Security & data

How we handle your data

What we collect, why, how long we keep it, and what you can do about it.

Last updated August 2, 2026

What we store and why

Resume upload text (analysis input)

Purpose
Generate recruiter-style feedback, scoring, and rewrite guidance.
Retention
RIYP does not store raw input for anonymous runs. OpenAI may retain API abuse-monitoring logs containing customer content for up to 30 days by default.
Your control
Sign in to save your history, or delete your account in Settings.
Processor
OpenAI, Supabase

Report output + resume preview

Purpose
So you can open past reports, compare versions, inspect evidence excerpts, and export.
Retention
A completed anonymous report output and its evidence excerpts are held for browser recovery for no more than 24 hours; the raw anonymous resume and job description are not stored by RIYP. If you sign in and save, history includes report output, evidence excerpts, a short resume preview, and any job description you add until you delete the report or account.
Your control
Anonymous recovery expires automatically. Delete saved reports in History, or delete your account in Settings.
Processor
Upstash, Supabase

Saved resume profile (default resume)

Purpose
Job matching and extension workflows.
Retention
Stored until you replace it, remove it, or delete your account. Includes raw resume text for matching plus derived skills, seniority signals, embeddings, hash, and preview.
Your control
Replace or remove it in Settings > Matching, or delete your account.
Processor
Supabase, OpenAI (embeddings)

Captured jobs and job descriptions

Purpose
Save roles from the extension, run role-fit checks, and compare your resume against specific postings.
Retention
Stored when you save a job or sync extension captures. Includes job title, company, URL, description text, match signals, and latest report links until you delete the saved job or your account.
Your control
Delete saved jobs from Jobs, delete linked reports from Reports, or delete your account in Settings.
Processor
Supabase, Chrome local storage, OpenAI when used in a report

Account identity (email, name)

Purpose
Authentication and account access.
Retention
Retained while account is active.
Your control
Update your profile in Settings, or delete your account.
Processor
Supabase

Support communications and attachments

Purpose
Respond to product, account, billing, privacy, and security requests sent to the public support address.
Retention
Kept only as long as reasonably needed to resolve the request, preserve security or billing evidence, meet legal obligations, and maintain support continuity. Provider logs follow their configured retention windows.
Your control
You choose what to send. You can ask us to delete a support conversation unless we need to retain it for security, fraud prevention, billing, or legal compliance.
Processor
Resend, Google (Gmail)

Usage, reliability, and abuse-prevention metadata

Purpose
Free-report eligibility, rate limiting, reliability diagnostics, billing state, and product health.
Retention
Signed browser cookies used for anonymous identity and free-report status may remain for up to 365 days, and their browser expiration renews when we set them again. Server-side anonymous eligibility records, including separately salted network hashes, expire within 40 days. Raw network addresses are not stored in the eligibility ledger. Rate-limit and idempotency records are short-lived; other operational records are retained for product and security needs.
Your control
Anonymous eligibility records are not attached to an account. Deleting your account removes app-level history.
Processor
Supabase, Sentry, Vercel, Upstash

Background job events and results

Purpose
Generate account exports and, when used, PDF files without keeping the request open.
Retention
Retained under Inngest's configured event and run-history windows. Completed account exports stored in Supabase expire after seven days.
Your control
Background export work starts only when you request it. You can delete your account and its app-level export records in Settings.
Processor
Inngest, Supabase

Product analytics and conversion telemetry

Purpose
Measure product quality, onboarding friction, and billing funnel health when analytics is enabled.
Retention
Retained under the analytics vendors' configured retention windows.
Your control
Respects browser Do Not Track and can be disabled at launch.
Processor
Mixpanel, Vercel

Billing events and invoices

Purpose
Charge processing, receipts, purchase restoration, refunds, and dispute handling.
Retention
Stripe retains authoritative billing records under its policies. RIYP keeps limited receipt and entitlement metadata for reconciliation, security, and reversal handling.
Your control
View receipts and restore purchases from Billing settings. Account deletion removes user-linked app billing records; opaque reversal identifiers may remain to prevent access from being re-granted.
Processor
Stripe, Supabase

What we commit to

  • Your upload is encrypted in transit.
  • Completed anonymous report output can be recovered in the same browser for up to 24 hours, but is not saved to an account automatically. RIYP does not store the raw anonymous resume or job description.
  • Signed-in reports save report output, evidence excerpts, a short resume preview, and any job description you add. You can delete reports from Reports.
  • Deleting your account removes your reports and usage history from our database.
  • We don't sell your data or opt it into model training. OpenAI API data is not used to train models by default.
  • The clarity summary scores this resume review out of 100. It does not predict interviews, offers, or other hiring outcomes.
  • Your first complete report is free. No card required. Eligibility can be affected by repeat use across browsers or shared networks, and daily beta capacity applies.
  • A Job Search Pass is one payment for five additional reports over 30 days. It does not renew, and you can restore it from Billing.
  • Security reports can be sent using the disclosure instructions on our Security page.

Responsible disclosure

If you discover a security issue, please email support@recruiterinyourpocket.com with steps to reproduce it. The same disclosure instructions are published at /.well-known/security.txt.