1. Data Minimization & Resume Storage
Uploaded resume files (DOCX) are stored in private Supabase S3 storage buckets accessible only via authenticated session tokens. We extract text strictly for tailoring, ATS simulation, and Fact-Graph matching.
2. Public Verification Tokens
When a user opts to share a Verified Proof Badge (`/verify/[token]`), the public page displays ONLY candidate name, skill tested, score percentage, date issued, and cryptographic signature hash. Personal contact information (email, phone, address) is NEVER exposed on public verification endpoints.
3. Third-Party Processing & Security
Resume processing is performed through secure LLM API standard instances operating under strict data non-retention agreements. Your resumes are never used to train public foundation models.
4. User Data Control & Deletion
You retain complete ownership of your data. Deleting a resume from your dashboard immediately removes the file from private storage buckets and purges associated Fact-Graph records.