Privacy Policy
1. Overview & Our Core Promise
At Fastlyy ("Fastlyy", "we", "us"), we believe your career search is confidential. Our privacy architecture is designed around minimal collection, rigorous encryption, and complete transparency:
Our Non-Negotiable Commitment
We do NOT sell, rent, monetize, or share your resume, personal data, IP addresses, or browsing history with third-party advertisers, data brokers, or recruiters. Your data is used exclusively to compute your job matches, secure your account against unauthorized access, and power your product experience.
2. Information We Collect on Fastlyy
We collect only the information necessary to provide and operate Fastlyy:
- Account Identity (Google OAuth): Authentication on Fastlyy is exclusively managed via Google Sign-In. We receive your verified email address, full name, and profile avatar via standard Google OAuth 2.0 / OpenID Connect. We do not create, request, or store passwords on our servers. We never request or access your private Google Drive documents, Gmail messages, calendar, or contacts.
- Resume & Career Profile: PDF or DOCX resume documents you upload. Our system extracts career experience, titles, skills, technologies, and education to calculate automated match scores.
- Job Preferences: Target job roles, location preferences (Remote, Hybrid, On-site), tracked "Dream Companies", and your saved job listings.
- Application Stages: Job tracking statuses you organize in your dashboard (e.g. Applied, Interviewing, Offer, Rejected).
- Payment Records: When purchasing an access pass, payment is processed directly by our Merchant of Record, Dodo Payments. We store only the transaction status, pass duration, and confirmation ID. We never see, handle, or store your credit or debit card numbers.
3. Technical Telemetry, IP Addresses & Sessions
To protect your account against credential stuffing, prevent unauthorized logins, and ensure our interface displays correctly on your device, we log technical session and diagnostic telemetry:
- Internet Protocol (IP) Address & Approximate Location: We log your IP address to verify device logins, enforce rate limits, and provide approximate geographic localization (country and city level). IP addresses are classified as personal data under GDPR and CCPA, and are treated with strict safeguards.
- Active Sessions & Device Identity: We record device type (Desktop, Mobile, Tablet), browser version, operating system, and login timestamps. This powers our security feature allowing you to inspect active logins and remotely terminate unrecognized devices.
- Session Token Security: Raw session tokens and authorization secrets are never stored in our databases. We store only one-way cryptographic SHA-256 hashes of session tokens, making it mathematically impossible for an attacker to reconstruct your credentials even in the event of an internal database breach.
- Engagement & Diagnostic Telemetry: We collect first-party performance metrics including active time on page, scroll depth percentage, viewport dimensions, screen resolution, display pixel ratio, and generalized click counts (e.g., clicking "Apply" or "Save Job").
- Sanitization & Privacy Masks: Our client-side telemetry strictly ignores text input fields, password boxes, and sensitive elements. Furthermore, any dynamic button labels containing email addresses, phone numbers, or card numbers are automatically masked before transmission.
4. How We Use Your Data & Legal Bases
Under international privacy regulations (including GDPR Art. 6 and India's DPDP Act), we process your information under specific legal grounds:
- Performance of Contract (Art. 6(1)(b)): To calculate resume-to-job match scores, maintain your active pass or trial, deliver your job feed, and provide customer support.
- Legitimate Interests (Art. 6(1)(f)): To maintain cybersecurity, detect brute-force attacks, defend against automated bot scraping, ensure fair usage (such as our 24-hour upload cooldown), and diagnose application performance errors.
- Compliance with Legal Obligations (Art. 6(1)(c)): To maintain financial transaction records for tax compliance and resolve billing disputes with our Merchant of Record.
5. AI Processing & Large Language Model Architecture
Fastlyy utilizes vetted enterprise artificial intelligence APIs and large language model architectures to analyze resume text, evaluate job descriptions, and generate match scores.
How AI Handles Your Career Data
- Text-Only Transmission: We transmit only extracted text snippets necessary to evaluate skills and experience. We never transmit original binary files, credentials, or financial information.
