Legal · Privacy

Privacy Policy

This policy explains what GetReady collects, why we collect it, who we share it with, and how you can exercise control over it. We have written it to be read, not skimmed past.

Last updated 20 August 2026Effective 20 August 2026

We never sell data

Your personal data is not sold, rented or traded to advertisers.

You stay in control

Export, correct or delete your account data whenever you want.

AI assists, humans decide

No hiring outcome is decided by an AI model on its own.

Recruiters see what you send

Your profile stays private until you apply or opt into talent pools.

GetReady is a career-readiness and recruitment platform. Candidates build resumes, rehearse AI interviews and apply to roles. Recruiters and organizations post those roles, screen applicants and run structured interviews. Both sides depend on personal data, so how we handle it matters.

This policy covers the https://getready.com.np website, the GetReady web application and every dashboard within it (candidate, recruiter, organization and administrator). It applies whichever role your account holds.

The short version

We collect what we need to run the product: your account details, the career information you choose to provide, the records your activity generates, and payment confirmations. We use it to operate the platform, power AI features, keep the service secure and bill you. We share it with recruiters only when you apply or opt in, and with a short list of infrastructure providers. We do not sell it.

GetReady Technologies operates GetReady and is the controller responsible for the personal data described in this policy.

Legal entity
GetReady Technologies
Registered office
[Registered office address], Kathmandu, Nepal
Registration
[Company registration number]
Privacy contact
privacy@getready.dev

Where employers are the controller

When a recruiter or organization uses GetReady to evaluate you for one of their roles, that employer decides how to use your application within their own hiring process. For those decisions the employer acts as controller and we act as their processor. Requests about an employer’s own records are best directed to the employer, though we will always help you reach them.

We group the data we hold by how it reaches us: what you give us, what your use of the platform generates, and what we receive from others.

Data you provide directly

  • Account details. Name, email address, a securely hashed password, your selected role, and an optional profile image. We store password hashes only, never the password itself.
  • Candidate profile. Headline, biography, phone number, address, and links to LinkedIn, GitHub or a personal site. Also your structured education history, work experience and skills.
  • Resumes and documents. Resume content you build or upload, generated PDFs, and any supporting files. Uploaded PDF and DOCX files are parsed so their text can be analysed.
  • Interview responses. Your answers to mock and scheduled interview questions, together with the questions asked and the session metadata.
  • Applications. The role you applied to, the resume you attached, cover material and answers to employer questions.
  • Recruiter and organization details. Company name, department, designation, team membership, job descriptions, interview templates and question banks.
  • Support correspondence. Anything you send us by email or through in-product support.

Data generated by your use of the platform

  • AI outputs about you. Resume analyses including ATS scores, skill-match percentages, strengths, weaknesses, missing skills and recommendations; interview feedback reports; and screening results generated for employers.
  • Application activity. Status changes, recruiter notes and evaluations, scheduled interviews, offers and your responses to them.
  • Plan and credit records. Your current plan, credit balance and a ledger of every credit granted, spent, refunded or adjusted.
  • Notifications. In-app notifications and whether they have been read.
  • Technical and security logs. Session records, IP address, browser and device information, timestamps and error diagnostics. We use these to keep accounts secure and to debug faults.

Data from third parties

  • Google sign-in. If you choose single sign-on, Google sends us your name, email address and profile image. We do not receive your Google password.
  • Payment gateways. Stripe, eSewa and Khalti confirm whether a transaction succeeded and return a reference, amount and status.
  • Employer-supplied data. A recruiter may upload a resume for screening. If that resume is yours, the data in it reaches us through them.

We never see your card number

Card details are entered directly with our payment providers and never reach our servers. We retain only the transaction reference, amount, purpose and status needed for receipts and accounting.

Every use below is tied to running the platform. We do not repurpose your data for unrelated ends.

