← Executive Signal

Privacy Policy

Last updated: May 2025

Executive Signal is built on a simple principle: your profile data is yours. We process it to generate your audit report and then discard it. We do not store profiles, sell data, or build user databases. This policy explains exactly what we do and don't do with your information.

1. What Data We Collect

We collect only what is necessary to provide the service:

  • Profile text you submit — LinkedIn profile copy, manually entered text, or PDF content you paste or upload for analysis.
  • Email address — only if you choose to receive your report by email or purchase a paid report. Never collected for free-tier usage.
  • Payment information — processed entirely by Stripe. We never see or store your card number, bank details, or any payment credentials.
  • Session identifiers — a short-lived, anonymous token stored in your browser to keep your report accessible during your session and to enable paid-access recovery via a magic link.
  • Usage analytics — anonymised interaction data via PostHog (e.g. which sections you view, funnel steps completed). No personal profile data is included in analytics events.

2. How We Use Your Data

Profile text is used for one purpose only: generating your audit report using an AI model (OpenAI). Once the report is generated:

  • Your profile text is processed in memory and discarded. It is not written to any database or long-term storage.
  • The generated report may be temporarily cached to allow you to retrieve it during your session or via your magic-link restore URL.
  • Your email address is used solely to deliver your report and, if applicable, to send your paid-access restore link. It is not used for marketing without your explicit consent.

3. Data Sharing

We do not sell, rent, trade, or share your personal data with third parties for their own purposes.

Limited data is shared with the following service providers, solely to operate the product:

  • OpenAI — receives your profile text to generate the audit report. Subject to OpenAI's API data usage policies. Profile data submitted via the API is not used to train OpenAI models by default.
  • Stripe — processes payments. Receives only what is required to complete a transaction.
  • Upstash (Redis) — stores short-lived session and entitlement state. No profile text is stored here.
  • Vercel — hosts the application. Standard server logs may be retained for a short period per Vercel's policy.
  • Zoho Mail — used to send report delivery and restore emails.
  • PostHog — anonymised product analytics. No profile content is included.

No other third parties receive your data.

4. Data Retention

  • Profile text: not retained. Processed in memory and discarded after your report is generated.
  • Report content: cached temporarily (typically 30 days) in Vercel Blob storage to support session recovery. Access is gated by your session token.
  • Email address: retained only as long as necessary to support report delivery and paid-access recovery. You may request deletion at any time.
  • Payment records: retained by Stripe in accordance with their policies and applicable financial regulations.

5. Cookies and Local Storage

We use a first-party session cookie (es_access) to track your access tier and keep you logged in during your session. We also use browser local/session storage to preserve your audit state across checkout redirects so you can return seamlessly after payment.

We do not use advertising or tracking cookies.

6. Your Rights (EU / UK Users)

If you are located in the European Union or United Kingdom, you have rights under the GDPR / UK GDPR, including the right to access, correct, or delete personal data we hold about you. Because we do not retain profile text, the primary personal data we may hold is your email address.

To exercise your rights or request deletion of your email, contact us at sales@valuehuman.ai. We will respond within 30 days.

Our legal basis for processing your email address is contractual necessity (delivering the service you paid for) and, where applicable, legitimate interests (enabling report recovery).

7. Children

Executive Signal is intended for professionals and is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from minors.

8. Security

We use industry-standard measures including HTTPS, signed session tokens, and access-controlled storage. Because profile text is not persisted, the risk surface for profile data exposure is minimal.

9. Changes to This Policy

We may update this policy from time to time. The “Last updated” date at the top of this page reflects when changes were last made. Continued use of the service after changes constitutes acceptance of the revised policy.

10. Contact

Questions about this policy or your data? Email us at sales@valuehuman.ai.

HomeTerms of ServiceContact