Ntern
Data Retention Policy
Ntern keeps personal and device data only while it supports a requested feature, a short operational need, or a legal obligation.
| Information | Normal retention | What ends retention |
|---|---|---|
| Unverified signup | 7 days after the last signup attempt | Automatic deletion if email verification is not completed |
| Verified account, consent record, profile, saved applications, and notes | Until account deletion | In-app deletion or a verified support request |
| Uploaded résumé and documents | Until individual document or account deletion | Removed from active Cloudflare R2 storage as part of the deletion request |
| Resume Tuner Master Bank, saved bases, pasted job descriptions, review drafts, embeddings, and generated PDF, TeX, and preview artifacts | Until account deletion | Removed with account data; derived R2 and Vectorize caches are deleted with canonical records and account export includes active private records |
| Authentication session | Up to 30 days | Sign-out, account deletion, or automatic expiry |
| Application-assistance access credential | 1 hour or less | Use, cancellation, completion, or expiry |
| Application-assistance metadata and masked field plan | 30 days | Automatic expiry or earlier account deletion |
| Gmail OAuth credential, account address, incremental history cursor, and sync state | While Gmail remains connected | Gmail disconnect or account deletion; local deletion proceeds even if remote revocation fails |
| Apply-triggered Gmail role check | Through the final check 24 hours after the Apply click, plus at most 1 hour for cleanup | Confirmation detection, automatic expiry, Gmail disconnect, or account deletion |
| Pending Gmail confirmation headers and derived candidate evidence (message text is not retained) | 30 days | Acceptance, dismissal, automatic expiry, Gmail disconnect, or account deletion |
| Keyed Gmail message deduplication value | 180 days | Automatic expiry, Gmail disconnect, or account deletion |
| Single-use Gmail OAuth state and PKCE verifier | 10 minutes or less | Callback use or automatic expiry |
| Anonymous installation, alert settings, and push token | Until 12 months without installation activity | Automatic inactivity cleanup; invalid push tokens are disabled earlier |
| Notification delivery receipt | 90 days after its last update | Automatic expiry or deletion of its inactive installation |
| Hashed authentication and installation rate-limit keys | Up to 7 days after the applicable window or block ends | Automatic cleanup |
| Employer organization, membership, source, proposal, submission, report, and publishing records | While active and for 1 year after organization closure or revocation | Private member, token, and review-note data is deleted or redacted after the retention period; redacted publication and trust evidence may remain for catalog provenance |
| Employer verification challenge token | Until its challenge expires or is consumed | Expired secrets are deleted immediately; only the audit outcome remains |
| Employer invitation | Invitation lifetime plus a 7-day operational grace period | Automatic deletion after the grace period or earlier account-access cleanup |
| Cloudflare Worker request, error, and performance logs | No more than 7 days; the active plan may retain them for less | Provider expiry |
| Private support correspondence | While a request is active and up to 12 months afterward | Routine deletion unless longer retention is reasonably required for security, disputes, or law |
| Public GitHub issues and contributions | Part of the public project history | Removal or redaction under GitHub and project moderation processes |
| Public catalog records and source-review evidence | Retained as needed for attribution, corrections, reliability, and audit history | Not normally personal user data; unsafe public content is hidden while reviewed |
Deletion and recovery history
Deletion removes information from the active service. Cloudflare D1 maintains automatic point-in-time recovery history for up to 30 days depending on the account plan. Deleted database records may remain in that protected recovery history until it ages out and are not used for ordinary product operation. Ntern does not restore deleted personal data except when necessary to recover from a service-wide incident, and any restored deletion must be re-applied.
Disconnecting Gmail deletes the active OAuth credential, connection and sync state, Apply-triggered role checks, processed-message deduplication values, and pending detections. Existing application status and applied timestamp remain while Gmail-specific provenance is removed. Account deletion attempts Google grant revocation and applies the same local cleanup.
Legal and safety exceptions
Specific information may be kept longer when reasonably necessary to comply with law, resolve a dispute, investigate abuse, protect users, or demonstrate that a deletion or consent request was handled. Any exception is limited to the information and duration needed for that purpose.
Questions
Ntern is operated by JD Krasnick. Email [email protected] for a retention question or verified deletion request.