← Back to DirectClients

DirectClients.com — Privacy Policy

Draft — v1, generated against REQUIREMENTS.md. Attorney review optional per founder decision; placeholders in brackets need a human decision before this is published.

Last updated: [Date]

This Privacy Policy explains what information DirectClients.com ("DirectClients," "we," "us") collects, how we use it, and the choices you have — particularly around the parts of the Service that are unusual enough to deserve specific explanation: AI processing of your resume, the Apply Direct browser extension, and the employer-portal credential vault.

1. Information We Collect

  • Account information: name, email, password (hashed), billing details (handled by Stripe — we do not store full card numbers).
  • Resume & profile data: your uploaded resume, parsed work history, skills, education, target roles, location/zip preferences, salary expectations, and work authorization status.
  • Voluntary disclosure (EEO) data: race, gender, veteran, or disability status — only if you explicitly opt in, field by field. We never infer, pre-fill, or submit these fields on your behalf without that opt-in.
  • Application data: every job you apply to via Apply Direct, and an audit record of exactly what field values were submitted, where, and when — kept so you can see your own submission history and so we can resolve any dispute about what was sent.
  • Employer portal credentials: where an employer's application portal requires an account, we generate and store a unique password for that portal in your encrypted vault (see §4).
  • Extension activity: which fields the extension filled or the candidate edited on an Apply Direct session, used to measure and improve pre-fill accuracy. The extension does not collect data from browsing outside an Apply Direct session it initiated.
  • Usage data: standard technical data (IP address, device/browser type, pages visited) for security and service operation.

2. How We Use Your Information

  • To parse your resume and build your candidate profile.
  • To match you to job postings and generate a plain-language reason for each match.
  • To pre-fill and support your Apply Direct applications, and to generate AI-assisted cover letters and resume tailoring.
  • To create and manage employer-portal accounts on your behalf when a posting requires one (§4).
  • To process your subscription and billing.
  • To provide customer support (support staff can see your account, application history, and resume; they cannot see your plaintext vault credentials — see §9).
  • To monitor and improve the accuracy of our AI matching and form-filling.

3. AI Processing Disclosure

Your resume, profile, and job-matching data are processed using Anthropic's Claude API to power resume parsing, the AI role-fit conversation, match-rationale generation, cover letter generation, and the extension's field-mapping. Anthropic processes this data as a service provider to DirectClients under its own data-handling terms and does not use your data to train its models by default under standard API terms. We do not sell your data to Anthropic or any other party.

4. Employer Portal Credential Vault

Where an employer's application portal requires its own account, DirectClients:

  • Generates a strong, unique password for that specific portal — never reused across sites or derived from your DirectClients password.
  • Encrypts it at rest using per-user encryption keys (not a single shared key across all users).
  • Makes it visible to you at any time in your account settings — you can view, edit, or delete any stored credential whenever you choose.
  • Uses it only to log back in on your behalf to check application status or resume an in-progress application — never to take an action beyond what Apply Direct's human-confirmation model already covers (§5 of our Terms of Service).

Deleting a stored credential removes it from our vault; it does not delete the account on the employer's portal itself, and does not withdraw an application already submitted.

5. Email Verification Alias

To complete portal-account email verification without requesting access to your personal inbox, we issue you a unique forwarding address (e.g., you@apply.directclients.com) via our email provider, Resend. Mail sent to that address is forwarded to your real inbox and is also processed by our systems for the limited purpose of detecting and completing portal verification links, and — if you use the application tracker — surfacing employer replies (e.g., interview invitations) into your tracker. We do not read or use this mailbox for any other purpose.

6. Browser Extension Permissions

The DirectClients Chrome extension requests permissions necessary to: read and fill form fields on a page you've navigated to as part of an Apply Direct session; communicate securely with our backend to fetch the data needed for that session and report back what was filled or submitted. It does not track your general browsing, read pages unrelated to an Apply Direct session, or collect data when inactive.

7. Third-Party Service Providers

We share data with the following categories of service providers, solely to operate the Service:

| Provider | Purpose | |---|---| | Supabase | Database, authentication, file storage | | Anthropic (Claude API) | AI processing (§3) | | Stripe | Subscription billing and payment processing | | Resend | Transactional and inbound email, including the verification alias (§5) | | Cloudflare | DNS, CDN, and bot/abuse protection for our own site | | Vercel | Hosting for the DirectClients web application | | Trigger.dev / Inngest | Scheduled background processing for job-data sourcing |

We do not sell your personal information to third parties.

8. Data Retention

  • Active accounts: profile, resume, and application data are retained while your account is active.
  • Closed job postings in our own job database (not your personal data) are retained with full detail for 90 days after closing, then reduced to lightweight metadata for historical/analytics purposes — see our Terms for how job data sourcing works.
  • After account closure: [retention window to be finalized — e.g., data deleted or anonymized within N days of account closure, except where retention is required for legal/audit purposes].
  • Application audit logs (what was submitted, where, when) are retained to support your ability to review your own submission history and to resolve disputes.

9. Internal Access Controls

Access to your data by DirectClients staff is role-scoped and logged: support staff can view your account and application history to help resolve issues, but cannot view plaintext vault credentials; only automated systems use those credentials operationally. Every internal access to vault metadata is itself logged for security review.

10. Your Rights

You can access, correct, or delete your profile and resume data at any time from your account settings. You may request full account deletion, which removes your profile, resume, vault credentials, and associated PII from our systems (retained audit logs may be anonymized rather than deleted where needed for dispute-resolution integrity). [State-specific rights — e.g., CCPA, other state privacy laws applicable as we expand beyond the initial pilot regions — to be finalized.]

11. Data Security

We encrypt data at rest and in transit, use per-user encryption keys for the credential vault backed by a dedicated secrets-management layer, and maintain audit logs of both candidate-facing submissions and internal staff access to sensitive data.

12. Children's Privacy

The Service is not directed to individuals under 18, and we do not knowingly collect data from anyone under 18.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We'll notify active subscribers of material changes before they take effect.

14. Contact

Questions about this Privacy Policy or your data: [privacy email, e.g. privacy@directclients.com]

This document was drafted with AI assistance based on DirectClients' documented product requirements. Bracketed items require a founder/business decision and, before public launch, we recommend a licensed attorney review — timing of that review is the founder's own call.