Legal
Privacy policy
Last updated 4 August 2026
Pomary exists so you can share your career details on your own terms. This page explains exactly what we store, who can see it, and how to get it all back or delete it. Plain English, no lawyer needed.
What we collect
Only what you type in or upload. Specifically:
- Account details — your email address and a password. Passwords are hashed by our authentication provider; we never see or store the plain text.
- Profile details — name, headline, bio, skills, photo, location, phone number and contact email, if you choose to add them.
- Documents — CVs, certificates, transcripts and similar files you upload (PDF, DOCX, PNG or JPG).
- History and links — the work experience, education and social or portfolio links you add.
We do not run advertising, we do not sell data, and we do not buy data about you from anyone else.
Who can see it
- Your public page is visible to anyone with the link or QR code while it is set to live. That is the point of the product — but you control the switch.
- Each document is public or private individually. Private documents never appear on your public page and are not reachable by anyone else.
- Your contact email is never printed on the page. It is revealed one request at a time, behind a rate limit, when a visitor taps “Contact me” — so it cannot be scraped in bulk.
- Your email address and password are never shown publicly under any circumstances.
- We can access stored data where we genuinely need to in order to run the service — fixing a fault you have reported, or investigating a report of abuse. We do not read your documents out of curiosity, and we never sell or share them.
When your profile is hidden, the public page returns a “not found” response to everyone but you.
Where it is stored
Data is held in a Postgres database and object storage operated by Supabase, and the site is served and measured by Vercel. Both are established infrastructure providers with their own security programmes. Transactional email — confirmation and password-reset messages — is sent through Resend.
These providers process data on our behalf and are not permitted to use it for their own purposes. Data may be stored or processed outside your country, including in the United States and the European Union.
How your files are protected
- Database access is restricted per-user at the row level, so one account cannot read another's private records.
- Public document downloads use short-lived links that expire after 60 seconds.
- Traffic is encrypted in transit over HTTPS.
- Sensitive endpoints are rate limited to slow down automated scraping.
No system is perfectly secure. Please do not upload documents containing information you would not be comfortable handing to an employer — for example bank details, or a scan of a passport or national ID.
Cookies and local storage
We use a small number of strictly necessary cookies to keep you signed in, and browser local storage to remember your light or dark theme choice. Page views and load times are measured with cookieless analytics that store nothing on your device and cannot identify you. There are no advertising or cross-site tracking cookies. See the cookie policy for the full list.
Your rights
You can exercise all of the following yourself, from the Account section of your dashboard, without contacting anyone:
- Access and portability — export everything we hold about you as a JSON file, at any time.
- Correction — edit any field on your profile directly.
- Erasure — delete your account. This permanently removes your profile, documents, uploaded files and login. It cannot be undone.
- Restriction — hide your public page without deleting anything.
If you are in the UK, EU or another region with data protection law, you also have the right to complain to your local supervisory authority.
How long we keep it
Your data stays until you delete it. When you delete your account, your database records and stored files are removed immediately. Backups held by our infrastructure providers roll off on their own schedule, typically within 30 days.
Children
Pomary is intended for people aged 16 and over. We do not knowingly collect data from anyone younger. If you believe a child has created an account, contact us and we will remove it.
Changes and contact
If this policy changes in a way that materially affects you, we will make that clear on this page and update the date at the top.
Questions, or want something removed? Email pomarydavid@gmail.com.