Privacy Policy

Last updated: July 16, 2026

This page explains what data CLAK (“the Service”) collects, why, and who it's shared with. If anything here changes, we'll update this page and the “Last updated” date above.

1. What we collect

  • Account info: your email address and authentication credentials (managed by Supabase Auth — we never see your raw password).
  • Resume content: any resume text you upload or paste, and the experience blocks, bullets, and Career Memory facts you create from it.
  • Job descriptions: the text of job descriptions you paste in to tailor a resume against.
  • Generated content: AI-tailored bullet variants and the resumes you export.
  • Basic usage metadata: timestamps of actions (e.g. when a variant was generated/accepted) used for in-app history and abuse/rate-limit prevention. We do not run third-party ad trackers.

2. How we use it

We use your data solely to provide the Service to you: storing your resume/experience data, running AI analysis and rewriting, and generating your exported PDF. We do not sell your data or use it for advertising.

3. Third parties who process your data

Because of how the Service works, the following third parties handle data on our behalf:

  • AI providers (OpenAI and/or Anthropic) — receive the job description text and resume/bullet text you submit, solely to generate analysis and rewrite suggestions. Per their current API terms, submissions through their API are not used to train their models.
  • Supabase — hosts our authentication system and Postgres database (where your account and resume data are stored).
  • Hosting provider (e.g. Vercel) — runs the application servers that process your requests.

We do not share your data with any other third party, and never sell it.

4. Data retention & deletion

Your data is kept for as long as your account exists. You can delete your account at any time from Settings — this permanently and immediately deletes your resumes, experience blocks, Career Memory, and generated content from our database. This action cannot be undone.

5. Cookies

We use only the session cookies Supabase Auth needs to keep you signed in. We do not use third-party advertising or tracking cookies.

6. Security

Data is stored in a managed Postgres database with row-level access scoped to your account, and transmitted over HTTPS. No system is 100% secure, but we don't take shortcuts with how your data is stored or transmitted.

7. Children's privacy

The Service is not directed at children under 16, and we do not knowingly collect data from them.

8. Changes to this policy

If we make material changes to how we handle your data, we'll update this page and, where appropriate, notify you directly.

9. Contact

Questions about this policy, or want to request deletion of your data outside the app? Email [email protected].