Skip to content
Corpus
Start building

Corpus · Legal

Privacy

Last updated 22 August 2026

This is a draft. Corpus has no registered company behind it yet, so every place a legal entity, address or jurisdiction would be named prints a placeholder instead of a name. What the product actually does with your data is described accurately here; what is missing is who you would be contracting with.

Corpus exists to hold one person’s career in one place. That only works if the person believes the place is theirs, so this page is written to be checked rather than skimmed: what is stored, where it sits, who can see it, and how to take it back.

1.What is stored

Three kinds of thing, and nothing else:

  • Your account. A name, an email address, and — if you sign in with Google — the identifier Google returns for you. There are no passwords, so there is no password to store.
  • Your career record. The records you write or approve, the connections between them, and the text read out of the files you import. This is the product; it is the only reason the rest of it exists.
  • How the product was used. Which screens were opened and when, an import’s outcome, an email’s delivery state. Enough to answer “why did that fail” and to count activation. Not enough to reconstruct what you wrote.

2.Where it lives

Corpus runs on Vercel, and your rows are in a Neon Postgres database in a single region. A file you upload during an import is never stored: it is read in the request that carries it and then dropped, and what is kept is the text it gave up and the records that came out of it. Nothing is replicated anywhere you have not been told about here.

A small number of other companies process parts of it on our behalf. Each is named in the subprocessor list, with what it touches and why.

3.Models, and what they are shown

Two features send text to a model provider: the assistant, which answers questions about your record, and embeddings, which make your record searchable by meaning rather than by exact words.

Both send only what the feature needs — the passage being embedded, or the records retrieved for the question being asked. Your record is not used to train anybody’s model, and the provider is contracted as a processor rather than as a recipient.

Every generated output cites the career items it drew on. That is a product rule, not a courtesy: an answer you cannot trace back to your own record is an answer you should not trust.

4.What an import reads

An import reads a file you hand over, or text you paste. Nothing holds a token that lets Corpus reach any other service on your behalf, and nothing is ever posted anywhere on your behalf. Reading profile pages — GitHub, LinkedIn — is not open at the moment; when it is, it will read only pages an anonymous visitor could already see.

What an import produces is proposed, never applied. It waits on the review screen until you approve it.

5.When somebody at our end can read your record

Almost never, and never quietly. Support and engineering work is done against counts and metadata. Opening the actual contents of one of your records or documents requires a reason to be typed first, and that reason is shown to you, with the date, on your own Data and privacy screen.

The same applies to signing in as you: it is possible, it is logged, and a banner sits across the product for as long as it lasts, so nothing can be done in your account without a trace of it.

6.How long it is kept

  • Your record: until you delete it, or 30 days after you ask for your account to be deleted.
  • Cached public pages: one month.
  • Email delivery log: kept while the account exists; deleted with it.
  • Usage rows: kept, but unlinked from you when your account is deleted. The visit happened; erasing the count would falsify history. Erasing who it was is the honest half.

7.Taking it back, and ending it

Both are buttons in the product rather than a request form. Settings → Data and privacy has a JSON export of every record and connection you hold, together with every resume a plugin has written for you and each of its versions, built when you press it and downloaded straight to your machine.

The same screen closes the account. Asking signs you out everywhere, shuts the product, and closes any graph you had shared — immediately. Nothing is destroyed for 30 days, and signing back in during that time cancels the whole thing and returns the record exactly as it was. You are shown the exact date when you ask, and that date is fixed at that moment: it cannot be brought forward afterwards.

After the date it is deleted for good — records, connections, the text read out of your files, conversations, shares, and anything a plugin made for you — with no hidden copy and nothing kept back, which is why the export sits directly above it. The one exception is the usage rows described above, which are unlinked from you rather than deleted.

Deleting from our end, at your request or because the law requires it, skips the 30 day window and happens at once.

8.Who to write to

Privacy questions: privacy@corpusai.tech.

The controller of this data is [legal entity not yet registered], at [registered address to be confirmed].