Privacy Notice
This engineering draft explains the data Career Agent currently processes. It requires legal review before production use.
Account and security
Email, account details, authentication and session metadata, and security events are used to operate and protect the account.
LEGAL_REVIEW_REQUIRED
Profile, jobs and applications
Experience, education, skills, certifications, profile evidence, resumes, saved or hidden jobs, application workspaces, prepared documents, screening answers, and lifecycle history support matching and application preparation.
Career Agent does not submit applications automatically.
Inbox intelligence
No production Gmail or Outlook connector is enabled in this release. If enabled later, the connector will be read-only for employment-related messages, disclose its actual OAuth scopes, retain only the structured hiring evidence needed by the product, and provide a disconnect path. Lifecycle changes still require user confirmation.
Assessment and interview practice
Practice attempts, answers, progress, writing responses, speaking transcripts, text or voice interview answers, factual speech metrics, presentation summaries, and mock history support preparation and recommendations.
These outputs are preparation tools, not employer decisions or hiring probabilities.
Microphone and camera
Microphone access is requested only during an active practice action. Audio may be sent transiently to the configured speech-to-text provider; raw audio is not permanently retained, while committed transcripts, timestamps, and factual derived metrics may persist.
Camera use is optional and requested only for presentation coaching. Raw video, images, frames, and face data are not retained; bounded observable summaries may persist. Career Agent does not perform biometric identity, emotion, personality, or confidence inference.
Outcomes, billing and operations
Confirmed career events and preparation exposure remain tenant-private. Plan, subscription, payment-operation metadata, security logs, bounded diagnostics, and operational telemetry support the service when those capabilities are enabled.
Billing and financial record retention is marked LEGAL_RETENTION_REVIEW_REQUIRED; no retention duration is asserted here.
Optional product improvement
Optional product-improvement permission is separate from core service processing and defaults off. Recording permission does not enable cross-user learning, advertising, model training, or a data export pipeline in this release.
Retention, export and deletion
Account export artifacts expire after 24 hours. Completed deletion purges primary operational data. Disaster-recovery copies may remain until bounded 35-day or 365-day backup retention expires, with restore suppression and re-purge safeguards before cutover.
These are current technical retention controls, not final legal retention conclusions. Legal retention exceptions require review.