▌CLASSIFIED DOCUMENT — DATA HANDLING PROTOCOL

PRIVACY POLICY

EFFECTIVE: MARCH 14, 2026  |  LAST UPDATED: MARCH 14, 2026

Introduction

Your privacy is important to us. It is AI Digital Productions LLC's policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, including across our website, https://thedossier.ai, and the services we provide through it.

The Dossier is an AI-powered behavioral intelligence platform that generates psychological profiles of interview subjects to help job candidates prepare for interviews. This policy explains how we collect, use, store, and protect your information in the course of providing this service.

In the event our site contains links to third-party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third-party content, you should read their posted privacy policy. This Privacy Policy does not apply to your activities after you leave our site.

Information We Collect

Voluntarily Provided Information

We collect information you knowingly and actively provide when using our services:

  • Account information: Name and email address (provided via Clerk authentication when you register)
  • Profile information: Company and desired role (optional, provided in your settings)
  • Resume: PDF or text file you upload for use in dossier generation and job match analysis
  • Dossier subject information: The full name, job title, and company of the person you are preparing to interview with, along with interview type and optional context notes
  • Job match data: Job title, company, job description text, and optional filters such as salary range, work arrangement preferences, and seniority level
  • Interview calendar data: Interview dates, times, interviewer details, location, video links, and notes
  • Contact form submissions: Name, email, subject, and message

Automatically Collected Information

We use authentication and session cookies managed by Clerk for login and session management. We do not use third-party analytics, advertising cookies, or tracking pixels.

How We Use Your Information

We collect, hold, use, and disclose information for the following purposes:

  • To generate AI-powered behavioral intelligence reports based on publicly available information about your interview subjects
  • To provide job match analysis comparing your resume against job descriptions
  • To manage your interview calendar and send reminders
  • To process payments and manage your credit purchases
  • To respond to contact form inquiries
  • To maintain activity logs for security and audit purposes
  • To improve and operate our services

How We Research Interview Subjects

When you create a dossier, our AI system researches your interview subject using only publicly available professional information. Sources include public web pages, professional profiles, published articles, company websites, and conference presentations.

We never access private accounts, email inboxes, or content behind authentication walls. The subject is never contacted or notified that a dossier has been created.

Third-Party Service Providers

We use the following third-party service providers to deliver our services. Each receives only the data necessary for its specific function:

ProviderPurposeData Shared
ClerkAuthentication and user managementName, email, profile image
ConvexReal-time database and serverless functionsAll application data (stored and processed)
Anthropic (Claude AI)Behavioral assessment generation, resume text extraction, job match analysisSubject name/title/company, gathered public intelligence, resume text, interview context
SerperWeb search for publicly available subject informationSearch queries containing subject name, title, and company
People Data LabsProfessional profile enrichment from public sourcesSubject name, title, company
StripePayment processing (PCI compliant)Email, purchase plan, payment method (handled entirely by Stripe)
ResendTransactional email for contact form submissionsContact form name, email, subject, and message
VercelWebsite hosting and deliveryStandard web request data

These third-party providers retain data according to their own privacy policies. We recommend reviewing each provider's privacy policy for details on their data retention practices.

Data Retention

Data TypeRetention
User account and profileRetained until you delete your account from the platform
Resume file and extracted textRetained until you delete your resume or account
Dossier behavioral profilesRetained until you delete the dossier from your dashboard
Raw research intelligence (search results, enrichment data, article content)Automatically purged after 30 days
Payment recordsRetained for accounting and legal compliance
Activity logsRetained for security and audit purposes
Contact form submissionsTransmitted through Resend and not stored as user-facing records within the app

You can delete dossiers, resumes, calendar entries, and your account from the platform interface. Deleted data may remain in internal backups, logs, or retained records for security, fraud prevention, legal compliance, and audit purposes for a limited period.

Security

When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use, or modification.

