Privacy Policy
Effective October 2, 2026
Information we process
Mansap processes your signed-in account identifier and email, contact details, professional profile, uploaded resumes, vacancy text, generated documents, interview-practice answers and feedback, support reports, and essential security and product events.
An optional password is stored as a salted cryptographic hash, never as readable text. Reset tokens are stored as hashes. Passwords are used only for authentication and are not sent to AI providers.
How information is used
We use this information to extract and organize career facts, generate and edit resumes and cover letters, calculate vacancy match, provide AI interview coaching and exports, protect the service, diagnose failures, and understand the core product journey.
AI processing and your choice
By accepting these Terms and requesting an AI feature, you authorize Mansap to send OpenAI the profile and resume content, vacancy text, chat messages, interview answers and instructions needed to perform that request. OpenAI processes this information outside Kazakhstan. You can view, edit manually and download saved data without requesting new AI processing. Do not provide other people’s personal data unless you are entitled to do so. Mansap requests that API responses are not stored (store: false); this does not eliminate OpenAI’s separate security and abuse-monitoring retention. See the Privacy Policy for providers and retention.
Storage and access
The current service uses Cloudflare D1 and R2 for account data and files, OpenAI for requested AI processing, Resend for sign-in email, and Google Workspace for support email. Storage and processing may take place outside Kazakhstan. Kazakhstan-based storage has not yet been implemented.
Retention and deletion
Account content and the record of the accepted policy version and time remain while your account exists. Email codes are valid for 5 minutes and password-reset links for 15 minutes; expired code, reset-link and session records are cleaned up within 24 hours. Sessions last 7 days and may be renewed. Error and security records are kept for 30 days; product events and detailed per-user AI usage for 90 days. Anonymous aggregate project costs may remain longer. Support reports are kept while open, then for 180 days after closure. Verified temporary recovery copies have a 7-day retention period; daily backup snapshots have a 30-day retention period. Provider-side logs follow the providers’ own retention rules.
Delete account and data in Settings removes your account-linked profile, uploaded files, generated documents, interviews, history, support reports, usage records and product events from the working service. Older backup snapshots expire separately within 30 days. A minimal deletion receipt containing account identifiers and the request time is retained until older recoverable copies are gone, plus 7 days, so restoration does not recreate a deleted account. It contains no resume text or email address.
Service limits and security
Mansap validates supported file types and sizes, limits repeated uploads and AI operations, and may suspend abusive activity. No internet service can guarantee absolute security.
Contact
Privacy and data-deletion questions can be sent to support@mansap.ai.