VirglBack to Virgl

Privacy Policy

Last updated 2026-07-28

Virgl holds your resume, your work history, what you want to be paid, and your notes on the people in your search. This page says what we keep, who else receives it, how long it stays, and how to get a copy or have it deleted.

Who runs Virgl. Virgl is operated by Isaac Bush, an individual based in North Carolina, United States.

Privacy requests and questions. privacy@virgl.ai

A person reads that inbox.

What we collect

All of it comes from you, either because you typed it, imported it, or ran an action that produced it. We do not buy data and we do not enrich your profile from outside sources.

Your account

Your email address and how you signed in. Virgl uses an email sign-in link or Google sign-in. If you use Google, Google tells us your email address and basic profile. We never see your password because there is no password.

Your career profile

Your name, headline, and time zone. Work authorization and whether you need sponsorship. Where you are based, whether you will relocate, and your stance on remote work. Your salary floor. Years of experience. Job function, job types, and the company stages you want. What you are looking for, what you want to avoid, and your positioning line. A short sample of your own writing, if you give us one, used only to shape the tone of drafts.

Your resume and experience

The resume you import, stored as text. Separate entries for roles, education, certifications, and summaries you add by hand.

If you import a PDF, the file is read in your browser. Only the extracted text is sent to us. The file itself never leaves your device.

Your search

Companies and roles you save, including the full job description text, the posting link, location, seniority, and any pay range. Your applications, their status, the dates of each move, your notes, and why an application closed.

What Virgl produces for you

Your odds score, its band, the reasons under it, and the hard gates that capped it. Tailored resumes, cover letters, company briefs, interview prep, and negotiation notes.

People you add

Recruiters, hiring managers, referrers, and interviewers you record against a role. For each one: name, title, LinkedIn link, email, how they relate to the role, your notes, and a dated log of your exchanges. See the next section.

Payments

Your plan, your plan status, when a pass started, and the Stripe customer, order, and subscription identifiers. Card details go straight to Stripe. We never see or store a card number.

Product usage

Which action ran, which model it used, how many tokens it cost, and when. Funnel events such as a page view, a read finishing, or a checkout starting. Those funnel events carry derived facts only, such as a band label or a plan name, and never resume or job description text. Any feedback you send us. A record that we sent you an email, so a bounce can be matched back.

Technical

Your IP address and normal request metadata sit in our host's logs. The free check keeps rate-limit counters keyed on a signed device cookie and on your IP address, so one person cannot drain the free tier. An IPv6 address is shortened to its network prefix before we store it. An IPv4 address is stored whole.

Records about other people

This is the part that deserves its own heading. The recruiters, hiring managers, and interviewers you record never signed up for Virgl and never agreed to anything. When you add them, you decide what we hold about them.

  • Record only what you need to run your own search.
  • Do not write a note you would not be comfortable showing that person.
  • We never contact them. We never sell or share these records.
  • Delete a person in the app and their record and their interaction log go with them.
  • If one of them asks us what we hold, we will tell them and delete it on request.

Why we hold it

  • To run the service you asked for. Scoring a role, tailoring a resume, and tracking your pipeline all need the data above. This is the contract between us.
  • To keep it working and safe. Rate limits, spend ceilings, error tracking, and abuse prevention. This is our legitimate interest and yours.
  • To see what works and improve the product.Funnel measurement, on derived facts only. If you are in the EU, the EEA, the UK or Switzerland, we ask first: the analytics cookie and the session recording below do not start until you agree, and saying no changes nothing about how Virgl works for you. Everywhere else we rely on legitimate interest, and we honour your browser’s Global Privacy Control signal wherever you are. Traffic counts that store nothing on your device run for everyone.
  • To keep payment and tax records. A legal obligation, handled by Stripe as the seller of record.

We do not sell personal information. We do not share it for cross-context behavioural advertising. There are no advertising trackers in Virgl.

Who else receives your data

Virgl is a small product built on other companies' infrastructure. This is every outside company that receives data, and what each one gets.

  • SlackOur own operations chat. When you send feedback in the app, the message text and your email address are posted to a private channel we read. Billing and system alerts go to the same place. Nobody outside the team sees it.
  • SupabaseThe database and sign-in. It holds everything listed above, in the United States.
  • AnthropicThe AI provider behind every generated output. It receives your resume text, your experience entries, your profile facts, the job description, and your writing sample, for as long as the request takes.
  • TavilyWeb search behind role discovery and company briefs. It receives the search terms built from your job function, headline, target titles, location, and the company name you asked about. It does not receive your resume.
  • StripePayments, as the seller of record. It receives your email address and your payment details, and it collects and remits tax.
  • ResendTransactional email. It receives your email address and the contents of the message we send you.
  • VercelHosting. Every request passes through it, so it sees your IP address and request metadata in its logs.
  • Vercel AnalyticsPage-level traffic counts. Aggregate, no cookie, not tied to your account.
  • Microsoft ClaritySession replay and heatmaps on the marketing pages only. See below.
  • GoogleOnly if you choose Google sign-in, and only for that sign-in.

