Privacy Policy

Last updated: March 2026

A note from the developer: Shortlisted is an indie project built by one person to help job seekers. I have no interest in your data, no advertising partners, and no investors asking me to monetise your information. This policy exists to be transparent about what I collect and why — not to hide anything behind legal language.

1. Who we are

Shortlisted ("we", "us", "our") is an independent software product operated by an individual developer based in India. This service is offered at shortlisted.app and related subdomains. For queries, contact us at the email address listed on the platform.

2. What data we collect and why

Account information

When you sign up, we collect your email address and a hashed password (or link your Google account). This is used exclusively to identify your account, allow you to sign in, and associate your data with you. We do not use your email for marketing without your explicit opt-in.

Resume and job description text

Resume analysis runs entirely in your browser. The text you paste into the resume and job description fields never leaves your device during analysis — no server receives it, no database stores it. This is a deliberate architectural choice, not a claim we make lightly.

If you use the Application Tracker, job description text you attach to an application is stored in our database linked to your account so you can retrieve it later. You can delete any application and its associated data at any time.

Usage data

We collect basic anonymised usage information (pages visited, feature usage frequency) to understand how the product is being used and where to improve it. This data is not linked to your identity.

3. What we do not do

  • We do not sell your data to any third party, ever.
  • We do not share your data with advertisers.
  • We do not use your resume content to train AI models without your explicit, informed, opt-in consent.
  • We do not build profiles of you for any purpose beyond operating the service.
  • We do not send marketing emails unless you have specifically opted in.

4. Future use of data for algorithm improvement or AI features

We may in the future wish to improve the keyword matching algorithm or introduce AI-powered features such as resume bullet rewriting. If we ever want to use user-contributed resume content to improve these systems, we will:

  • Ask for volunteers explicitly — no data will be used without a clear, separate opt-in.
  • Explain exactly what data would be used, how, and for how long.
  • Allow you to withdraw consent at any time.
  • Never use data from users who have not opted in.

This is a commitment, not just a policy clause.

5. Data storage and security

Account data and application tracker entries are stored on Supabase, a managed database platform with industry-standard encryption at rest and in transit. Access to your data is restricted by row-level security policies — meaning the database itself enforces that you can only read and write your own records.

While we take reasonable precautions, no internet service can guarantee absolute security. We encourage you to use a strong, unique password.

6. Data retention

We retain your account data for as long as your account is active. If you delete your account, all associated data — profile, application tracker entries, scan history — is permanently deleted within 30 days. You may request deletion at any time by contacting us.

7. Your rights under Indian law

Under the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian law, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request erasure of your data.
  • Withdraw consent for data processing where consent is the legal basis.
  • Nominate a person to exercise these rights on your behalf.

To exercise any of these rights, contact us through the platform. We will respond within 30 days.

8. Cookies

We use session cookies strictly for authentication — to keep you signed in. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

9. Changes to this policy

If we make material changes to this policy, we will notify signed-in users by email and update the "last updated" date above. Continued use of the service after notification constitutes acceptance of the revised policy.