Privacy Policy
Draft for legal review. This policy was written by the Pathcast team in plain language. It has not yet been reviewed by a lawyer. It must be reviewed before launch, and it is not legal advice.
Effective date: 23 September 2026 Who we are: Agori Labs Inc., a Delaware corporation ("Pathcast", "we", "us") Privacy contact: [email protected]
The short version
You upload a résumé. We read it to work out what you actually do at work. We use that, plus a few answers from you, to write a report about what AI means for your job. That is the whole reason we collect anything.
Three promises, up front:
- We never sell your data. Not to anyone, not in aggregate, not "anonymized".
- We never share your data with recruiters or employers. Your current employer, your next employer, a staffing agency — none of them. Nothing you do on Pathcast reaches them.
- We never scrape or connect to LinkedIn. We do not ask for your LinkedIn URL. We do not use LinkedIn's API. If you give us a LinkedIn PDF you exported yourself, we treat it exactly like a résumé you typed.
The rest of this page explains the details.
What we collect, and why
We collect only what we need to make your report and run the service. Here is the full list.
1. Your résumé file
What: The PDF or photo you upload, or the PDF LinkedIn lets you export about yourself.
Why: It is the raw material for your report. We read it to find the tasks that make up your week.
Where it goes: The file is sent to the model provider that generates your report (see "Who we share with" below) to extract text and tasks. Once your report is generated, we delete the file (see "Résumé retention" below). It is not shown to any person at Pathcast unless you ask us for help with a parsing problem and agree to that.
2. Your extracted profile
What: What we pulled out of your résumé — job title, employer type, years of experience, and a list of the roughly fifteen things you do. We show you this list and you can correct it. Your corrections become part of the profile.
Why: This is what the report is actually built from. We score tasks, not titles, so this list is the core of the product.
3. Your situation and clarifying answers
What: Which of four situations you are in (stable job, think I'm losing it, looking now, still in school), and your answers to five short questions. One of those questions is what part of the job do you quietly dread?
Why: These shape which moves we recommend and how we rank them. We know these answers can be personal. They are treated with the same care as your résumé.
4. Your scenario settings
What: The three dials you set: how far agents get in three years, how fast your employer adopts, and pressure on entry-level hiring.
Why: Your report is built for the future you think is coming. We store the dials so you can come back and change them.
5. Your email address
What: The email you sign up with.
Why: To create your account, send you your report, send receipts, and — only if you are on the monthly plan — send you re-scoring updates and alerts. We do not send marketing email you did not ask for.
6. Payment information
What: If you buy a report or subscribe, your card details go to Stripe, our payment processor. We never see or store your full card number. We store what Stripe sends back: a customer ID, the plan you are on, and whether the payment succeeded.
Why: To charge you for what you bought and to know which parts of your report to unlock.
7. Usage analytics
What: We use PostHog to understand how the site is used: which pages load, where people drop off, which buttons get pressed, rough device and browser type. This is tied to your account once you sign in.
Why: So we can see where the product is confusing and fix it. We do not use analytics to build advertising profiles, and we do not share it with advertisers.
What analytics does not include: Your résumé, your extracted tasks, and your answers to the five questions are not sent to PostHog.
8. Technical logs
What: Server logs with IP address, timestamps, and error messages. Standard for any website.
Why: Security and debugging. Logs are kept for 30 days and then deleted.
What we do not collect
- We do not ask for your LinkedIn URL, password, or connection.
- We do not collect your contacts, calendar, or anything from other apps.
- We do not collect your employer's name from anywhere but your own résumé.
- We do not track you across other websites.
- We do not use third-party advertising cookies.
Résumé retention
We delete the original résumé file once your report is generated.
Once your tasks are extracted, you have confirmed them, and your report has been made, the original PDF or photo is deleted. We keep only the extracted profile — the task list, corrected by you — with your account. That is enough to re-run your report, change your scenario settings, and get quarterly re-scoring without uploading again.
If you later want a report built from a new résumé, or you buy the résumé-rewrite add-on, you upload the file again. We delete that file too, once the work is done.
What we always do:
- The résumé file is never used for anything except generating your report and, if you choose it, the add-ons you buy.
- Your résumé and answers are not used to train any AI model. Not ours, and not our model provider's. See "Does my data train a model?" below.
- Deleting your account deletes the extracted profile and everything built from it.
How long we keep everything else
| Data | How long |
|---|---|
| Original résumé file | Deleted once your report is generated. See "Résumé retention" above |
| Extracted profile and corrections | Until you delete your account. On the free plan, we also delete inactive accounts 12 months after your last sign-in |
| Situation and clarifying answers | Same as extracted profile |
| Scenario settings | Same as extracted profile |
| Your report | Same as extracted profile |
| Email address | Until you delete your account |
| Payment records (Stripe) | As long as tax and accounting law requires, typically 7 years. This is a legal requirement we cannot shorten. It covers the transaction record, not your résumé. |
| Analytics events (PostHog) | 12 months |
| Server logs | 30 days |
How to delete your data
You can delete your account at any time from your account settings. When you do:
- Your résumé file (if we still have it), your extracted profile, your answers, your settings, and your reports are deleted from our live systems within 7 days.
- Backups that include your data are overwritten on their normal cycle, within 30 days.
- Your email is removed from our systems. If you are on the monthly plan, your subscription is cancelled at the same time.
- Payment records stay with Stripe for as long as the law requires. They do not include your résumé.
If you would rather email us, write to [email protected] from the address on your account and we will do it by hand. We may ask you to confirm it is really you.
