Privacy
Privacy Policy
Effective July 23, 2026
What changed: this revision itemizes the cookies we set, adds the YouSourced property and its application-outcome data, spells out what account deletion does and does not erase, and states the boundary of each service provider.
Source of You is a Professional Identity Record. You build one structured record, and the product generates every surface from it. That only works if you trust us with that record, so here is plainly what we store, what we don’t, and the control you keep.
What we store
- Your account: email and name.
- The record you build, meaning the facts and text you enter.
- Versions and the outputs generated from it.
- Conversations with the in-app assistant.
- Basic, first-party usage analytics.
What we don’t
- We don’t sell your personal data. Ever.
- We don’t let AI providers train models on your data.
- We don’t store passwords. Sign-in is by link or Google.
- We don’t run third-party advertising trackers.
Who we are
Source of You is operated by Chaos Theory Studios LLC (“we,” “us”) and provides the Professional Identity Record platform at sourceofyou.com. This policy also covers YouSourced (yousourced.com), our honest-apply property, which runs on the same platform and the same service providers described here. Questions: hello@sourceofyou.com.
Information we collect
- Account information. Your email address and name, established when you claim a record or sign in. If you sign in with Google, we receive your basic Google profile (name, email, avatar), never your Google password.
- Your record content. Everything you put into your Professional Identity Record: roles, work, story, proof, links, and any other fields you choose to provide. You decide what goes in.
- Generated outputs and versions. The resume, source page, LinkedIn summary, bio, and visibility audits produced from your record, plus version history so you can track changes.
- Assistant conversations. Messages you exchange with the in-app assistant, including the text extracted from any file you upload to it, so it can help edit your record in context.
- Application outcomes (YouSourced). If you use YouSourced to track applications, we store the employer, role, application stage, and any note you add. This capture is behind a feature flag today, and these entries are private to you, visible only in your own YouSourced view.
- Usage and technical data. First-party analytics events (for example, page views and when a record is published) and standard server logs (browser, timestamps, and a truncated one-way hash of your IP for abuse prevention) used to operate and secure the service.
How we use your information
- To provide the product. Store your record and generate the surfaces you ask for from it.
- To improve and secure it. Understand how features are used, prevent abuse, and debug, using aggregate or first-party data, not profiling for ads.
- To communicate. Send the sign-in links and essential service messages you request.
AI processing
Generating your outputs requires sending the relevant parts of your record to Anthropic’s Claude API. Anthropic represents that, under its commercial API terms, inputs and outputs are not used to train its models; that is a statement about their terms, not something we can enforce in our own code. The optional AI-visibility audit reads publicly available web pages you point it to, to assess how AI systems describe you. It reads public sources; it does not publish on your behalf.
When your information is public
Your record stays private until you publish. When you publish a source page (or share a resume link), that surface and the content you placed on it become publicly accessible to anyone with the link and to search engines and AI crawlers. That is the point of the product. The YouSourced jobs feed is a public page; your application outcomes are not, and are never shown on it. Unpublishing removes your source page from public view going forward, though see retention below for what can persist.
Who we share it with
We don’t sell your data. We share it only with the service providers that run the product, under their data-protection terms. Each entry states the boundary of what that provider receives:
- Supabase. Authentication (including Google sign-in), our Postgres database, and Storage for the images you upload (portraits and work plates). Boundary: holds your account, record, and uploaded files; no card details. Hosted in the United States.
- Anthropic. Generating outputs from your record, as described above. Boundary: receives the record content needed for a given output, plus the pages the visibility audit fetches; nothing else.
- Voyage AI. Turning record and assistant text into search embeddings so the product can find the right parts of your record. Boundary: receives record-derived text and assistant replies as text to embed; no account identifiers or card details.
- Stripe. Payment processing if you upgrade. Boundary: receives your email and customer id; card details are entered on Stripe's own hosted pages, and we never see or store your card number.
- Resend. Delivering the transactional emails the product sends you. Boundary: receives the recipient address and message body for that email; no record content beyond what the message contains.
- Vercel. Hosting. Boundary: processes requests in transit as our server host; there is no separate Vercel data-processing integration in our code.
- Google. Only if you choose Google sign-in. Boundary: authenticates you and returns your basic profile; we never receive your Google password.
We may also disclose information if required by law, or to protect the rights and safety of our users and the service.
Retention and deletion
We keep your data while your account is active. You can delete your account yourself from the account page. That erases your records, versions, generated outputs, assistant conversations, usage history, and the extracted claim data derived from your record, cancels any subscription, and deletes your sign-in identity; or write to hello@sourceofyou.com and we will do it for you.
To be straight with you, a few things fall outside that erasure:
- Support correspondence. Messages you send our support team are kept by design, because the email is how we reply and we may still owe you an answer. They are not tied to your account record.
- Public copies already out there. Anything you previously published may persist in third-party caches, search indexes, or archives outside our control.
- Uploaded images. Images you uploaded are stored in a Supabase Storage bucket that our deletion routine does not yet clear automatically. Until that fix ships, ask us at the address below and we will remove them.
- Administrative removal. If we remove an account for a policy reason, that action unlinks and unpublishes its records rather than running the full self-serve erasure above. For complete erasure, use the account-page deletion or email us.
Limited records may also be retained where the law requires it.
Your rights
Depending on where you live (for example, under GDPR or CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Deletion is self-serve on the account page. Export is not yet a self-serve download, so request it at hello@sourceofyou.com and we will provide your data. We don’t sell personal data, so there is nothing to opt out of there.
Security
Data is encrypted in transit. Authentication is passwordless (magic link or Google), so there is no password for us to lose. No system is perfectly secure, but we work to protect your record and limit access to it.
Cookies
We set only first-party cookies, and only the essential ones the product needs to work. We use no third-party advertising or cross-site tracking cookies. Here is every cookie we set:
| Cookie | Purpose | Lifetime |
|---|---|---|
| sb-…-auth-token | Keeps you signed in (issued by Supabase Auth). | Session, rotated; cleared on sign-out |
| soy_claim_… | Lets you attach a draft you started before signing in to your account. | 30 days |
| soy_ask | Rate-limits and remembers your session when you ask a question on a public source page. | 1 year |
| soy_vc_… | Lets you delete a visibility check you ran on the free tool. | 1 year |
| ys_jobs_seen | Shows how many roles are new since your last visit to the YouSourced jobs feed. | 90 days |
| soy-theme | Remembers your light or dark appearance preference. | 1 year |
Our page-visit counts are separate: they are first-party, anonymous, and cookieless. You can turn them off in the cookie notice shown on our public pages, and we honor Global Privacy Control and Do Not Track signals automatically. This applies across our sites, including aipoweredresumebuilder.com, howvisibleareyou.com, and yousourced.com.
When you upgrade, checkout and billing happen on Stripe’s own hosted pages. Any cookie set there is set by Stripe on Stripe’s domain, under Stripe’s privacy policy, not by us.
For visitors in the EU and UK: our anonymous measurement is opt-out and is suppressed whenever a Global Privacy Control or Do Not Track signal is present. We are reviewing this posture with counsel and may update it.
Open source
The Source of You software is open source under the MIT License, so you can inspect exactly how your data is handled. Open code does not change this policy: our hosted service still stores and processes data as described here.
Children
Source of You is for working professionals and is not directed to anyone under 16. We don’t knowingly collect data from children.
Changes
We may update this policy. We’ll revise the effective date above and, for material changes, give notice in-product. Continued use after a change means you accept the updated policy.
Contact
Questions or requests about your data: hello@sourceofyou.com. See also our Terms and Contact page.