Back to home

Privacy and Data Trust

CVs, AI processing, exports, deletion, and POPIA alignment

PersonalBrandOS should make privacy understandable at the point where users upload CVs, create goals, use AI, export data, or delete their account. The product should avoid broad compliance claims and instead show clear controls, processing limits, and sensitive-data boundaries.

Open Data Controls

Explain the main data categories the app stores and why each exists.

Show when CV, profile, goals, proof, and voice data may be included in AI prompts.

Give users visible export and deletion controls in Settings > Data & Privacy.

Document sensitive-data boundaries for Z83, WhatsApp, and future provider integrations.

Data map

CV and Resume Files

Uploaded CVs, parsed text, extracted roles, education, skills, certifications, and projects.

Purpose: Build the user profile, improve job matching, and avoid asking users to repeat career history.

AI use: Sent to AI only when the user asks for parsing, scoring, matching, or generation that needs resume context.

Control: Users can delete individual resumes from Resume Vault and request a full account export or deletion.

Profile and Goals

Name, headline, location, target roles, career goals, blockers, next actions, and skills to build.

Purpose: Personalise guidance so recommendations are based on the user's desired career outcome.

AI use: Used as prompt context for scoring, content, Smart Suggest, job matching, interview prep, and weekly planning.

Control: Users can edit profile details and goals from Profile, Dashboard, and onboarding review screens.

Proof Vault and Projects

Wins, projects, metrics, story angles, proof links, and selected public proof-profile items.

Purpose: Turn real evidence into CV bullets, LinkedIn content, interview stories, and application material.

AI use: Used when the output needs evidence. Hidden or unselected proof is not included in public proof profiles.

Control: Users choose what proof to save, update, delete, and publish to a shareable profile.

AI Prompts and Generated Content

Prompts, generated drafts, calendar plans, comments, interview reports, and usage metadata.

Purpose: Save useful outputs, preserve credit history, and let users continue work across devices.

AI use: Generated outputs are returned by the selected AI provider and stored only when the workflow saves them.

Control: Users can delete generated Content Vault items and request a full export or account deletion.

Voice and Style Samples

Optional voice/style samples and derived voice-profile traits used to make content sound more personal.

Purpose: Improve tone matching for posts, interview prep, and career content.

AI use: Used only for voice analysis or generation flows where the user asks for personal tone matching.

Control: Users can reset voice profile data from Settings and avoid voice workflows entirely.

Account, Credits, and Activity

Authentication ID, email, subscription status, credit usage, onboarding events, and app activity records.

Purpose: Operate the account, prevent surprise credit use, and understand where onboarding needs improvement.

AI use: Usage metadata is not needed for normal AI generation, except for routing and cost-control decisions.

Control: Users can request export, schedule deletion, and keep billing-provider choices separate until decided.

User rights

Know what personal information is collected and why.

Access a record or description of personal information held by the app.

Request correction or deletion of inaccurate, excessive, outdated, incomplete, misleading, or unlawfully obtained information.

Object to processing where the law allows it.

Be notified when there are reasonable grounds to believe personal information was accessed or acquired by an unauthorised person.

AI boundaries

Use the minimum career context needed for the task.

Do not route sensitive Z83 personal fields through AI providers in the current product scope.

Do not use private user content to train public AI models.

Keep provider/model routing server-side so users are not asked to make privacy decisions through raw model names.

Show credit cost and generated-output persistence clearly before paid AI work runs.

Not collected now

Do not store ID or passport numbers unless a future reviewed workflow truly requires it.

Do not ask for race, disability, health, criminal-record, disciplinary, or equity information inside reusable prompts.

Do not send WhatsApp messages automatically or store WhatsApp phone numbers before explicit opt-in.

Do not publish proof-profile items unless the user selects them for sharing.

Do not treat generated AI outputs as final application material without user review.

Sources and next work

Add production-ready privacy policy and PAIA/Information Officer details before launch.

Add a saved consent ledger for WhatsApp opt-in, provider routing, public proof profiles, and future Z83 helpers.

Add data-retention settings for stale resumes, exports, voice samples, and unpublished proof.

Add an admin privacy-requests queue so exports, correction requests, and deletion events are auditable.