Privacy Policy
Shortlist helps recruiters rank job applicants using AI. Resumes contain sensitive personal information, so we want to be clear about what we do with it, what we don't, and what you can ask us to do.
01Who we are
Shortlist is operated by Stephen Dalanon, an independent developer based in Metro Manila, Philippines. We are not a registered corporation. The service is operated as a sole proprietorship.
Contact: heystephn@gmail.com
Data Protection Officer (DPO): Stephen Dalanon (same email) — under the Data Privacy Act's Implementing Rules and Regulations, every personal information controller and processor must designate a DPO. For a solo operator, the operator serves as DPO until the role can be delegated.
02Our role under the Data Privacy Act
The Philippines Data Privacy Act of 2012 (Republic Act 10173, "DPA") uses two specific terms that matter here:
Personal Information Controller (PIC) — the entity that decides how and why personal information is processed. For candidate resumes, the recruiter (our customer) is the PIC. They chose to collect the resume, they decide what to do with the candidate, and they hold the hiring relationship.
Personal Information Processor (PIP) — an entity that processes personal information on behalf of a PIC. Shortlist is the PIP. We process resumes only on the recruiter's instructions, for the purpose of producing a ranked shortlist.
Even as a PIP, we have direct obligations under Sec. 14 of the DPA — confidentiality, security measures, breach notification, and subcontractor controls. We take those obligations seriously even though we do not own the relationship with the candidate.
If you are a candidate reading this and want to access, correct, or delete information about yourself, your first point of contact is the recruiter who collected your resume. We will assist them in fulfilling your request.
03What we process
3.1 From the recruiter (you)
There are two ways to use Shortlist, and they collect slightly different account data:
- Google sign-in accounts (self-serve): your Google account email and display name, provided through our sign-in provider Clerk; a unique account identifier; trial/plan status; and, only if you choose to connect one, the ID of a Google Sheet you own
- Access-code accounts (issued manually): access code, recruiter name, company, email, and the Google Sheet ID configured for output
- For both: usage data — number of resumes processed, dates of analysis runs, trial vs paid plan status, and a log of consent confirmations
- The job descriptions you submit for matching
- Authentication cookies (see Section 13)
We never see or store your Google password. Sign-in is handled by Clerk (see Section 05), and we receive only your email, name, and a session token.
3.2 From candidate resumes (uploaded by recruiters)
When a resume is uploaded, the file is parsed and its text is sent to an AI provider for scoring. Resume content typically includes:
- Full name and contact details (email, phone, location)
- Work history, education, certifications, skills
- Anything else the candidate chose to put on their resume
We do not ask for, store, or attempt to derive sensitive personal information under DPA Sec. 3(l) — health, religion, philosophical beliefs, political affiliation, etc. — but if a candidate volunteers any of that on their resume, it is processed as part of the resume text. We do not single it out for analysis.
3.3 Technical and operational
We collect first-party product analytics about landing visits, signup actions, account activation, completed screening runs, plan changes, and retention. Anonymous sessions may later be linked to your recruiter account after signup.
Product analytics do not store IP addresses, browser fingerprints, candidate data, resume text, job descriptions, or Google Sheet contents. Campaign attribution is limited to UTM fields and the referring website hostname.
- Request IP addresses (in hosting provider logs, for abuse prevention and rate limiting)
- Application logs of AI provider calls (provider, success or failure, timing, and error category — never candidate names, resume text, job descriptions, or model responses)
04How long we keep things
We try to keep retention windows narrow and aligned with what the code actually does, not what sounds good in a policy.
Uploaded files live in a temporary directory on the server only for the duration of the analysis run — typically under two minutes. They are deleted as soon as the run finishes (or fails). They are never written to long-term storage.
Resume text is held in memory while we call the AI provider, then released. It is not written to disk or to a database.
If you choose "View results here," the scored results are held only in server memory and shown in your browser. They are automatically purged from server memory within about one hour of the run finishing, and disappear from your browser when you refresh or leave the page. They are never written to a database or to disk on our side. The only lasting copy is the Excel file you download — which lives on your device, under your control.
We log which provider was called, whether the call succeeded, timing, and a non-sensitive error category. Logs never include candidate names, resume text, job descriptions, or model responses. Log files rotate automatically and old rotations are deleted.
Access code records (name, company, email, Sheet ID, usage counters) are kept while the access code is active and automatically deleted 90 days after expiry or revocation. Google sign-in account records (email, name, plan status, usage counters, connected Sheet ID) follow the same automatic 90-day expiry window; if you ask us to delete your active account, we remove the record within 30 days. No candidate data is ever stored in account records.
