Skip to main content
Protected local Preview · projection-backed public presentation · no public release or indexing authority

Technical review draft · not legal approval

Privacy and data handling

A code-observable description of the protected Preview's current data boundaries, owner controls, and known gaps.

This page describes the bounded private Preview implementation. It is not a legal conclusion, public notice, contract, or authorization to launch, register users, or process real personal data.

Status and admitted use

This is not a privacy notice or a compliance statement. The controller role, legal purposes and bases, retention schedule, international transfers, subprocessors, and statutory-rights process still require qualified review before real-user operation.

  • The current Product boundary is a private, synthetic, non-Production Preview.
  • Public registration and real personal or immigration data remain unauthorized.
  • Noindex is a crawler instruction; it is not privacy, confidentiality, or access control.

What the implementation can hold

An existing invited account can use authentication and private candidate features. Depending on enabled Preview features, the code supports an account email and session, candidate mobility profile, work-right answers and evaluation history, search preferences, and saved-journey records.

The Phase-B2 public presentation is designed without candidate or Founder props. That design does not prove that hosting, security, or infrastructure logs contain no request metadata.

Verified owner controls

Signed-in users currently have separate, owner-scoped controls to:

  • export the mobility profile as JSON;
  • export search preferences as JSON;
  • delete work-right answers and evaluation history;
  • delete the mobility profile; and
  • delete search preferences.

Open the signed-in account controls.

What those controls do not prove

They are not a complete account export or complete erasure workflow. The Product has no self-service deletion of the authentication identity. Deleting a profile or work-right answers explicitly leaves other records such as saved jobs outside that operation.

Production retention, backup erasure, audit/legal-hold treatment, and deletion propagation through every derived record have not been cleared or proven by these pages.

Corrections and other requests

Use the documented data-rights request path for anything outside the self-service controls. The current technical channel is preview-feedback@staff.zone.

This email route creates no automatic deletion, verified request receipt, response deadline, or legal conclusion. Current Preview participants must send only approved synthetic identifiers and never passwords, access codes, passports, or immigration documents.

Technical dependencies

The application code is designed to use Supabase for authentication and private Product data and can be hosted in a protected Vercel Preview. Exact vendor roles, deployed configuration, regions, retention, transfers, and agreements require environment-specific evidence and qualified review; this draft does not establish them.

Technical implementation snapshot reviewed . Qualified legal, privacy, accessibility, security, and operational review remains open.