Privacy Policy
Back to sign up · Log in · Terms of Service
1. What we collect and store
- Account info: your email address and password (the password itself is never stored by us — Supabase Auth handles hashing/verification).
- Profile: plan status (free or paid-until date), optional target-role fields (role, industry, seniority, salary range), and resume-detail fields you fill in (name, email, phone, LinkedIn/portfolio URLs, summary).
- Resumes: the original file or pasted text you upload, plus a structured/parsed version of it.
- Skill cards: the individual pieces of your work/education history (jobs, projects, accomplishments, professional development, education) that power gap analysis and resume generation.
- Jobs: postings you save — title, company, description, source URL, and your own status/notes on them.
- Generated content: gap analyses, tailored/general/“current” resumes, and cover letters produced from the above.
- Uploaded files: the original resume file you upload, and the PDF/DOCX files we generate, are stored in Supabase Storage, scoped so only your account can access them.
- Feedback reports: anything you submit through the in-app feedback form (bug reports, feature requests).
- Usage metadata for cost/abuse monitoring — see Section 4.
We don't collect anything beyond what's needed to run the features above. We don't buy or receive data about you from third parties.
2. Your resume and job text is sent to Anthropic
Gap analysis, resume generation, and cover letter generation work by sending your resume/skill-card content and job posting text to Claude, via the Anthropic API. This is the core mechanism of the product. We don't use your content to train AI models, and we don't share it with anyone besides the AI provider needed to run the analysis. Anthropic's own handling of API data is governed by their own terms, which we don't control.
3. Analytics
We run Google Analytics 4 (GA4), but only on public/marketing pages — the landing page, login, signup, forgot-password, terms, and this page — never on any page inside the logged-in app. That's a deliberate boundary: pages inside the app can contain your real name, resume content, and employment history, and we don't run any tracking script there. GA4 collects pageviews only — no click tracking, no session replay — with IP anonymization and ad-personalization signals turned off.
We do not currently have any in-app behavior analytics (no PostHog, no Clarity, no session replay anywhere) — that's an explicitly pending, not-yet-built idea, blocked specifically on doing PII-masking work first, precisely because the app's pages carry resume content.
4. LLM call metadata (not your resume text) is logged internally
Every call this app makes to Claude is logged for cost tracking and abuse prevention, visible only to admins on an internal page. What's logged is metadata: which feature was used, token counts, timing, success/error status, and your user ID for per-user cost attribution. The prompt and response text themselves — i.e., your actual resume/job content — are not stored in this log, specifically because these calls carry whole resumes and job descriptions and storing a copy would be unnecessary PII exposure. The one exception is the “Make a plan” coaching chat, which is currently disabled for the alpha and, when it is enabled, does log redacted excerpts (common PII patterns like email/phone/SSN-shaped strings stripped) for abuse-prevention purposes only, since that feature accepts open-ended freeform input rather than a resume.
5. Feedback reports and email
Submitting the in-app feedback form sends an email notification to support@climbiq.io, and creates an internal record tied to your account so we can follow up. If someone on our team replies from that inbox, the reply is captured and stored internally against your report, but it is not currently shown back to you in the app — replies happen over email, not in-app.
6. Who can see your data
Row-level security in our database and per-user-scoped file storage mean your resumes, jobs, cards, and generated content are visible only to your own account — not to other users — enforced at the database layer, not just in the app's own logic. A small number of ClimbIQ admins (currently: the founder and anyone explicitly granted sys-admin) can access account/billing-adjacent data and feedback reports through internal admin tooling for support and moderation purposes. If your account is a member of an organization/group (a b2b feature), a group admin can see aggregate counts about your library and adopted content, but not your resume content directly.
7. Retention
We keep your data until you ask us to delete it (Section 8) — there is currently no automatic expiration or purge of inactive accounts. Superseded versions of a resume or gap analysis (e.g. after a re-run or restore) are kept, not deleted, so you can see history — this is a product feature, not incidental retention.
Not yet decided: an automatic retention/expiration policy for long-dormant accounts. Nothing currently deletes an inactive account's data on its own.
8. Deleting your account
You can ask us to delete your account and everything tied to it at any time. This is currently a documented request, not self-serve — there is no in-app “Delete my account” button yet:
- Email support@climbiq.io, or use the in-app feedback form (Account → the feedback link), and ask for your account to be deleted.
- We aim to complete a deletion request within 14 days.
- Deletion removes your account, resumes, skill cards, jobs, gap analyses, generated resumes/cover letters, uploaded and generated files in storage, and feedback reports.
- If you'd rather keep your account but clear specific data (e.g. start your resume/job history over), say so explicitly — that's a smaller, separate operation and your account/login/plan stay intact.
Self-serve deletion (a button you click yourself, with no admin involved) is deferred past the alpha.
9. Payments
If you purchase a pass, payment is processed by Stripe — we don't store your card details ourselves. See the Terms of Service for what a pass covers.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated to active users.
11. Contact
Questions about this policy, or a deletion/data request: support@climbiq.io.