What a careers office needs to know before students use Involve Resume: where the data lives, who processes it, how students sign in, and how data is deleted.
The short version.
Involve follows the UK and EU GDPR. The database is hosted by Supabase in the EU (Paris, eu-west-3), and the server functions that read it run there too. Where a provider below processes data outside the UK or the EEA, that transfer relies on the EU Standard Contractual Clauses and the UK Addendum.
A student's data is private to that student. The database itself stops other users from reading it, not only the app. There are two deliberate exceptions: what a student chooses to share on a practice board is seen by other students, and your careers-office staff see the summary described below.
Careers-office staff we give access to see, for each student at your school: name, email, date joined, plan, last active date, number of resumes, number of applications and best match score. They also see cohort totals and the employers students apply to most. Staff do not see the text of a student's resume or documents.
| Provider | What it does | Data it handles |
|---|---|---|
| Supabase | Database, sign-in, server functions. Paris, France (eu-west-3) | Everything stored, listed above |
| Cloudflare | Serves the website | Web requests |
| Google, Microsoft | Sign-in | Name, email and a stable account ID |
| n8n Cloud | Our workflow that carries AI requests, and the job search | The text of an AI request, only when the student presses that button, and the student's sign-in token (account ID and email) so we can check their plan |
| OpenRouter | Routes an AI request to the model | The same text. Not the sign-in token |
| Anthropic (Claude) | The model for rewrites, message drafts and translation, and the backup for the extension's prepare step | The same text |
| DeepSeek's model | The extension's prepare step. It runs on an inference host that OpenRouter picks; we tell OpenRouter to use only hosts that do not keep or train on the text | The same text |
| Web fonts on every page (Google Fonts). Speech-to-text in interview practice, when the browser cannot do it on the device | Visitor IP address. Practice audio, only in that case | |
| Stripe | Payments, only for students who pay themselves | Payment details, on Stripe's own pages. Card numbers never reach us |
An AI request carries only what that button needs, for example one line being rewritten. The CV file, email address, phone number, links and account ID are never sent to a model. The text itself can still include the student's name, job titles and employers, for example in a message drafted for them to sign.
A student can delete all their data from the account screen. It runs in one database transaction, so it either all goes or none of it does, and it cannot be undone. A student can also delete a single document, job or answer. A request by email to [email protected] is done within 30 days.
We do not hold SOC 2 or ISO 27001 certification. We would rather tell you than let you assume it. We are happy to answer a security questionnaire.
Ask us for our Data Processing Agreement: [email protected].
More: Involve for careers offices · Privacy policy · Why you can trust Involve.