This is a working draft, not legal advice. It accurately describes how Gradus handles data today, but has not been reviewed by a lawyer and must not be relied on as a finished policy. Fields shown like this are placeholders that still need to be filled in, and several sections are marked (verify) pending confirmation. Have qualified privacy counsel review this against the laws that apply to you (e.g. GDPR, UK GDPR, CCPA/CPRA) before relying on it publicly.

Privacy Policy

Draft last updated: August 4, 2026 · Applies to the Gradus web application at [app domain]and related services (the “Service”), operated by [Legal Entity Name](“Gradus”, “we”, “us”).

1. Overview

Gradus is a recruiting workspace and AI coaching tool for students. This policy explains what personal information we collect, how we use it, who we share it with, and the choices and rights you have. We collect only what we need to run the Service, and your data is scoped to your own account.

2. Information we collect

Account information. When you sign up we collect your name and email address. Authentication (including your password) is handled by our authentication provider (Supabase). We never see or store your password — it is hashed and managed by the provider.

Profile information you provide. School, major/minor, graduation year, GPA (optional), skills, any constraints you describe, optional LinkedIn/portfolio links, your recruiting track, and an optional target deadline.

Content you create in the Service. Job applications you track, tasks, networking contacts you add, calendar events, and weekly check-in reflections.

Hiring contacts from job postings. When you use Gradus to save or import a job posting, we may detect the name and public professional profile (such as a LinkedIn URL) of a recruiter or hiring-team member the posting itself names, and show them to you so you can keep them as a networking contact for your own follow-up. This happens only for a posting you choose to save; you can edit or remove these details before saving; and the resulting contact becomes part of your own private records — visible only to you and subject to the same deletion rights as any other contact (Section 8).

Documents you upload. Resumes, cover letters, and similar files (PDF/DOC/DOCX/TXT). We store the file itself and extract its text so the AI coach can reference it.

AI coach conversations. The messages you exchange with the AI coach, and which of your applications/documents you attach to a conversation.

Feedback and diagnostics. Feedback you submit in-app, and technical error reports — an error message, diagnostic details such as a stack trace, and a label for the part of the app where the problem occurred — used to detect and fix problems. These reports are tied to your account, but are not designed to capture the contents of your documents or your coach conversations.

Technical data. Standard information needed to operate a web app (e.g. session cookies, IP address, and basic request logs held by our infrastructure providers). (verify — confirm whether any analytics tooling is in use; if so, list it here.)

We do not collect payment information — the Service is free during beta. (verify — update when a paid plan launches.)

3. How we use your information

  • To provide the Service — store and display your applications, tasks, contacts, documents, calendar, and check-ins.
  • To power the AI coach, which uses your profile, applications, and documents to give personalized guidance (see Section 4).
  • To generate features like your recommended “next best action” and recruiting-timeline guidance.
  • To maintain security, prevent abuse, debug errors, and improve the Service.
  • To communicate with you about the Service. (verify — add marketing email practices if applicable, with opt-out.)

We do not sell your personal information, and we do not use it for third-party advertising.

4. AI features and automated processing

The AI coach is powered by Anthropic's Claude API. To answer your questions and tailor advice, we send relevant context to Anthropic — this can include your profile details, the applications you're tracking, the text of documents you've uploaded, and your chat messages.

  • Anthropic processes this data to generate the coach's responses on our behalf, as a service provider/subprocessor.
  • Under Anthropic's commercial API terms, your inputs and outputs are not used to train their models. (verify against Anthropic's current Commercial Terms / DPA at the time of publishing.)
  • The coach's responses are AI-generated and may be inaccurate or incomplete. They are informational and are not professional, legal, financial, or career-placement advice, and are not guarantees of any outcome.

We only send this data when you use the coach. You can choose what documents/applications to attach to a conversation, and you can delete your data at any time (Section 8).

5. How we share information

We don't sell your data. We share it only with infrastructure providers (“subprocessors”) that help us run the Service, each acting on our instructions:

ProviderPurposeData involved
SupabaseDatabase, authentication, file storageAccount, profile, all app content, uploaded files
Anthropic (Claude API)AI coachingProfile, applications, document text, chat messages
VercelApp hosting / deliveryTechnical/request data (e.g. IP address, request logs)

We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a business transfer (e.g. merger or acquisition). (verify — confirm the full subprocessor list, including any analytics/email tools, and each provider's data-processing location.)

6. Data storage and security

  • Data is stored with our hosting/database provider (Supabase). Access is enforced at the database level with row-level security, so each user can only access their own records.
  • Passwords are hashed by our authentication provider; we never store them in plaintext.
  • Uploaded files are kept in a private storage bucket; access requires a short-lived, per-request authorized link, not a public URL.
  • Data is encrypted in transit (HTTPS). (verify — confirm encryption-at-rest posture with your providers and state it here.)
  • No method of storage or transmission is 100% secure; we cannot guarantee absolute security.

7. Data retention

We keep your information for as long as your account is active. When you delete your account (Section 8), your profile, applications, tasks, contacts, documents, calendar events, check-ins, and coach conversations are permanently deleted, and your uploaded files are removed from storage. Backups and provider logs may persist for a limited period before expiring. (verify — state your providers' backup/log retention windows.)

8. Your rights and choices

  • Access & correction. You can view and edit your profile and content anytime in the app.
  • Deletion. You can permanently delete your account and all associated data yourself from Edit Profile → Delete account. This is irreversible.
  • Depending on where you live, you may have additional rights (access, portability, correction, deletion, objecting to or restricting processing, and the right to complain to a data-protection authority). To exercise these, contact us at [privacy contact email]. (verify — add the specific GDPR/CCPA rights language and any “Do Not Sell/Share” statement your counsel requires; note that we do not sell data.)

9. Cookies

We use essential cookies to keep you signed in and secure your session. These are required for the Service to function. (verify — if you add analytics or any non-essential cookies, disclose them here and implement a consent mechanism where required, e.g. in the EU/UK.)

10. Children and eligibility

The Service is intended for users who are [16 / 18] or older. It is not directed to children under 13, and we do not knowingly collect their data. (verify — choose the minimum age based on your target users and applicable law; adjust for GDPR's age-of-consent rules if you have EU/UK users.)

11. International users

Your information may be processed in [country/countries] and other locations where our providers operate. (verify — if you have EU/UK/other international users, add the required transfer mechanism, e.g. Standard Contractual Clauses, and your legal bases for processing.)

12. Changes to this policy

We may update this policy from time to time. We'll post the new version here and update the effective date, and provide additional notice for material changes.

13. Contact

Questions or requests: [privacy contact email][Legal Entity Name, mailing address].