Data and trust

You are handing this your career history. Here is exactly what happens to it.

A career evidence record is more personal than a résumé. It holds the projects, the numbers, the mistakes, and the things you have never written down anywhere else. That deserves a plain answer rather than a policy nobody reads.

A pair of hands resting on a well-worn personal notebook on a desk in warm morning light, a pen beside it.

It is yours, and it leaves in one file

Everything you write belongs to you. Your account settings include a complete export of your data as a single file, at any time, on any plan, including the free one. There is no paid tier required to get your own work back out, and no export queue.

This matters more than it sounds. A career record you cannot remove is a career record held hostage, and the entire argument of this product is that the evidence should outlast any one tool, including this one.

What is never done with it

  • Never sold. Not to recruiters, data brokers, advertisers, or anyone else.
  • Never used to train AI models. Your evidence is used to answer your own requests and nothing else.
  • Never shown to employers. This is a place you build evidence, not a place you are listed. No employer browses profiles here, because there are none.
  • No ads, no ad tracking. The product is funded by subscriptions, which is the whole reason it can promise the three above.

Who else can see it

Nobody, unless you invite them. There is no shared view, no organisation that can look over your shoulder, and no default that opens your record to anyone.

You can invite one person at a time — a résumé writer, a coach, a counselor, a mentor — into specific experiences you tick one by one. Nothing is shared by default, anything you leave unticked is never listed or counted to them, and being able to read a record is never the same as being able to download the files attached to it. You set how long it lasts, and you can end it in one click. Both are enforced on every single request, so a page they already have open stops working too.

They cannot change anything. A collaborator proposes wording and says why; you see their version beside yours and accept, reject, or ask them something. Nothing they write enters your record unless you accept it, and who suggested it and who accepted it is kept permanently.

One asymmetry worth stating plainly rather than leaving you to find out: a professional working with you keeps private working notes that you cannot read. They are that person’s own thinking about the engagement, they are never part of your evidence or anything you export, and they are destroyed with the rest of it when you delete your account. We would rather tell you they exist than have you assume they don’t.

Professionals are verified by a person before anyone can invite them, because handing over the record of your career is not something that should be available to whoever signs up.

Support staff can look up an account to answer “it isn’t working” — whether you are past the threshold that unlocks the AI tools, and whether your monthly allowance is spent. That screen does not show your evidence.

Where it lives

Your data is held in a managed Postgres database hosted in the United States, with encryption in transit and at rest. Sign-in uses an emailed link rather than a password, so there is no password of yours to store or leak. Payments are handled entirely by Stripe, and card numbers never reach this system.

What AI can and cannot see

When you ask for an analysis, the relevant evidence is sent to a large language model provider to produce that specific result, and comes back to you. It is not retained by the provider for training. Nothing is sent anywhere until you ask for it: the manual path through the entire method involves no AI call at all, and works on every plan.

AI here also has a hard constraint that matters for privacy as well as honesty: it only ever works from evidence you wrote. It does not enrich your record from outside sources, look you up, or import anything about you from the internet.

The No Unsupported Claims Principle

That constraint has a name, because it is the rule the rest of the product is built to keep. Nothing Standing Proof produces will contain a claim that does not trace back to something you wrote down yourself: not an accomplishment inferred from a job title, not a number nobody entered, not a capability assumed from an industry or a seniority level.

The limit on that promise matters as much as the promise. We can guarantee where a claim came from. We cannot verify that it is true, and we will not pretend to. Whether your record is accurate is yours to answer, and it should be, because it is your name on the document and your voice in the room. What this product owes you is the guarantee that it never put words in either.

For programs and institutions

If you are evaluating this for a cohort, three things usually come up in procurement, so here they are directly.

Participants own their records, not the program. A sponsoring organization does not receive participants’ career histories. Cohort reporting is aggregate: how many claimed a seat, how many built a working evidence base, how many stayed active. Counts, not contents.

No participant payment data is involved. Class codes grant access without a card, so participants never enter payment details and the program is not processing anything on their behalf.

For your security reviewer: the security overview covers architecture, residency, and subprocessors, the accessibility statement says what has actually been measured, and a standard DPA is available on request.

The record survives the program. When a class grant ends, the participant keeps their account and everything in it on the free plan. Nothing is deleted because a cohort concluded.

Deleting your record

There is a delete button in Settings. It destroys every experience, opportunity, résumé, interview session and growth item in the account, and it cannot be undone. Export first if you want to keep the record; the export is one file.

One thing survives, and it is a number. If you took part in a sponsored cohort, deleting your account adds one to a counter on that cohort recording that a seat was taken by someone who has since left. It carries no name, no email, no timestamp and none of your results. It exists so a program that was already shown “24 of 30 claimed” does not later see 23, with a seat appearing never to have been taken. Your outcomes are not frozen into the report either: once you are gone, the cohort counts only the participants still there.

Your sign-in email is kept, on purpose. Not because deleting it is difficult. It is retained so we know an account once existed at that address, which is what stops free grants and class codes being claimed over and over by deleting and signing up again. It is a bare address: once your record is gone it is attached to no career history, no cohort, and no results of any kind, and signing in again simply starts a new, empty account.

That is a deliberate trade against a real abuse problem, not a gap we are hoping you will not notice, and it is the one thing on this page where we keep something after being asked not to. If you want the address removed as well, email us and we will do it, no questions and no retention script.

What is not built yet

There is no formal third-party security certification such as SOC 2. If your institution requires one, that is a real constraint and this is not the tool for you yet. Saying so is more useful than implying otherwise. What does exist — the architecture, subprocessors, residency, and a plain list of what is and is not in place — is written up for reviewers on the security page.

The full legal versions

This page is the plain-language summary. The privacy policy and terms of service are the binding documents, and they are written to be readable rather than to be survived.

A question this page did not answer, or a requirement your organization needs met?

Ask directly