Quiet matters · privacy

Privacy notice.

The Candidature is a hosted SaaS product in private beta. This page explains what we collect to run the waitlist, authenticate accounts, prepare application materials, and improve the product.

What lives in your account

Your profile, resume material, job preferences, drafts, application history, and review decisions are stored so the product can prepare your search and remember your instructions. We use that data only to operate your account and support the workflows you ask us to run.

What we do collect

Early-access email

If you join the launch list, we store the email you submit, the source page, referrer, user agent, and whether the request came from a signed-in or anonymous visitor. We use it to send setup instructions before early access opens. We do not rent or sell the list.

Account email

When you sign up, we store the email you sign in with so we can authenticate you on return visits. We use Supabase for authentication. The email is not used for marketing.

Anonymous usage telemetry

The landing page uses Google Analytics to count visits, referrers, and section reads. This is aggregate and anonymous. It tells us whether the product story is being understood, not who is reading it. You can block this with any standard analytics blocker.

Product telemetry

We may store operational events such as onboarding progress, workflow state, and review decisions so we can debug the product and show you what happened. We do not sell this data or use it for ad targeting.

In-app problem reports

When you file a report using the button in the corner of the app, we store the kind of report you picked, your subject line, your description exactly as you wrote it, and the email address, name, and user ID on your account, along with the time you sent it.

We attach diagnostic context automatically so we can reproduce the problem without a second round of questions: the page you were on, your browser and window size, the app build you were running, identifiers for any workflow run or job that was active, the last several in-app navigations and actions, and any error messages the app itself produced during that browser session. The report dialog lists all of this before you send it.

We deliberately do not attach your resume text, job descriptions, search terms, anything you typed into another form, the contents of network requests, or any access token. Reports are readable only by studio administrators, are used only to fix the problem, and are deleted with the rest of your data when you delete your account.

Email we send you

When we write to you individually from inside the studio, we keep a record of it: the address we sent to, which of our addresses it came from, the subject, the message itself, when it was sent, and which administrator sent it. We keep that record so we can see what you were told and when, which is what lets a later conversation pick up where the last one left off.

This record is kept even if you delete your account. It is a log of what we did rather than information you gave us, and erasing it would also erase our own account of a message you may want to hold us to. It is readable only by studio administrators.

Authorized support access

If you ask us to investigate or repair an account issue, an authorized operator may use a local support session that acts on data owned by your user ID without creating a sign-in to your account. We record the target user ID, temporary role mode, action and path, request ID, timestamp, and outcome. The audit does not store request bodies, resume or job content, email addresses, or support session tokens. The short-lived support token stays in the operator's browser session storage and expires after eight hours.

What we never collect

  • Payment card details for the waitlist.
  • Recruiter commission or placement-fee data.
  • Behavioral profiles for ad targeting.
  • Third-party enrichment from data brokers.

What we do not sell

  • Your resume material.
  • Your drafted application content.
  • Your target companies or search preferences.
  • Behavioral profiles for ad targeting.

Cookies and storage

We use localStorage on your browser to remember small preferences, such as your theme and your dismissal of one-time prompts. We use a session cookie when you are signed in, for authentication only. We do not set advertising cookies.

Data we share with vendors

These are every third party that receives your data in the course of running the product, and what each one gets. We do not use any other analytics, advertising, attribution, or data-enrichment service.

  • Supabase · authentication, database, and file storage. Holds your account, profile, resume material, job records, and uploaded files.
  • Anthropic · AI processing for requested workflows. When you run Resume Tailor, the relevant resume, job description, and any Interview answers you chose to use are sent to Anthropic to generate the requested materials. Review generated content before approving or using it.
  • Stripe · payment processing for paid plans. Receives your email and the card and billing details you enter at checkout. We never see or store your full card number; it goes to Stripe directly.
  • Resend · delivery of the email we send you. Receives your email address and the contents of that message.
  • ImprovMX · inbound mail routing, for accounts where the correspondence relay is enabled. Receives mail addressed to your relay address, including sender, subject, body, and attachments.
  • Perplexity · company research for the roles you are looking at. Receives the name of the company being researched. It does not receive your profile, your resume, or anything else that identifies you.
  • Vercel and Fly.io · hosting for the site and the application server. As part of serving requests they process your IP address, browser user agent, and standard request logs.
  • Google Analytics · aggregate landing-page traffic.

We do not sell data to anyone. We do not buy data about you from anyone. We do not enrich your record from third-party data brokers.

Your rights

Detailed workflow event payloads are retained for up to 30 days for reliability and troubleshooting. Smaller run summaries remain with your account until it is deleted. Generated resume files and review sidecars are removed as part of account deletion.

You can ask us to delete your account or your early-access entry at any time. Write to support@thecandidature.com from the address on file and we will confirm and remove it. Deletion removes your account record, your uploaded files, and the generated documents tied to your account.

Changes to this notice

If we change anything material, we will update the date at the top of this page and, if you have a seat, write to you before the change takes effect.

Last updated · 14 aug 2026