/ legal
Privacy Policy
Version 3 · Effective 2026-07-13 · Plain language on purpose. Questions: [email protected]
What we collect
Information you give us (customer forms, job applications and attachments, account sign-in, support, and sales conversations) and information generated by using the service (redacted telemetry such as event types, token counts, latency, and hashes, plus derived metrics, reports, and operational records). Public forms also record a random visitor and session ID, first and last form-page touch, referrer without query parameters, allowlisted campaign or click IDs, completed field names without their contents, submission outcomes, browser language, and coarse Cloudflare location and network context such as country, region, city, timezone, data center, and ASN. We do not retain the raw IP address or cookies in the form record. Authentication is handled by our sign-in provider; we receive an account identifier and email address and never see or store your password. Data is stored in US-based infrastructure.
Public form reliability
We use browser local and session storage to keep an unsent draft, a random visitor ID, a 30-minute form session, and first-touch attribution so a failed upload can be retried without losing the application or customer request. You can remove those device-local records by clearing site data in your browser. Submitted form records are kept in our operating database and independently archived with attachment hashes and delivery history so we can prove whether a résumé or request was stored.
What we refuse to store
Our upload pipeline rejects, server-side, traces containing raw prompts or credential-shaped strings (API keys, tokens, private keys), and our public forms reject submissions containing credential-shaped strings. We do not want your prompts, your source code, or your secrets. This is enforced by code, not policy.
No health information
This service is not intended for protected health information (PHI). Do not submit PHI in traces, forms, or anywhere else. Uploads are gated against raw content as described above, and we do not offer a Business Associate Agreement at this time. If your use case involves health data, contact us before sending anything.
How we use it
To operate, secure, and improve the service, respond to you, and deliver engagements. We do not sell your personal information. We do not use customer telemetry to train models without your permission. We share data with the service providers that help us run the service; the current list is on our trust page.
Retention and deletion
We keep data for as long as it is needed for the purposes above or to meet legal obligations, and then delete or de-identify it. You can ask us to delete your workspace data at any time by email; self-serve tooling is on the roadmap.
Your rights
Email [email protected] to access, correct, export, or delete your data. We respond within a reasonable time.
Changes
We may update this policy as the product evolves. The effective date above will change when we do, and we will provide notice of material changes as appropriate, by email or on this page.