Privacy Policy
Last updated: July 12, 2026
This policy describes how the operator of ThreeArrow.ai ("ThreeArrow," "we," "us," or "our") handles information when you use the service. Contact privacy@threearrow.ai with privacy questions or requests.
1. Information we process
- Account information: your name, email address, account role, and a one-way password hash when you use password authentication. For Google sign-in, a Google access token is exchanged for a ThreeArrow session and is not stored as a reusable Google credential by the application.
- Career information: resumes, contact details contained in a resume, work history, education, skills, projects, certifications, profile edits, and saved profile versions.
- Job and application information: job URLs and descriptions you submit, tailored content, form answers you confirm, application status, notes, submission results, and confirmation identifiers returned by supported application systems.
- Billing information: plan status and Stripe customer or subscription identifiers. Payment-card details are handled by Stripe and are not stored by ThreeArrow.
- Technical analytics: page path, referrer origin and path with query parameters removed, bot classification, timestamp, and a keyed hash of the requesting IP address. We do not store the raw IP address in new page-view records.
2. How we use information
- Provide authentication, profile storage, resume parsing, tailoring, and PDF generation.
- Fill and submit supported employer forms in an isolated browser at your request.
- Pause for required answers that cannot be inferred safely and reuse answers you confirm.
- Provide application tracking, interview preparation, career tools, and support.
- Enforce plan limits, operate billing, secure the service, and diagnose failures.
- Measure aggregate product usage and service reliability.
3. AI processing
Resume, profile, job-description, and career-tool inputs may be sent to Anthropic Claude. The deployment may connect directly to Anthropic or use Claude through Microsoft Azure AI Foundry. AI output can be incomplete or inaccurate, so review every generated change before using or submitting it.
4. Service providers
Depending on deployment and the features you use, information may be processed by:
- Supabase for PostgreSQL and optional private resume storage. Privacy Policy
- Cloudflare R2 as an optional private resume-storage provider. Privacy Policy
- Stripe for paid-plan checkout and billing management. Privacy Policy
- PostHog for optional product analytics when a PostHog project key is configured. ThreeArrow configures the browser client without persistent analytics storage, autocapture, or session recording. Privacy Policy
We do not sell personal information or use resume content for advertising.
5. Storage and security
- Resume files may be stored locally, in private Supabase Storage, or in private R2 storage.
- Private cloud files are accessed through short-lived signed URLs.
- Passwords are stored as bcrypt hashes, not plaintext.
- Saved third-party login passwords, when explicitly provided, are encrypted before storage.
- Administrative routes require both an authenticated session and an admin authorization check.
No system can guarantee absolute security. Do not upload information that is unnecessary for your job search.
6. Browser storage and cookies
The web application stores your ThreeArrow session in browser local storage and mirrors it to a SameSite=Lax cookie so protected web routes can recognize the session. The cookie is marked Secure on HTTPS connections. Because this session is created by browser JavaScript, it is not an HttpOnly cookie. Signing out removes the local session and cookie.
ThreeArrow's own page-view analytics does not require a tracking cookie. When PostHog is configured, its browser persistence is set to memory for the current page session.
7. Retention
- Account, profile, resume, and application data is retained while the account is active.
- New page-view records are automatically removed after approximately 12 months.
- Queue records and generated signed URLs expire or are removed according to service settings.
To request account deletion or a data export, email privacy@threearrow.ai. We may need to verify the request before acting on it.
8. Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability. You can edit profile information inside the product and can contact us for requests not currently available as self-service controls.
9. Changes
We may update this policy as the product or its service providers change. The date above shows the latest revision.