legal // privacy and data control

Privacy Policy

Humetric is a consent-first professional identity and talent-discovery service. This policy explains, in plain language, what personal data we process, why we process it, when it can become public, and how you can control or delete it.

Effective and last updated: July 15, 2026

Localized versions are provided for convenience. If a translation conflicts with the English version, the English version controls to the extent permitted by applicable law.

1. Scope and controller

This policy applies to humetric.net, Humetric accounts, profile submission and management, public profiles, search, APIs, MCP access, recruiter early access, and related support communications (the “Service”). Humetric, operated from Taipei, Taiwan, determines how personal data is processed for the Service. Questions and rights requests may be sent to [email protected].

2. Our privacy commitments

  • You own and control your content. Humetric processes it only to help you structure, improve, trim, publish, promote, secure, or withdraw it as you direct.
  • We do not use your résumé or profile to train Humetric or general-purpose AI models.
  • We do not currently sell personal information or share it for cross-context behavioral advertising. Any future compensated data-sharing feature would require separate, explicit, informed, and revocable opt-in consent.
  • A submitted résumé starts as a private draft. It is not published until you review and confirm it.
  • You control exposure by field—public, verified-only, or hidden—and may change or withdraw it. Contact email and phone are private by default.
  • Public and authorized profile access is filtered through exposure rules and logged for auditability.
  • Connecting an external account does not authorize posting; each outbound social post requires separate approval of the exact text.
  • We collect and disclose only what is reasonably necessary for the stated purpose.

3. Data we collect and its sources

Data you provide. Résumés and their text; name; email; phone; professional history; education; skills; location; links; profile summary; contact preferences; desired queries; exposure settings; recruiter name, work email, company, and support messages. We must store some of this data in our cloud database and file storage to maintain your private draft, profile, settings, and later deletion controls. We do not keep a separate hidden marketing copy.

Account and connection data. When you use an email magic link, Google, LinkedIn, Facebook, GitHub, X, or another enabled sign-in provider, we receive the email address or provider identifier and basic account details you approve, which may include name, email, and profile image.

Service and device data. Authentication sessions, timestamps, consent and access logs, API usage, security events, request metadata, IP-derived abuse-prevention values, browser or device information, and basic product analytics. Rate-limit identifiers are hashed rather than stored as raw IP or email values by that protection mechanism.

Public or authorized sources. If you provide a GitHub, LinkedIn, or website link, we may process information at that link when the feature clearly indicates it. We do not claim ownership of third-party data, and we do not treat public availability as permission for unrestricted use.

We do not ask for government IDs, financial account data, medical information, criminal records, or other sensitive personal data. Do not include unnecessary sensitive information in a résumé or free-text field.

4. Why and on what basis we process data

Where local law requires a different legal basis, we rely only on a basis permitted there. We do not use OAuth provider data for advertising.

  • Provide the Service and perform our agreement: authenticate users, parse a résumé, create a private draft, publish only approved fields, operate search and APIs, manage connections, and provide requested recruiter access.
  • Your consent: publish fields you mark public, enable optional discovery methods, connect an external account, send an approved social post, and send optional communications where consent is required. You may withdraw consent prospectively.
  • Legitimate operational interests: secure, debug, measure, and improve the Service; prevent fraud and abuse; keep audit records; and understand aggregate usage, balanced against your rights.
  • Legal obligations and protection: comply with lawful requests, enforce our terms, establish or defend legal claims, and protect users, the public, or the Service.

5. AI processing, search, and public profiles

Humetric may send limited résumé text to a configured cloud language-model provider to turn it into a structured draft. That transfer is for inference, not for Humetric model training; provider retention and training controls depend on the selected provider and our configuration. If that service is unavailable, a rules-based parser may be used. You review the draft before publication. Search and ranking systems may compare approved professional fields with a query, but Humetric does not make hiring decisions, determine legal eligibility, or guarantee a job, ranking, citation, or discovery result.

Fields you choose to publish may be visible on public pages and in machine-readable formats such as JSON-LD, JSON, Markdown, REST, MCP, sitemaps, or search indexes. Public information can be copied or cached by third parties outside our control. Hiding or deleting data stops future disclosure by Humetric and triggers our available withdrawal mechanisms, but cannot guarantee deletion from every third-party cache or prior recipient.

