What data we collect
To run the service we need only the minimum:
- Email and name — at signup and in your profile
- Resume data you upload or import yourself (from HH.ru, LinkedIn)
- Service usage history: AI copilot sessions, sent auto-applications, mock-interview results
- Technical data: IP address, browser/device type, timestamps — for security and stability
- Payment data — handled by payment providers (YooKassa, Platega); we only store the fact of payment and the last 4 digits of the card
How we use the data
Collected data is used strictly for:
- Running the AI copilot on the call: transcripts are sent to the LLM in the moment and not stored
- AI resume analysis and generating tailored resumes/cover letters
- Sending auto-applications on HH.ru on your behalf (via your personal token)
- Account, billing and product update notifications (you can opt out in settings)
- Preventing fraud and abuse (e.g. mass free-tier signups)
We don't record your conversations
The AI copilot processes interview audio in real time — transcripts are streamed to the LLM in a few-second batches and are not kept on our servers. After the session ends, a text summary is available (if you opted in), but the audio file and full transcript are not.
How we protect your data
Security is foundational:
- TLS 1.3 on every connection, HSTS enabled
- Encryption at rest at the database and disk level
- LLM traffic isolated, request bodies not logged
- Employee access on a need-to-know basis with audit logs
- Regular security audits and dependency updates
Your rights
Under Russian Federal Law 152-FZ and GDPR, you have the right to:
- Receive a copy of all your data (Export in settings or by request)
- Correct inaccurate profile data
- Delete your account and all related data — removed within 30 days
- Withdraw consent and cancel your subscription
- Disable marketing emails and push notifications
How long we retain data
Account data is kept for the lifetime of the account plus 90 days after deletion (for fraud prevention and billing obligations). AI copilot session logs — 30 days. Financial transaction records — 3 years (Russian tax-code requirement for legal entities).
Policy changes
We will notify you by email at least 30 days before any substantial change. Minor edits (typos, wording) are published immediately, with the 'Last updated' date refreshed at the top of the page.
Privacy contact
Data deletion requests, complaints and clarifications — support@jobpath.world. DPO and legal questions — hello@jobpath.world. We respond within 72 hours.