UBuildUs

Privacy Policy

Effective Date: February 26, 2026  ·  Last Updated: August 31, 2026

This Privacy Policy explains how UBuildUscollects, uses, and protects your personal information when you use our website, platform, and related services (collectively, the “Services”). We do not sell your personal information — ever — and we do not sell user data to advertisers. If you do not agree with this policy, please do not use the Services. Capitalized terms used in this Privacy Policy have the meanings given to them in our End User License Agreement (EULA).

1. Introduction

UBuildUs is a career platform that helps candidates build, manage, and share professional profiles and resumes, and helps recruiters discover qualified candidates. In providing these Services we process personal information on your behalf and take that responsibility seriously.

This policy describes: (a) what personal information we collect and why; (b) how we use and protect it; (c) with whom we share it; and (d) your rights regarding that information. “Personal information” means any information that identifies or can reasonably be linked to an individual.

2. Who We Are

UBuildUs is a brand owned and operated by Simple People Holdings LLC-s, headquartered in the State of Indiana, United States. We operate under Indiana law, including the Indiana Consumer Data Protection Act (ICDPA), Ind. Code § 24-15, which became effective January 1, 2026. Where applicable, we also respect applicable federal privacy laws.

For questions about this policy, please see the Contact Us section below.

3. Your Ownership of Your Data

Throughout the Services and our marketing materials (for example, the phrase “Hiring, where you have agency over your story”) we describe you as having agency over — and “owning” — your data, profile, and content. As defined in our EULA, this language refers to a specific, defined editorial right: User Ownership. In plain English, User Ownership means that, with respect to your personal data and User Content, you have the right to:

  • Read — access and view your data at any time through the Services or by exercising your data-access rights described in Section 13.
  • Create & update — modify, edit, add to, or change your data through the Services.
  • Delete— remove your data from the Services’ active production data store, subject to the standard retention windows described in Section 12 and any legally required record-keeping.

Simple People Holdings LLC-s retains all Financial and Control Rights in the Services, as defined in the EULA — including economic rights arising from operation of the platform, operational and editorial control of the platform, and intellectual property rights in the platform software, brand, AI models, and aggregated or de-identified analytics. Your User Ownership of your content does not transfer any of those Financial and Control Rights to you, and Ownership Language used in our marketing does not constitute a transfer of legal title in the platform itself.

What this means for your privacy in practice: because we treat your content as yours to read, modify, and delete, you can exercise meaningful control over what we hold about you at any time — directly through the product, without having to ask permission or wait for a response from us.

4. Information We Collect

4.1 Information You Provide Directly

  • Account details: first name, last name, middle name, suffix, username, email address, and hashed password (we never store your password in plain text).
  • Contact information: phone number, city/location, and country.
  • Professional profile: job title, current employer, professional summary, profile overview, career role, and any social/ professional links you add (or that we detect in your uploaded resume).
  • Resume & career history: work experience (employer, job title, dates, responsibilities), education (degree, institution, graduation year), skills, certifications, and other career details you include in your resume.
  • Projects & references: project names, descriptions, URLs, technology tags, dates; professional reference names, titles, companies, email addresses, phone numbers, and relationship types you choose to add to your profile.
  • Uploaded files: resume documents (PDF or DOCX) and profile avatar images you upload.
  • Persona Builder uploads: if you use the About Me feature, any self-description documents you upload (such as a personal bio, autobiography draft, or character sketch in PDF or DOCX format). We extract the text for AI analysis and retain a capped text excerpt (up to 6,000 characters) for later re-curation. The original file is not retained.
  • Journal entries: any text, photos, audio recordings, or short videos you save to your Persona Builder journal, plus the mood and entry type you select, and whether you mark an entry private. Voice notes are transcribed to text by our AI provider; audio remains stored alongside the transcript.
  • Personality answers: your responses to the seven personality survey questions in the Personality section of the Persona Builder.
  • Cause selection: the nonprofit you choose to receive your giving (its Every.org name, slug, and EIN, and when you selected it). See Sections 4.5 and 9.
  • Support communications: messages you send to us through our contact form or by email.

