Privacy Policy
This Privacy Policy is effective as of August 25, 2026 and explains how HonestFit collects and uses information.
1. Overview
This Privacy Policy explains how HonestFit, Inc. collects, uses, shares, and protects information when you use honestfit.ai and related HonestFit services.
HonestFit is a voice-first, candidate-first career profile platform. The service helps users build career profiles, capture stories, generate resumes, analyze role fit, manage public profile settings, and optionally publish public-safe candidate-controlled profile data.
This policy is launch-provisional and should be reviewed by legal counsel, but it is intended to describe HonestFit's actual data practices accurately as of the effective date above.
2. Information We Collect
- Email address used for magic-link sign-in, account access, support, and transactional messages.
- Account and session information needed to authenticate users, maintain sessions, protect accounts, and operate the service.
- Career profile information you provide, including roles, skills, achievements, work history, preferences, and related profile details.
- Text, documents, resumes, notes, source material, and other content you upload, paste, import, or enter into the service.
- Voice, audio, and transcription inputs when you use voice capture or speech-to-text features.
- Job descriptions, role requirements, and fit-analysis inputs you provide.
- Generated outputs such as profile drafts, summaries, resumes, role-fit reports, explanations, recommendations, and exports.
- Billing and campaign-purchase information from Stripe, such as checkout, payment, tax, refund, dispute, campaign activation, and access-period status. HonestFit does not receive or store full payment card numbers.
- Public profile settings and public-safe profile content when you choose to enable a public profile or related sharing feature.
- Aggregate telemetry such as page path, referrer domain, event counts, error counts, and operational usage trends.
- Technical logs and security information needed to operate, debug, protect, and maintain the service.
3. Mission Telemetry Limits
HonestFit's Mission telemetry is designed for aggregate operational visibility. Mission telemetry tables do not store raw IP addresses, hashed IP addresses, emails, user IDs, profile content, resume content, job-description content, transcript content, or generated career outputs.
Campaign payment and activation reporting is calculated from protected campaign-purchase records rather than client click telemetry. Aggregate Mission reporting does not expose Stripe Customer IDs, Checkout Session IDs, PaymentIntent IDs, payment details, or the user relationship stored in protected billing records.
Other operational systems, such as infrastructure logs, security tools, authentication systems, or service-provider logs, may process technical information as needed to run and protect the service.
4. How We Use Information
- Provide, maintain, and improve the HonestFit service.
- Authenticate users through magic-link email sign-in and maintain account sessions.
- Build, update, structure, and display career profiles.
- Capture, transcribe, process, and organize user-provided stories and source material.
- Generate resumes, fit analyses, summaries, public-safe profile views, exports, and related outputs.
- Operate public profile settings, public links, partner API access, and candidate-controlled public-safe sharing.
- Process one-time campaign checkout, payments, taxes, refunds, disputes, billing status, and campaign access through Stripe.
- Monitor reliability, debug errors, protect against abuse, and secure the service.
- Respond to user requests, support questions, legal requests, compliance obligations, or safety and security concerns.
5. AI and Model Processing
HonestFit may send user-provided career content, profile information, documents, transcripts, job descriptions, prompts, and related context to AI or model providers to generate, classify, summarize, transform, or evaluate service outputs.
AI outputs can be inaccurate or incomplete. You should review generated materials before publishing, exporting, submitting, or relying on them. Do not submit content to HonestFit unless you have the right to use it and allow it to be processed for the service.
6. How We Share Information
We do not sell personal information. We do not share personal information with third parties for their independent marketing use without your consent.
- Service providers and processors that help us operate HonestFit, including hosting and infrastructure providers, email providers such as Resend, payment processors such as Stripe, Cloudflare, AI/model providers, analytics or telemetry tools, support tools, security tools, and similar vendors.
- Public profile visitors, partner API consumers, search engines, or other third parties when you enable a public profile or public-safe sharing feature.
- Legal, compliance, safety, and security recipients when we believe disclosure is required by law or reasonably needed to protect rights, users, the public, or the service.
- Business transaction recipients if HonestFit is involved in a merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction.
7. Service Provider Transparency
Which AI provider receives content depends on the feature and the configured route at the time of the request. HonestFit does not make a blanket promise that every downstream provider has the same training or retention policy. Provider terms and account settings can differ and change.
- DigitalOcean provides current production hosting and may process relevant content when a configured DigitalOcean AI route handles a generation task.