Raw first-party analytics events are retained for 90 days. Daily aggregate totals may be retained longer so we can understand broad service trends without keeping the underlying event history.
The Google Sheet that holds the ranked shortlist belongs to you. We write to it; we do not retain a copy on our side. Sheet retention is governed by your Google Workspace policies. Excel exports are generated on demand from in-memory results and downloaded directly to your device; we keep no copy.
05Who we share information with (sub-processors)
Shortlist depends on a small number of third-party services. All of them are based in the United States, which means resume data is transferred outside the Philippines for processing. This is a cross-border transfer under the DPA and is subject to NPC Circular 2022-01 on personal data protection in cross-border transfers. As the Personal Information Controller (PIC), the recruiter is responsible for ensuring that candidates have been informed of this transfer before their resume is uploaded. We provide a candidate privacy notice template to help recruiters meet this obligation.
| Provider | Country | What we send | Why |
|---|---|---|---|
| Together AI | United States | Resume text + job description, per analysis call | Primary AI provider for resume scoring. The exact serverless model may change over time based on availability and account access. Per Together AI's API terms, inputs are not used to train models when the account's training opt-in is disabled (which it is on our account). |
| Groq | United States | Resume text + job description, only when Together AI is unavailable | Fallback AI provider. Per Groq's API terms, API inputs are not used to train Groq's models. |
| Clerk, Inc. | United States | Recruiter sign-in data only: your Google account email, name, and authentication session. Never candidate or resume data. | Authentication provider for Google sign-in accounts. Clerk manages the sign-up/sign-in flow and session tokens so we never handle your Google password. |
| Google LLC (Sheets API) | United States | Scored, structured shortlist rows; daily operational backups of recruiter account records (never candidate or resume data) | To write the output spreadsheet you specify (the Sheet remains in your Google account), and to keep a disaster-recovery backup of account records in the operator's Google Drive. Sheets output is used only for access-code accounts and Google sign-in accounts that choose to connect their own sheet. |
| Railway | United States | Application traffic, environment variables, persistent volume contents | Hosting and infrastructure for the Shortlist service. |
These sub-processor terms are accurate as of the policy's "Last updated" date. If a provider materially changes its terms (e.g., starts training on API inputs), we will update this policy and notify active recruiters by email.
We do not sell personal information. We do not share it with other recruiters, advertisers, or data brokers. We do not use it to train our own models (we have no models of our own to train).
06Lawful basis for processing
Under DPA Secs. 12–13, we rely on the following lawful bases:
- Contract — processing is necessary to deliver the service the recruiter signed up for
- Legitimate interests — operating, securing, and improving the service, balanced against candidate rights
- Consent — the recruiter, when they accept these terms, confirms that they have obtained candidate consent before uploading resumes (this consent itself is governed by the recruiter, not by us)
07Automated decision-making and AI
Shortlist uses a large language model to assign each resume a numerical score from 0 to 10 against the job description, plus structured fields like "shortlist verdict" and "gaps." This is profiling as defined under NPC Circular 17-01.
How the AI works, in plain terms: the resume text and job description are sent to the AI provider with a prompt that asks for a structured JSON evaluation. The model returns a score and supporting fields. We sort the results and write them to your Sheet. We do not train the model — it is a third-party model.
The recruiter makes the hiring decision, not the AI. Shortlist produces recommendations for recruiter review. Final hiring decisions are made by a human (the recruiter) who can — and should — override, ignore, or further investigate any AI output. Our terms of service require this.
Known limitations: AI scoring may reflect biases present in the model's training data. Resume parsing (especially OCR on scanned PDFs) may miss or misread fields. Scores should be treated as a triage signal, not a final verdict.
Candidate rights regarding AI processing: a candidate has the right to object to fully-automated decision-making about them under DPA Sec. 16(c). Because the recruiter remains in the decision loop, Shortlist is not fully automated. Candidates wishing to exercise this right should contact the recruiter that collected their resume.
08Anti-discrimination commitment
Recruiters using Shortlist remain bound by Philippine labor law, including:
- RA 10911 (Anti-Age Discrimination in Employment Act)
- RA 6725 (prohibition of sex discrimination in employment)
- RA 7277 as amended by RA 10524 (Magna Carta for Persons with Disabilities)
- Labor Code Art. 135 and related provisions
The prompts we send the AI explicitly ask for fit against job requirements and do not ask the model to consider age, gender, race, religion, marital status, or disability. We cannot, however, prevent the recruiter from acting in a discriminatory way using the output. That responsibility sits with the recruiter as PIC and employer.