On the AI provider. Your resume and profile text go to Anthropic to produce your odds, your tailored resume, your cover letter, and your briefs. That is what makes the product work. Anthropic processes the text to return the output and does not use it to train models. Anthropic is the only AI provider in Virgl.

Session replay, said plainly

Microsoft Clarity records page sessions on our marketing pages, virgl.ai and try.virgl.ai. It cannot run on app.virgl.ai: the block is by hostname in our code, not a vendor setting, so your saved pipeline, your tailored materials and your contacts are never recorded. We never tie a recording to your account.

Note what that does include. The free check at try.virgl.ai is a marketing page, and it is where you paste a resume. Clarity masks what you type into a form field, and we set its masking to strict so page text is hidden too. If you would rather not be recorded at all, use the free check with your browser's tracking protection on, or skip it and create an account, where replay never runs.

Cookies and browser storage

  • Supabase sign-inKeeps you signed in. Names begin with sb-. Required. Block it and you cannot use the app.
  • virgl_anonA random visitor id, kept one year across virgl.ai, used to measure how people move through the site. Only set where we are allowed to, and never if you said no or your browser sends Global Privacy Control.
  • virgl_carryA random id kept for one day. It is what lets a check you ran before signing up follow you into your new account. Required for that to work, so it is set even if you decline analytics. You asked for the check; we are not going to lose it.
  • virgl_consentYour answer to the cookie question, kept six months. We have to remember it, or we would keep asking.
  • virgl_geoWhether your country is one where we have to ask first. One of two values, kept a day, so we do not look it up on every page.
  • virgl_refA referral code, so the person who invited you gets credit. Treated as analytics, so it follows the same choice.
  • virgl_devA signed device marker your browser cannot read or edit. It is how the free check counts one device instead of trusting whatever a script claims.
  • virgl_adminThe operator portal session. Only we ever hold it.
  • Browser storageA per-tab session id and the campaign tags from the link you arrived on, kept in your browser so we do not double count you.

How long we keep it

  • Your account data stays for as long as your account is open.
  • Free check leftovers. A resume you paste into the free check stops working after 24 hours, so it can carry into a new account you make that day and not after. A daily cleanup job then deletes it, usually within a day of that. Cached reads and rate-limit counters expire on the same pattern, at 24 and 48 hours plus however long it is until the next daily run.
  • Funnel analytics have no automatic deletion yet. Those rows stay until we build a sweep for them. We would rather say that than publish a schedule we do not run. They carry derived facts only, never resume or job description text.
  • Backups. Our database host keeps routine backups, so a deleted row can survive in a backup for a while after it leaves the live database.

Your rights, and how to use them

Wherever you live, you can ask us for a copy of what we hold, a correction, an export, deletion, a limit on how we use it, or to object to a use.

What you can do right now, yourself

In the app you can edit or delete your profile, your resume and experience entries, saved roles and applications, and the people you recorded against a role.

You can delete your whole account from Settings.Open Settings, choose “Delete my account”, and type your email address to confirm. It takes effect at once and cannot be undone. Your profile, resume, experience, roles, applications, scores and saved materials all go. If you pay monthly, we cancel your subscription first, so you are never billed for an account that no longer exists.

Three kinds of record survive a deletion with your account id stripped off them: funnel analytics, referral credit, and the log that an email was sent. None of those carry your resume, a job description, a name, or a contact detail, and once your account is gone nothing links them back to you.

What you have to ask us for

A full copy or export of what we hold. Email us and we will confirm and finish within 30 days. If you would rather we delete the account by hand than press the button yourself, we will do that too.

Send any request to privacy@virgl.ai.

If you are in the EU or the UK

You can complain to your data protection authority. You do not have to come to us first.

If you are in California

You can ask what we collected, ask for a copy, and ask us to delete it. We do not sell or share your personal information, so there is nothing to opt out of. We will not treat you differently for asking.

Where your data lives

Virgl runs in the United States. The database, the hosting, the email provider, the payment provider, and the AI provider are all United States companies. If you use Virgl from the EU, the UK, or anywhere else outside the United States, your data is transferred to the United States and stored there.

A transfer to the United States is lawful because of the European Commission's standard contractual clauses, which form part of the data processing agreement we hold with each provider. Those are in place for every provider listed above except Tavily, where the agreement is still being completed.

Security

Every row is scoped to its owner and that scoping is enforced by the database itself, not only by the app, so a bug in one screen cannot hand your data to another account. Sign-in has no password to steal. The free check runs behind a signed device marker and hard spend limits.

No system is perfectly safe and we will not claim ours is. If we ever find a breach that affects you, we will tell you.

Age

Virgl is not for anyone under 16. Do not use it if you are under 16. If we learn we hold a child's data, we delete it.

Changes

If this policy changes we update the date at the top. If a change matters to you, we email account holders before it takes effect.

Contact

Isaac Bush, North Carolina, United States. privacy@virgl.ai

A person reads that inbox. See also the Terms of Service.

virglPrivacyTerms© 2026 Virgl