4.2 Information from Third-Party Sign-In & Connections

If you choose to sign in through, or connect, a third-party provider, we receive limited profile data from that provider:

  • Google sign-in: name, email address, Google account ID, and profile picture URL.
  • Apple sign-in: name and email address (if shared by Apple). Apple sign-in may not be available in all environments.
  • GitHub connection:if you connect GitHub from your profile, we fetch your public GitHub profile and public repositories via GitHub’s public API (no GitHub login or access token is used) and store your GitHub username. GitHub is a profile-import connection, not a sign-in method.

Any other professional links (such as a LinkedIn URL) are simply links you type into your profile; we do not connect to those services or import data from them.

We do not receive or store third-party access tokens beyond what is necessary to complete authentication and initial profile data import.

4.3 Information Collected Automatically

  • Session data: signed (authenticated) session tokens stored in HTTP-only cookies used to keep you signed in.
  • Usage and log data: pages visited, features used, timestamps, and error logs. We record system events (e.g., AI service requests) for performance monitoring and debugging.
  • Device and browser data: browser type, operating system, and IP address collected via standard server logs.
  • Push notification tokens: if you enable push notifications (for example, in a mobile app), we store the device push token used to deliver notifications to you via Firebase Cloud Messaging.

4.4 AI-Generated Data

When you upload a resume or interact with the AI assistant, we generate and store derived data including an AI-authored profile overview, resume improvement suggestions, and numerical vector embeddings of your profile. These embeddings are used internally to power candidate search and matching features and are never shared outside UBuildUs.

Estimated skill levels. We also generate, for each skill on your profile, an estimated proficiency label (e.g., Beginner, Intermediate, Advanced, Expert) and an internal numeric score, computed by an algorithm from signals in your own submissions — how often a skill appears across your roles and projects, the years and recency of use, the seniority of the roles it appears in, any certifications, and your own self-ratings, optionally refined by a single bounded AI pass. These labels are estimates, not tested, verified, or certified credentials, and you can adjust them at any time.

If you use the About Me feature in the Persona Builder, we additionally generate AI-curated personality traits (values, voice, interests, motivations, communication style, and background summary) derived from the documents you upload. These traits are stored on your profile as proposals; no trait influences the AI representation of you until you explicitly approve it in the review queue. You can edit, reject, or delete any trait at any time.

We also generate a personality summary from your Personality survey answers, and an AI-derived structured version of each journal entry you save. Both are stored alongside the original input on your profile.

4.5 Billing & Subscription Information

If you start a paid subscription, our payment processor Stripe, Inc. collects and stores your payment card or other payment-method details directly. We never receive or store your full card number, CVC, or bank details. On our own systems we store only:

  • opaque Stripe reference identifiers (customer ID, subscription ID, invoice/charge IDs);
  • your subscription status and billing-period dates, trial start date, and founding-member status;
  • a per-invoice donation record (amount paid, the 25% cause amount, and a snapshot of your selected nonprofit at the time of payment); and
  • if you cancel, the reason and any free-text feedback you provide in Stripe’s cancellation flow.

5. How We Use Your Information

We use personal information only for legitimate purposes directly related to operating and improving the Services:

  • Providing the Services: creating and managing your account, authenticating your identity, rendering your profile, and enabling search and matching features.
  • Processing your resume and documents: extracting text from uploaded files, generating AI-assisted profile summaries and skill estimates, and updating your profile through the AI assistant.
  • Candidate search and matching: using vector embeddings of your profile to surface your profile to recruiters who use the platform and to show you relevant matches.
  • Billing & charitable giving: processing your subscription through Stripe and directing the 25% cause portion of your membership to the nonprofit you select, via Every.org.
  • Communications: sending transactional emails (e.g., account verification, password reset OTPs, service notices). We do not send unsolicited marketing emails without your consent.
  • Security and fraud prevention: detecting abuse, unauthorized access, and policy violations.
  • Service improvement: analyzing usage patterns in aggregate to improve features, fix bugs, and optimize performance.
  • Legal compliance: fulfilling legal obligations or responding to lawful requests from authorities.

