Privacy Policy
What we collect, who receives it, and how long we keep it. The two things worth knowing up front: your resume text is sent to OpenAI to produce match scores, and we never sell your data or train models on it.
Last updated August 23, 2026
1.Who is responsible
internOS operates internOS and is the controller of the personal data described here. Reach us at support@internos.app.
2.What we collect
An anonymous session, before you sign up. Visiting internOS creates an anonymous account so that saving a role works immediately. It holds a random identifier and nothing about you — no name, no email. It becomes a real account only if you choose to sign up.
Account data. Your email address, and if you sign in with Google, the identity Google confirms to us.
Profile data, all optional. Name, school, major, graduation year, and links to LinkedIn, GitHub, or a portfolio.
Your resume. The file you upload, plus the structured text we extract from it (education, experience, skills) so it can be compared against postings. This is the most sensitive data we hold.
Activity. Roles you save and mark applied, notes you attach, application status, match scores we generated for you, companies whose contacts you unlocked, and your remaining search credits.
Billing. Your Stripe customer identifier and subscription status. We never receive your card number — Stripe collects it directly.
Technical data. The request logs that come with serving a website: IP address, browser, pages requested, timestamps.
3.Why we use it
- To run the service — keep you signed in, remember saved roles, show your application board. Basis: performance of our contract with you.
- To score and write. Match scores, cover letters, and resume tailoring require sending your resume text and the job description to OpenAI. Basis: performance of our contract, at your request.
- To take payment and manage subscriptions. Basis: performance of our contract.
- To keep it working and fair — debugging, abuse prevention, and the rate limits on our AI endpoints. Basis: legitimate interests.
- To comply with law, including tax records for payments.
We do not sell your personal data, we do not share it with advertisers, and we do not use your resume or activity to train machine-learning models.
4.Who receives it
We use these processors, and only for the purposes listed. Each is bound to handle the data on our instructions.
| Processor | What it does | Personal data |
|---|---|---|
| Supabase | Hosts the database, authentication, and the storage bucket your resume file sits in. | Yes |
| OpenAI | Receives your resume text and a job description to produce match scores, cover letters, and tailored resume suggestions. | Yes |
| Stripe | Processes subscription payments. Stripe collects your card details directly — they never reach our servers. | Yes |
| Vercel | Serves the site and processes the request logs that come with it. | Yes |
| Only if you choose Google sign-in, in which case Google confirms your identity to us. | Yes | |
| Serpent API / A-Leads | Searches for recruiters and hiring managers at a company. Sent a company name and role title only, never anything about you. | No |
| logo.dev | Supplies company logos by domain name. | No |
We may also disclose data if the law requires it, or to protect our rights or someone’s safety. If the business is ever sold, data may transfer with it, and this policy will continue to apply to it.
5.Employers do not get your profile
internOS is not a candidate marketplace. We do not send your resume or profile to employers, and employers cannot browse our users. When you apply, you leave for the employer’s own site and deal with them directly under their privacy policy, not ours.
The people-search feature works the other way round: we look up recruiters and hiring managers at a company using the company name and role title. Nothing about you is sent to those providers.
6.Where it is stored, and for how long
Our database, authentication, and file storage are hosted by Supabase; the site runs on Vercel. Data is processed in the United States and may be transferred there from wherever you are, under the transfer safeguards those providers offer.
- While your account is open — we keep your profile, resume, and activity so the product works.
- Your resume — deleted from storage when you replace or remove it. Removing it also clears the extracted text.
- When you delete your account — your profile, resume, saved roles, notes, and match scores are deleted within 30 days.
- Abandoned anonymous sessions — deleted once dormant, since they hold no way to contact or identify anyone.
- Payment records — kept as long as tax and accounting law requires, typically seven years, even after account deletion.
- Request logs — retained for a short operational period by our hosting providers.
7.Your rights
Wherever you live, you can ask us to show you the data we hold, correct it, delete it, or send you a copy. Email support@internos.app and we will respond within 30 days. Most of it you can do yourself from your profile page.
If you are in the UK or EEA, the GDPR also gives you the right to restrict or object to processing, to withdraw consent, and to complain to your national data-protection authority. If you are in California, you have the rights to know, delete, and correct, and the right not to be discriminated against for exercising them — we do not sell or share personal information as those terms are defined, so there is nothing to opt out of. If you are in Canada, PIPEDA gives you access and correction rights and a complaint route to the Office of the Privacy Commissioner.
8.Cookies and tracking
We use browser storage for one thing: keeping you signed in and holding your session. There are no advertising or third-party analytics trackers, so there is no consent banner to dismiss. Clearing this storage signs you out, and if the session was anonymous, loses what it held.
9.Children
internOS is for university students and recent graduates and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has given us any, write to support@internos.app and we will delete it.
10.Security, and its limits
Access is enforced in the database itself: row-level security policies mean a signed-in user can read only their own profile, resume, saved roles, and match scores. Traffic is encrypted in transit, and resume files sit in a private bucket rather than a public one.
No service is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data, we will notify you and any regulator we are required to tell.
11.Changes
We will update this policy as the product changes. Material changes will be announced in the product, and the date above will change. Governing law is that of the Province of Ontario, Canada. See also our Terms of Service.