6. When we disclose data

Providers may process data under their own terms and privacy policies. We do not authorize them to use Humetric data for their independent advertising.

  • Your chosen audience: public visitors, search services, AI agents, API or MCP clients, or verified users only to the extent allowed by your exposure settings.
  • Service providers: Supabase for authentication, storage, and database services; Vercel for hosting and analytics; your selected OAuth provider; and a configured résumé-parsing model provider, which may include OpenRouter or another compatible provider.
  • Legal and safety recipients: courts, regulators, law enforcement, advisers, or other parties when reasonably necessary to comply with law or protect rights and safety.
  • Business transfer: a successor in a merger, financing, reorganization, or asset transfer, subject to appropriate confidentiality and notice where required.

7. Retention

We apply need-based retention rather than keeping personal data indefinitely. Humetric does not retain deleted active data for AI training. You may ask for the current retention assessment for your data.

  • Private submission drafts and source files are kept while needed for review, recovery, security, and profile management, then deleted or de-identified when no longer necessary.
  • Published profile data is kept until you hide it, delete it, or close the profile. Exposure changes remove fields from future Humetric public responses; full deletion removes active copies, subject to limited backup, legal, and security retention.
  • Early-access contact data is kept until access outreach is complete, you opt out, or it is no longer needed.
  • Security, consent, access, and transaction records may be kept longer where reasonably required for audit, fraud prevention, dispute resolution, or law.
  • Deleted data may remain temporarily in encrypted backups until normal rotation completes and is not restored to active use except for disaster recovery.

8. Security and incident response

We use measures designed for the sensitivity of the data, including access controls, private-by-default contact fields, hashed credentials and tokens where appropriate, rate limiting, validation, exposure filtering, append-only audit records, and encrypted transport. No system is perfectly secure. If a breach creates a legally reportable risk, we will investigate, contain it, notify affected people and authorities as required, and document corrective action.

9. Your rights and choices

Depending on applicable law, you may request access, a copy, correction, deletion, restriction or cessation of processing, portability, information about recipients or sources, or objection to certain processing. You may also withdraw consent and complain to your local privacy authority. We will not discriminate against you for exercising a privacy right.

Taiwan data subjects may exercise the rights provided by Article 3 of the Personal Data Protection Act. EEA, UK, and similar-law residents may also object to legitimate-interest processing and request restriction or portability where applicable. California residents may request to know, correct, or delete covered information and may opt out of sale or sharing; Humetric does not sell personal information or share it for cross-context behavioral advertising.

Use profile controls where available or email [email protected]. Describe the account or profile and the right you want to exercise. We may verify identity and authority, respond within the legally required period, explain any lawful exception, and support an authorized agent where local law requires it.

account and data deletion

Request deletion

Email [email protected] from the account email when possible, with the subject “Humetric data deletion request.” After reasonable verification, we will delete or de-identify the account, profile, source submission, and active copies within the period required by applicable law, except data we must retain for security, legal compliance, or legal claims. Revoking an OAuth provider connection alone does not delete data already held by Humetric.

10. Taiwan collection notice

For Taiwan’s Personal Data Protection Act: the collecting party is Humetric; purposes and data categories are described in Sections 3 and 4; use continues for the periods in Section 7; processing may occur in Taiwan and locations where our providers operate; recipients and methods are described in Sections 5 and 6; and rights and exercise methods are in Section 9. Providing optional data is voluntary. If required account, contact, résumé, or agreement data is not provided, we cannot create the requested draft, profile, account, or early-access request.

11. International transfers and minors

Humetric and its providers may process data outside your country. Where required, we use recognized contractual or legal safeguards and provide information about them on request. The Service is for professional users age 18 or older and is not directed to children. If we learn that a minor submitted personal data, contact us so we can remove it.

12. Policy changes and contact

We may update this policy as the Service or law changes. We will post the revised date and provide additional notice or obtain renewed consent when legally required or when a material change needs it. Continued use does not override rights that require affirmative consent.

Privacy contact: [email protected]. Please also review our Terms of Use.