What we store, and what we don't.
Hallstamp is built on being honest about your skills. It would be strange to be shifty about your data, so here it is in plain language: exactly what we keep, why, where it lives, and how you stay in control.
What we collect
Only what the product needs to work for you:
- Your account. Your email address, and your password stored only as a one-way hash. We never see or store your password in plain text.
- The work you create. The resumes, job postings, statuses, notes, and course outlines you add. This is yours. We store it so the app can show it back to you and match against it.
- Skills and their receipts. The skills the engine surfaces, each tied to the exact evidence that supports it. A skill is never claimed on your behalf; you ratify it.
- Product analytics, only if you turn them on. Off by default. When on, we record privacy-safe event names and counts to understand what is used. Your resume text, notes, and full job descriptions are never sent as part of analytics.
How we use it
To run the service you asked for: to match your real skills against a posting, to tailor your resume from what is actually true, to name honest gaps, and to keep your work available when you sign back in. That is the whole list.
We do not sell your data. Not to advertisers, not to recruiters, not to anyone.
We do not train AI models on your resume. The matching and scanning are plain, deterministic code that runs on our servers and sends your data to no outside model. If you use AI-assisted tailoring, only the specific text you choose to tailor is sent to our AI provider to generate that draft; they process it to return your result and do not use it to train their models.
Where it is stored
On managed cloud infrastructure: a Postgres database (Neon) for your account and saved work, and a hosting provider (Vercel) that serves the app. Each account's data is isolated from every other account at the database level. We keep what you save until you delete it or close your account.
Captured job postings sent from the browser extension are held very briefly (about one hour) in a temporary handoff buffer so the app can pick them up, then they expire.
Who we share it with
No one, other than the infrastructure providers above that are required to run the service, and only to the extent they need to store or serve it. We do not share your data with employers, schools, or third parties for their own use. If the law ever compels disclosure, we will limit it to what is legally required.
Cookies and local storage
A sign-in cookie keeps you logged in. Your browser also keeps a local working copy of your data so the app is fast and works offline; that copy stays on your device. We do not use advertising or cross-site tracking cookies.
Your control
- See it. Everything we hold for you is visible in the app.
- Export it. Your data is yours to take with you.
- Delete it. Delete individual items, or close your account and we remove your stored data.
To exercise any of these, or to ask a question, email us at the address below.
Students and the college pilot
In any school pilot, participation is the student's own choice, and the data is the student's own entries. No institutional records move to us unless the school's own privacy office, registrar, and records staff scope and approve exactly what flows and how. That review is a precondition, not an afterthought.
Changes
If we change this policy, we will update this page and its effective date. Material changes will be surfaced in the app.
Contact
Questions about your privacy or your data: hello@hallstamp.com.