Privacy Policy
Last updated: October 2026 • Effective for all GRADNEO users
GRADNEO is engineered to help students prepare for careers safely. We never sell your personal information, resumes, or academic records to third-party data brokers or unaffiliated marketing agencies.
1. Data Controller & Scope
This Privacy Policy describes how GRADNEO ("GRADNEO", "we", "us", or "our") collects, uses, stores, and protects personal data when you use the GRADNEO website, student workspace, and associated services.
2. Categories of Information We Collect
We collect only the categories of data necessary to provide career-readiness diagnostics, resume analysis, interview coaching, and opportunity matching:
Full name, email address, password hash (salted via bcrypt with work factor 12), and email verification status.
College / institution name, university, degree, department, current academic year, graduation year, CGPA / percentage, city, state, country, and career target goals (primary role, compensation preferences, preferred locations).
Technical skills, frameworks, tools, self-assessed proficiencies, project titles, descriptions, GitHub repository URLs, live demo links, and internship records.
Uploaded resume files (PDF, DOCX), extracted text sections, generated resume versions, ATS diagnostic reports, and customized tailoring drafts. Uploaded files are stored in private, access-controlled storage buckets and are never made publicly browsable.
Companies and roles you track in your Kanban Application Tracker, application deadlines, custom candidate notes, and application stages.
Interview booking categories, recorded practice responses, standardized rubric evaluations, STAR-method scores, and coaching recommendations from Interview Lab.
Code deliverables, architecture diagrams, milestone submissions, and evaluator rubric feedback for practical programs.
Issued completion credentials, 10-character verification IDs, completion timestamps, and cryptographic signature digests for public certificate validation.
IP address (for rate limiting and brute-force protection), user-agent string, session version counters, audit timestamps, and password reset tokens (stored exclusively as one-way SHA-256 hashes).
GRADNEO DOES NOT collect or store sensitive payment card details: We never store credit card numbers, debit card numbers, CVV/CVC codes, or UPI PINs on our servers. When payment integration is active, all payments are processed directly by PCI-DSS Level 1 compliant payment gateways (such as Razorpay). GRADNEO stores only transaction reference IDs, plan purchased, and payment status for account entitlement provisioning.
3. How We Use Your Information
Your data is processed strictly for the following purposes:
- Computing your 8-dimensional Career Readiness diagnostic benchmark.
- Analyzing resume structure, ATS readability, and providing actionable suggestions.
- Evaluating profile match percentages against curated job opportunities.
- Conducting practice mock interviews and generating rubric-based feedback.
- Evaluating Experience Hub milestone submissions and issuing verifiable credentials.
- Account security, rate limiting, and fraud prevention.
- Transactional communications: OTP email verification and password reset links.
4. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We disclose information only to vetted service providers under strict data-protection obligations:
- Cloud Infrastructure & Storage: Secure hosting providers and encrypted object storage for private resume files.
- Transactional Email Providers: Domain-verified services (e.g. Resend, SendGrid) to deliver verification codes and security notices.
- Payment Gateways: PCI-DSS compliant processors when online billing is active.
- AI Intelligence Providers: Stateless API requests to evaluate resume suggestions. Candidate inputs are not used to train public foundational models.
- Legal Obligations: When required by applicable law, court order, or governmental authorities.
5. Security & Storage Controls
We implement industry-standard administrative, physical, and technical controls:
- HTTPS / TLS encryption in transit for all web traffic and API endpoints.
- HTTP-only, Secure, SameSite session cookies preventing client-side script theft.
- Passwords hashed with bcrypt (work factor 12); OTPs and reset tokens stored only as one-way SHA-256 hashes.
- Private resume storage with signed, time-limited download URLs enforcing student ownership checks.
- Distributed rate limiting preventing credential stuffing and brute-force attacks.
6. Data Retention & Student Rights
You retain ownership of your data. You have the right to:
- Access, review, or update your career profile records at any time.
- Download your resume versions and earned certificate verification summaries.
- Request permanent account deletion and erasure of your uploaded documents by emailing support@gradneo.com.
Upon verified account deletion, personal profile and resume records are permanently purged from active databases within 30 days, except where legal, accounting, or fraud-prevention obligations require retention.
7. Public Credential Verification Privacy
GRADNEO certificates issued through the Experience Hub are publicly verifiable via an exact 10-character Credential ID at /verify/[credentialId]. To protect student privacy, the public verification page displays only minimal factual completion data (Recipient Name, Program Title, Issue Date, Credential Status, and Evaluated Competencies). Phone numbers, email addresses, and detailed internal scores are never publicly exposed.
8. Grievance Officer & Contact Information
In accordance with the Information Technology Act, 2000 and applicable digital personal data protection rules, if you have any questions, feedback, or grievances regarding our privacy practices, please contact our Data Protection Officer:
Grievance Desk — GRADNEO
Email: legal@gradneo.com
Support Email: support@gradneo.com
Location: Bengaluru, Karnataka, India