Blog ·
Resume PII, redaction, and retention basics for screening tools
What ReviewStack retains, what gets redacted before model calls, and how long files stay available.
Resume files contain personal data. Screening tools should be clear about storage, subprocessors, and deletion — especially when AI providers may process text outside your country.
Retention window
ReviewStack retains resume files and derived analysis for 90 days from first successful upload unless you delete earlier. Notifications are retained for 30 days.
Redaction before model calls
Deterministic server-side redaction runs before text is sent to AI providers. The goal is to reduce unnecessary sensitive fields while keeping employment history usable for scoring.
Subprocessors
Auth (Clerk), backend storage (Convex), AI providers, optional OCR, and payments (Paddle) are part of the service path. See our privacy policy.