CV CVPortal Privacy notice

Prototype privacy boundary

Privacy Notice

This page describes the current CVPortal / ChatMyApp prototype behavior. It is a product placeholder for deployment review and should be reviewed by counsel before a commercial launch.

What this product is

CVPortal helps candidates gather and share role-ready career evidence. It also provides paid employer hiring rooms for role outcomes, candidate-approved proof, communications, structured reviews, and offers. The Patrick Kelly workspace is the seed implementation.

Information handled

  • Candidate workspace records such as profile details, sources, claims, artifacts, interview answers, and dossier spaces.
  • Uploaded files such as resumes, PDFs, screenshots, images, headshots, and project notes.
  • Generated access-link metadata such as source label, recipient label, status, use count, expiry, and last-used time.
  • Candidate model-provider configuration such as provider, model, key hint, validation time, and an encrypted API-key envelope.
  • Remote-agent authorization metadata such as OAuth client, reviewer dossier scope or candidate workspace scope, subject user, connector grant, expiry, refresh-token rotation, and revocation status.
  • Candidate-private job-search records such as search terms, location preference, selected official source identifiers, public posting details, evidence-based match explanations, visible gaps, saved or dismissed status, candidate notes, and application-preparation packets.
  • Recruiting-room records such as employer role outcomes, success criteria, private invitation hashes, candidate-selected room profiles, hiring stage history, human or agent message provenance, structured job-related evidence notes, offer terms, approvals, and candidate responses.
  • Founding-access or partner requests such as name, email, selected offer, target role or organization, country, message, source attribution, contact consent, status, and timestamps.
  • Platform billing metadata such as the selected public offer key, Stripe customer/subscription identifiers, subscription status, renewal period, and entitlement state. Payment-card details are handled by Stripe and are not returned to CVPortal.
  • Interaction metadata such as resume source, timestamp, broad question category, message length, model status, hashed session, and hashed client identity.
  • Redacted workspace export metadata such as inventory counts, review status, analytics summaries, audit events, billing posture, and explicit omission flags.

Payments and separate model-provider charges

Candidate platform payments are processed through Stripe. Employer recruiting pilots and subscriptions may be handled through a scoped order form and supported payment process. CVPortal may retain the billing identifiers and status needed to provide access, reconcile signed webhook events, support cancellation, and meet accounting or legal obligations, but does not receive full payment-card details. Candidate OpenAI or Anthropic usage is a separate relationship with that provider. Reviewer, candidate, and employer use of a compatible agent is governed by that account holder's provider agreement and is not billed as model usage by CVPortal.

What is not stored by default

  • Raw hiring-manager chat transcripts are not stored by default; if transcript capture is enabled, visitors or recruiting agents must opt in unless that consent guard is deliberately disabled by the operator. Expired raw transcripts can be purged through a private operator command whose report exposes counts only.
  • Raw access codes are not stored in generated workspace access links; the workspace stores HMAC hashes.
  • Reviewer ChatGPT, Claude, or other agent-provider passwords, subscription credentials, and API keys are not received by CVPortal.
  • Candidate OpenAI or Anthropic API keys are never returned after save. They are encrypted at rest with a dedicated key and are excluded from public APIs, exports, connector tools, analytics, and audit logs.
  • OAuth authorization codes and refresh tokens are HMAC-hashed at rest. Short-lived access tokens are audience-bound to the reviewer dossier, private candidate workspace, or private employer recruiting MCP resource.
  • Raw recruiting invitation tokens are returned for private delivery once; the recruiting store keeps a dedicated HMAC hash. One side's unsent message drafts and the employer's unsent offer drafts are not exposed to the other side.
  • CVPortal does not receive employer-site passwords, silently submit job applications, or store an employer application form on the candidate's behalf. A candidate may record that they submitted externally after doing so themselves.
  • Candidate-visible analytics omit session hashes, IP hashes, raw transcripts, request bodies, and credential material.
  • Candidate workspace data exports omit raw workspace JSON, registered source URLs, raw evidence bodies, prompt and answer text, access-code hashes, object keys, storage paths, local paths, vectors, and credentials.
  • Public dossier and agent endpoints do not expose private-review records, object keys, storage paths, or private upload internals.

Published dossier boundary

Public hiring-manager and agent-readable surfaces may retrieve only reviewed evidence marked public-safe, generalized, or published. Private-review uploads, draft claims, off-limits material, protected records, credentials, private production configuration, and trade-secret implementation detail are outside the published agent boundary.

Bring-your-own-agent boundary

A hiring manager may authorize a read-only CVPortal connector inside a compatible agent. The agent provider receives the candidate-approved dossier content needed for the requested tool call under the reviewer's own account and provider settings. CVPortal receives only its own scoped OAuth grant, not the reviewer's provider login. The candidate can revoke either the originating access link or the individual connector grant.

Opportunity Radar and candidate agents

An authenticated candidate may authorize a separate private career-agent connector. CVPortal checks the candidate's active workspace membership on every request and limits tools to the granted workspace, job, and application-preparation scopes. Opportunity Radar requests public job postings from official Greenhouse, Lever, Ashby, and, when configured, USAJOBS APIs. A provider may receive the network request and source or search parameters needed for that retrieval. CVPortal then performs candidate-side matching against reviewed evidence, shows supporting evidence and gaps, excludes protected traits, and does not make hiring decisions for employers.

Application packets are private drafts until the candidate reviews them. CVPortal requires explicit truth, target, and official-form confirmations before approval, then returns the employer's official application URL. The candidate remains responsible for reviewing and submitting the external form.

Employer hiring rooms and employer agents

An authenticated employer workspace may create role briefs, invite candidates, keep a stage history, exchange messages, record structured job-related evidence notes, and prepare or send offers. A candidate chooses whether to accept a room invitation and which role-ready profile or portal link to share. CVPortal does not use protected traits for matching, create a hidden numeric candidate rank, or make an employment decision for an employer.

An employer may authorize a preparation-only agent connector. Employer-agent tools can read authorized hiring rooms and prepare role briefs, messages, and offer drafts. They cannot publish a role, move a stage, submit a review, send a message, rank or reject a candidate, or approve, send, withdraw, accept, decline, or counter an offer. Those actions require an authenticated person and are recorded with provenance.

Visitor guidance

Do not enter confidential, sensitive, protected, or proprietary information into the hiring-manager chat. Treat access links and QR URLs as bearer credentials. Anyone with a valid access code may reach the gated dossier until the candidate revokes the link or the link expires.

Candidate controls

The candidate workspace can review, edit, approve, generalize, reject, or keep evidence private before it becomes visible in a published dossier. Workspace write, private search, upload, analytics, and audit APIs require candidate workspace authorization. The authenticated workspace also exposes a redacted data export so the candidate can inspect stored categories, review posture, analytics, audit, and billing metadata without downloading bearer material or raw private evidence bodies. Candidates can also delete saved provider keys, disable managed-model fallback, revoke reviewer or candidate connector grants, dismiss or restore opportunity records, edit application pitches, choose whether to join employer hiring rooms, keep private drafts from the employer until sent, and personally decide how to respond to an offer.

Prototype status

The local prototype is not yet production SaaS. A hosted launch should use managed identity, durable database storage, private object storage, secure cookies, production secrets, backups, monitoring, and completed legal review.

Terms Back to chat Readiness manifest