Sub-processors

These are the third parties that process data on our behalf. We keep this list current; if the stack changes, this page updates with it.

Sub-processorPurposeData shared
OpenAILarge-language-model inference (resume parsing, tailoring, key insights, match analysis)Resume text and uploaded resume files; job descriptions; AI prompts
Google (Gemini)Optional alternative LLM provider, selected via configurationSame as OpenAI when configured as the active provider
SupabaseObject storage for uploaded resume files (private bucket; backend-proxied)Raw PDF, DOCX, and TXT files you upload
StripeSubscription billing, Checkout, Customer PortalEmail, name, Stripe customer/subscription metadata (we never see card details)
ResendTransactional email delivery (one-time login codes)Your email address and the OTP for that login attempt
Cloudflare (Turnstile)Bot prevention on the passwordless login request endpointIP address and browser metadata at the moment you request a code
SentryApplication error monitoring (frontend + backend)Stack traces, request paths, and your user id; PII scrubbed at the SDK boundary
Production hosting infrastructureApplication serving and inbound HTTPS terminationAll HTTP request data routed through the platform

We do not use third-party analytics or advertising trackers.