We do not use your personal information for targeted advertising, and we do not build advertising profiles based on your activity.

6. AI Processing

UBuildUs uses AI features to operate the platform. Two processors are involved:

  • Document parsing (Docling / Google Document AI): when you upload a resume or Persona Builder document, the file is first sent to our layout-aware document parser (an open-source Docling service running on our own cloud infrastructure) to extract structured text. If that parser is unavailable, PDFs fall back to Google Document AI for text extraction.
  • AI analysis (Google Gemini): extracted text and profile content are processed by Google Gemini (operated by Google LLC) to parse structured resume data, generate profile overviews and resume suggestions, estimate skill levels, power the real-time profile assistant chatbot, transcribe voice notes, describe images, structure journal entries, propose Persona Builder personality traits for your review, and generate vector embeddings used for search and matching.
  • AI representation to recruiters: if you grant recruiters permission via your AI Response Scope setting (default: professional resume only), our AI may respond on your behalf to recruiter questions, grounded in your resume, personality answers, and approved curated traits. You control the scope at any time from the Privacy tab.

When AI features are used, relevant portions of your resume or profile text are transmitted to Google’s APIs for processing. This processing is subject to Google’s Privacy Policy. We use these APIs under terms that restrict Google from using your data to train its general models.

AI-generated outputs (summaries, suggestions, overviews, and skill estimates) may be inaccurate. You are responsible for reviewing and verifying any AI-generated content before relying on it.

7. Third-Party Services & Sub-Processors

We use the following service providers (also referred to as “sub-processors”) to operate the platform. Each processes only the data necessary for their specific function. None of these providers is authorized to sell your data, use it for their own marketing, or onward-share it with advertisers:

ProviderPurposeData Shared
MongoDB Atlas
(MongoDB, Inc.)
Database hostingAll profile and account data stored in the platform
Cloudinary
(Cloudinary Ltd.)
File & image storageResume files (PDF/DOCX), avatar images, and journal media/audio
Google Gemini
(Google LLC)
AI analysis & embeddingsResume, journal, and personality text for AI processing; uploaded Persona Builder document text for trait proposal
Docling (self-hosted)
(open-source parser on our cloud)
Primary resume/document text extractionRaw uploaded resume and Persona Builder files, to extract structured text
Google Document AI
(Google LLC)
PDF text extraction (fallback)Resume and Persona Builder PDF contents when our primary parser is unavailable
Google Cloud Run
(Google LLC)
Application hostingAll platform traffic; runs the UBuildUs app and our document-parsing service
Stripe
(Stripe, Inc.)
Subscription paymentsYour name, email, and payment-method details (card data is held by Stripe, never by us)
Every.org
(Every.org)
Charitable-giving disbursementYour selected nonprofit and pooled, aggregate donation amounts — no personal identity is sent (see Section 9)
Resend
(Resend, Inc.)
Transactional email deliveryEmail address and message content for OTPs and service notices
Firebase Cloud Messaging
(Google LLC)
Push-notification deliveryYour device push token and the notification title/body (only if you enable push notifications)
Google Sign-In
(Google LLC)
Optional sign-inName, email, Google account ID (if you choose Google sign-in)
Apple Sign In
(Apple Inc.)
Optional sign-in (where available)Name and email (if you choose Apple sign-in)
GitHub
(GitHub, Inc.)
Optional profile connectionYour public GitHub profile and repositories via GitHub’s public API (if you connect GitHub)
unavatar.ioAvatar image lookupA professional reference’s public social handle (e.g., a LinkedIn URL you add for a reference), used only to display that reference’s avatar
Slack
(Slack Technologies, LLC)
Optional Slack chat integrationYour Slack user and workspace identity, and the messages you exchange with our assistant — only if you connect Slack
Microsoft Teams / Azure Bot Service
(Microsoft Corporation)
Optional Microsoft Teams chat integrationYour Teams / Microsoft account identity, and the messages you exchange with our assistant — only if you connect Teams

We require each service provider to protect personal information consistent with this policy and applicable law. We do not authorize them to use your data for their own marketing or to sell it.

