Your career data, handled with care.
This page is maintained by the Tired2Hired team to answer common security and privacy questions about the platform. It describes controls we have enabled today — not an independent certification.
Controls we run today
Authentication
Email + password and Google sign-in. Sessions are managed by our backend provider with rotating refresh tokens.
In-transit encryption
Every request between your browser and Tired2Hired is served over HTTPS with modern TLS.
Data storage
Your resume, conversations, and generated artifacts are stored in our backend provider's managed Postgres with row-level security scoped to your account.
Access controls
Only you can read your data through the app. Support staff can access account data only when you open a ticket that requires it.
Retention & deletion
You can delete your account from Settings. Deletion removes your profile, resume, and generated artifacts within 30 days from active storage.
AI processing
AI features send the prompt content needed for the request to our model provider. Your data is not used to train third-party models.
Subprocessors
We use a small set of vetted providers to run the platform. Each is scoped to the purpose below.
Shared responsibility
What Tired2Hired does
- • Encrypts traffic in transit and enforces row-level security on your data
- • Restricts admin access and logs privileged actions
- • Deletes your data on request within 30 days
What we ask of you
- • Use a strong, unique password
- • Don't share your login
- • Report suspicious activity to support