There is normally no résumé file on your account to delete separately, because we delete it as soon as your report is generated. If you uploaded a file and stopped before the report was made, deleting your account removes it.
Does my data train a model?
No.
We use a model provider to read your résumé and to help draft parts of your report. Our contract with that provider bars them from training on the data we send. We do not train our own models on your résumé, your answers, or your report.
The 50 role analyses that power Pathcast were researched and written by hand before you arrived. Your data does not feed back into them.
Who we share with
We share your data only with companies that help us run the service, and only the parts they need. We call these sub-processors. We do not have partnerships, data brokers, or advertising relationships.
| Category | What they receive | Why |
|---|---|---|
| Payment processing (Stripe) | Your email, card details (entered directly with Stripe), and what you bought | To take payment |
| Product analytics (PostHog) | Page views, clicks, device type, your account ID | To see how the product is used |
| Email delivery (Cloudflare Email Routing) | Your email address and the content of emails we send you | To send reports, receipts, and alerts |
| Model inference (our model provider) | Your résumé text, extracted tasks, and answers, at the moment your report is generated. They are contractually barred from training on it | To extract tasks and draft your report |
| Hosting and storage (Cloudflare) | Everything, encrypted, because that is where the service runs | To run the site |
Each of these has its own privacy policy and is bound by a contract with us. We will keep this list current. If we add a sub-processor that handles résumé data, we will update this page and note the date at the bottom.
We will also share data if the law requires it — a valid court order, for example. If that ever happens, we will tell you unless we are legally prohibited from doing so.
If Agori Labs is ever acquired or shut down, your data could transfer to the new owner. They would be bound by this policy. We would tell you by email before that happened, and you would have the chance to delete your account first.
Security
Your data is encrypted in transit (HTTPS) and at rest. Access inside the company is limited to the two people who build Pathcast, and only when needed to fix a problem. We are a small company and we do not claim to have a security certification. We do the ordinary, careful things: strong access controls, no shared passwords, prompt patching, and as little data kept as we can manage.
If we ever have a data breach that affects you, we will tell you by email as fast as we can and no later than the law requires.
Your rights
Wherever you live, you can ask us to show you, correct, or delete your data, and we will do it. The sections below describe what the law specifically guarantees in some places. Writing to [email protected] is enough to exercise any of them.
If you are in the European Union, European Economic Area, or United Kingdom (GDPR)
You have the right to:
- Access — ask what data we hold about you and get a copy.
- Correction — ask us to fix anything wrong. You can also correct your extracted profile yourself, any time.
- Erasure — ask us to delete your data. Account deletion does this.
- Restriction — ask us to stop using your data while a dispute is resolved.
- Portability — get your data in a common file format (we can give you JSON).
- Objection — object to processing based on our legitimate interests, such as analytics.
- Withdraw consent — for anything we do based on your consent, such as analytics cookies, you can withdraw it any time.
- Complain — to your local data-protection authority, if you think we have got something wrong.
Our legal basis for processing: Performing our contract with you (making your report); your consent (analytics cookies, if you are in the EU or UK); our legitimate interest in running and improving a working service (analytics, security logs); and legal obligation (payment records).
Data transfers: Pathcast runs in the United States. If you are in the EU, EEA, or UK, your data is transferred to the US. We rely on Standard Contractual Clauses with each sub-processor that handles your data.
EU/UK representative: Pathcast is offered in the United States. We have not appointed a representative in the EU or UK.
If you are in California (CCPA / CPRA)
You have the right to:
- Know what personal information we collect, use, and share. This page is that disclosure.
- Delete your personal information. Account deletion does this.
- Correct inaccurate personal information.
- Opt out of sale or sharing. We do not sell your personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. We have not sold personal information in the past twelve months.
- Limit use of sensitive personal information. We use what you tell us only to make your report. We do not use it for anything else.
- Not be discriminated against for using any of these rights. We will not charge you more, give you a worse report, or treat you differently.
You can use an authorized agent to make a request on your behalf. We will ask for proof that you gave them permission.
Other US states
Several other states (including Virginia, Colorado, Connecticut, and others) have similar laws. If you live in one, the same rights apply, and the same email address works.
Children
Pathcast is for people in or entering the workforce. It is not intended for anyone under 16, and we do not knowingly collect data from anyone under 16. If you think a child has given us data, email us and we will delete it.
Cookies
We use a small number of cookies:
- Essential — to keep you signed in. You cannot turn these off and still use your account.
- Analytics — PostHog sets a cookie so it can recognise your browser when it comes back, and tell a returning visitor from a new one. If you are in the EU or UK, we ask for your consent before analytics loads. If you say no, no analytics cookie is set.
We do not use advertising cookies.
Changes to this policy
We will change this policy when the product changes or the law does. When we do:
- We will update the effective date at the top.
- We will keep a short change log at the bottom of this page.
- If a change affects how we handle your résumé or your answers, or adds a sub-processor that receives them, we will email you before it takes effect.
We will not make a change that reverses the three promises at the top of this page — no selling, no recruiters or employers, no LinkedIn — without giving you the chance to delete your account first.
Contact
Questions, requests, or complaints about privacy:
Email: [email protected] Post: We do not publish a postal address. Every privacy request is handled by email, so please write to the address above. Data Protection Officer: We are not required to appoint a Data Protection Officer and have not appointed one. Privacy questions go to the email above.
We aim to reply within 5 business days and to complete requests within 30 days.
Change log
- 23 September 2026 — First version.