Privacy

Privacy Policy

1. Scope

This Privacy Policy explains how Yevly processes personal information for the Yevly platform and Yevly Resume service. The initial service is intended for individual users who are at least 18 years old and located in the United States.

Yevly processes uploaded documents, pasted job descriptions, and résumé-builder and clarification content only to provide, secure, support, and maintain the service requested by the user. Yevly does not sell user content, use it for advertising, place it in public datasets, or use it to train Yevly or third-party AI models.

2. Information we process

We collect only information reasonably needed to provide and protect the service.

  • Account information, including name, verified email address, authentication provider, profile preferences, and session/security metadata.
  • Restricted service content, including uploaded résumés; pasted job descriptions; résumé-builder questions and submitted answers; text the user chooses to submit after optional speech-to-text; extracted facts and their supporting excerpts; fact confirmations, corrections, and deletions; draft and clarification progress; clarification questions and answers; parsed text; optimized output; comparisons; missing requirements; and generated PDF and DOCX files.
  • Commercial records, including purchased credit packages, immutable credit-ledger entries, Stripe payment references, legally required or payment-processor-initiated refunds, receipts, and legally required accounting evidence. Yevly does not receive or store full card numbers or card security codes.
  • Operational and agreement records, including opaque request and resource identifiers, safe status/error codes, job timing, download attempts, exact policy-version acceptance, audit events, support references, and security signals.
  • Communications and preferences, including transactional-email delivery status and whether optional optimization-complete messages are enabled.

3. How we use information

Yevly uses personal information to authenticate accounts; privately store and resume drafts; organize customer-supplied facts; ask focused résumé-intake and material job-qualification clarification questions; let users review and correct facts; privately store, parse, scan, optimize, validate, score, generate, and deliver documents; process payments and credits; provide support; send transactional notices; prevent abuse and fraud; investigate security issues; maintain backups and recovery; and satisfy accounting obligations. Yevly uses content-redacted operational metadata—not résumé, job-description, builder-answer, clarification-answer, or extracted-fact text—to diagnose failures and improve service reliability.

4. AI processing

Résumé, job-listing, builder-conversation, clarification, and structured-fact content is treated as untrusted data, not as instructions. The content needed for guided fact extraction, job-requirement clarification, requested optimization, and separate factual validation is sent to OpenAI. Yevly requires structured output, sends no provider tools, configures API response storage off, and validates the result before using or showing it.

Yevly does not authorize OpenAI to train models on user content and does not add résumé, job-listing, builder, or clarification content to public datasets. Under OpenAI's standard API data controls, abuse-monitoring logs may include prompts, responses, and derived metadata for up to 30 days, or longer if legally required; approved Zero Data Retention or Modified Abuse Monitoring controls can reduce that content retention. Yevly's response-storage-off setting prevents application-state storage for these requests but does not by itself remove standard abuse-monitoring logs. AI systems and speech recognition can make mistakes, so users should review submitted text, facts, and every result before using them.

5. Service providers

Yevly uses service providers only for defined operational purposes. Current provider roles include:

  • Vercel for application hosting and delivery, including processing requests that carry user-submitted text.
  • Supabase for authentication, PostgreSQL, and private object storage, including private résumé-builder and clarification state.
  • Google and Apple for optional federated sign-in when the user chooses those methods.
  • OpenAI for guided résumé fact extraction, job-requirement clarification, requested résumé optimization, and factual-validation processing.
  • Stripe for Checkout, wallet payments where supported, receipts, legally required or payment-processor-initiated refunds, disputes, and payment records.
  • Trigger.dev for durable background-job execution using opaque identifiers rather than document or conversation text in queue payloads.
  • Resend for transactional email; résumé files and raw résumé-builder or clarification content are not attached to email.
  • Sentry for privacy-minimized error monitoring, without document text, builder or clarification content, or signed URLs.
  • Upstash and Cloudflare for rate limiting, DNS/security controls, and risk-triggered bot verification.
  • Amazon Web Services for managed encryption keys and encrypted recovery storage.
  • An isolated ClamAV service for malware scanning.

If a user chooses microphone input, the browser, operating system, or its speech-recognition provider may process microphone audio under that provider's terms and privacy practices. Yevly's servers do not receive or store raw microphone audio. Recognized text remains editable in the browser, and only text the user chooses to submit is sent to and stored by Yevly.

