Privacy Policy
Effective and last updated: August 30, 2026
Operator: Openlin (early-stage project)
Contact: privacy@openlin.ai
This policy explains how Openlin processes personal data in the Openlin iOS app and website.
1. Data we process
- Where account features are available, account identifiers and profile data received through Sign in with Apple or Google sign-in, such as name, email address, and profile image where provided.
- Career data you submit, including roles, skills, work history, résumé content, goals, salary expectations, learning progress, and interview material.
- AI conversation text and images you choose to upload, together with generated insights and preferences needed to provide the service.
- Where in-app purchases are available, purchase data from Apple and RevenueCat, including product, entitlement, transaction status, renewal, expiration, refund, and an Openlin user identifier. We do not receive or store full payment-card details.
- Device, app version, IP address, diagnostic, security, and feature-usage events needed to operate, secure, and improve the service.
- If you join the website waitlist, your email address, language, form entry point, campaign parameters, legal and optional marketing consent choices, email-verification challenge and delivery status, and relevant timestamps. Verification codes expire after a short period and are stored only as a one-way keyed hash, not in readable form. Cloudflare Turnstile processes security signals to prevent automated abuse. We do not store the Turnstile token or raw IP address in the waitlist record.
- If you complete Career Parallel, we process a short-lived anonymous attempt identifier, your responses, six work-signal values, pattern and driver identifiers, assessment versions, and language. The assessment does not request your email address. Raw responses are deleted after scoring, and only an anonymous versioned result summary is retained for up to 90 days. Shared result pages are common catalog pages and do not expose your answers or other personal data.
2. Why we use it
We process data to create and secure accounts; provide personalized career coaching, learning and résumé features; respond to support requests; manage subscriptions and entitlements; prevent fraud and abuse; diagnose reliability problems; and comply with legal obligations. Career Parallel uses your answers only to calculate and deliver the exploratory result. Joining the waitlist is a separate step after the result and follows the waitlist consent and email-confirmation process described in this policy. Where consent is required, you may withdraw it without affecting earlier lawful processing.
3. AI processing
Conversation text, uploaded images, résumé or job text, and relevant context may be sent to a commercial AI processor enabled for the feature you request, which may include Google Cloud Vertex AI, OpenRouter, or OpenAI. Provider availability and the feature may affect which processor is used. Generated results may be inaccurate and are not legal, tax, financial, or professional career advice. Do not submit sensitive data that is unnecessary for your request.
4. Service providers and disclosure
We do not sell personal data. We disclose only data needed to operate the service to:
- Supabase and its infrastructure providers for authentication, database, storage, and backend services.
- The AI processors listed above for generation, embeddings, and retrieval.
- Apple and RevenueCat when in-app purchases are offered, for purchase processing, subscription status, fraud prevention, and customer support.
- Hosting, monitoring, email, and analytics providers that are actually enabled in the released build.
- Cloudflare for website hosting and Turnstile abuse prevention, and Resend for transactional verification email and delivery events. We add a confirmed address to marketing contacts only when the separate optional marketing consent is selected.
We may also disclose data when legally required, to protect users or the service, or during a lawful business transfer. The App Store privacy label must be updated whenever enabled SDK behavior changes.
5. International transfers
Providers may process data outside the country or region where you live, including in the United States. We use provider contracts and safeguards appropriate to the transfer and as required by applicable law. Privacy laws in those locations may differ from those where you live.
6. Retention
- Account, career, learning, conversation, and generated-content data: while the account is active, then deleted or de-identified within 30 days after a verified deletion request unless a shorter in-app deletion applies or law requires retention.
- Unsent temporary uploads: targeted for deletion within 48 hours.
- Security and diagnostic events: normally up to 90 days; limited audit or transaction records may be retained longer for security, dispute, tax, or legal duties.
- Apple/RevenueCat transaction and accounting records: for the period required by applicable tax, accounting, fraud-prevention, or dispute rules.
- Backups: expire on the normal backup rotation and are not restored for ordinary product use after deletion.
- Unconfirmed waitlist records: deleted after 30 days.
- Confirmed waitlist records: deleted after unsubscribe or within 12 months after the final launch communication, subject to applicable legal duties. We may retain only a necessary email hash suppression record to prevent messages after unsubscribe, bounce, or complaint.
- Career Parallel attempts expire after 24 hours. Raw answers are deleted when scoring completes. Anonymous versioned result summaries are deleted after 90 days.
7. Your choices and rights
Where account features are available, you may access or correct profile data in the app, request a portable copy where available, and initiate deletion through Settings → Account → Delete account. A waitlist verification email is transactional and does not require marketing consent. If you select optional marketing consent, you may later unsubscribe using a message link or email privacy@openlin.ai. You may also use openlin.ai/account-deletion or email privacy@openlin.ai. Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent, or obtain a portable copy. We may verify identity and will respond within the period required by applicable law.
8. Security
We use access controls, TLS in transit, managed encryption at rest, secret separation, and database row-level controls. No system is completely secure; contact privacy@openlin.ai if you suspect unauthorized access.
9. Children
Openlin is intended for people aged 16 or older. If we learn that data from a child under 16 was collected, we will take reasonable steps to delete it.
10. Changes and contact
Material changes will be announced in the app, on this page, or by email where appropriate. Questions and privacy requests may be sent to privacy@openlin.ai. This policy will be updated with the operating legal entity and its registered contact details after incorporation, and requires qualified legal and privacy review before Production launch.