Privacy Policy
Last updated: March 2026
1. Information We Collect
Account information: When you sign in with Google, we receive your name, email address, and profile picture. We do not receive or store your Google password.
Resume and job listing content: The text you provide (resume text, job listings, company names, role names) is stored in our database to deliver scan results and allow you to review past scans.
Payment information: Payments are processed by Stripe. We do not store your credit card number or full payment details. We store a reference to your Stripe customer ID, payment intent IDs, and transaction amounts for record-keeping.
Usage data: We track which AI provider and model processed your scan, token counts, and estimated costs for internal cost management.
Analytics: We use Vercel Analytics and Vercel Speed Insights to measure page views and site performance. These services collect anonymized, aggregated data (no personal information or resume content). See Vercel's privacy policy for details.
2. How We Use Your Data
To provide the Service: Your resume text and job listing are sent to third-party AI providers (Anthropic and/or OpenAI) to generate analysis results, cover letters, and skill gap reports.
To store your results: Scan results are stored in our database so you can access them later from your scan history.
To process payments: We use Stripe to handle payments securely.
To improve the Service: We may analyze aggregate, anonymized usage patterns (e.g., average scan volume, cost per scan) to improve pricing and performance. We do not read individual resume content for this purpose.
Model training (opt-in only): If you consent, we may use anonymized versions of your scan data (resume text, job listing text, match scores) to evaluate and improve our AI prompts and models. This data is stripped of personally identifiable information before use. You can opt in or out at any time from your account settings.
Recruiter access (opt-in only): If you consent, we may make your candidate profile and skill data available to recruiters through a future recruiter dashboard or API. Only aggregated skill and experience information is shared — never your full resume text. You can opt in or out at any time from your account settings.
3. Third-Party AI Processing
Your resume text and job listing are sent to Anthropic (Claude) or OpenAI (GPT) for analysis. These providers process your data according to their own privacy policies and data processing agreements. We use their API services, which typically do not use API inputs for model training. Please review their privacy policies for details.
4. Data Storage and Security
Your data is stored in a PostgreSQL database. We use encryption in transit (HTTPS/TLS) for all communications. Access to the database is restricted to authorized systems only. We do not store uploaded files; only the extracted text is retained.
5. Data Retention
Your scan data is retained as long as your account is active. You may request deletion of your account and all associated data at any time from your account settings or by contacting us. Upon account deletion, your personal information is removed and all data consent preferences are revoked.
If you have opted in to model training or recruiter access, revoking your consent or deleting your account will immediately stop any further use of your data for those purposes. Data that has already been anonymized and aggregated for model evaluation cannot be individually removed, as it is no longer linked to your identity.
6. Your Rights
Under GDPR, CCPA, and similar privacy regulations, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your scan history
- Withdraw consent for model training or recruiter access at any time via your account settings
All data access and consent changes are logged for auditability. To exercise these rights, visit your account settings or contact us at teampair.ai@gmail.com.
7. Cookies
We use the following cookies:
- Session cookies: Required for authentication (managed by NextAuth.js).
- Visitor ID cookie: A randomly generated identifier stored for up to 1 year, used for anonymous analytics and to improve the user experience. This cookie does not contain personal information.
We do not use advertising or third-party tracking cookies.
8. Children
The Service is not intended for users under 16 years of age. We do not knowingly collect data from children.
9. Changes to This Policy
We may update this Privacy Policy at any time. We will notify users of material changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance.
10. Contact
For privacy-related questions, contact us at teampair.ai@gmail.com.