Skip to content
QuratedAI

Privacy

What we hold, and what we refuse to

QuratedAI has no recruiter side. You are not the product, because there is nobody to sell you to. Below is the plain-English version, then the formal detail.

Last updated: 9 August 2026

The matching profile is anonymous

The file that does the actual job matching contains no name, no email and no phone number. It's identified only by an irreversible hash of your sign-in identifier.

Your resume is never published

It's stored privately, readable only by the app itself. It is not listed, not indexed, not searchable, and not shared with recruiters or anyone else.

Nothing is sold

We don't sell, rent or broker your data. There are no advertising trackers on this site, only privacy-plain visitor analytics, which count pages, not people.

One click deletes almost all of it

Profile, resume, generated documents and any Telegram link. The matching run stops immediately and your data is removed from storage. Three things are deliberately kept. The record of a paid term, the date a free trial started for an account that had one, and the counters that meter your allowances, all with nothing personal attached. Section 7 says exactly what and why.

1. Who we are

Vectra Mind Private Limited ("we", "us") operates QuratedAI, an automated job-discovery service available at app.quratedai.com. For data protection purposes we are the controller of the personal data described below. You can reach us at hello@quratedai.com or support@quratedai.com, or by post at A0820, ATS Bouquet Tower‑B, Plot 1406-1407, Block B, Sector 132, Noida, Uttar Pradesh 201304, India.

2. What we collect

We collect only what the service needs in order to work. Specifically:

  • Sign-in data. You can sign in with Google or with an email address and password. With Google we receive your account identifier, your email address, your display name, and confirmation that the email is verified. With email sign-in we hold your address and a one-way hash of your password, never the password itself. Your display name is shown back to you on your own screen only; it is never written into your matching profile.
  • Your resume. A PDF you upload. We extract its text on our server to derive skills, industries and your professional field.
  • Your stated preferences. Target roles, skills, locations, years of experience, work mode, salary floor, geography rules, and optionally your GitHub and LinkedIn profile URLs.
  • Your Telegram chat identifier, if (and only if) you choose to link the bot. Telegram is optional and the service works fully without it.
  • Job-matching history and your feedback. Which postings have already been shown to you so they are not repeated, and any thumbs-up or thumbs-down you give a match, which feeds back into your scoring.
  • Documents you generate. Tailored resumes, cover letters and resume reviews you ask us to produce, kept in your library so you can find them again.
  • A profile picture, if you upload one. It is shown only to you.
  • Payment records. When you buy a plan, our payment provider handles the transaction and returns us a payment reference, an order reference, the plan and term you bought and the amount charged. We never receive or store your card number, CVV or expiry, those are entered on the payment provider's own form, and our checkout page contains no card fields at all.
  • Support tickets. If you contact support, we keep your messages and any files you attach so we can answer you and refer back to the conversation.
  • Where you came from. If you arrive on a link carrying a ?ref= or ?utm_source= tag, we store that short tag in a cookie and record it against your account at signup, so we can tell which channels are worth continuing. It is a marketing counter, it is never used to decide what you are charged or what you can access, and it holds nothing beyond the tag itself.
  • Operational logs. Records of pipeline runs, kept for a limited period for debugging and reliability.

We do not ask for your phone number, date of birth, government identifiers, financial details, or any special-category data. Please don't include such information in your resume if you would prefer that we never process it.

3. The PII-free matching profile

This is the central design decision of the service, so it's worth stating precisely. The matching pipeline runs against a profile file containing your roles, skills, industries, experience band, acceptable locations, work mode, salary floor, matching rules, and a Telegram chat identifier. It contains no name and no email address.

That file is named using a one-way hash of your sign-in identifier; the hash cannot be reversed to recover the account it came from. The matching pipeline therefore processes your preferences without ever handling your identity.

Your email address is retained separately, in a private account record, so that we can recognise you when you sign back in and contact you about the service. That record is never read by the matching pipeline.

4. Why we process it (lawful bases)

  • Performance of a contract. Matching jobs to your profile and delivering alerts is the service you asked us to provide.
  • Consent. Uploading a resume and linking Telegram are voluntary acts, which you can withdraw at any time by deleting your account.
  • Legitimate and lawful uses. Keeping the service secure and working, preventing abuse, and understanding aggregate usage such as the number of active profiles.
  • Legal obligation. Where you buy a plan, retaining the transaction record for as long as tax and accounting law requires.

5. Who processes your data

We use a small number of third-party providers. Each receives only what it needs to do its job, and none of them receive your data for their own marketing purposes.

  • Google: authentication and website analytics. For sign-in it provides us your identifier, email and name. Separately, Google Analytics receives the usual web request data (page visited, referrer, approximate location, device and browser) for visits to this site and the app. The two are not joined together by us.
  • Telegram: message delivery, only if you have linked it. Receives your chat identifier and the content of your alerts.
  • Our payment provider (Razorpay): takes the payment. It collects your card or UPI details directly. They never pass through our systems, and returns us a transaction reference and the amount. Its own privacy terms govern what it holds.
  • Our email provider: delivers your digests, sign-in codes and service notices. Receives your email address and the content of those messages.
  • Our cloud infrastructure provider: hosts the application and stores your profile and resume in private storage with no public address.
  • Our AI provider: receives your resume text and profile details at signup in order to derive your skills and field, and receives your profile alongside job descriptions in order to score them.
  • Our search provider: receives search queries assembled from your roles, skills and target cities. It does not receive your resume or your identity.
  • Our pipeline compute and logging provider: runs the daily matching job and stores operational logs.
  • Our website host: serves this marketing site. It receives no account data of any kind.

