Privacy Policy

Last updated: August 18, 2026

PathPilot (“we,” “us,” or “our”) is an independent project built and operated by Javier Padilla. This policy explains what information PathPilot collects when you use the app, why we collect it, who we share it with, and the choices you have. We've tried to write it in plain language rather than legal boilerplate.

1. Information we collect

Account information

When you sign up, we collect your email address, your name (if provided), and a securely hashed password, handled by our authentication provider, Supabase.

Your CV and questionnaire responses

When you request an analysis, we collect either the PDF file you upload or the text you paste, along with your answers to our questionnaire (work style, priorities, target location, salary expectations, and similar details you choose to share).

Analysis results and feedback

We store the career analysis generated for you so you can revisit it later, and any optional feedback you submit about whether an analysis was helpful.

What we don't collect

PathPilot does not currently use analytics tools, advertising trackers, or third-party cookies. We don't know which pages you visited before signing up, and we're not building an ad profile of you.

2. How we use your information

  • To generate your career analysis and action plan
  • To let you log in and view your analysis history
  • To respond if you contact us with a question or an issue
  • To improve PathPilot's prompts and question set, using aggregated feedback rather than reviewing individual CVs

3. Who we share it with

We use a small number of third-party services to run PathPilot. We don't sell your data, and we don't share it with advertisers.

OpenAI

Your CV text and questionnaire answers are sent to OpenAI's API to generate your analysis. OpenAI processes this data to return a result to us and, per their API data usage policies, does not use API content to train their models by default.

Supabase

Supabase hosts our database, handles authentication, and stores uploaded CV files. Your data is encrypted in transit and access is restricted to your own account through row-level security.

4. Data retention

We keep your account information, CVs, and analyses for as long as your account is active. If you delete your account, we permanently delete your CV files, questionnaire responses, and analysis history within 30 days.

5. Your rights and choices

  • Access: your dashboard shows every analysis tied to your account.
  • Deletion: email jvra0102@gmail.com to request full deletion of your account and data.
  • Correction: you can re-run an analysis at any time with updated information.

6. Security

We rely on Supabase's infrastructure for encryption at rest and in transit, and we restrict data access using row-level security so that users can only ever read their own records. No system is perfectly secure, and we can't guarantee absolute protection against every threat.

7. Children's privacy

PathPilot is not directed at, and should not be used by, anyone under 16 years old. We do not knowingly collect information from children under 16.

8. International users

PathPilot is operated as an independent project. If you access it from outside the country where it's hosted, your information will be processed there. By using PathPilot, you consent to this transfer and processing.

9. Changes to this policy

If we make material changes to this policy, we'll update the date at the top of this page. Continued use of PathPilot after a change means you accept the updated policy.

10. Contact us

Questions about this policy or your data? Reach out at jvra0102@gmail.com.