Security
Pawhala handles résumés and job descriptions — documents that often contain personal detail. This page describes how that data is protected. For the full picture of what we collect and why, see the Privacy Policy.
Data in transit
All traffic to and from Pawhala is served over HTTPS (TLS). We enforce HSTS so browsers refuse to connect over plain HTTP.
Your content is not used to train models
Résumé text and job descriptions you submit are used only to generate your optimized résumé and cover letter. They are not sold, and under our providers’ enterprise terms they are not used to train their models. We do not train models of our own on your content.
Authentication
Sign-in is handled through Google OAuth. We never see or store your Google password. Session state is kept in a single essential cookie — see the Cookie Policy.
Payments
Subscriptions are processed by Stripe. Card numbers are entered on Stripe’s infrastructure and never reach our servers; we store only a Stripe customer reference and your plan status.
Access and infrastructure
Production systems run on managed cloud infrastructure. Access to production data is restricted to what is required to operate the service. Data is encrypted in transit; no method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Reporting a vulnerability
If you believe you’ve found a security issue, email hello@pawhala.com with details and steps to reproduce. Please don’t publicly disclose until we’ve had a reasonable chance to respond.