Privacy

Privacy Notice

What we store

To provide verified access, Lineup CV stores your email address, full name, professional role, personal LinkedIn URL, optional phone number, optional location, email-verification timestamp, consent versions and timestamps, your marketing email agreement, and your confirmation that you subscribe to salari.dev on LinkedIn. Your latest role may also be stored with its title, company, location, dates, employment type, project summary and achievement lines. When an exported CV scores 70 or higher, Lineup stores a metadata-only local reference including its local document ID, filename, target role, score, page count, paper format and export count. Verification challenges and authenticated sessions are stored for security. Security events record outcomes such as failed verification, lockouts, unauthorized requests, invalid uploads and server errors using pseudonymized actor and network-prefix identifiers. They do not contain passwords, verification codes, session tokens, raw IP addresses, request bodies, CV text or CV files.

What stays local

Your complete CV draft, generated PDF, roles other than your latest role, imported files, profile photo and target job description remain in browser storage. The Supabase CV reference does not contain a cloud copy or a link that can open the local CV on another device. Files are sent to the Lineup server only when required to parse an upload or generate a PDF and are not retained in the account database.

Product analytics

Optional first-party product analytics begin only after you accept them or enable them in Configure. They include events such as pages and controls used, device class, imports completed, onboarding progress, reported bugs and successful PDF exports. Analytics never include form values, CV text, job descriptions, profile photos, uploaded files, keystrokes or precise pointer recordings.

Marketing email and free access

Free access requires you to agree that salari.dev may store your email address and send occasional emails about salari.dev products, tools and updates. The signup checkbox is not preselected. If you do not agree, you cannot create a free-access account. You may unsubscribe using the method included in a marketing email. Withdrawing this agreement may end free access, but it does not affect processing that occurred before withdrawal.

Why we process it

Profile and verification information is processed to provide requested access, prevent abuse, maintain agreement records and support account security. The email address and recorded marketing agreement are used for the product emails described above. Limited first-party analytics are used to understand feature adoption and improve reliability.

Retention and deletion

Your profile is retained while verified access remains active. Expired verification challenges and sessions are removed automatically. Security-event records are retained for 90 days. Product-event retention must remain limited to the documented operational period. You can export your stored profile and permanently delete it from Account. Deployment backups may retain deleted records until their documented retention period expires.

Your choices

You can keep optional product analytics disabled through Configure while using essential authentication, security and local draft storage. You can also correct contact information, export your stored profile as JSON, log out, or delete your profile and linked analytics from Account. Privacy questions can be directed through salari.dev. Final legal rights depend on where you live.

Service providers

Supabase provides the production profile and first-party analytics database in the configured EU region. The production email provider processes the minimum name, email address and message content required to deliver verification codes. Provider agreements, retention and deletion processes must be documented before release.