This page describes the controls Upplio operates today. It's app-owner content, not an independent audit. If you need our SOC 2 report or a DPA, email customerservice@upplioai.com.
Resumes, cover letters, STAR stories, interview transcripts, support messages, and feedback are encrypted before they hit the database, on top of managed disk-level encryption.
Every data table is protected by row-level policies — users can only access their own rows, and admin reads of user data are audit-logged.
Email + Google sign-in via Supabase Auth. Sessions are short-lived JWTs with refresh rotation.
Inactive free accounts are deleted after 12 months; sign-in logs are stripped after 30 days; support and feedback data after 24 months. Full schedule on the Privacy page.
We never sell your data, and our AI providers are contractually prohibited from training foundation models on your content.
Material security incidents are disclosed to affected users within 72 hours of confirmation.
Found a security issue? Email customerservice@upplioai.com with the steps to reproduce. We acknowledge within 2 business days and credit researchers in our hall of fame on request.
From Settings → Account → Delete account, your data is permanently removed within 30 days.