PurposeWhat this involves
Providing the serviceCreating your account, authenticating you, rendering your dashboard and storing your work.
Career toolsBuilding and formatting resumes, running mock interviews and producing feedback.
Applications and hiringDelivering your application to the employer, tracking its status and coordinating interviews.
AI featuresAnalysing resumes, matching you to roles, generating interview questions and scoring responses.
PaymentsProcessing plan purchases and credit top-ups, issuing receipts and maintaining billing records.
CommunicationSending transactional email and in-app notifications about your account, applications and interviews.
Safety and integrityDetecting fraud and abuse, enforcing our Terms, and investigating security incidents.
Improving the productUnderstanding which features are used and where they fail, using aggregated or de-identified data wherever it will do.
Legal complianceMeeting tax, accounting and other obligations, and responding to lawful requests.

What we do not do

We do not sell or rent your personal data. We do not share it with advertising networks or data brokers. We do not use your resumes or interview answers to train our own foundation models, and our AI providers are engaged under terms that prohibit training on the content we send them.

AI is central to GetReady, so it deserves a section of its own rather than a footnote.

What gets sent to an AI model

  • Resume text, when you request an analysis, an AI writing suggestion or a job-match score.
  • Job descriptions and requirements, so a role can be compared against a resume.
  • Interview questions and your answers, so feedback and scores can be produced.
  • Question documents an organization uploads to generate an interview set.

Who processes it

Requests are routed to OpenRouter, with NVIDIA as a fallback when the primary provider is unavailable. Both process the content only to return a response. Prompts are not used to train their models.

Automated decision-making

AI output on GetReady is advisory. Scores, rankings and screening summaries are decision support for a human reviewer. No application is rejected, shortlisted or advanced by a model acting alone, and employers agree to this when they use the platform.

AI can be wrong

Models can misread a resume, miss context or score inconsistently. An ATS score is an estimate, not a verdict, and interview feedback is practice guidance rather than an assessment of your ability. If an AI output about you looks wrong, contact privacy@getready.dev and we will review it and correct the record where warranted.

Nothing in your candidate profile is broadcast to employers by default. Visibility follows your actions.

Action you takeWhat becomes visible
You create a profileNothing. Your profile and resumes stay private to your account.
You apply to a jobThe employer that posted it sees your profile, the resume you attached, your answers and the AI screening result for that role.
You mark a resume publicAnyone holding the link can view that resume. You can turn this off at any time.
A recruiter saves you to a talent poolThat recruiter and their organization retain a record of you, along with their own notes and category.
You accept an interview or offerThe employer sees your response, schedule and any interview record produced.
You run a mock interviewNothing. Practice sessions and their feedback are yours alone and are never shown to employers.

Recruiter notes and internal evaluations belong to the employer that wrote them. They are not shown to you inside the product, and requests to see them should go to that employer.

We disclose personal data in these situations only.

  • Employers you engage with. Applying to a role shares your application and profile with the organization that posted it and the recruiters assigned to it.
  • Within an organization. Recruiters, department leads and the organization owner can see hiring records belonging to their organization, subject to their role.
  • Service providers. The infrastructure and processing partners listed in the next section, bound by contract to use the data only on our instructions.
  • Platform administrators. A small number of our staff can access records to provide support, investigate abuse and keep the service running. Access is limited to what the task requires.
  • Legal and safety. Where we are legally required to disclose, or where disclosure is necessary to protect our rights, our users or the public from harm.
  • Corporate transactions. If the business is merged, acquired or reorganized, data may transfer as part of it. We will tell you before your data becomes subject to a different policy.

These providers process personal data on our behalf. We keep the list current as our stack changes.

ProviderPurposeData involvedRegion
SupabaseManaged PostgreSQL database hosting and storageAll account, profile, application and platform recordsAsia Pacific (Sydney)
UploadcareFile upload, storage and CDN deliveryResume files, profile images, question documentsGlobal CDN
OpenRouterAI model routing for interviews, resume analysis and screeningResume text, interview responses, job descriptionsUnited States
NVIDIAFallback AI inference when the primary provider is unavailableResume text, interview responses, job descriptionsUnited States
GoogleOptional single sign-on authenticationName, email address, profile imageGlobal
StripeCard payment processing and recurring subscriptionsBilling details, transaction recordsUnited States
eSewaDigital wallet payment processingTransaction references and amountsNepal
KhaltiDigital wallet payment processingTransaction references and amountsNepal

Each provider operates under a data processing agreement that limits them to our instructions and requires appropriate security measures.

