Privacy Policy & Data Security Standards

Effective Date: August 8, 2026 | NexCV Data Governance

1. Data Minimization & Resume Storage

Uploaded resume files (DOCX) are stored in private Supabase S3 storage buckets accessible only via authenticated session tokens. We extract text strictly for tailoring, ATS simulation, and Fact-Graph matching.

2. Public Verification Tokens

When a user opts to share a Verified Proof Badge (`/verify/[token]`), the public page displays ONLY candidate name, skill tested, score percentage, date issued, and cryptographic signature hash. Personal contact information (email, phone, address) is NEVER exposed on public verification endpoints.

3. Third-Party Processing & Security

Resume processing is performed through secure LLM API standard instances operating under strict data non-retention agreements. Your resumes are never used to train public foundation models.

4. User Data Control & Deletion

You retain complete ownership of your data. Deleting a resume from your dashboard immediately removes the file from private storage buckets and purges associated Fact-Graph records.