Privacy

Privacy Policy — commercial draft

1. Scope and product promise

This policy covers the Yevly platform and its Yevly Resume job-seeker service. User documents are processed only to provide and operate the service. Yevly does not sell user content, use it for advertising, add it to public datasets, or permit model training on it by default.

2. Information processed

  • Account information: verified email, name, authentication provider, profile preferences, and security/session metadata.
  • Restricted documents: uploaded résumés, pasted job descriptions, parsed content, optimized output, comparisons, missing requirements, and generated PDF/DOCX files.
  • Commercial records: credit ledger, package and purchase status, Stripe references, refunds, receipts, and legally required accounting evidence.
  • Operational records: opaque request/resource IDs, safe status and failure codes, job timing, download attempts, audit records, and support references.
  • Optional analytics: explicitly allowlisted product events using a pseudonymous identifier. Document text, filenames, contact details, payment details, and signed URLs are prohibited.

Yevly does not request Social Security numbers, government identification, banking credentials, dates of birth, full home addresses, or demographic profiles.

3. Purposes and legal basis

Information is used to authenticate users, process documents, run truthful optimization and factual validation, calculate alignment scores, generate and deliver files, process payments and credits, prevent abuse, provide support, communicate transactional status, meet accounting obligations, and improve service reliability. The applicable legal basis depends on jurisdiction and must be confirmed by launch counsel.

4. AI processing and training

Résumé and job content is treated as untrusted data and sent only to approved AI processing needed for the requested optimization. Provider calls are stateless where supported, use structured output, disable provider storage where contracted/configured, and exclude unnecessary file binaries and contact information. User content is not used for model training by default. Provider terms, retention, regions, and data controls must be verified before activation.

5. Providers and disclosures

The planned provider categories are hosting, Supabase authentication/database/private storage, OpenAI processing, Stripe Checkout, Resend transactional email, PostHog product analytics, Sentry monitoring, background processing, malware scanning, and managed key custody. The final policy must name active subprocessors, regions, retention, international-transfer mechanisms, and material changes before public launch.

6. Security and access

Private documents use authenticated ownership checks, Row Level Security, private object storage, application encryption for generated files, bounded parsers, validation, and no public storage paths. Admin lists hide résumé and job content. Elevated content access is unavailable by default and would require a permitted role, recent authentication, reason, time limit, and immutable audit record.

7. Analytics, cookies, and communications

Yevly does not initialize analytics autocapture or session replay. Optional product events use strict names and properties, avoid person profiles, and can be disabled in Settings. Essential authentication, security, and payment state cannot be disabled where required to provide the service. Purchase receipts and security alerts are required; optimization-complete messages can be disabled. Marketing and product updates default off.

8. Retention

9. User choices and deletion

Users can correct profile information, manage optional communications and analytics, delete individual optimizations/documents, and request account deletion. Account deletion blocks access immediately, removes eligible private content, anonymizes profile data, and preserves only legally required payment/audit evidence. Backup copies expire on schedule and deletion tombstones must be reapplied after disaster recovery.

10. Rights and contact

Applicable privacy rights may include access, correction, deletion, restriction, objection, portability, and complaint rights. Yevly provides authenticated deletion and metadata-only support intake through the contact page. A verified privacy address, legal entity identity, response process, and regulator information must be published before launch.

11. Changes

Policy versions are recorded. Material changes requiring renewed notice or consent will be identified before they take effect. Privacy statements must always match configured provider and product behavior.