ClimbIQ

Privacy Policy

Back to sign up · Log in · Terms of Service

1. What we collect and store

We don't collect anything beyond what's needed to run the features above. We don't buy or receive data about you from third parties.

2. Your resume and job text is sent to Anthropic

Gap analysis, resume generation, and cover letter generation work by sending your resume/skill-card content and job posting text to Claude, via the Anthropic API. This is the core mechanism of the product. We don't use your content to train AI models, and we don't share it with anyone besides the AI provider needed to run the analysis. Anthropic's own handling of API data is governed by their own terms, which we don't control.

3. Analytics

We run Google Analytics 4 (GA4), but only on public/marketing pages — the landing page, login, signup, forgot-password, terms, and this page — never on any page inside the logged-in app. That's a deliberate boundary: pages inside the app can contain your real name, resume content, and employment history, and we don't run any tracking script there. GA4 collects pageviews only — no click tracking, no session replay — with IP anonymization and ad-personalization signals turned off.

We do not currently have any in-app behavior analytics (no PostHog, no Clarity, no session replay anywhere) — that's an explicitly pending, not-yet-built idea, blocked specifically on doing PII-masking work first, precisely because the app's pages carry resume content.

4. LLM call metadata (not your resume text) is logged internally

Every call this app makes to Claude is logged for cost tracking and abuse prevention, visible only to admins on an internal page. What's logged is metadata: which feature was used, token counts, timing, success/error status, and your user ID for per-user cost attribution. The prompt and response text themselves — i.e., your actual resume/job content — are not stored in this log, specifically because these calls carry whole resumes and job descriptions and storing a copy would be unnecessary PII exposure. The one exception is the “Make a plan” coaching chat, which is currently disabled for the alpha and, when it is enabled, does log redacted excerpts (common PII patterns like email/phone/SSN-shaped strings stripped) for abuse-prevention purposes only, since that feature accepts open-ended freeform input rather than a resume.

5. Feedback reports and email

Submitting the in-app feedback form sends an email notification to support@climbiq.io, and creates an internal record tied to your account so we can follow up. If someone on our team replies from that inbox, the reply is captured and stored internally against your report, but it is not currently shown back to you in the app — replies happen over email, not in-app.

6. Who can see your data

Row-level security in our database and per-user-scoped file storage mean your resumes, jobs, cards, and generated content are visible only to your own account — not to other users — enforced at the database layer, not just in the app's own logic. A small number of ClimbIQ admins (currently: the founder and anyone explicitly granted sys-admin) can access account/billing-adjacent data and feedback reports through internal admin tooling for support and moderation purposes. If your account is a member of an organization/group (a b2b feature), a group admin can see aggregate counts about your library and adopted content, but not your resume content directly.

7. Retention

We keep your data until you ask us to delete it (Section 8) — there is currently no automatic expiration or purge of inactive accounts. Superseded versions of a resume or gap analysis (e.g. after a re-run or restore) are kept, not deleted, so you can see history — this is a product feature, not incidental retention.

Not yet decided: an automatic retention/expiration policy for long-dormant accounts. Nothing currently deletes an inactive account's data on its own.

8. Deleting your account

You can ask us to delete your account and everything tied to it at any time. This is currently a documented request, not self-serve — there is no in-app “Delete my account” button yet:

Self-serve deletion (a button you click yourself, with no admin involved) is deferred past the alpha.

9. Payments

If you purchase a pass, payment is processed by Stripe — we don't store your card details ourselves. See the Terms of Service for what a pass covers.

10. Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated to active users.

11. Contact

Questions about this policy, or a deletion/data request: support@climbiq.io.