This is a working draft, not legal advice. It accurately describes how Gradus handles data today, but has not been reviewed by a lawyer and must not be relied on as a finished policy. Fields shown like this are placeholders that still need to be filled in, and several sections are marked (verify) pending confirmation. Have qualified privacy counsel review this against the laws that apply to you (e.g. GDPR, UK GDPR, CCPA/CPRA) before relying on it publicly.
Draft last updated: August 4, 2026 · Applies to the Gradus web application at [app domain]and related services (the “Service”), operated by [Legal Entity Name](“Gradus”, “we”, “us”).
Gradus is a recruiting workspace and AI coaching tool for students. This policy explains what personal information we collect, how we use it, who we share it with, and the choices and rights you have. We collect only what we need to run the Service, and your data is scoped to your own account.
Account information. When you sign up we collect your name and email address. Authentication (including your password) is handled by our authentication provider (Supabase). We never see or store your password — it is hashed and managed by the provider.
Profile information you provide. School, major/minor, graduation year, GPA (optional), skills, any constraints you describe, optional LinkedIn/portfolio links, your recruiting track, and an optional target deadline.
Content you create in the Service. Job applications you track, tasks, networking contacts you add, calendar events, and weekly check-in reflections.
Hiring contacts from job postings. When you use Gradus to save or import a job posting, we may detect the name and public professional profile (such as a LinkedIn URL) of a recruiter or hiring-team member the posting itself names, and show them to you so you can keep them as a networking contact for your own follow-up. This happens only for a posting you choose to save; you can edit or remove these details before saving; and the resulting contact becomes part of your own private records — visible only to you and subject to the same deletion rights as any other contact (Section 8).
Documents you upload. Resumes, cover letters, and similar files (PDF/DOC/DOCX/TXT). We store the file itself and extract its text so the AI coach can reference it.
AI coach conversations. The messages you exchange with the AI coach, and which of your applications/documents you attach to a conversation.
Feedback and diagnostics. Feedback you submit in-app, and technical error reports — an error message, diagnostic details such as a stack trace, and a label for the part of the app where the problem occurred — used to detect and fix problems. These reports are tied to your account, but are not designed to capture the contents of your documents or your coach conversations.
Technical data. Standard information needed to operate a web app (e.g. session cookies, IP address, and basic request logs held by our infrastructure providers). (verify — confirm whether any analytics tooling is in use; if so, list it here.)
We do not collect payment information — the Service is free during beta. (verify — update when a paid plan launches.)
We do not sell your personal information, and we do not use it for third-party advertising.
The AI coach is powered by Anthropic's Claude API. To answer your questions and tailor advice, we send relevant context to Anthropic — this can include your profile details, the applications you're tracking, the text of documents you've uploaded, and your chat messages.
We only send this data when you use the coach. You can choose what documents/applications to attach to a conversation, and you can delete your data at any time (Section 8).
We don't sell your data. We share it only with infrastructure providers (“subprocessors”) that help us run the Service, each acting on our instructions:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage | Account, profile, all app content, uploaded files |
| Anthropic (Claude API) | AI coaching | Profile, applications, document text, chat messages |
| Vercel | App hosting / delivery | Technical/request data (e.g. IP address, request logs) |
We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a business transfer (e.g. merger or acquisition). (verify — confirm the full subprocessor list, including any analytics/email tools, and each provider's data-processing location.)
We keep your information for as long as your account is active. When you delete your account (Section 8), your profile, applications, tasks, contacts, documents, calendar events, check-ins, and coach conversations are permanently deleted, and your uploaded files are removed from storage. Backups and provider logs may persist for a limited period before expiring. (verify — state your providers' backup/log retention windows.)
We use essential cookies to keep you signed in and secure your session. These are required for the Service to function. (verify — if you add analytics or any non-essential cookies, disclose them here and implement a consent mechanism where required, e.g. in the EU/UK.)
The Service is intended for users who are [16 / 18] or older. It is not directed to children under 13, and we do not knowingly collect their data. (verify — choose the minimum age based on your target users and applicable law; adjust for GDPR's age-of-consent rules if you have EU/UK users.)
Your information may be processed in [country/countries] and other locations where our providers operate. (verify — if you have EU/UK/other international users, add the required transfer mechanism, e.g. Standard Contractual Clauses, and your legal bases for processing.)
We may update this policy from time to time. We'll post the new version here and update the effective date, and provide additional notice for material changes.
Questions or requests: [privacy contact email] — [Legal Entity Name, mailing address].