Technical review draft · not legal approval
Privacy and data handling
A code-observable description of the protected Preview's current data boundaries, owner controls, and known gaps.
This page describes the bounded private Preview implementation. It is not a legal conclusion, public notice, contract, or authorization to launch, register users, or process real personal data.
Status and admitted use
This is not a privacy notice or a compliance statement. The controller role, legal purposes and bases, retention schedule, international transfers, subprocessors, and statutory-rights process still require qualified review before real-user operation.
- The current Product boundary is a private, synthetic, non-Production Preview.
- Public registration and real personal or immigration data remain unauthorized.
- Noindex is a crawler instruction; it is not privacy, confidentiality, or access control.
What the implementation can hold
An existing invited account can use authentication and private candidate features. Depending on enabled Preview features, the code supports an account email and session, candidate mobility profile, work-right answers and evaluation history, search preferences, and saved-journey records.
The Phase-B2 public presentation is designed without candidate or Founder props. That design does not prove that hosting, security, or infrastructure logs contain no request metadata.
Verified owner controls
Signed-in users currently have separate, owner-scoped controls to:
- export the mobility profile as JSON;
- export search preferences as JSON;
- delete work-right answers and evaluation history;
- delete the mobility profile; and
- delete search preferences.
What those controls do not prove
They are not a complete account export or complete erasure workflow. The Product has no self-service deletion of the authentication identity. Deleting a profile or work-right answers explicitly leaves other records such as saved jobs outside that operation.
Production retention, backup erasure, audit/legal-hold treatment, and deletion propagation through every derived record have not been cleared or proven by these pages.
Corrections and other requests
Use the documented data-rights request path for anything outside the self-service controls. The current technical channel is preview-feedback@staff.zone.
This email route creates no automatic deletion, verified request receipt, response deadline, or legal conclusion. Current Preview participants must send only approved synthetic identifiers and never passwords, access codes, passports, or immigration documents.
Technical dependencies
The application code is designed to use Supabase for authentication and private Product data and can be hosted in a protected Vercel Preview. Exact vendor roles, deployed configuration, regions, retention, transfers, and agreements require environment-specific evidence and qualified review; this draft does not establish them.