- OpenAI may process relevant text or voice context when an OpenAI model or Realtime feature is selected for the requested task.
- OpenRouter may route relevant prompt and output content when it is selected as the configured model gateway.
- Resend processes the email address and message content needed for magic links and transactional email.
- Stripe processes payment, tax, refund, dispute, and billing information. HonestFit receives transaction status and identifiers, not full payment card numbers.
- Cloudflare processes request and network metadata for DNS, traffic routing, rate protection, and security.
- Sentry may process bounded technical error context used to diagnose failures. HonestFit is designed not to place raw Career Memory, resumes, job descriptions, transcripts, or payment details in Sentry events.
8. Cookies, Sessions, and Similar Technologies
HonestFit uses cookies and similar technologies for authentication, session management, security, service operation, and user experience. Cloudflare and other security or infrastructure providers may also use cookies or similar technologies to protect and route traffic.
Stripe may use cookies and related technologies in checkout, billing, or payment-related flows. We may also use analytics or telemetry technologies to understand aggregate service behavior and reliability.
You can adjust browser cookie settings, but blocking cookies may prevent sign-in, checkout, or other service features from working correctly.
9. Public Profiles
Public profiles are default private unless you enable them. If you publish a public profile, public-safe candidate-controlled profile content may be visible to anyone with the link and may be copied, shared, indexed by search engines, or accessed through allowed public or partner API surfaces.
You control whether to enable a public profile through the settings available in the service. Disabling a public profile may stop future access through HonestFit, but it may not remove information already copied, cached, indexed, or shared by third parties.
10. Data Retention and Account Deletion
We retain information for as long as needed to provide the service, maintain accounts, support user-requested features, operate security and reliability controls, comply with legal obligations, resolve disputes, enforce agreements, maintain billing records, and preserve backups.
Settings → Account provides self-service account deletion. A completed deletion removes the account email and name, live Career Memory, public profile, stories, source material, Trust data, job descriptions, Application Kits, and active sessions. The same email may later create a new empty account.
Limited payment records, security records, and backups may remain where required or permitted for billing, tax, legal, dispute, fraud-prevention, security, recovery, or operational obligations. HonestFit removes your email and name from its retained account record, but payment providers may retain their own transaction data. Deleted candidate content is not restored to a new account from those retained records.
11. Your Choices and Rights
- Settings → Account lets you download an owner-private JSON archive containing account identity, Career Memory and profile history, conversation text, jobs and Application Kits, Trust data and evidence files, Story Review data, and safe billing status. Tokens, provider credentials, storage keys, and Stripe identifiers are excluded.
- Settings → Account lets you permanently delete your account after entering an exact confirmation phrase. You may also request access, correction, deletion, or other privacy assistance by contacting support@honestfit.ai.
- You may manage profile content and public profile settings through the service where those controls are available.
- If HonestFit sends marketing emails in the future, you may unsubscribe using the instructions in those emails.
- Transactional, security, billing, legal, and account-related emails may still be sent even if you opt out of marketing messages.
12. California Privacy and Do Not Track
HonestFit does not sell personal information. If you are a California resident, you may contact support@honestfit.ai to make privacy requests about access, correction, deletion, or other rights that may apply under California law.
Some browsers offer Do Not Track signals. There is not currently a consistent industry standard for responding to those signals, and HonestFit does not currently respond to Do Not Track browser signals.
13. Children
HonestFit is not directed to children or minors. Users must be at least 18 years old to use the service. If you believe a minor has provided information to HonestFit, contact support@honestfit.ai so we can review the request.
14. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. No internet service, transmission, storage system, or security measure can be guaranteed to be completely secure.
You are responsible for keeping control of the email account used for magic-link sign-in and for protecting devices and sessions that can access your HonestFit account.
15. Links and Third-Party Services
HonestFit may link to or integrate with third-party websites and services. Those third parties have their own privacy practices and terms. This Privacy Policy applies to HonestFit's service, not to third-party services we do not control.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we may provide notice by posting an updated policy on the site, sending an email to the address associated with your account, or using another reasonable method.
Your continued use of HonestFit after an updated policy becomes effective means the updated policy applies to your use of the service.
17. Contact
Questions or requests about this Privacy Policy may be sent to HonestFit, Inc. at support@honestfit.ai.
Contact: support@honestfit.ai | Back to home