Privacy Policy & Security.
ATS Friendly AI operates on strict data minimization, explicit retention windows, zero-training AI sandboxes, and full GDPR/CCPA erasure compliance.
1. Zero AI Model Training Guarantee
Your resume text, career details, job descriptions, and mock interview transcripts are never used to train, fine-tune, or reinforce foundation AI models (including OpenAI, Anthropic, Google Gemini, or Meta models). All LLM inference sessions run through enterprise zero-retention API endpoints where inputs and outputs are isolated exclusively to your generation turn.
2. Concrete Data Retention Windows
We believe privacy requires explicit, predictable expiration lifecycles rather than indefinite document retention:
When you delete a resume from your dashboard, it enters a soft-deleted quarantine window (userCvPurgeDays, default 90 days). After 90 days, automated daily scheduled jobs permanently purge all underlying file data and parsed text.
All cover letters, match analyses, and generation outputs in the Generation storage cluster carry an automated MongoDB Time-To-Live index (expireAfterSeconds: 7,776,000). Records are purged automatically by the database engine 90 days after creation.
Applications submitted to verified company job postings retain candidate materials during active hiring pipeline review. Rejected or archived applications are automatically pruned according to company data retention policies.
Anonymous trial sessions are tied solely to temporary browser cookies and expire within 24 hours. AI assistant threads are decommissioned when sessions conclude.
3. User Erasure Rights & Anonymization Mechanics
In compliance with GDPR Article 17 (Right to Erasure) and CCPA/CPRA, users can delete their entire account and all associated data at any time directly through account settings or by contacting support:
- Authoritative Cascade Hard-Delete: Deletion removes all saved resumes (UserCV), generations (Generation), mock interview recordings, chat messages, parsed sections, and notifications.
- Profile Anonymization: All personal identifiable information (name, email address, phone number, location, social links) is irreversibly wiped and replaced with a non-invertible SHA-256 cryptographic hash (deleted_<hash>).
- Financial Ledger Pseudonymization: To comply with statutory tax and accounting auditing requirements, financial transaction entries (Transaction) are permanently pseudonymized with the cryptographic hash rather than deleted, completely severing personal identification while preserving transaction ledger balance integrity.
4. Cloud Infrastructure & Trusted Sub-Processors
We work exclusively with SOC2-compliant enterprise infrastructure providers:
5. Cookies & Telemetry Consent
Non-essential analytics and performance insights (Vercel Speed Insights and Telemetry) are strictly gated and remain inactive until you explicitly choose “Accept All”in the cookie consent banner. Choosing “Essential Only” completely suppresses analytical telemetry.