← Back to PavedIT

Trust center

Privacy principles

Beta notice · Updated August 8, 2026

What PavedIT collects

Account details, career goals, preferences, saved roles, application activity, recommendation feedback, and résumés you explicitly upload. PavedIT does not create sample candidate profiles.

Product improvement analytics

Product improvement analytics are off by default and are not required for job search, matching, saving, or applications. If you opt in from Profile, event-specific allowlists permit only defined categories and bounded counts. PavedIT does not retain search phrases, free-form career-goal text, résumé text, messages, names, or email addresses in product analytics. You can turn this consent off or delete your stored product analytics at any time.

Recommendation outcome research is a separate, off-by-default choice. If enabled, a future candidate-reported application-stage change may be linked to the most recent still-retained ranking snapshot for that job. The observation contains model version, rank, score, signal coverage, ranking timestamp, and the stage transition—not résumé text or protected attributes. It is observational evidence and does not show that a recommendation caused an interview, offer, rejection, or hire. Observations expire after 365 days; withdrawing consent deletes them immediately without changing your private application history.

Performance diagnostics

Performance diagnostics are off by default. If you enable them in Profile, PavedIT stores bounded timing measurements such as response, load, largest-contentful-paint, layout-shift, and interaction latency. These owner-scoped records include only the workspace route, a mobile-or-desktop viewport class, and the observation window. They do not contain search queries, page contents, résumé text, user-agent strings, or hardware identifiers. You can turn diagnostics off or delete the stored measurements at any time.

Résumé handling

Résumé files are stored in a private, user-scoped bucket. They are not public and are not shown to recruiters by default. Uploaded files enter a private processing queue, are scanned for malware before text extraction, and fail closed when the scanner is unavailable. Detected files are moved outside the user-accessible path. Derived evidence remains labeled as unconfirmed until the candidate reviews it.

Recruiter access

Recruiter discovery is off by default. A verified recruiter may initiate contact only when an active candidate consent record permits it. Consent can be withdrawn.

Your controls

Authenticated Profile controls create trackable data-export and account-deletion requests, and résumé deletion uses a durable owner-scoped storage workflow. Fulfillment operations and legally reviewed retention periods must be completed before general availability.

Beta limitation

This is a product transparency summary, not final legal advice or a substitute for the jurisdiction-specific privacy notice required before commercial launch.