to worry about, and nothing that disappears when the subscription stops.
How does RecruiterClaw store email and ATS credentials?
In the machine's encrypted keychain. Not in plain-text configuration files, and not on vendor servers, because RecruiterClaw operates no servers holding client data.
What does a good answer from any AI vendor sound like?
Structural, short, and in plain English. A vendor that says a risk is impossible by design, and can explain why in a sentence, is giving you a stronger guarantee than one reciting policies about what their team would never do.