Chat integrations (Slack & Microsoft Teams)

You can optionally connect Slack or Microsoft Teams so our assistant can help you build your profile through a chat. These integrations are off until you connect them, and you can disconnect at any time from your settings. When connected:

  • We collect and store your Slack or Teams identity (to link the chat to your UBuildUs account) and a limited, recent history of your conversation with the assistant (so it can keep the conversation coherent).
  • The messages you send to the assistant are processed by our AI provider (Google Gemini, as described in Section 6) so it can converse with you and draft profile content. Content you confirm is saved to your UBuildUs profile — exactly as if you had entered it in the app — and you can edit or remove it at any time.
  • Your messages travel through Slack’s or Microsoft’s systems, which handle them under their own privacy policies. Disconnecting stops the assistant and unlinks your account.

8. Data Connect — Connecting Your Profile to External AI Tools

Data Connect is an optional feature that lets you generate scoped API keys so that external AI tools you choose (for example, ChatGPT, Claude, or your own assistant) can read parts of your profile. It is candidate-only, off until you create a key, and fully under your control.

  • What a key can access: depending on the scope you choose (personal, professional, or both), a key can return your name, email, social links, and — by scope — your location, company/role, personality summary and answers, and up to your 100 most recent journal entries. Journal entries you mark private are never included.
  • You control keys: you name each key, set its scope and an expiration (up to one year), and can revoke it at any time. Keys are subject to rate and monthly usage limits.
  • Important — data leaves our control: when you provide a key to an external tool, the data that tool fetches is handled under that tool’s privacy policy and terms, not ours. We cannot control what an external service does with data it retrieves. Only share a key with tools you trust, and revoke keys you no longer use.

9. How Your Information Is Shared & Made Public

Apart from the sub-processors in Section 7 and the external tools you connect in Section 8, we share your information only as described here:

  • Recruiters on the platform: your professional profile (name, title, skills, experience, education, and any projects or references you have added) is visible to recruiters who use UBuildUs to search for candidates. You control the information on your profile and can update or delete it at any time.
  • Your opt-in public profile: you may turn on a public profile page (at a /p/ link) to share a read-only view of your profile with anyone you send the link to. It is off by default, shows your name, headline, city-level location, AI overview, skills, experience, and education, and never exposes your email, phone, or street address. It is excluded from search-engine indexing, and turning it off makes the page immediately unavailable.
  • Recruiter share links: a recruiter you have accepted a connection with can generate a link to share your profile with their hiring team without a login. These links show your name, title, city-level location, AI overview, and skills; they do not display your email, phone, or street address, and do not include your downloadable resume file (a connected recruiter can still view your resume inside the signed-in app). Share links are excluded from search-engine indexing and expire 24 hours after they are created.
  • Charitable giving (Every.org): to disburse the 25% cause portion of memberships, we send Every.org the selected nonprofit and pooled donation amounts aggregated across contributing members. We do not send Every.org your name, email, or other identifying information; UBuildUs is the donor of record.
  • Payment processing (Stripe): as described in Sections 4.5 and 7, Stripe processes your payments.
  • Legal requirements: when we are required by law, court order, or lawful government request, or to protect the rights, property, or safety of UBuildUs, our users, or the public.
  • Business transfers: if UBuildUs is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.
  • With your consent: in any other circumstance where you have given us explicit permission.

