WormioSign in

Effective August 29, 2026 · Last revised September 5, 2026

Privacy Policy

Wormio reads your resume in order to rank jobs for you. This page describes exactly what that means: what is stored, who else sees it, and how to get rid of it.

The short version

  • Your resume is stored as text and used to match you against job postings. Nothing else.
  • If you upload a PDF, the text is extracted and the file itself is discarded. It is never stored.
  • Your resume text is sent to Anthropic and OpenAI, which do the matching. Under their API terms, they do not train on it.
  • There are no analytics, no advertising, and no third-party trackers anywhere on this site.
  • Nothing is sold, and nothing is shared for advertising.
  • Deleting your account deletes your data, from the account page, immediately, without asking anyone.

The rest of this page is the detail behind those six lines. Where a claim below can be checked against the running system, it was written by checking it.

What is collected

Only what the product needs to run. There is no background collection, no enrichment from data brokers, and no profile assembled from anything you did not type in.

If you join the waitlist and never get an invite, the only thing held is your email address and the date you submitted it.

If you start creating an account and never confirm your email, the same is true, and the retention section below says what happens to it.

If you have an account, that grows to:

  • Account basics: your email address, your time zone, the hour you want the digest, and whether you want digest email at all.
  • A record that you accepted these agreements: which version, and when. Kept because it is the evidence the agreement exists, and it cannot be edited from your account.
  • Your resume: the text you pasted, or the text extracted from a PDF you uploaded.
  • A condensed profile derived from your resume, generated once and reused, plus a numeric embedding of it used for matching.
  • Your stated preferences: target locations, keywords, seniority levels, work arrangement, and your match threshold.
  • The companies whose job boards you asked to track.
  • Your digest history: which postings you were shown, the score and reason each was given, and whether you saved or dismissed it.
  • Your theme choice (light, dark, or system), saved to your account and mirrored to a cookie so the page does not flash the wrong colors while loading.
  • Operating records of what each daily run cost, in tokens and dollars.
  • A scrambled form of your email address, stored with the date, so that deleting your account and signing up again does not hand out another free first digest. It is a one-way hash: the address cannot be read back out of it, and nothing else is kept alongside it.

Your password is never stored, and is not visible to the operator. Authentication is handled by Supabase, which stores a one-way hash. There is no way to read your password back out of it.

Your resume specifically

This is the sensitive part, so it gets its own section.

When you upload a PDF, it is parsed in memory on the server, the text is pulled out, and the text is what gets saved. The PDF file is not written to disk and not uploaded to any file store. There is no bucket it could be sitting in, because the project does not provision one.

Your resume text is then condensed once into a short profile summary, and that summary is what the daily run actually uses. This is a cost optimization rather than a privacy feature, but the privacy effect is real and worth stating: your full resume text goes to a model provider one time, when you first upload it. After that, the daily ranking works from the condensed profile.

Your resume is not shown to other users, not shown to employers, and not sent to any company whose board is tracked. Wormio reads public job boards and brings them to you. It never sends you to them. No employer learns that you exist, that you are looking, or that their posting was ranked for you.

What it is used for

  • Matching open job postings against your resume and preferences, and scoring them.
  • Assembling and delivering your daily digest, in the app and by email if you want it.
  • Not showing you the same posting twice.
  • Keeping your account working: signing you in, sending password resets, and honoring your settings.
  • Understanding what the service costs to run, so it can keep running.

That is the complete list. Your information is not used to build a product for anyone else, not aggregated into a dataset for sale, and not used to market anything to you beyond the digest you asked for.

Who else processes your information

Wormio is a small service built on other companies' infrastructure. These are all of them, and everything each one receives:

CompanyRoleWhat it receives
SupabaseDatabase and authenticationEverything stored: your account, resume text, preferences, and digest history.
VercelApplication hostingRequests you make to the site, including your IP address, as any web host does.
AnthropicResume condensing and job rankingYour resume text once, then your condensed profile and stated preferences each day, alongside the job postings being scored.
OpenAIEmbeddings for matchingYour condensed profile and the text of job postings.
ResendEmail deliveryYour email address and the contents of the messages sent to you.
CloudflareDNS and email forwardingNetwork-level request data, and mail sent to the contact address on this page.

Anthropic and OpenAI both state in their commercial API terms that inputs submitted through the API are not used to train their models. Wormio has not opted into any program that would change that, and has no arrangement with either company beyond ordinary paid API access.

There is no one else. No analytics provider, no error tracker, no advertising network, no session recorder, no customer data platform. You can confirm the absence of front-end trackers yourself by opening your browser's network tab on any page of this site.

What is never done

  • Your personal information is not sold, and has never been sold.
  • It is not shared or disclosed for cross-context behavioral advertising.
  • It is not used to train any machine learning model, by Wormio or by anyone Wormio sends it to.
  • It is not disclosed to employers, recruiters, or job boards.
  • You are not tracked across other websites.

The one exception to non-disclosure is legal compulsion: a valid subpoena, court order, or comparable legal process. If that ever happens and the law permits telling you, you will be told.

