Sub-processors
These are the third parties that process data on our behalf. We keep this list current; if the stack changes, this page updates with it.
| Sub-processor | Purpose | Data shared |
|---|---|---|
| OpenAI | Large-language-model inference (resume parsing, tailoring, key insights, match analysis) | Resume text and uploaded resume files; job descriptions; AI prompts |
| Google (Gemini) | Optional alternative LLM provider, selected via configuration | Same as OpenAI when configured as the active provider |
| Supabase | Object storage for uploaded resume files (private bucket; backend-proxied) | Raw PDF, DOCX, and TXT files you upload |
| Stripe | Subscription billing, Checkout, Customer Portal | Email, name, Stripe customer/subscription metadata (we never see card details) |
| Resend | Transactional email delivery (one-time login codes) | Your email address and the OTP for that login attempt |
| Cloudflare (Turnstile) | Bot prevention on the passwordless login request endpoint | IP address and browser metadata at the moment you request a code |
| Sentry | Application error monitoring (frontend + backend) | Stack traces, request paths, and your user id; PII scrubbed at the SDK boundary |
| Production hosting infrastructure | Application serving and inbound HTTPS termination | All HTTP request data routed through the platform |
We do not use third-party analytics or advertising trackers.