We describe the infrastructure providers by the role they play rather than by name. Publishing a full component list of a system mostly helps people attack it, and the protection that gives your data is worth more to you than the trivia of which vendor sits behind which function.

These providers operate in various countries, including outside India. Where data is transferred internationally, we rely on the transfer mechanisms set out in those providers' own data-processing terms. If you are in the UK or the European Economic Area, those terms are also what we rely on for transfers out of your region.

6. Where it is stored, and who can reach it

Your profile and resume are held in private storage that has no public address and is not reachable from the internet, only our application can address it. The application's access is write-oriented; the matching engine holds a separate, read-only credential and can never modify or delete your data. Neither component can do the other's job, which limits how much any single failure could expose.

7. How long we keep it

  • Your profile, resume, generated documents and account record: for as long as your account exists. Deleting your account removes them.
  • Your job history and feedback: kept while your account is active, so that previously seen jobs are not resent.
  • Support tickets and their attachments: kept after a ticket is closed so we can refer back to what was agreed, and removed with your account.
  • Operational logs: retained for a limited period (currently 30 days), then deleted automatically.
  • Payment records: retained for as long as tax and accounting law requires, independently of your account.

Three things deliberately survive account deletion, and it is fair that you know exactly what. Account identifiers are derived deterministically from your sign-in identity, which means deleting an account and registering again produces the same identifier. So:

  • The record of a paid term. The plan and the date it runs to. Without it, deleting and re-registering would be a way to keep a paid plan without paying for it.
  • The date a free trial started, for accounts that had one, and nothing else about it. The 15-day trial ran from 29 August to 1 September 2026 and is withdrawn; the Free plan replaced it. Nothing new is written to this field. The dates already held are kept because a trial was once per account, and without them deleting and re-registering would have been a way to take another one.
  • The counters that meter your allowances, how many resume reviews and reports you have used in the current period. Without them, the same loop would reset an allowance on demand.

Neither carries your name, your email, your resume or your preferences. Both are keyed only to the derived identifier, and neither is used for anything except deciding what a returning account is entitled to.

8. Your rights

You have the right to access your data, correct it, delete it, restrict or object to its processing, and request a copy in a portable form. In practice:

  • Access and correction: sign in and open your account page. Editing your profile and resubmitting replaces the previous version.
  • Deletion: the delete control on your account page removes your profile, your resume and your Telegram link, and stops the daily run. No email to us is required.
  • Anything else: write to hello@quratedai.com and we'll action it. If you're unhappy with our response, you may complain to the Data Protection Board of India. If you are in the UK or the European Economic Area, you may instead complain to your local supervisory authority.

9. Security

  • API keys and secrets are held server-side only and are never exposed to your browser.
  • Session cookies are signed, HTTP-only and secure. A session lasts up to 90 days when you stay signed in, or 8 hours if you sign in without asking to be remembered. Signing out ends it immediately, and we can revoke every session issued for an account at once.
  • Sign-in is protected against cross-site request forgery.
  • The Telegram integration, where used, is authenticated on every request; link tokens are single-use and expire within 15 minutes. Each Telegram account can be bound to exactly one QuratedAI account, and vice versa.
  • Our checkout collects no card fields of any kind. No number, no CVV, no expiry. Card and UPI details are entered on the payment provider's own form and never reach our systems.
  • Uploaded files are validated by inspecting their actual bytes rather than trusting what your browser claims about them, are size-limited, and encrypted PDFs are rejected.
  • The application sends a strict content security policy and related security headers on every response.

No system is perfectly secure, and we won't claim otherwise. If you believe you've found a vulnerability, please write to hello@quratedai.com. We'd much rather hear from you than not.

10. Cookies and tracking

This site and the application at app.quratedai.com use Google Analytics to measure how many people visit, which pages they read, and where they arrive from. It sets its own cookies to tell a returning visit from a new one. We use it to understand traffic in aggregate. It is not wired to any advertising network, and we do not use it to build a profile of you or to follow you around other websites.

The application also sets one essential cookie: your signed session, which is required to keep you signed in.

If you'd rather not be counted, any browser-level tracker blocker or Google's own opt-out add-on will stop it, and the site works exactly the same without it.

11. Children

QuratedAI is not intended for anyone under 18, and we do not knowingly process their data. If you believe a child has signed up, contact us and we will remove the account.

12. Changes to this policy

If we change how we handle your data, we will update this page and revise the date above. Material changes affecting active users will also be announced by email to the address on your account, which is the channel every account has.

Matching that doesn't need to know your name

Set it up in about four minutes. Delete it in one click, whenever you like.