Cookies

Two kinds, both strictly functional:

  • Session cookies set by Supabase, which are what keep you signed in. Without them there is no way to have an account.
  • A theme cookie mirroring whether you chose light, dark, or system. The choice itself is saved to your account; the cookie exists so the page does not flash the wrong colors before it loads.

There are no advertising cookies and no analytics cookies, which is why this site has no cookie consent banner. There is nothing to consent to beyond the cookies that make signing in work.

How long things are kept

While your account exists, your information is kept, because the product does not work without it. When you delete your account, it goes.

Deletion happens from the account page and takes effect immediately. It is not a request that gets reviewed. It removes your login, your profile, your resume text and its derived profile and embedding, your preferences, your tracked companies, and your entire digest history. Almost all of that goes in one cascading database operation; the record of the invite your account was created through sits outside that chain and is removed by a separate step in the same request.

Three honest caveats about what survives:

  • Operating cost records (how many tokens a run used, and what it cost) are kept, with the link to you severed. What remains is a row saying a run of some size happened on some date, attached to nobody. This is how the service tracks its own running costs over time.
  • Ordinary infrastructure logs and email delivery records held by the providers above expire on their retention schedules, not on Wormio's. This is true of every hosted service, and there is no mechanism to reach into a provider's logs and purge a single user.
  • The scrambled form of your email address described above outlives the account on purpose, because its whole job is to recognize a repeat signup. It is a one-way hash and a date, it is not linked to anything else once the account is gone, and it cannot be turned back into your address or used to contact you.

Waitlist entries are a separate case, because there is no account to delete. A waitlist email address is kept until an invite is sent or you ask for it to be removed. To have it removed before then, email hello@wormio.app.

An unconfirmed signup is the other separate case, for the same reason: deletion runs from a page you cannot reach until you confirm. Two things are held in that state, and both hold nothing but your email address, because nothing else about you exists yet. The authentication service keeps the unconfirmed account, which does not expire on its own. Beside it sits the short-lived permission slip that let the signup past the invite gate, and confirming your email spends and deletes it. If you never confirm, that slip is cleared no sooner than 30 days later, by a sweep that runs on the next signup rather than on a clock. To have an unconfirmed signup removed before then, email hello@wormio.app.

Your choices

  • See and correct your information: your resume, preferences, and settings are all editable in the app, and what is shown there is what is stored.
  • Turn off digest email: use the toggle on your account page, or the unsubscribe link in the footer of any digest. Unsubscribing stops the email and leaves your in-app feed alone.
  • Delete everything: the account page, any time, no explanation required.
  • Ask a question or make a request another way: email hello@wormio.app.

Requests sent by email get a response, and identity is verified before acting on one, which in practice means the request has to come from the address on the account. This is a small operation run by one person, so the honest expectation is days rather than minutes.

California residents

If you live in California, the CCPA as amended by the CPRA gives you the rights to know what is collected about you, to get a copy of it, to correct it, to delete it, and to opt out of sale or sharing. The sections above describe how to exercise the first four, and they apply to everyone rather than only to California.

On the fifth: Wormio does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined in the CCPA. It has not done so in the preceding twelve months. There is no opt-out link because there is nothing to opt out of.

You will not be discriminated against for exercising any of these rights. There is no premium tier that costs more for asking, because there is no premium tier.

The categories in the statute's vocabulary: identifiers (your email address), professional or employment-related information (your resume), and inferences drawn from it (the condensed profile and match scores). Each is collected directly from you, used for the purposes in the section above, and retained per the retention section.

Security

  • Every table holding user data is protected by row-level security in the database, so one user's query cannot reach another user's rows even if the application layer has a bug.
  • Passwords are hashed by Supabase and are not recoverable by anyone, operator included.
  • Access is invite-only, so the set of people with accounts is a set that was deliberately let in.
  • Traffic is served over HTTPS.

None of this is a guarantee. No online service can promise it will never be breached, and one that does is not being straight with you. If a breach affects your information, you will be notified at your account email address.

Where this happens

Wormio is operated from the United States, and the providers listed above process data in the United States. If you use it from elsewhere, your information is being handled in the US, under US law.

This service is built for US users and is not currently offered in the European Economic Area or the United Kingdom, and it is not set up to meet GDPR obligations.

Children

Wormio is not for anyone under 18, is not directed at children, and does not knowingly collect information from them. If you believe a minor has created an account, write to the address below and it will be deleted.

Changes to this policy

Two kinds of change happen to this page, and they are treated differently. A correction or a clarification, where what the system does has not changed or where this page was describing it imprecisely, updates the "last revised" date at the top and nothing else. Those are expected to be routine, because this document is checked against the code and fixed when it drifts.

A material change is one that changes what happens to your information: a new use for it, a new company that receives it, a longer time it is kept. That moves the "effective" date at the top, notice goes to your account email address before it takes effect, and you will be asked to accept the new version the next time you sign in.

Until you accept it, nothing is processed for you. The daily run skips your account entirely, so no part of your resume or profile is sent to the providers listed above and no digest is sent to you. The account page stays reachable throughout, so turning off email or deleting the account never requires agreeing to the new version first.

Contact

Questions about privacy, requests about your data, or anything on this page: hello@wormio.app. It reaches Anthony Arellano, who is the person who built this and the only person who reads it.