Privacy Policy
Last updated: [insert date before publishing]
1. What we collect
- Name and surname you type into the analysis form (used as-is; we never take your name from your CV).
- Your uploaded CV (PDF or DOCX) - processed to extract text for scoring.
- Your selected target career.
- Account information (e.g. email address), only if you create a free account to generate a certificate - handled by our authentication provider, Clerk, not stored by us directly.
- Certificate data: name, career, score, and issue date, if you generate a certificate. This is intentionally public via the certificate's verification link - see Section 4.
We do not knowingly collect any special categories of personal information (e.g. health, biometric, or similarly sensitive data) - please don't include such information in your CV.
2. Why we collect it
Solely to run the career readiness analysis you request, generate your results and (if requested) certificate, and let you or a third party verify a certificate you choose to share. We do not use your CV content for any purpose beyond generating your analysis.
3. What we don't do
- We do not sell your personal information.
- We do not show ads, and we do not share your data with advertisers.
- We do not publish your CV content anywhere, including on the public certificate verification page.
- We do not use your CV to train any AI model - the readiness score is computed by a deterministic scoring algorithm we built, not an AI model, and no AI provider ever sees your CV as part of that scoring.
4. What's public
If you generate a certificate, its ID, your name, your target career, your score, and the issue date become viewable by anyone who has (or guesses) the certificate's verification link. This is intentional - it's how a third party checks a certificate is genuine. Nothing else (your CV, your email, your full analysis breakdown) is made public.
5. Who we share data with
The following third-party services process data on our behalf ("subprocessors"):
- Clerk - authentication, if you create an account.
- [Supabase / database provider] - stores analysis and certificate records once the Service is fully deployed. [Fill in once you connect Supabase or an alternative.]
- [Hosting providers, e.g. Netlify, your Python-hosting provider] - run the application itself.
We don't share your data with anyone else, and we don't sell it.
6. How long we keep data
[Fill in your real retention policy once decided - for example: uploaded CV files are processed in memory and not stored beyond what's needed to generate your immediate results; analysis and certificate records are retained for as long as your account exists, or for a fixed period like 12 months for anonymous analyses, after which they may be deleted.]
7. Your rights
Depending on where you live, you may have rights to access, correct, or request deletion of your personal information (for example, under South Africa's Protection of Personal Information Act (POPIA), or similar laws elsewhere). To make a request, contact us at [insert contact email]. Note that deleting an already-issued certificate's underlying record may break its public verification link.
8. Cookies
If you create an account, Clerk sets cookies needed to keep you signed in. We don't use advertising or tracking cookies.
9. Children
The Service isn't directed at children, and we don't knowingly collect personal information from anyone under [insert your chosen age threshold, e.g. 16].
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the date at the top of this page.
11. Contact
Questions or requests about your data: [insert contact email].
See also our Terms of Service.