6. Analytics and advertising

Optional product analytics is disabled for the controlled MVP launch. Yevly does not run session replay or analytics autocapture, and does not send product events to PostHog while analytics remains disabled.

If optional analytics is enabled later, Yevly will first update this policy and the in-product controls. Résumé text, job-description text, builder conversations, clarification questions or answers, extracted facts or supporting excerpts, submitted speech-to-text, names from documents, contact details, private filenames, signed URLs, and payment details are prohibited from analytics.

7. Sharing and disclosure

Yevly shares information with the providers above only as needed to operate the service, or when reasonably necessary to comply with law, protect users, investigate fraud or security incidents, enforce the Terms, or complete a business transaction subject to appropriate safeguards. Yevly does not sell personal information or share user content for targeted advertising.

8. Security

Yevly uses HTTPS, server-side ownership checks, Row Level Security, private object storage, authenticated no-store download streaming, encryption for generated files and recovery copies, malware scanning, bounded parsers, rate limits, audit logs, multi-factor protection for administrative access, and content-redacted monitoring. No service can guarantee absolute security. Please use the contact page immediately if you suspect unauthorized access.

9. Retention and deletion

Retention is limited by operational, security, recovery, and legal needs. The controlled-MVP rules are:

  • Active résumé-builder drafts: until the user deletes the draft or account. After a draft is converted, its submitted answers, structured facts and supporting excerpts, confirmations, and any clarification records remain with the account until account deletion or a validated deletion request. Target-job content, documents, and generated output remain until their applicable deletion workflow or account deletion. Eligible primary-system deletion is targeted within 7 days and completed within 30 days.
  • Failed, rejected, or abandoned uploads: automatically queued for deletion after 24 hours unless a documented security or legal hold lawfully requires longer retention.
  • User-linked background-job and download metadata: retained while the related account or record remains available and removed or anonymized through the applicable deletion workflow. Document and conversation content is not placed in logs or queue payloads.
  • Routine operational and provider logs: retained under Yevly's configured provider schedules only as long as reasonably needed for reliability, fraud prevention, security, and incident response. Material security and administrative audit records may be retained for at least 12 months. Minimized policy-acceptance evidence may be retained as reasonably needed to document the agreement and respond to legal claims.
  • Payment, legally required or processor-initiated correction, tax, credit-ledger, and accounting records: retained for the legally or operationally required period, generally up to 7 years, and longer only when a legal hold or applicable requirement applies.
  • Encrypted rolling backups: up to 35 days. Deletion tombstones are reapplied after a restore so deleted content is not made active again.

10. Your choices

Users can review, correct, or remove résumé-builder facts; delete an active résumé-builder draft; update profile information; manage optional notification preferences; delete individual résumés and optimizations; download available files; and request account deletion in Settings. Deleting an individual résumé or optimization does not by itself delete a converted builder conversation or clarification record; users may request deletion of that content through the authenticated contact page or delete the account. Account deletion is permanent: it revokes sessions, blocks new processing and credit use, deletes eligible private files, anonymizes profile data, and preserves only records that Yevly reasonably must retain, including applicable payment, credit-ledger, tax, dispute, policy-acceptance, and security evidence. Unused credits remain non-cash accounting records but cannot be used after voluntary account deletion. Depending on applicable law, users may also request access, correction, deletion, or a copy of personal information through the authenticated contact page.

11. Cookies and similar storage

Yevly uses essential cookies or local storage for authentication, security, account routing, draft continuity, and payment continuity. Optional analytics is disabled at launch. Browser speech-recognition and provider payment interfaces may use their own essential technologies under their policies.

12. Children

Yevly Resume is not directed to children and is available only to users who are at least 18 years old. Yevly does not knowingly collect personal information from children. Contact Yevly if you believe a child has created an account.

13. United States processing

The controlled MVP is offered from Washington State to users in the United States. Information may be processed in the United States and in provider locations used to deliver the service. International expansion requires a separate privacy review before activation.

14. Changes and contact

Yevly records policy versions and will provide appropriate notice before material changes take effect. When law or the nature of a change requires renewed consent, Yevly will request it. Use the Yevly contact page for privacy requests, security concerns, or questions about this policy.