GetReady is operated from Nepal, and some of our providers are located elsewhere , our database is hosted in Asia Pacific, and our AI and card-payment providers operate from the United States. Using the platform involves transferring your data to those countries.

Where a transfer leaves a jurisdiction with data-export rules, we rely on the safeguards available to us, including standard contractual clauses with the provider and an assessment of the protections they apply.

We keep data for as long as it serves the purpose it was collected for, then delete or anonymise it.

DataRetention
Account and profileFor the life of your account, then deleted within 30 days of a deletion request.
Resumes and uploaded filesUntil you delete them, or 30 days after account deletion.
Mock interviews and feedbackUntil you delete them, or 30 days after account deletion.
Job applications and screening resultsRetained by the employer for their hiring and compliance needs, typically up to 24 months after the role closes.
Talent pool entriesUntil the recruiter removes the entry or you ask us to remove it.
Payment and credit recordsUp to 7 years, as financial and tax rules require.
Security and audit logsUp to 12 months, unless retained longer for an active investigation.
Support correspondenceUp to 24 months after the matter is closed.

Backups roll off on their own schedule, so a deleted record may persist in an encrypted backup for a short period after removal from the live database.

  • Passwords are hashed with Argon2, a memory-hard algorithm built for credential storage. We cannot read your password.
  • Data is encrypted in transit with TLS, and at rest by our database and storage providers.
  • Access to production data is restricted to staff who need it and is authenticated per person.
  • Role-based authorization is enforced on the server for every request, so a candidate cannot read recruiter records and one organization cannot read another’s.
  • Payment card data never touches our infrastructure.

No system is perfect

Strong measures reduce risk but cannot eliminate it. Use a unique password and keep your email account secure. If you believe your account has been compromised, or you have found a vulnerability, write to security@getready.dev. We investigate every report and will notify affected users and regulators where a breach requires it.

Subject to the law that applies to you, you can exercise the following rights over your personal data.

  1. 1.Access. Get a copy of the data we hold about you.
  2. 2.Correction. Fix anything inaccurate. Most profile and resume fields are editable directly in your dashboard.
  3. 3.Deletion. Ask us to erase your account and associated data, subject to records we must keep.
  4. 4.Portability. Receive your data in a structured, machine-readable format.
  5. 5.Objection and restriction. Object to processing based on legitimate interests, or ask us to pause processing while a dispute is resolved.
  6. 6.Withdraw consent. Turn off anything you opted into, including marketing email and public resume links.
  7. 7.Human review. Ask a person to review any AI output that affected you.
  8. 8.Complain. Raise a concern with your local data protection authority. We would appreciate the chance to resolve it first.

Email privacy@getready.dev to exercise any of these. We respond within 30 days and will verify your identity before acting, so that nobody else can make a request in your name. Exercising a right never costs you anything and will not degrade your service.

We keep browser storage to the minimum the product needs. We do not run third-party advertising or cross-site tracking.

WhatWhyType
Session cookieKeeps you signed in and protects against request forgery.Strictly necessary
Theme preferenceRemembers your light or dark mode choice.Functional
Onboarding and UI stateRemembers dismissed prompts and in-progress steps so you are not asked twice.Functional

Blocking strictly necessary cookies will prevent you from signing in. Everything else can be cleared from your browser without losing access.

GetReady is built for people in or entering the workforce and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact privacy@getready.dev and we will remove the account and its data.

We update this policy as the product and the law change. The date at the top always reflects the current version. For material changes , a new purpose, a new category of sharing , we will notify you in the product or by email before the change takes effect, and where consent is required we will ask for it.

Continuing to use GetReady after a change takes effect means you accept the updated policy.

Privacy questions, requests and complaints all reach a person who can act on them.

Privacy requests
privacy@getready.dev
Legal notices
legal@getready.dev
Security reports
security@getready.dev
General support
support@getready.dev
Post
GetReady Technologies, [Registered office address], Kathmandu, Nepal

See also our Terms of Service, which govern your use of the platform.

Questions about this document?

Our team reads every message. Reach out and we will get back to you within five business days.