10. No Sale of Your Data & No Advertisers

🔒 We do not sell user data to advertisers. We do not sell, rent, trade, license, share for commercial advertising purposes, or otherwise transfer your personal information to any third party — including any advertiser, advertising network, data broker, or marketing intermediary — for monetary or other valuable consideration. This is a core, binding commitment of UBuildUs, mirrored as a contractual covenant in our EULA.

11. Cookies & Sessions

We use the following types of cookies and browser storage:

  • Session cookies: signed, HTTP-only cookies that maintain your authenticated session. These are required for the Services to function and are deleted when you sign out.
  • OAuth state cookies: short-lived (10-minute) cookies used solely for CSRF protection during third-party sign-in flows.
  • Local storage:your browser’s local storage may be used to cache your profile data locally to reduce loading times. No sensitive information is stored in local storage.

We do not use third-party advertising cookies, tracking pixels, or analytics cookies that follow you across other websites. You can control cookies through your browser settings; disabling session cookies will prevent sign-in.

12. Security & Data Retention

We implement reasonable administrative, technical, and organizational safeguards to protect your personal information, including:

  • Passwords hashed using the scrypt key-derivation function with a random salt — never stored in plain text.
  • Sensitive settings (such as stored API keys) protected at rest; Data Connect keys are stored only as a one-way hash, never in a recoverable form.
  • Session tokens transmitted over HTTPS only, stored in HTTP-only cookies.
  • Database access restricted to application-level credentials with least-privilege principles.
  • Files stored on Cloudinary with access-controlled URLs.

No method of transmission or storage is completely secure. If you believe your account has been compromised, please contact us immediately.

Retention: We retain your personal information for as long as your account is active or as needed to provide the Services. If you delete your account, we delete or anonymize your personal information — including your profile, resume, journal, and uploaded media — within 30 days, except for records we are required to keep for legal, tax, accounting, or dispute-resolution purposes. In particular, billing and donation transaction records (which contain only opaque payment identifiers and amounts) are retained as required for financial record-keeping.

13. Your Rights Under Indiana Law

Under the Indiana Consumer Data Protection Act (ICDPA), Ind. Code § 24-15, Indiana residents have the following rights with respect to their personal data:

Right to Access & Confirm

You may confirm whether we process your personal data and request a copy of the personal data we hold about you.

Right to Correct

You may request that we correct inaccurate personal data we hold about you. Many fields can be updated directly from your profile settings.

Right to Delete

You may request that we delete personal data we hold about you. You may also delete your account at any time from your account settings.

Right to Data Portability

You may request a copy of your personal data in a portable, commonly used, and machine-readable format.

Right to Opt Out of Sale & Targeted Advertising

You have the right to opt out of the sale of your personal data and its use for targeted advertising or profiling in furtherance of significant decisions. As stated throughout this policy, UBuildUs does not sell personal data and does not engage in targeted advertising — this right is therefore satisfied by default.

To exercise any of these rights, please submit a request via our contact page or email us directly (see Section 16). We will respond within 45 days of receiving a verifiable request, as required by the ICDPA. We may extend this period by an additional 45 days when reasonably necessary, with notice. We may need to verify your identity before processing your request.

If you disagree with our response, you may appeal by contacting us. If your appeal is denied, you may contact the Indiana Attorney General’s office to submit a complaint.

14. Children’s Privacy

The Services are not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us immediately and we will delete it promptly. If you are between 16 and 18 years of age, you should only use the Services with the consent of a parent or guardian.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top of this page and, where appropriate, notify you by email or by a notice within the Services before the changes take effect. Your continued use of the Services after the effective date of any update constitutes your acceptance of the revised policy. We encourage you to review this page periodically.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or the handling of your personal information, please contact us:

UBuildUs — a brand of Simple People Holdings LLC-s

Indiana, United States

Contact form: ubuildus.com/contact

We take privacy inquiries seriously and will respond as promptly as possible.