Privacy Policy & DPDP Act Notice
Last Updated & Effective Date: August 24, 2026 | Version 2.4 (Statutory Indian & Global Compliance Edition)
1. Operating Entity & Statutory Corporate Details
This Privacy Policy and Statutory Notice is published pursuant to Section 43A of the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and Sections 5 & 6 of the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023).
2. Zero-Backend Privacy Architecture (How We Protect You)
Unlike traditional recruitment portals that monetize candidate profiles or aggregate personal information in persistent cloud databases, ZenScout AI is engineered with a strict Zero-Backend Privacy Architecture:
- No Persistent Database Storage: We do not store or persist your resume, contact number, employment history, or work projects in any centralized database.
- Local Browser Memory: Your uploaded PDF resume, target roles, and application records exist strictly in your browser's private local storage.
- Stateless AI Ingestion: When evaluating ATS match compatibility, drafting cover letters, or conducting voice mock interviews, data is encrypted via TLS 1.3 to Google Gemini 2.5 Flash API endpoints, processed statelessly in memory, and immediately discarded.
3. Itemized Notice & Consent Architecture (DPDP Act, 2023 - Sections 5 & 6)
In compliance with Section 5 of the DPDP Act 2023, we provide notice of the categories of digital personal data processed and their specific, limited purposes:
| Data Category | Specific Purpose | Storage Location & Retention |
|---|---|---|
| Resume PDF & Work Profile | Calculating ATS score, custom letterhead generation, and mock interview context | Client-Side LocalStorage only. Erased on cache clear. |
| Job Search Query & Location | Fetching live job listings from Google Jobs / SerpApi | Ephemeral API request. Never linked to identity. |
| Contact Inbound Inquiries | Customer assistance, feedback ticketing, and technical support | Encrypted Email dispatch to aneevarpsolutions@gmail.com. |
| Authentication Profile | Single Sign-On (SSO) and binding Pro subscription tier | Encrypted Firebase Auth session token. |
4. Data Principal Rights (DPDP Act 2023 - Sections 11, 12, 13 & GDPR)
As a Data Principal under Indian law and international privacy frameworks, you possess complete autonomous statutory rights:
5. Google AdSense, DoubleClick Cookies & 100% Ad-Free Guarantee
For free tier users, this website partners with Google AdSense (Google LLC) to display contextual advertisements.
- Google and its certified ad vendors use cookies, web beacons, and device identifiers to serve ads based on prior website visits.
- 100% Ad-Free Guarantee for Pro Users: Upon activating any ZenScout Pro subscription, our platform automatically unmounts all Google AdSense scripts and completely suppresses all display advertising.
- You can manage personalized ad preferences via Google Ads Settings or AboutAds.
6. Statutory Grievance Redressal Officer (IT Rules 2021 / 2023 & DPDP Act)
In compliance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Section 13 of the DPDP Act, 2023, the details of the designated Grievance Officer and Data Protection Officer (DPO) are published below:
7. CERT-In Cyber Security & Vulnerability Reporting Desk
Pursuant to the CERT-In Cyber Security Directions (2022) issued by the Indian Computer Emergency Response Team (Ministry of Electronics and Information Technology, MeitY), we maintain a dedicated Vulnerability Reporting Desk for security researchers.
If you discover any security anomaly, rate-limit flaw, or vulnerability, please report it immediately to our security response desk at aneevarpsolutions@gmail.com.