Who operates KairoMatch
KairoMatch is built, deployed, and operated by Emergence LLC, which acts as the data controller for the information described in this policy and as the merchant of record for any purchases. Charges will appear from Emergence LLC.
Where this beta operates
KairoMatch is in beta and is offered to users in the United States, with data processed on United States infrastructure. It is not currently offered to users in the European Economic Area or the United Kingdom, and we do not represent it as compliant with the EU GDPR or the UK GDPR today.
We are building the platform to that standard — versioned consent, a real data-request channel, deletion that reaches every table, and a cookie-consent gate — so those markets can open without re-architecting the product. Until they do, treat the GDPR-grade capabilities described here as the bar we are building toward, and the United States as the scope this policy covers. California residents have rights under the CCPA/CPRA today; see “Your Rights” below.
Data We Collect
When you use KairoMatch, we collect the information you provide directly: résumé text and uploaded résumé files (PDF or Word .docx), work history and career experiences entered in your profile, job descriptions you analyze or save. If you separately allow optional product analytics in Data settings, we collect a bounded set of feature and reliability events. Those events exclude résumé and job text, your name and email, exact location, and session recordings. We also collect basic account information (name, email address) provided via your authentication provider.
Where Your Data Lives
Running an AI analysis sends your résumé text and the job description to our servers, on every plan — that is where your contact details are stripped out and where the Claude call is made.
Signed in, your account details, career timeline, saved jobs and notes, company research and interview prep guides are stored in our database under your account.
Your résumé text, its versions and your cover letters are stored securely in your account, on every plan, so they follow you to any device you sign in from — and you can erase them at any time with “Delete all my data” in Settings.
Before you create an account there is nothing to store it against, so a preview you run while signed out is kept in this browser until you sign up — then it moves into your account with everything else.
Working state — checklist drafts, Studio layout choices, assessment answers and your list and dashboard preferences — is kept in this browser's storage and is not sent to us.
That browser copy is not permanent. Signing out clears it from the device you sign out on, and any copy left behind — by closing the tab, or by a session that simply expired — is deleted automatically after 30 days without use. Until then it is held unencrypted in your browser's local storage, so on a shared or public computer, sign out.
How We Use Your Data
Your résumé and job description content is sent to Anthropic's Claude API solely to generate AI-powered feedback, fit analysis, and interview preparation guides. Your name, email address, phone number, street address and profile links are replaced with placeholders before that request is made. Anthropic does not train its models on this data. Our database is hosted on Supabase; what we keep there, and what stays in your browser, is described above. Optional product analytics is off by default and, when allowed, helps us understand which features are useful and where reliability needs attention. You can withdraw that permission from Data settings at any time.
Data Retention
Your data is retained for as long as your account is active. When you delete your account, we delete every record we hold under your account id — résumés and their versions, job records, career history, research, prep guides, analysis results, feedback and billing history — within 30 days. You may also delete individual items, or reset your content while keeping the account, from within the app.
Five things sit outside that sweep, and we would rather say so than imply otherwise. Product analytics events are held by our analytics provider and are removed on request through the address below rather than automatically. Data held in a browser on a device you have signed in on is cleared on the device you delete from — clear the site's data in any other browser you used, and note that the deleted account can no longer sign in to read it. Cached AI responses are stored under a content hash with no account id attached, so they cannot be looked up by account; they are purged on the schedule below.
Fourth: a new account receives a one-time credit grant, and with no record of who has already had one, deleting an account and signing up again would mint it over and over. So when you delete your account we keep a single row — an irreversible token derived from your email address, and the date the account was deleted. The token is a keyed hash: your address is not stored beside it, and it cannot be reversed or guessed from the token without a secret that never leaves our servers. It is used for exactly one check — whether a new signup has already had its free credits — and for nothing else. Your email address itself goes with the rest of your account. We keep the token for 24 months and then delete it. Our basis for keeping it is our legitimate interest in preventing abuse of the free grant.
Fifth, when you delete your account we retain one private deletion tombstone: the deletion time and a deterministic one-way SHA-256 token derived from your opaque Clerk account identifier. We do not retain the raw Clerk identifier, your email, résumé, payment amount, credit balance, or Stripe identifiers in this tombstone. It is used only to stop delayed or retried Stripe, subscription-credit, metering, and operator requests from recreating a credit balance or paid entitlement after deletion. This safety tombstone currently has no automatic expiry: we retain it for the lifetime of that anti-resurrection control, because deleting it while delayed provider work can still arrive would make the account deletion reversible.
A few categories have their own schedules. Usage records and the credit ledger (which AI features you ran and their metered cost) are kept while your account is active to enforce rate limits, spend caps, and fair use, and are deleted with your account. Product feedback you submit (ratings, thumbs up/down, decision responses) is kept while your account is active and deleted with your account. Cached AI responses — stored under a content hash with contact details redacted so repeated identical requests don't re-bill — are purged automatically within 90 days (cached company research refreshes after 60 days).
If you use the support form without being signed in, we store the message you send and the reply address you type into it, because that address is the only way we can answer you. A message sent that way is attached to no account, so no account deletion can reach it: we delete the whole message — address, topic and text — 90 days after we have answered it. If we have not answered it, we keep it until we have, because deleting an unanswered request for help protects nobody; it is flagged to us every day until it is handled. There is no self-service way to erase it sooner, because we cannot verify that an address someone typed belongs to the person asking us to act on it — write to us from that same address and we will erase it by hand. A support message you send while signed in belongs to your account and is deleted with it.
Your Rights
Whatever jurisdiction you are in, you can access, export, correct or delete the personal data we hold about you. Deleting your account from the account settings page removes it as described above; for an export or a correction, write to the address below. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
California residents have rights under the CCPA/CPRA — to know, to delete, to correct, to opt out of sale or sharing, and not to be discriminated against for exercising them. We honor those requests through the same channel. We give EU and UK users the same access, export, correction and deletion rights as a matter of practice while we build to the GDPR and UK GDPR standard, but the beta is not offered in those markets and this policy does not claim compliance with them yet.
Contact
For a data request — access, export, correction, deletion, or removal of your analytics events — or any question about this policy, write to privacy@local-emergence.com. We acknowledge data requests within 30 days and, where we can verify the account, complete them in the same window. We may need to confirm you control the account's email address before we act on a request.