  • All data transmitted via HTTPS/TLS encryption
  • Authenticated access controls enforced throughout the platform
  • Stripe handles payment data in PCI-compliant infrastructure
  • Webhook signatures verified for all payment-related events

Although we will do our best to protect the personal information you provide to us, no method of electronic transmission or storage is 100% secure and no one can guarantee absolute data security. You are responsible for maintaining the security of your account credentials.

Children's Privacy

We do not aim any of our products or services directly at children under the age of 13, and we do not knowingly collect personal information about children under 13.

Your Rights

You have the following rights regarding your personal information:

  • Access: You may request details of the personal information we hold about you.
  • Correction: If you believe any information we hold is inaccurate or incomplete, please contact us and we will take reasonable steps to correct it.
  • Deletion: You can delete your dossiers, resumes, and account from your dashboard. You may also contact us to request deletion.
  • Marketing opt-out: Contact us to unsubscribe from any communications.
  • Non-discrimination: We will not deny you goods or services for exercising your privacy rights.

US State Privacy Laws (CCPA/CPRA)

If you are a California resident, you have the right to request:

  • The categories of personal information we have collected about you
  • The categories of sources from which the information was collected
  • The business purpose for collecting the information
  • The categories of third parties with whom we share information
  • The specific pieces of personal information we have collected about you
  • Deletion of your personal information

We do not sell personal information. To exercise any of these rights, contact us at support@thedossier.ai with the subject line "California Privacy Request."

Under California Civil Code Section 1798.83, you may also request information about the disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

EU/EEA General Data Protection Regulation (GDPR)

We, AI Digital Productions LLC, are a Data Controller with respect to the personal information you provide to us.

Legal Bases for Processing

We will only collect and use your personal information when we have a legal right to do so. Our lawful bases depend on the services you use and how you use them:

  • Consent: Where you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time.
  • Contract performance: Where you have entered into a contract or transaction with us, or to take preparatory steps prior to entering into one.
  • Legitimate interests: Where necessary for us to provide, operate, improve, and communicate our services, including research and development, understanding our audience, and marketing.
  • Legal compliance: Where we have a legal obligation to use or keep your personal information, such as court orders, regulatory obligations, or government requests.

Your GDPR Rights

  • Right to restrict processing: You may request that we restrict processing of your personal information in certain circumstances.
  • Right to object: You may object to processing based on legitimate interests or public interest.
  • Right to data portability: You may request a copy of the personal information we hold about you in a machine-readable format.
  • Right to erasure: You may request that we delete your personal information, subject to legal retention requirements.

International Transfers

The personal information we collect is stored and processed in the United States. If we transfer your personal information to third parties in other countries, we will perform those transfers in accordance with the requirements of applicable law and protect the transferred information in accordance with this privacy policy.

UK General Data Protection Regulation (UK GDPR)

For residents of the United Kingdom, we comply with the UK GDPR and the Data Protection Act 2018. You have the same rights as described in the EU GDPR section above, including the rights to access, rectification, erasure, restriction, portability, and objection.

Where we transfer personal information outside of the UK, we will ensure appropriate safeguards are in place in accordance with UK GDPR Article 45 and the Data Protection Act 2018, including the use of standard contractual clauses or binding corporate rules where applicable.

Cookies

We use authentication and session cookies managed by Clerk to maintain your login session and protect your account. These are essential cookies required for the service to function.

We do not use third-party analytics cookies, advertising cookies, or tracking pixels. We do not use Google Analytics or any similar third-party tracking service.

Business Transfers

If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data, including your personal information, among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may continue to use your personal information according to this policy.

Changes to This Policy

At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at this URL.

If the changes are significant, or if required by applicable law, we will contact our registered users with the new details and links to the updated policy.

Contact Us

For any questions or concerns regarding your privacy, you may contact us:

Email: support@thedossier.ai
Entity: AI Digital Productions LLC
Website: https://thedossier.ai

THE
DOSSIER

INTELLIGENCE-GRADE INTERVIEW PREPARATION
A PRODUCT OF AI DIGITAL PRODUCTIONS LLC
© 2026 ALL RIGHTS RESERVED