Privacy policy

How we handle your data

What data flows through the product, why it's there, and how you can remove or export it.

Last updated August 2, 2026

1. Who operates the service

Recruiter in Your Pocket (RIYP, we, or us) is an independent software service operated from Colorado, United States. RIYP is the service operator and controller for personal data collected directly through this website and product. Stripe and the other providers listed below act under their own terms or as processors for the services they provide.

This policy covers resume inputs, account information, usage data, extension capture data, saved job data, analytics metadata, support requests, and billing events processed by the web app.

Resume upload text (analysis input)

Purpose
Generate recruiter-style feedback, scoring, and rewrite guidance.
Retention
RIYP does not store raw input for anonymous runs. OpenAI may retain API abuse-monitoring logs containing customer content for up to 30 days by default.
Control
Sign in to save your history, or delete your account in Settings.

Report output + resume preview

Purpose
So you can open past reports, compare versions, inspect evidence excerpts, and export.
Retention
A completed anonymous report output and its evidence excerpts are held for browser recovery for no more than 24 hours; the raw anonymous resume and job description are not stored by RIYP. If you sign in and save, history includes report output, evidence excerpts, a short resume preview, and any job description you add until you delete the report or account.
Control
Anonymous recovery expires automatically. Delete saved reports in History, or delete your account in Settings.

Saved resume profile (default resume)

Purpose
Job matching and extension workflows.
Retention
Stored until you replace it, remove it, or delete your account. Includes raw resume text for matching plus derived skills, seniority signals, embeddings, hash, and preview.
Control
Replace or remove it in Settings > Matching, or delete your account.

Captured jobs and job descriptions

Purpose
Save roles from the extension, run role-fit checks, and compare your resume against specific postings.
Retention
Stored when you save a job or sync extension captures. Includes job title, company, URL, description text, match signals, and latest report links until you delete the saved job or your account.
Control
Delete saved jobs from Jobs, delete linked reports from Reports, or delete your account in Settings.

Account identity (email, name)

Purpose
Authentication and account access.
Retention
Retained while account is active.
Control
Update your profile in Settings, or delete your account.

Support communications and attachments

Purpose
Respond to product, account, billing, privacy, and security requests sent to the public support address.
Retention
Kept only as long as reasonably needed to resolve the request, preserve security or billing evidence, meet legal obligations, and maintain support continuity. Provider logs follow their configured retention windows.
Control
You choose what to send. You can ask us to delete a support conversation unless we need to retain it for security, fraud prevention, billing, or legal compliance.

Usage, reliability, and abuse-prevention metadata

Purpose
Free-report eligibility, rate limiting, reliability diagnostics, billing state, and product health.
Retention
Signed browser cookies used for anonymous identity and free-report status may remain for up to 365 days, and their browser expiration renews when we set them again. Server-side anonymous eligibility records, including separately salted network hashes, expire within 40 days. Raw network addresses are not stored in the eligibility ledger. Rate-limit and idempotency records are short-lived; other operational records are retained for product and security needs.
Control
Anonymous eligibility records are not attached to an account. Deleting your account removes app-level history.

Background job events and results

Purpose
Generate account exports and, when used, PDF files without keeping the request open.
Retention
Retained under Inngest's configured event and run-history windows. Completed account exports stored in Supabase expire after seven days.
Control
Background export work starts only when you request it. You can delete your account and its app-level export records in Settings.

Product analytics and conversion telemetry

Purpose
Measure product quality, onboarding friction, and billing funnel health when analytics is enabled.
Retention
Retained under the analytics vendors' configured retention windows.
Control
Respects browser Do Not Track and can be disabled at launch.

Billing events and invoices

Purpose
Charge processing, receipts, purchase restoration, refunds, and dispute handling.
Retention
Stripe retains authoritative billing records under its policies. RIYP keeps limited receipt and entitlement metadata for reconciliation, security, and reversal handling.
Control
View receipts and restore purchases from Billing settings. Account deletion removes user-linked app billing records; opaque reversal identifiers may remain to prevent access from being re-granted.

3. Third-party processors

OpenAI generates reports, Supabase handles auth and database storage, Stripe handles billing, Vercel provides hosting, Sentry handles error monitoring, and Mixpanel handles product analytics when enabled. Upstash provides shared rate limiting and short-lived idempotency storage. Inngest coordinates background account-export jobs and PDF generation when those features are used. Resend delivers authentication email and receives public support mail; support messages and attachments are forwarded to and handled in Google (Gmail). Stripe manages card data on its systems. We never have access to it.

4. Your controls

You can export your account data, delete individual reports, and permanently delete your account from Settings. Account deletion removes user-owned product data from RIYP's application database and cancels any legacy RIYP subscription we can verify. Stripe may retain payment records, and RIYP keeps narrowly scoped deletion and billing-reversal records when needed to prevent restored access, investigate fraud, meet accounting obligations, or comply with law. We don't sell personal data, and anonymous history is not silently attached to an account.

5. Privacy requests

To request access, correction, deletion, portability, restriction, or an appeal where those rights apply, email support@recruiterinyourpocket.com with the subject “Privacy request.” We may verify that you control the account email before releasing or changing personal data. We aim to acknowledge requests within 10 days and complete verified requests within 45 days unless the applicable law permits more time. We will explain any extension or denial and will not discriminate against you for making a privacy request.

6. Contact and complaints

Questions, privacy complaints, and authorized-agent requests can be sent to support@recruiterinyourpocket.com. If a privacy concern is not resolved, you may contact the regulator or attorney general available in your jurisdiction. Security disclosures should follow the instructions on /security or /.well-known/security.txt.