09Geographic scope and the EU AI Act
Shortlist is licensed for use only by recruiters located in the Philippines and Southeast Asia, screening candidates for roles based in the Philippines and Southeast Asia. The Service is not licensed for use in screening candidates for roles based in the European Union, the United Kingdom, or the European Economic Area.
Under the EU AI Act (Regulation 2024/1689), resume-screening systems are classified as high-risk under Annex III, with extraterritorial reach where outputs are used inside the EU. Shortlist is not currently certified as a high-risk AI system under that regime. Recruiters who use Shortlist for EU-bound hiring do so in breach of these terms and assume all resulting compliance risk.
10Your rights as a data subject
Under DPA Sec. 16, you have the right to:
- Be informed about how your personal information is processed (this policy)
- Access the personal information we hold about you
- Object to processing, including profiling
- Erasure or blocking of your data when no longer necessary or unlawfully processed
- Rectification of inaccurate or incomplete data
- Data portability — receive your data in a structured, commonly used format
- Damages for unlawful processing that causes harm
- File a complaint with the National Privacy Commission (NPC)
To exercise any of these rights, email heystephn@gmail.com with subject line "DPA Request." We respond within 30 days, as required by the DPA. Candidates should normally contact the recruiter who collected their resume first; if that recruiter is unresponsive, contact us and we will help where we can.
11Security
We use commercially reasonable technical and organizational measures:
- HTTPS/TLS encryption for all traffic in transit
- API keys and credentials stored only in environment variables on the hosting platform, never committed to the source code
- Authentication cookies are httpOnly, SameSite=Lax, and Secure in production
- Google sign-in sessions use cryptographically signed tokens verified on every request; sign-in itself is delegated to Clerk, so we never handle your Google password
- Access codes are individually issued, revocable, and rate-limited
- Temporary resume files are deleted immediately after processing
- In-app results can only be viewed or exported by the account that created the analysis run
- The admin interface requires a separate password and uses a short-lived (24h) token
We do not currently encrypt the small operational data files (access code records and the account database) at rest beyond filesystem-level access controls. We will be transparent about this rather than claim more than we do. These files contain recruiter account data only — never candidate data.
No system is fully secure. We cannot guarantee absolute security of any data.
12Data breach notification
Following NPC Circular 16-03, if a personal data breach occurs that involves sensitive personal information or is likely to cause real risk of serious harm:
- We notify the National Privacy Commission within 72 hours of becoming aware of the breach
- We notify affected data subjects (or, for candidate data, the recruiter who is the PIC) without undue delay
- We provide details about the nature of the breach, its likely consequences, and the measures taken
- We file a full report with the NPC within five days, as required
13Cookies
We use two authentication cookies and one first-party analytics cookie:
__session— set by our authentication provider Clerk when you sign in with Google. Holds a short-lived, cryptographically signed session token that our server verifies on every request. Refreshed automatically while you use the app; ends when you sign out.access_key— for access-code accounts only. Holds your access code so you don't have to re-enter it on every page. httpOnly, Secure, SameSite=Lax. Expires when your access code's trial period or subscription expires.shortlist_anon— a first-party product analytics identifier with a 90-day lifetime. It is httpOnly, SameSite=Lax, and Secure in production. It records a limited anonymous landing session and may be linked to your recruiter account after you sign up.
We do not use advertising cookies, browser fingerprinting, or third-party analytics trackers. The shortlist_anon cookie is used only for Shortlist's own privacy-limited product analytics.
14Children
Shortlist is a B2B tool for recruiters. We do not knowingly permit minors to register as recruiter accounts. Resumes uploaded by recruiters may, however, belong to candidates of any working age. We do not target or single out minor candidates in any way.
15Changes to this policy
We may update this policy from time to time. If we make material changes — for example, adding a new sub-processor, changing retention periods, or expanding what we process — we will update the "Last updated" date and notify active recruiters by email. Continued use after a change means you accept the updated policy. If you do not accept it, contact us to terminate your subscription.
16Contact and complaints
For any privacy question, request, or concern:
Stephen Dalanon — Operator & DPO
Email: heystephn@gmail.com
Subject line: "Privacy Request — Shortlist"
Response time: within 30 days
If we have not resolved your concern to your satisfaction, you may file a complaint with the National Privacy Commission:
National Privacy Commission
5th Floor, Philippine International Convention Center (PICC)
Vicente Sotto St., Pasay City, Metro Manila 1307
Email: info@privacy.gov.ph
Website: privacy.gov.ph