Privacy Policy
Last updated 6 September 2026
This page explains what gradai collects, why, who else sees it, and how to get it deleted. It covers gradai.in and everything you can reach from a gradai account.
Who this is about
gradai is a resume and portfolio builder that also hosts job posts and the applications sent to them. Two kinds of people use it, and the answers below differ for each. A candidate builds a resume, publishes a portfolio, and applies to roles. A recruiter posts a role, collects applications, and reads the scores we produce for them.
What we collect
- Account details. Your name, email address, and a hashed password. If you sign in with Google we receive your name, email address, and profile picture from Google instead of a password.
- Your role. Whether you use gradai as a candidate or a recruiter.
- Profile and document content. Everything you type into a resume, a portfolio, or an onboarding form, including work history, education, skills, links, and images you add.
- Files you upload. Resumes and attachments sent with an application.
- Recruiter content. Job posts, application forms, scorecards, and organisation details.
- Applications. The answers a candidate submits to a job form, the resume attached to it, and the score and reasoning we generate from them.
- Technical data. IP address, browser type, and timestamps recorded in server logs, plus a session cookie that keeps you signed in.
We do not ask for identity documents, payment card numbers, or government identifiers, and you should not put them in a resume you upload here.
Why we collect it
- To create your account, keep you signed in, and verify your email address.
- To store and render the documents you build, and to publish them when you choose to publish.
- To generate resume suggestions, portfolio content, and application scores when you ask for them.
- To deliver an application to the recruiter whose link you used.
- To send transactional email such as verification codes and password resets. We do not send marketing email unless you ask for it.
- To keep the service working and to investigate abuse.
What becomes public, and when
Most of what you write stays private to your account. Three things do not, and each one is public only after you choose to publish it:
- A published resume is readable by anyone with its link.
- A published portfolio is readable by anyone with its link, at the address you pick.
- A published job post and its application form are readable by anyone with the link, including people who are not signed in.
A published page shows only the fields needed to display it. Your email address, your account id, and your unpublished documents are never included. Unpublishing removes the page from public view, though search engines and anyone who saved the link may keep a copy for a while, and that is outside our control.
An application is never public. It goes to the recruiter who owns the job post, and to nobody else.
Automated scoring
When a candidate applies, we send the text of the application and the attached resume, together with the job description and the recruiter scorecard, to Google Gemini, and store the score and the reasoning it returns. The same service generates resume and portfolio suggestions when you ask for them.
A score is a ranking aid, not a decision. It does not accept or reject anyone by itself, and the recruiter sees the reasoning behind every number so they can disagree with it. If you believe a score about you is wrong, write to us and we will pass your objection to the recruiter and correct our record.
Who else handles your data
We use a small number of service providers. They process data on our instructions and for no purpose of their own:
- MongoDB Atlas, which stores the database.
- Supabase Storage, which stores uploaded files.
- Google, for sign in with Google and for the Gemini models behind our scoring and writing features.
- Resend, which delivers transactional email.
- Our hosting provider, which runs the application and keeps server logs.
When a candidate applies to a role, the recruiter who posted it receives that application and decides what to do with it. From that point they are responsible for it under their own privacy practices.
We do not sell your data, and we do not share it with advertisers.
How long we keep it
- Account data, for as long as your account exists.
- Resumes, portfolios, and job posts, until you delete them or delete your account.
- Applications and their scores, until the recruiter deletes them or closes the role, because they are the recruiter's hiring record as well as yours.
- Server logs, for a short operational period and then deleted.
Deleting your account removes your profile, your documents, and your published pages. Applications you already sent stay with the recruiters who received them, in the same way a sent email does.
Your choices
- You can read and edit everything in your account from the dashboard.
- You can unpublish a resume, a portfolio, or a job post at any time.
- You can ask for a copy of your data, ask us to correct it, or ask us to delete it.
- You can withdraw consent for the writing and scoring features by not using them. The rest of gradai works without them.
Write to gradai.connect@gmail.com for any of these. We reply within thirty days and will ask you to confirm your identity first, so that nobody else can request your data.
Security
Passwords are hashed, never stored in readable form. Traffic runs over HTTPS. Access to the production database is limited to the people who keep the service running. No service can promise perfect security, and we will tell affected users without unnecessary delay if a breach puts their data at risk.
Age
gradai is built for people looking for work and people hiring them. It is not intended for anyone under 16, and we do not knowingly collect data from them. If you believe a child has an account here, write to us and we will remove it.
Changes
If we change this policy we will update the date at the top. If a change affects what we do with data you have already given us, we will tell you by email before it takes effect.
Contact
Write to gradai.connect@gmail.com for anything on this page or anything else about gradai.