Public policy draft

Privacy Notice

How the current implementation collects, uses, transfers, retains, and deletes data.

Draft for professional legal review before launch. This is not legal advice and has not been approved by counsel.

Effective date: [PLACEHOLDER — set after legal review]

Last updated: July 27, 2026 (local draft)

Data we handle

Depending on features used, the application handles account and profile data; resumes and generated files; job searches, imports, matches, and source evidence; application packages and customer relationship management (CRM) history; reusable answers; interview questions, finalized answers, corrections, and scores; usage and billing records; consent records; and safe operational metadata.

Private files are stored in app-controlled resume and application-package storage. Reusable provider credentials, live browser links, and bearer tokens are excluded from user exports and should not appear in logs.

Purposes and consent

Data is used to provide requested job-search, application-drafting, resume, application-tracking, interview, billing, security, and reliability functions. Versioned confirmation is required before application drafting transfers resume, profile, and job details to configured AI providers.

Text interview practice requires consent to store finalized answers and correction history. Voice asks once per account and policy version for microphone capture and OpenAI speech processing consent. Browser microphone permission is controlled separately by the browser and can be changed in site settings.

AI and service providers

Configured providers may process the minimum data needed for a requested feature. Current or planned integrations include Firebase for identity, Supabase/Postgres and private storage for app data, Trigger.dev for queued work, Anthropic for drafting/interview text, OpenAI for speech processing, Stripe for billing, Resend for transactional email, and Browserbase for browser sessions when an authorized mode is enabled.

The Subprocessors draft identifies which integrations are currently active, test-only, disabled, or conditional. Provider retention can differ from app-controlled retention and requires legal/vendor review before launch.

Retention

Career content is generally kept while the account exists or while the content remains visible and useful. CRM-linked application history remains until account deletion. Default operational windows are 90 days for worker runs and terminal queue rows, 365 days for system events and legacy application events, with configuration bounded between 30 days and 10 years.

The application does not store raw voice audio. It stores finalized transcript text, consent history, and safe voice-operation/usage metadata. Provider-side processing and temporary retention are separate and require launch review.

Export and deletion

Export requires authentication within the last five minutes and produces a single archive: a machine-readable manifest, one file per data domain covering account, resumes, jobs, application packages and their versions, applications, saved answers, browser assistance, interviews, voice records, usage and costs, billing projection, and operations, plus the account’s own resume, package, and builder resume files. The manifest states, per domain and per storage area, whether it was gathered completely; an export that could not gather something is labelled incomplete rather than presented as a full copy.

Deletion can be requested by the account holder or by an administrator, in both cases only after authentication within the last five minutes. The account is made unavailable first, then new work is stopped, sessions and provider authority are revoked, owned files are removed, and career content is deleted. Each step is recorded separately, so an interrupted deletion resumes from the step that failed and never returns the account to service.

After deletion, the service keeps only a minimum billing record and a deletion audit record. Those hold provider and transaction identifiers, plan and billing period, amounts and credit quantities, timestamps, step names, and safe status codes, identified by a pseudonymous reference rather than the account. They contain no resume, job, application, answer, interview, transcript, or voice content, no email address, and no provider tokens or file locations. How long those records are kept is not yet decided and requires legal review.

Messages and choices

Current email consists of transactional service messages about requested job-discovery or application activity. Delivery is disabled by default and test mode requires an allowlisted recipient. Marketing messages are not implemented. If marketing is added later, it must use separate consent, unsubscribe, and suppression controls.