1. Our approach
BuildCareer processes career information that may be important and personal.
We use reasonable technical and organizational safeguards designed to reduce the risk of unauthorized access, loss, misuse, or disclosure.
No system can guarantee absolute security. We continually improve safeguards as the product develops.
2. Authentication
BuildCareer uses managed authentication for:
- account registration;
- email verification;
- login sessions;
- password resets;
- session management.
Passwords are handled by the authentication provider and are not visible to BuildCareer administrators.
Users should:
- use a strong, unique password;
- protect access to their email account;
- log out of shared devices;
- report suspected unauthorized access promptly.
3. Access controls
User data is protected through application-level authorization and database access controls.
Administrative functionality requires a separately authorized admin account and server-side permission checks.
Privileged server credentials are not intended to be exposed to browser code.
Access to operational data should be limited to people and systems that need it to provide, secure, or support the service.
4. Encryption
BuildCareer uses HTTPS to encrypt information transmitted between supported browsers and the service.
Infrastructure and service providers may use encryption at rest and other safeguards according to their platforms and configurations.
5. Resume and document storage
Resume and career-document files are stored using managed storage infrastructure with access controls.
Users should avoid uploading unnecessary sensitive information such as:
- government identification numbers;
- financial-account credentials;
- medical records;
- passwords;
- confidential third-party information not required for career use.
BuildCareer may extract text and structured information from uploaded documents to provide requested features.
6. AI processing
Relevant resume, profile, job-description, or application information may be transmitted to the configured AI provider when a user requests an AI-assisted feature.
BuildCareer is designed not to store prompts or career-document content in admin AI-usage analytics.
AI usage events may record operational information such as:
- feature name;
- model;
- token counts;
- latency;
- success or failure;
- estimated cost.
Users remain responsible for reviewing AI-generated content.
7. Payment security
Payment details are collected and processed by the payment provider through its checkout experience.
BuildCareer does not receive or store complete card numbers, CVVs, online-banking passwords, or UPI PINs.
BuildCareer may store limited subscription and transaction identifiers required to manage access and billing status.
8. Monitoring and diagnostics
We may record limited diagnostic information to:
- detect errors;
- investigate failures;
- prevent abuse;
- improve reliability;
- monitor AI usage and service health.
We aim to sanitize diagnostic records and avoid storing passwords, authentication tokens, payment secrets, complete request bodies, resume text, job descriptions, or generated document content in admin error logs.
9. Data ownership and control
Users retain ownership of the career content they upload or create.
BuildCareer processes that content to provide requested features, maintain the service, and meet legal or security obligations.
Users may request account deletion or another privacy action as described in the Privacy Policy.
10. Infrastructure and service providers
BuildCareer relies on reputable third-party providers for services such as hosting, database, authentication, storage, artificial intelligence, email, payments, analytics, and feedback.
Each provider maintains its own security program, contractual terms, and operational responsibilities.
11. Security limitations
Security depends partly on user behaviour, third-party providers, software dependencies, and systems outside BuildCareer’s control.
We cannot guarantee that:
- every attempted attack will be prevented;
- third-party services will always be available;
- transmitted information is immune from interception;
- deleted data disappears instantly from every backup;
- vulnerabilities will never exist.
12. Responsible disclosure
If you believe you have found a security vulnerability, email: support@buildcareer.pro
Use the subject: Security report — BuildCareer.PRO
Include:
- a clear description;
- affected page or feature;
- steps to reproduce;
- potential impact;
- supporting screenshots or logs with secrets removed.
Do not:
- access another person’s data;
- modify or delete data;
- disrupt the service;
- run denial-of-service tests;
- use automated scanning that creates unreasonable load;
- publicly disclose the issue before we have had a reasonable opportunity to investigate.
We do not currently operate a formal bug-bounty program and cannot promise payment or reward.
13. Incident response
If we identify a security incident affecting personal information, we will investigate and take reasonable steps to contain and remediate it.
Where required by applicable law, we will provide notifications to affected users or authorities.
14. Contact
Security questions and responsible-disclosure reports may be sent to: support@buildcareer.pro
Questions?
For questions about these policies, contact support@buildcareer.pro.
