Hatch
Sign in
← Back

Privacy Policy

Last updated: YYYY-MM-DD — update when finalized

What stays on your device

Hatch is local-first. Your résumé text, job descriptions, tailored variants, notes, and pipeline state all live in your browser's IndexedDB storage. They are never sent to our servers and never stored in our database. We count usage — not content.

When you clear your browser storage or use a different device, that local data is gone. Hatch has no copy of it server-side.

What we store on our servers

We store only what is necessary to run the service:

  • User account: your email address, your subscription plan, and account timestamps (created, last sign-in).
  • Session tokens: short-lived magic-link verification tokens used to authenticate you via email (Resend). These expire after use or after a short window.
  • Handoff tokens: short-lived tokens that allow you to transfer a résumé snapshot to another device. These expire after one use or a set TTL.
  • Waitlist entry: if you joined the waitlist on the landing page, we store your email address, the source attribution (e.g., "landing" or a referral code), and the HTTP Referer header from your browser at submission time. See the Waitlist section below.

We do not store your résumé text, job descriptions, or any content you work with inside the app.

What we meter — usage ledger

To enforce free-tier limits and track service costs, we record usage events in a UsageEvent table. Each event stores:

  • The action type (e.g., "tailor", "analyze", "prep")
  • Token counts (input and output) and estimated cost in USD
  • A counted flag indicating whether the action is quota-relevant
  • The timestamp of the action

Usage events contain no résumé or job description content. We count usage, not content.

AI inference transit

When you run an AI-powered action (tailoring a résumé, analyzing a job, generating interview prep), your input — including résumé text and job descriptions — transits Hatch's servers to reach the AI model (Claude, provided by Anthropic). This transit is necessary for inference to work.

Hatch does not log or persist the content of these AI calls after the response streams back. The content is used to fulfill the request and is not written to any database. Anthropic's data practices for API calls are governed by Anthropic's own privacy policy.

Cookies and authentication

Hatch uses magic-link authentication. When you sign in, we send a one-time link to your email address (via Resend). Clicking the link creates a session stored in a secure, HTTP-only session cookie. No password is stored.

We do not use third-party tracking cookies or advertising cookies. We do not use Google Analytics or similar behavioral tracking.

Waitlist email

If you submitted your email on the landing page to join the waitlist, we store your email address in our Waitlist table. This email is used solely to notify you when paid tiers become available. We will not use it for any other marketing purpose without your consent.

You can request removal from the waitlist by contacting us at the address below.

Data deletion

Local data: clearing your browser's storage (IndexedDB) removes all locally-stored résumé and pipeline data immediately. Hatch has no copy of this data.

Account deletion: you can delete your Hatch account from the Settings page. Account deletion removes your User record, usage events, and any associated server-side data. Waitlist entries are deleted separately — contact us if you wish to be removed from the waitlist.

Contact

For privacy questions or data requests, contact us at: [support@yourdomain.com — replace with monitored address]