Privacy Policy

Last updated March 4, 2026

This Privacy Policy explains how Path collects, uses, and protects your information.

1. Information We Collect

We collect information you provide directly to us, such as:

  • Account details like name, email, phone number (optional), and username.
  • Profile content you choose to publish, including blog posts and projects.
  • Direct messages and contact form messages you send or receive.
  • Custom domain information you configure for your profile.
  • Resume files uploaded for AI import (processed and not permanently stored).
  • Images submitted for AI avatar generation.
  • Payment details for subscriptions (processed by our payment provider).

2. Information We Collect Automatically

We collect basic usage data to operate and improve the service, such as page views, device information, and approximate location based on IP address.

We may also collect:

  • IP address (used for security, rate limiting, and approximate geolocation).
  • User-Agent and device information.
  • Session identifiers.
  • Referrer information.

When you are signed in, profile views may be associated with your account to power identified viewer insights for Pro profile owners. Pro members can opt out from appearing by identity in account settings.

3. How We Use Information

  • Provide and maintain the service.
  • Process payments and manage subscriptions.
  • Power AI-powered features such as resume import and avatar generation.
  • Send transactional emails (onboarding, message notifications).
  • Provide analytics and viewer insights to profile owners.
  • Communicate with you about your account.
  • Improve product performance and reliability.
  • Detect, prevent, and enforce against spam, abuse, fraud, and other misuse.

4. Third-Party Services

We use trusted third-party services to help operate Path. Data is shared with these providers only as needed for them to perform their function:

  • Stripe for payment processing.
  • Google Gemini for AI features (resume extraction, avatar generation).
  • Tinybird, PostHog, and Google Analytics for usage analytics.
  • Resend for transactional emails.
  • PhotoRoom for image processing.
  • Vercel for hosting and file storage.
  • Supabase for database and authentication.
  • Upstash for rate limiting.

5. AI Features

When you use AI-powered features, your content (such as resume files or images) may be sent to third-party AI providers for processing. These providers handle data according to their own privacy policies. Uploaded files are not permanently stored after processing. AI-generated content is stored as part of your profile.

6. Sharing of Information

We do not sell your personal data. We share information with trusted service providers who help us operate the service, and only as needed for them to perform their work.

7. Data Retention

We retain information for as long as your account is active or as needed to provide the service. You can delete your account at any time.

Files such as avatars and images are deleted when replaced. Account deletion removes your profile and associated data; authentication records are cleaned up accordingly.

We may retain limited records after deletion where needed for legal compliance, dispute resolution, security, and prevention of spam, abuse, or fraud.

8. Security

We take reasonable measures to protect your data, but no system is completely secure. Please use a strong password and keep your account credentials safe.

9. Your Choices

You can update your profile information, manage privacy settings, or delete your account from your dashboard. Public profiles are visible to anyone with the link.

  • Opt out of identified viewer analytics in account settings.
  • Control messaging and contact form availability.
  • Control whether your profile appears in search and discovery.

10. Cookies

We use cookies and similar technologies to keep you signed in and to understand how the service is used. You can control cookies through your browser settings.

We also use localStorage and sessionStorage for caching and session management. Third-party analytics providers (PostHog, Google Analytics) may set their own cookies.

11. Email Communications

We send transactional emails for onboarding, direct message request notifications, and contact message notifications. We do not currently send marketing emails. Emails are delivered via Resend.

12. Children's Privacy

Path is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such data, please contact us so we can remove it.

13. Changes to This Policy

We may update this policy from time to time. We will reflect changes by updating the date above or by providing additional notice when appropriate.

14. Terms

Your use of Path is also governed by our Terms of Service.

15. Contact

If you have questions about this policy, please contact us through the support channels available on the site.