Privacy Policy
Last updated: 2026-03-04
This Privacy Policy explains how Xorna (the “Service”, “we”, “us”) collects, uses, and shares information when you use our website and application.
1) What we collect
Information you provide
- Account info: email address, name (optional), login credentials or third‑party sign‑in tokens (Google/LinkedIn when enabled).
- Profile/Vault content: resume/CV uploads, portfolio links, work history, skills, case studies, preferences (rate, availability, industries), and any notes you enter.
- Job application content: job details you view/apply to, generated proposals/pitches, edits you make, and submission metadata.
- Support messages: information you send via in‑app support or feedback forms.
Information we collect automatically
- Usage data: pages/screens viewed, clicks (e.g., “Generate Proposal”, “Copy”, “Submit”), feature usage, and timestamps.
- Device/technical data: IP address (approximate location), browser type, device identifiers, and crash logs.
- Cookies/local storage: used for authentication, session management, and basic product functionality (and analytics when enabled).
2) How we use your information
- Provide and operate the Service.
- Personalize your experience (matching, recommendations, UI preferences).
- Maintain security and prevent abuse (rate limits, fraud prevention).
- Improve the product (analytics, debugging, performance, planning).
- Communicate with you (support responses, service notices).
3) AI / proposal generation
When you request proposal generation, we process relevant job context and your Vault/profile inputs to produce drafts. If we use third‑party AI providers, we send only what’s necessary to generate the output.
4) Sharing and disclosure
- Service providers that help us run the product (hosting, database, analytics, error monitoring, email).
- Legal/Compliance when required by law or to protect our rights and users.
We do not sell your personal information.
5) Data retention
We keep data only as long as needed for providing the Service, complying with legal obligations, resolving disputes, and enforcing our agreements.
You can request deletion of your account and associated data (subject to legal requirements).
6) Cookies & analytics
We use cookies/local storage for core functionality. If analytics are enabled, we may use tools (e.g., PostHog/Google Analytics) to understand product usage. We’ll add an opt‑out mechanism when required.
7) Security
We use reasonable safeguards designed to protect your information. No system is 100% secure.
8) Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, or object/restrict certain processing.
9) International transfers
Your data may be processed in countries other than your own. We take steps intended to ensure appropriate safeguards.
10) Children
The Service is not intended for children under 13 (or the age required by local law). We do not knowingly collect children’s data.
11) Changes
We may update this policy from time to time. We will update the “Last updated” date and provide notice if changes are material.
12) Contact
TL;DR
- We store what you put in your Vault (resume/CV, skills) and what you generate (proposals).
- We use it to run matching + proposal generation.
- We don’t sell your data.
- You can request deletion.
