Security & data
Last updated September 10, 2026
What is stored
- Your account: email, name, and avatar from Google sign-in. Volition AI never sees or stores a password.
- Your record: the resume text you imported, the job descriptions you pasted, and the facts, accomplishments, work history, and target roles you approved.
- Eligibility facts you choose to provide — work authorization, citizenship, visa or sponsorship status, security clearance — used only to surface a posting’s eligibility requirements as warnings; they never affect your fit score.
- Generated documents, their validation results, and the application tracker that ties them to each job.
- Product-usage events (which step you reached, never its content), error reports with message content stripped, and billing records for any purchase.
Where it lives
Records are held in a Supabase Postgres database and finished files in a private Supabase storage bucket; the production project is hosted in Canada (ca-central-1). The application servers run on Render in Oregon, United States. Traffic between your browser, the servers, and these providers is encrypted in transit. Volition AI is operated from the United States; by using it you agree to your data being processed in the United States and Canada.
Who processes your text
To draft wording, your resume text, the job description, and your approved record are sent to these AI providers under their API terms. Volition AI never trains models on your data. The providers are outside our control: we choose providers and settings that do not train on API content and will make every effort to keep it that way, but we cannot guarantee a third party’s conduct. Providers may retain a copy briefly for abuse monitoring under their own terms.
- DeepInfra — runs the models that read your resume into facts, score fit, and draft resume, cover-letter and answer wording — the default for every step
- Anthropic (Claude) — drafts wording, and takes over automatically if the primary provider is unavailable
- Google (Gemini) — an alternative model Volition AI can switch to from its console; not used by default, but able to receive the same content if switched
Other providers see only what their job requires: Supabase (sign-in, database, storage), Render (servers), Sentry (error reports, content stripped), Stripe (payments; card details never reach Volition AI), and Resend (transactional email).
Access controls
- Every request to the service carries a signed sign-in token and is checked against the account that owns the data; there is no anonymous access to records.
- Application tables are locked down at the database with row-level security and no client-side policies, so records cannot be read around the service.
- Per-account and per-address rate limits, request-size ceilings, and upload bounds limit abuse.
- Generated content is checked against your approved record before download; a line Volition AI cannot trace is flagged, and nothing is charged for a document it refuses to finish.
Volition AI is in beta and has not yet completed a third-party security audit or certification.
Retention and erasure
- In-progress applications are discarded after a period of inactivity, shown in the product: the job description, fit result, plan, and any evidence added only for that job. Your saved record is unaffected.
- Your record and finished documents are kept until you delete them.
- Export everything as one ZIP from your account at any time.
- Delete a document without deleting your record.
- Delete your account for a full erasure: every record you own, every stored file, usage and billing records, and your sign-in identity. A later sign-in creates a fresh, empty account.
Erasure cannot reach copies held briefly by the AI providers under their own terms, or error reports that carry no message content and expire on their own schedule. If a stored file cannot be removed at the moment you ask, the request is recorded and retried until it succeeds.
Reporting a problem
If you believe you have found a security or privacy issue, contact Volition AI through the company page on LinkedIn. Please do not access data that is not yours while investigating.