Ask a recruiter what happens when their ATS hits its retention cap and deletes a candidate they rated highly two years ago, and you'll get a version of the same answer. A small pause. Then: "well, I have her in a spreadsheet."
Nobody is proud of the spreadsheet. It exists because the alternative was losing eight years of work to a setting somebody else chose.
What the cap moves, and where
A 24-month hard delete is easy to market. It reads as responsible and it takes one line on a security page. In practice it changes where the data lives.
The candidate record leaves the system with access controls, an audit trail, and a working process for handling a deletion request. It reappears in an Excel file on someone's laptop, or a Notion page shared with the team. The same personal data, without any of the protections around it.
The platform's compliance record stays clean. The risk moved to a place with no record at all.
A retention policy that people route around is not a retention policy. It's a relocation policy.
You set the rules
Vouch now lets you decide how long you keep candidates, source by source. Someone who applied to your job sits in a different relationship with your company than a profile you sourced or a list you migrated out of your last ATS, so each gets its own window.
You choose whether the clock runs from the day a candidate was added or from the last time you engaged with them, which is the difference between a pool that ages out on the calendar and one that ages out on contact. You choose what happens at the end. And when you want to keep someone longer, you can, with a reason attached.
You can show your work
Everything that happens to a candidate's record is written down: the window they're on, the basis you're holding them under, who extended it and why, when they were archived. You can export the lot.
That matters the day a client's procurement team sends you a questionnaire, or a candidate asks what you still have on file. Instead of reconstructing an answer from memory and a folder of old CVs, you open the log.
There's also a queue that surfaces what needs attention: candidates coming up on their window, records imported without a documented basis, anyone sitting in the archive. You work it in bulk, the way you work a pipeline.
Candidates can see where they stand
Every workspace now has a public privacy page that Vouch generates from your own settings. It states the real numbers: how long you keep each type of record, what happens when that runs out, who to contact. Your application and referral forms link to it. Change a setting and the page changes with it, so what you publish and what you do can't drift apart.
Candidates get a page of their own too, where they can ask what you hold, ask to be removed, or object. Requests land in your inbox with the matching record already found, and you answer them in a couple of clicks.
And when someone's window is running out, you can ask them directly whether they want to stay in your pool, rather than deleting a strong candidate on a technicality.
Nobody writes the privacy page. It reads your settings, so it can't describe a system you don't have.
The test we set ourselves
If a recruiter still needs a private spreadsheet to do their job properly, we've failed, no matter how tidy the deletion log looks.
Everything above exists so the good version of your talent pool, the one with eight years of context in it, can live in the system that protects it. Open Talent pool → Data retention and have a look at what your privacy page currently says. It's the fastest read on where you stand.
The rest of this release is on our changelog.