SkillDoc.ai policies
Privacy
Effective August 2026
SkillDoc is a candidate-side career intelligence product. This page describes the information the product uses today, why it uses it, the service providers involved, and the controls available to you.
1. Information you provide
SkillDoc processes information you submit to create an account and use career tools. Depending on the feature, this can include your email address, career targets, skills, evidence, job titles, employers, locations, job links, job-posting text, and action-plan information.
2. Account and authentication data
Account records include an email address, verification and account timestamps, account source and consent information, and a session version used to invalidate sessions. SkillDoc stores salted, one-way password hashes rather than plaintext passwords. Verification and password-reset records use hashed codes or tokens, expiration times, attempt limits, and hashed network-address information for abuse prevention.
Signed session cookies keep you signed in. Separate short-lived cookies support request protection, enrollment, and Google sign-in or linking. Authentication cookies are configured as HttpOnly, Secure, and SameSite=Lax.
3. Google Sign-In and account linking
If Google Sign-In is enabled and you choose it, SkillDoc requests the OpenID Connect scopes openid, email, and profile. SkillDoc uses Google's stable account identifier, verified email address, and basic profile claims to authenticate you or link a Google identity after additional verification when required.
- SkillDoc does not request access to Gmail, Drive, Calendar, Contacts, or other Google product content.
- The linked identity stores the Google account identifier and a provider-email snapshot. Your SkillDoc account email remains the canonical account email.
- The sign-in exchange receives an ID token for verification. SkillDoc does not request or retain Google access tokens or refresh tokens for ongoing access.
- Disconnecting removes the Google identity from SkillDoc and rotates your SkillDoc sessions. It does not delete or change your Google account.
4. Career tools and job-posting data
The Job Skill Scanner stores a sanitized job URL and host, an input digest, available job metadata, bounded findings, short evidence excerpts, generated project or action suggestions, and review status. It is designed not to store the complete posting in the Scanner run record.
Other features work differently. For example, when you use the Check 5 Jobs workflow, SkillDoc stores the job-posting inputs you submit with that audit so the audit can be displayed and used in your career workspace. Career records can also include skills, evidence, targets, plans, activity, audit results, and task-impact results.
5. AI processing
When an AI-powered feature is enabled, the text needed for that feature may be sent to Google Gemini to generate analysis. For example, Scanner analysis can include the bounded posting text being analyzed. SkillDoc records operational usage information such as feature, model, token and cost estimates, status, and a pseudonymous user identifier. Provider diagnostics are designed to use metadata and hashes rather than submitted content.
6. Product analytics, logs, and storage
SkillDoc uses first-party product events to understand feature use and campaign attribution. These events can include an event name, account identifier, campaign parameters, and sanitized metadata. Sensitive text fields such as posting text, resume text, raw text, evidence content, and email addresses are removed from analytics metadata.
Operational logs and security records may include event categories, status information, timestamps, hashed identifiers, and technical request information needed to operate, secure, and troubleshoot the service. SkillDoc retains information for as long as reasonably needed for the feature, account, security, and operational purposes described here.
7. Service providers
SkillDoc uses Cloudflare for application hosting and data infrastructure, Resend for account and security email delivery, and Google for optional Google authentication and optional Gemini-powered analysis. Those providers process information on SkillDoc's behalf or at your direction to provide their relevant service.
8. Cookies and browser storage
SkillDoc uses cookies that are necessary for sessions, request protection, authentication enrollment, and optional Google sign-in or linking. Some interfaces may also use browser session storage for an in-progress form draft. SkillDoc does not currently describe these necessary mechanisms as advertising cookies.
9. Security
SkillDoc uses measures including one-way credential hashing, signed and secure cookies, expiring verification records, request protection, bounded inputs, session invalidation, and additional verification for sensitive linking actions. No system can guarantee absolute security, so protect your credentials and report suspected account misuse.
10. Your choices and controls
You can change or reset your password, sign out active sessions, and disconnect a linked Google identity from the Sign-in & Security page. Product interfaces also provide controls to delete certain audits and task-impact results and to reset supported career-workspace data. These controls do not currently represent deletion of the underlying authentication account.
11. Changes to this notice
SkillDoc may update this notice as the product and its data practices change. The effective date above will be revised when a new version is published.
12. Contact
For privacy questions or requests, use the support contact shown within SkillDoc.