Privacy Policy
How VeriWorkly handles personal data — local-first storage, cloud sync, AI processing, and third-party processors.
Privacy Policy
The canonical policy lives on veriworkly.com
This page is a technical summary written for developers and self-hosters. The full, legally operative privacy policy for the hosted service is at veriworkly.com/privacy. Where the two differ, the canonical policy governs.
VeriWorkly is open-source software that can be run by the VeriWorkly Team (the official hosted instance) or by independent operators (self-hosted instances). The data controller is the operator of the instance you are using.
- Official instance operator: VeriWorkly Team
- Contact: [email protected]
- Official instance: veriworkly.com
If you self-host, you are the operator and are responsible for your own regulatory compliance.
1. Local-first storage
VeriWorkly writes your documents to your browser's localStorage first. Nothing is transmitted
to a server until you take an action that requires it.
Storage keys follow a versioned scheme:
| Key | Contents |
|---|---|
veriworkly:docs:v2:active | The currently open document. |
veriworkly:docs:v2:{type} | The document collection for a type. |
veriworkly:sync-outbox | Pending sync work items. |
veriworkly:sync-telemetry | Sync attempt timestamps and the last error message. |
Clearing your browser's site data removes anything that was never synced.
2. What is collected
Account information
- Email address — authentication, session management, and security notifications.
- Display name, username, and profile image — optional, and the username is required only if you create a public share link.
- OAuth account links — provider account IDs and tokens for Google, GitHub, or LinkedIn if you sign in with them.
Document content
Stored server-side only when you enable cloud sync or use a feature that requires the server:
- Professional data — experience, education, skills, projects, certifications, and contact details.
- Document metadata — custom section headers, template preferences, layout configuration.
- The Master Profile record.
Portfolio content and media
Portfolio text and any uploaded images. Images are stored in Cloudflare R2 (S3-compatible object storage) and served from a public base URL. There is no local-filesystem storage backend — R2 is the only asset store the code implements.
Billing
Dodo Payments is the payment processor and collects payment method details directly. VeriWorkly receives transaction and subscription status, not full card numbers.
Product telemetry
VeriWorkly records aggregate-only event counters — for example the number of resumes created, exports performed, and logins — buffered in Redis and flushed daily into a per-day, per-event count table. These rows carry no user identifier. There is no third-party analytics, no session replay, no heatmaps, and no advertising trackers anywhere in the codebase.
3. AI processing
AI features send your content to third-party model providers
When you explicitly trigger an AI action, the relevant content is sent to a third-party large language model provider — currently Anthropic (Claude) and OpenAI (GPT) models, routed dynamically per request.
- Content is sent only when you trigger an action: "Improve with AI", resume tailoring, cover letter generation, portfolio copy generation, AI resume conversion, LinkedIn import parsing, or the AI-powered ATS deep-analysis layer.
- Your Master Profile and documents are never run through AI models in the background.
- The credit cost and mode are shown before generation, and generated text never replaces yours without an explicit action.
- Content sent to a provider is subject to that provider's own retention and data-handling policies. VeriWorkly does not train models on your content.
- The credit ledger records that an AI action occurred and its cost — not necessarily the generated content itself.
Avoid pasting highly sensitive data (government ID numbers, medical or financial account details) into AI-assisted fields beyond what a resume normally contains.
4. What stays on your device
- PDF and DOCX generation. Both run entirely in your browser via
@react-pdf/rendererand thedocxpackage. Document content is never uploaded to produce an export. - All six export formats, for the same reason.
Some processing is inherently server-side and does leave your device: uploaded file text extraction (PDF/DOCX parsing), AI generation, ATS analysis, GitHub and LinkedIn import, share-link creation, and portfolio publishing.
5. Cookies
Only essential, first-party cookies:
| Cookie | Purpose |
|---|---|
veriworkly-auth.session_token (__Secure- prefixed in production) | Authenticated session. |
veriworkly-guest-mode | A 30-day guest session so you can use the builder without an account. |
All are HttpOnly with Secure set in production. On the official instance, session cookies are
scoped to the root domain so a login carries across VeriWorkly subdomains.
No advertising cookies, cross-site tracking pixels, or third-party analytics cookies are used.
6. Third-party processors
| Processor | Purpose |
|---|---|
| Dodo Payments | Payment processing and billing. |
| Cloudflare R2 | Portfolio image and asset storage. |
| Anthropic / OpenAI | AI model inference, only when you trigger an AI action. |
| Google / GitHub / LinkedIn | OAuth sign-in, if you choose those providers. |
| GitHub | Repository data, when you use GitHub profile import. |
| SMTP provider | Transactional email delivery. |
A self-hosted instance uses whichever of these its operator configures — a deployment with no AI key and no payment credentials simply has those features disabled.
7. Retention and deletion
- Local data persists until you clear site data or delete the document.
- Cloud data is retained while the account is active.
- Document deletion is a soft delete server-side — the record is flagged and stops being served, and the slot is freed against free-tier limits.
- Account deletion currently requires emailing [email protected]; Studio does not yet expose a self-service control. Deletion cascades to documents, Master Profile, share links, portfolio publication and assets, API keys, and sessions, and you receive a confirmation email.
8. Security measures
See the Security Policy for the full list. In brief: passwordless
authentication, HttpOnly/Secure session cookies, scrypt-hashed share passwords with timing-safe
comparison, HMAC-hashed API keys, tiered rate limiting, SSRF protections on outbound URL fetching,
and upload verification on presigned object storage writes.
9. Contact
- Email: [email protected]
- Full policy: veriworkly.com/privacy