Purpose-specific choices
Core storage, AI extraction, fit analysis, document generation, optional analytics, marketing, and future integrations are designed as separate, versioned choices with optional purposes off by default.
Privacy approach
The product plan limits MeritLog to a direct-to-consumer Career Operating System. Employers and recruiters have no product route into Career Memory, and private user records are excluded from public Market Observer aggregates.
The policies below are design requirements for later milestones. This preview does not collect accounts, career records, or optional analytics.
Core storage, AI extraction, fit analysis, document generation, optional analytics, marketing, and future integrations are designed as separate, versioned choices with optional purposes off by default.
User-provided jobs, résumés, Career Memory, search history, applications, outcomes, exact compensation, and pasted text are never planned inputs to cross-user public aggregates.
The complete platform requires export and account-deletion workflows with processor receipts, failure recovery, and honest backup-expiration language before those capabilities can be claimed.
Choice and lifecycle
Explain what data is needed, why, which provider category is involved, and what happens if the optional purpose is declined.
Record a versioned receipt only after an explicit action; product access may not depend on optional analytics or marketing consent.
Use the minimum necessary data for the selected purpose and keep private content out of logs, analytics, fixtures, and error reports.
Stop future purpose-bound work after revocation and provide the documented deterministic or manual fallback where applicable.
Support correction, export, retention controls, and deletion status without claiming that processors or immutable backups disappear instantly.
Protected product preview
Binding legal notices and jurisdiction-specific review remain founder-owned launch dependencies.