Privacy Policy

Last updated: August 21, 2026

1) Information we collect#

Depending on how you use BorealPath, we may collect and store the following categories of information:

  • Account and authentication data, such as your email address, Google account identifier, and profile image if provided via Google Sign-In.
  • Diagnostic and report data, such as your responses, role context, saved runs, generated summaries, and result history.
  • Uploaded documents, such as a resume or CV you upload or paste, and the role, employer, date, and scope information extracted from it. Resumes submitted without an account are processed to generate your result and are not retained after your session ends. If you create an account, the extracted fields and your result are stored with your account; the original file is retained only where you have chosen to save it.
  • Session and continuity data, such as application session identifiers, browser-level identifiers used for continuity, and account-linking events.
  • Technical and security data, such as timestamps, approximate IP-derived security signals, device or browser signals, hashed fraud-prevention data, and operational logs.
  • Consent records, such as the policy or consent version presented, when consent was captured, and the context in which it was recorded.
  • Messages you send us, such as your name, email address, the reason you’re writing, and the content of your message, submitted through the contact form. We use these to reply to you. We do not store form submissions in our systems — they are delivered to our inbox and retained there.

2) How we collect information#

We collect information directly from you when you sign in, use the diagnostic experience, save results, or contact us. We also collect limited technical information automatically through the website and app to operate the Service, maintain session continuity, and protect against misuse.

3) How we use information#

  • To authenticate you and maintain your account session.
  • To generate diagnostic outputs, saved results, and report continuity.
  • To associate diagnostic history with your account across sessions or devices.
  • To send service-related communications, such as account or access notices.
  • To detect abuse, investigate issues, and maintain service reliability and security.
  • To improve the Service using internal analytics, debugging, and operational telemetry.

4) Automated and model-assisted processing#

Parts of the Service use automated processing, including third-party language models, to read uploaded documents, extract structured fields such as role, dates, and scope, infer contextual attributes such as operating model or industry cycle, and generate written findings and summaries.

Scoring itself is rule-based: the same answers produce the same scores. The reading, inference, and written-narrative layers are model-assisted and may be incomplete or incorrect. You review and confirm extracted fields before they are scored.

Outputs are informational. They are not decisions made about you by BorealPath, and no employment, credit, or eligibility determination is made using them.

5) Google Sign-In#

BorealPath currently uses Google Sign-In for account authentication. If you continue with Google, Google provides BorealPath with basic identity information needed to authenticate you. BorealPath then creates and manages its own application session. BorealPath does not rely on Google to store your diagnostic history or result records.

6) Cookies and similar technologies#

BorealPath uses cookies and similar mechanisms to keep you signed in, support cross-page or cross-subdomain continuity, remember session state, and support security and reliability. Disabling cookies may limit parts of the Service.

7) Sharing#

We do not sell personal information. We may share information with service providers that help us operate BorealPath, such as hosting, infrastructure, authentication, analytics, logging, and security providers, subject to appropriate contractual or operational controls. We may also disclose information if required by law or to protect the rights, safety, or integrity of BorealPath, our users, or others.

Some service providers, including hosting, model, and analytics providers, may process information outside Canada, including in the United States. Information processed in another country may be accessible to that country’s authorities under its laws.

Our contact form uses Cloudflare Turnstile to distinguish people from automated submissions. Cloudflare receives technical signals from your browser for that check. It is not used to track you across sites.

8) Retention#

We retain information for as long as reasonably necessary to provide the Service, preserve your account and result continuity, maintain security, resolve disputes, enforce our terms, and meet legal or operational requirements. Some information may remain in backups, logs, or archived systems for a limited period after deletion or update requests.

Diagnostic runs completed without an account are retained only for the duration of the session and are not linked to an identity. Uploaded resume files, where retained, are deleted on account deletion.

9) Your choices and requests#

Where applicable, you may request access to, correction of, or deletion of your personal information. You may also request deletion of your BorealPath account or saved results, subject to legal, security, backup, and operational retention needs.

10) Security#

We use reasonable administrative, technical, and organizational measures designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11) Children#

BorealPath is intended for adults and professional users. The Service is not directed to children.

12) Changes to this policy#

We may update this Privacy Policy from time to time. When we do, we will post the revised version on this page and update the effective date.

13) Contact#

Privacy requests: use the contact form and select “A request about my data.”