One authorized analysis. No retained candidate file.

Policy version 2026-08-13 defines consent, transient processing, suppression, result handling, and the records the analysis workflow may keep.

15 minVerified analysis session
0Uploaded documents retained
30 daysOperational lead expiry

Authority and consent.

Before analysis, the visitor must confirm that they own the resume or have authority to process it and agree to the current policy version. The service records only the policy version and consent timestamp, never the resume or job description in the consent record.

Marketing consent is optional, unticked by default, and separate from the operational email needed to verify an analysis request.

Accepted input and limits.

Job description

Pasted text from 500 to 15,000 characters.

Resume

One PDF, DOCX, or UTF-8 text file up to 5 MB.

PDF boundary

Up to 10 pages, no encryption, attachments, or image-only scan.

Text boundary

Up to 50,000 extracted characters, with no OCR in the live analysis workflow.

Transient content processing.

The application server validates and extracts the document, normalizes text while preserving citation offsets, suppresses specified identity and proxy categories, sends only redacted text to the configured private model service, verifies returned citations, and returns a short-lived result.

Uploads, extracted content, redacted content, model payloads, result data, and generated dossiers are not written to databases, object storage, analytics, email, monitoring attachments, provider volumes, or application caches.

Suppression before inference.

The analysis workflow suppresses names, email addresses, phone numbers, street and postal addresses, photographs, gendered pronouns, graduation years, school names where degree context can remain, and citizenship or national-origin markers.

The result includes category names and counts only. Suppressed values are not shown in the suppression manifest.

Browser-only result handling.

The validated result and generated dossier remain in browser memory. They are not stored in local storage, IndexedDB, a service-worker cache, a server cache, or a shareable result URL. Reset, navigation away, or closing the tab clears the result state.

Limited operational records.

The service may keep a verification record, HMAC-based email identifier, consent version and timestamp, attempt counters, and a daily rotating HMAC of the network address for abuse prevention. Raw network addresses are not stored.

Operational analysis records expire after 30 days. Rotating network identifiers expire within 48 hours. A separately consented marketing record remains until unsubscribe or deletion.

Model and decision limits.

The live analysis workflow uses no external enrichment and does not train on candidate data. It does not calculate an overall candidate score or make an employment decision. Every output is marked Evidence output requires human review.

Continue only with an authorized file.

The live analysis workflow verifies an operational email and asks for authority consent before accepting input.