Skip to content

Your Data is Private

We built this tool for people who need to trust it. Here's exactly how we protect you.

What We Collect

  • •Your resume text — so we can find your skills and match you to jobs
  • •Your answers to Forge questions — so we can match jobs and resources to your situation
  • •Your activity in the Refinery — so we can track your progress and suggest next steps
  • •Your conversations with t.ROY when you are signed in, so he can remember your recent work. You can delete them anytime in Settings.
  • •That's it. No browsing history. No location tracking. No social media.

Who Can See Your Data

Your work is private from program staff unless you open sharing.

  • •Joining a program does not by itself give staff access to your resumes, cover letters or application details. Where sharing is available, you see what will be shared and who can see it before you turn it on. Programs can still see membership and permitted program records.
  • •You can stop sharing in Settings. This stops new viewing through the sharing feature; it cannot erase what someone already read, copied or put in their own records. You can see a log of access through this feature.
  • •Required sharing is currently limited to demo programs. A program requirement must be shown separately and acknowledged before it opens any items. Stopping sharing here does not decide a program's rules or any outside obligations.
  • •An employer, supervising officer or law enforcement agency does not get access just because of that role. Information you share outside Steel Man may be kept by its recipient. We may also have to disclose information when the law requires it.

Our own staff can open an account to help you, for example when you ask for support or something breaks. Every staff access is recorded in an audit log with who and when, and full-access sessions require a written reason. Day to day we look at usage counts, not your personal information.

Where Your Data Lives

  • •Stored in a database that is encrypted at rest. If someone stole the physical disks, they could not read your data.
  • •Every connection uses HTTPS — your data is encrypted while it moves between your device and our servers
  • •Everything is hosted in the United States

We are building a document vault that adds a second lock on top of the database: each file is sealed with AES-256-GCM encryption tied to your account, so it can only be opened for you. That vault is coming soon and is not turned on yet.

What the AI Sees

  • •The AI reads your resume and answers to help you — that's its only job
  • •Every AI interaction is logged — we can check exactly what the AI said to you and why
  • •When you are signed in, t.ROY remembers your recent conversations so he can pick up where you left off. You can delete that history anytime. Without an account, nothing is remembered between visits.
  • •The AI never shares your information with other users

You're in Control

Export Your Data

Download a copy of your data: your resume, Forge results, applications, chat history, and more. You can pick which parts to include. We ask you to confirm it's you first.

Delete Your Data or Account

You choose: delete just your data and keep your login, or delete your whole account. Either way it's a two-step action. You confirm it's you, then confirm again. It can't be undone.

Consent Preferences

Manage optional sharing in Settings. You can stop access through the sharing feature; copies and program records already made may remain.

No Account Required

The Forge works without creating an account. Nothing is stored unless you choose to sign in.

Locking Down Your Account

  • •Set a password, or sign in with a one-time magic link sent to your email. Passwords are stored as a scrambled hash, not as the words you typed.
  • •Turn on two-step verification. You add a code from an authenticator app when you sign in, and you get one-time backup codes in case you lose your phone. The secret behind those codes is stored encrypted.
  • •See every device signed in to your account and sign out any one you don't recognize. It loses access right away.
  • •Exporting or deleting your data asks you to prove it's you first, with your password, or by typing DELETE if you use magic-link sign-in. That way a borrowed or unlocked device can't wipe or copy your data.

What You Share Is Your Choice

You control a few separate choices in Settings. You can change any of them anytime:

  • •Better help: let the AI use more of your Forge answers to give you sharper, more personal suggestions.
  • •Research: allow your data, with your name and details removed, to help study what helps people find work.
  • •Outcomes: share whether you landed a job so partner programs can see if this is working. You can share this without sharing anything else.

What We Don't Do

  • No ads. Ever.
  • No selling your data. Ever.
  • No ad networks and no data brokers. We use basic visit counting (Google Analytics and Vercel) to see which tools help people, and we keep it off the sensitive pages: disclosure practice, interview practice, and your vault.
  • We use service providers for hosting, storage, AI and visit counting. Program sharing and legally required disclosures are described above.
  • No data mining
  • No surprises — if something changes, we'll tell you first

For Organizations

If you're considering this platform for your clients:

  • •Staff access to participant materials is limited by organization, staff permissions and the participant's active sharing grants
  • •All AI decisions are logged for compliance and audit
  • •Voice practice audio passes through OpenAI, which may retain it up to 30 days for abuse monitoring. We do not store your audio.
  • •Users can export or delete their data independently — you don't control it, they do
  • •Rate limiting protects against abuse without blocking legitimate use
  • •Partner access codes let you onboard your clients with elevated permissions

Technical Details

For security professionals and compliance teams:

Database: PostgreSQL on Neon (encrypted at rest, TLS in transit)

Object Storage: Cloudflare R2 (S3-compatible, encrypted at rest)

Document encryption: AES-256-GCM envelope encryption for secure objects, bound to owner and purpose (rolling out with the vault)

Auth: Auth.js v5, email magic link or optional password (bcrypt hash only)

Two-factor: TOTP with an encrypted secret and bcrypt-hashed one-time backup codes

Sessions: tracked per device with self-service revocation; new-device sign-ins alert the account owner

Sensitive actions: export and delete require re-authentication (password or typed confirmation)

AI -- writing and coaching: Anthropic Claude. No training on user data.

AI -- fact checking: OpenAI (gpt-4o-mini). A second model re-reads what the first one wrote and flags anything it cannot trace back to what you told us. This means your resume text and our draft both pass through OpenAI on that check. No training on user data.

Voice practice: audio streamed to OpenAI; retained by them up to 30 days for abuse monitoring, not stored by us

Hosting: Vercel (SOC 2 compliant, automatic HTTPS)

Rate Limiting: Per-user daily limits with atomic enforcement

Decision Logging: Every AI call logged with input hash, model, latency

Session: JWT-based auth cookies; audited staff-assist sessions use a separate short-lived cookie

Questions about your data or privacy?

Ask t.ROY — he's on every page. Or email us at troyrichardcarr@gmail.com