VULTURE

Privacy policy

Vulture is local-first. This page says exactly what leaves your device, when, and why. Last updated 6 September 2026.

Local profiles

Without an online account, everything (résumés, applications, notes, settings, AI keys you enter) stays in your browser's storage or the desktop app's storage, encrypted with your passphrase. Nothing is uploaded. Clearing the browser removes it; export a backup from Settings first.

Online accounts

With an online account, your profile data is encrypted on your device and the encrypted copy is stored on our database host (Supabase) so your other devices can fetch it. We also store your username, display name, email address, permissions, the plan's dates, and the counts described below. Your AI keys and Apify tokens never reach the server; they are used from your device.

What the server records

Who else is involved

Supabase (database and sign-in), Render (hosting), Razorpay (payments), Resend and Brevo (transactional email). When you use shared resources, your queries reach Tavily (web search), Apify (scraping) or the model provider behind a pro model. When you use your own keys, your requests go straight from your device to that provider under its terms. Job postings come from public boards and company career sites.

Cookies and storage

The app uses browser storage for your data and preferences and a signed session token for online accounts. The admin panel uses a cookie for its own sign-in. There is no advertising and no third-party tracking.

Retention and deletion

Synced data stays while the account exists. Activity and prompt logs rotate at a fixed size; the email log is pruned after 90 days; unpaid orders after 30 days. To delete an online account and everything stored with it, email gixts@hrsraiden.com from the account's address; payment records are kept as the law on accounts requires.

Contact

Questions about anything on this page: gixts@hrsraiden.com. Vulture is made by Harsh Sharma (hrsraiden) under Gixts Labs, India.