- No Public Model Training: Under commercial enterprise API terms, data processed via paid enterprise endpoints is never used to train, retrain, or improve public AI models.
- Stateless Real-Time Inference: Data is analyzed in real time for inference and is not retained or indexed by the AI model provider.
6. Third-Party Technical Partners
We partner with vetted, industry-leading technical infrastructure providers bound by strict Data Processing Agreements:
- Cloud Hosting & Edge Network Infrastructure: Global edge compute, serverless application hosting, and Content Delivery Network (CDN) services with secure TLS 1.3 termination.
- Managed Database & Secure Cloud Storage: High-availability cloud PostgreSQL databases and encrypted document storage protected by strict Row Level Security (RLS) policies.
- Dodo Payments: Merchant of Record handling secure global payments, currency conversion, fraud detection, and tax remittance.
- Enterprise AI Service Providers: Vetted cloud AI infrastructure providers for semantic resume parsing and deterministic match scoring under zero-retention commercial terms.
- Google Authentication: Exclusive Single Sign-On (SSO) provider, enabling secure, passwordless account access without storing user passwords on our platform.
7. Cookies & Tracking Protections
Fastlyy is intentionally built with privacy by default:
- Strictly Essential Storage: We use essential HTTP cookies and local storage exclusively to authenticate your session, protect against CSRF attacks, and persist UI theme preferences.
- No Third-Party Advertising Pixels: We do NOT employ Meta Pixels, Google Ads remarketing cookies, or behavioral advertising trackers.
- No Cross-Site Surveillance: We never track your activity across other websites or sell behavioral data to data brokers.
8. Data Retention & Permanent Deletion
We store personal information only as long as necessary to fulfill the purposes outlined in this policy:
- Active Accounts: Your resume and profile remain saved during your active pass and subsequent dormant periods so you can resume your job search without starting over.
- Session & IP Audit Logs: Detailed page-view and session audit logs are retained for active account protection and automatically rotated and pruned on a ninety (90) day retention schedule.
- Permanent Account Erasure: You have the absolute right to permanent deletion. When an account is deleted, all resumes, sessions, IP logs, and activity records are permanently purged via database cascade deletion within thirty (30) days.
9. Global Privacy Rights (GDPR, CCPA/CPRA & DPDP)
Depending on your location, you hold statutory data protection rights under regulations such as the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and India's Digital Personal Data Protection Act (DPDP):
Request an export of all personal data, resumes, and session records we hold about you.
Request permanent deletion of your account, resumes, and historical activity logs.
Update or correct inaccurate resume details, target roles, or account information at any time.
We will never deny services, charge different prices, or degrade quality for exercising your privacy rights.
We do not "sell" or "share" personal information for cross-context behavioral advertising as defined under the California Consumer Privacy Act (CCPA).
10. Security Safeguards & Access Controls
We protect your data using comprehensive multi-layered security controls:
- Encryption in Transit: 100% of data transmitted between your browser and our servers is secured using modern TLS 1.3 encryption.
- Encryption at Rest: All databases, documents, and backups are encrypted at rest using AES-256 standard encryption.
- Row Level Security (RLS): Our database enforces strict Row Level Security policies. Public or client-side tokens are cryptographically forbidden from accessing other users' sessions or activity logs.
- Administrative Access: Admin tools are secured behind dedicated multi-factor authentication, secret keys, and constant-time cryptographic verification.
11. External Career Links
Fastlyy provides direct links to external employer career portals (such as Greenhouse, Lever, Ashby, or Workday). When you click "Apply", you navigate to the employer's external website. We have no control over how external employers process job applications, and their independent privacy notices govern your submission.
12. Contact & Data Protection Requests
To exercise your privacy rights, request data export, or request account erasure, email our Data Protection team at:
Fastlyy Data Protection & Privacy Office
Email: hello@fastlyy.com
We respond to verified privacy requests within thirty (30) days in accordance with applicable laws.