Blog ·

Resume PII, redaction, and retention basics for screening tools

What ReviewStack retains, what gets redacted before model calls, and how long files stay available.

Resume files contain personal data. Screening tools should be clear about storage, subprocessors, and deletion — especially when AI providers may process text outside your country.

Retention window

ReviewStack retains resume files and derived analysis for 90 days from first successful upload unless you delete earlier. Notifications are retained for 30 days.

Redaction before model calls

Deterministic server-side redaction runs before text is sent to AI providers. The goal is to reduce unnecessary sensitive fields while keeping employment history usable for scoring.

Subprocessors

Auth (Clerk), backend storage (Convex), AI providers, optional OCR, and payments (Paddle) are part of the service path. See our privacy policy.

Resume PII, redaction, and retention basics for screening tools · ReviewStack