Ntern

Data Retention Policy

Version 2026-08-26 · Effective August 26, 2026

Ntern keeps personal and device data only while it supports a requested feature, a short operational need, or a legal obligation.

InformationNormal retentionWhat ends retention
Unverified signup7 days after the last signup attemptAutomatic deletion if email verification is not completed
Verified account, consent record, profile, saved applications, and notesUntil account deletionIn-app deletion or a verified support request
Uploaded résumé and documentsUntil individual document or account deletionRemoved from active Cloudflare R2 storage as part of the deletion request
Resume Tuner Master Bank, saved bases, pasted job descriptions, review drafts, embeddings, and generated PDF, TeX, and preview artifactsUntil account deletionRemoved with account data; derived R2 and Vectorize caches are deleted with canonical records and account export includes active private records
Authentication sessionUp to 30 daysSign-out, account deletion, or automatic expiry
Application-assistance access credential1 hour or lessUse, cancellation, completion, or expiry
Application-assistance metadata and masked field plan30 daysAutomatic expiry or earlier account deletion
Gmail OAuth credential, account address, incremental history cursor, and sync stateWhile Gmail remains connectedGmail disconnect or account deletion; local deletion proceeds even if remote revocation fails
Apply-triggered Gmail role checkThrough the final check 24 hours after the Apply click, plus at most 1 hour for cleanupConfirmation detection, automatic expiry, Gmail disconnect, or account deletion
Pending Gmail confirmation headers and derived candidate evidence (message text is not retained)30 daysAcceptance, dismissal, automatic expiry, Gmail disconnect, or account deletion
Keyed Gmail message deduplication value180 daysAutomatic expiry, Gmail disconnect, or account deletion
Single-use Gmail OAuth state and PKCE verifier10 minutes or lessCallback use or automatic expiry
Anonymous installation, alert settings, and push tokenUntil 12 months without installation activityAutomatic inactivity cleanup; invalid push tokens are disabled earlier
Notification delivery receipt90 days after its last updateAutomatic expiry or deletion of its inactive installation
Hashed authentication and installation rate-limit keysUp to 7 days after the applicable window or block endsAutomatic cleanup
Employer organization, membership, source, proposal, submission, report, and publishing recordsWhile active and for 1 year after organization closure or revocationPrivate member, token, and review-note data is deleted or redacted after the retention period; redacted publication and trust evidence may remain for catalog provenance
Employer verification challenge tokenUntil its challenge expires or is consumedExpired secrets are deleted immediately; only the audit outcome remains
Employer invitationInvitation lifetime plus a 7-day operational grace periodAutomatic deletion after the grace period or earlier account-access cleanup
Cloudflare Worker request, error, and performance logsNo more than 7 days; the active plan may retain them for lessProvider expiry
Private support correspondenceWhile a request is active and up to 12 months afterwardRoutine deletion unless longer retention is reasonably required for security, disputes, or law
Public GitHub issues and contributionsPart of the public project historyRemoval or redaction under GitHub and project moderation processes
Public catalog records and source-review evidenceRetained as needed for attribution, corrections, reliability, and audit historyNot normally personal user data; unsafe public content is hidden while reviewed

Deletion and recovery history

Deletion removes information from the active service. Cloudflare D1 maintains automatic point-in-time recovery history for up to 30 days depending on the account plan. Deleted database records may remain in that protected recovery history until it ages out and are not used for ordinary product operation. Ntern does not restore deleted personal data except when necessary to recover from a service-wide incident, and any restored deletion must be re-applied.

Disconnecting Gmail deletes the active OAuth credential, connection and sync state, Apply-triggered role checks, processed-message deduplication values, and pending detections. Existing application status and applied timestamp remain while Gmail-specific provenance is removed. Account deletion attempts Google grant revocation and applies the same local cleanup.

Legal and safety exceptions

Specific information may be kept longer when reasonably necessary to comply with law, resolve a dispute, investigate abuse, protect users, or demonstrate that a deletion or consent request was handled. Any exception is limited to the information and duration needed for that purpose.

Questions

Ntern is operated by JD Krasnick. Email [email protected] for a retention question or verified deletion request.