Trust Center
This page is maintained by Oveus Career Accelerator to answer common security and privacy questions about Oveus. It describes the controls currently enabled in our application and the platform features we rely on. It is not an independent certification, audit, or attestation, and it is not endorsed by any third party.
Related pages: Privacy & Security notice · Terms of Service · Submit a request
Last updated: August 2026
Who can use the platform
Oveus supports these account roles: students, employers (organizations posting opportunities), career coaches, principals, school administrators, student support contacts, and platform administrators. Features such as posting opportunities, applying, reviewing applicants, managing cohorts, and approving accounts are restricted by role.
Staff accounts do not self-activate. A staff signup creates a pending request that must be approved by a platform administrator or an authorized school leader, and approvals are bounded: a principal cannot approve platform administrators, and a school administrator can only approve staff within their own school.
Accounts & access control
- Sign-in is provided through email and password and through Google sign-in.
- New and changed passwords are checked against a known-breached password database.
- Sessions are managed by our backend provider and stored in your browser; signing out clears your session, and you can sign out of all devices from your profile.
- Roles are stored server-side in a dedicated roles table — never on the user profile — and are enforced through database access policies, not just in the user interface.
- Only platform administrators can grant or revoke administrator access.
- Privileged actions — role changes, employer approval decisions, and administrative edits — are written to an audit log that ordinary users cannot modify.
Student data visibility
- Students see and edit only their own profile, applications, saved items, goals, and reflections.
- Career coaches, principals, school administrators, and support contacts see student information only for the schools they are approved for.
- School scope is stored server-side; changing the interface or a URL does not widen it.
- Cohort reporting shown to staff is participation-focused and scoped to their approved schools.
Employer data visibility
- Employer accounts are reviewed before postings become visible to students, and approval status can be suspended.
- Employers see a limited applicant view: name, grade level, RIASEC theme, about-me, and resume.
- Employers see only students who applied to their own opportunities — there is no student directory browse, and no access to other employers' applicants.
- Employer contact details are column-restricted at the database layer so they are not broadly readable by other accounts.
- Employers may not request sensitive documents through Oveus, and may not export, resell, or market to student information.
Data we collect
The application stores the information you provide so it can power your profile, applications, and posts:
- Student profiles: name, email, headline, bio, school, grade level, GPA, interests, skills, RIASEC career themes, and uploaded resume.
- Employer profiles: organization name, industry, website, location, description, contact, and ownership.
- Opportunities & applications: postings created by employers and the applications students submit, including optional cover notes and status history.
- Career development content: goals, reflections, journal entries, academic plan and course selections, saved careers and colleges, and progress in interactive career experiences.
- School roster data: when a school or coach uploads a cohort roster, it may include student name, email, grade level, and school assignment.
- Security data: sign-in events and audit records of privileged actions.
Database access is governed by row-level security so students see their own records, employers see applicants for their own opportunities, staff see students at their approved schools, and administrative views are reachable only from the admin area.
For the full breakdown of purposes, legal basis, sharing, and your rights, see the Privacy & Security notice.
Resumes & file uploads
Resumes and generated success-plan exports are stored in access-controlled storage that is not publicly listable. Students upload their own resume and can replace or remove it from their profile at any time. Employers can only access resumes attached to applications submitted to their own opportunities.
When a student shares a success plan with someone outside the platform, the recipient must confirm a one-time code sent to their email, and each access attempt is recorded for the student.
Platform & hosting
Oveus runs on the Lovable Cloud platform. Application code is served from a managed edge runtime, and authentication, database, and file storage are provided by the underlying managed backend. Traffic is encrypted in transit with HTTPS/TLS, and data is encrypted at rest by the infrastructure provider. Privileged server credentials exist only in the server runtime and are never shipped to the browser. Describing these capabilities is a factual statement about the platform we build on — it is not a certification of Oveus.
Cookies, analytics & subprocessors
The application uses cookies and browser storage strictly to keep you signed in and to remember preferences such as language and atmosphere effects. We do not use advertising cookies or cross-site tracking. We rely on the following providers and data sources to operate the service:
- Hosting, database, authentication & storage: our managed backend provider.
- Google Sign-In: used only when you choose to sign in with Google.
- Email delivery: a managed sending service used for account, approval, sharing, and notification emails.
- Managed model gateway: powers Oveus Insights features such as recommendations, coaching feedback, and content extraction; only the minimum context required for the feature is sent.
- Public data sources (read-only): U.S. Bureau of Labor Statistics wage data, the U.S. Department of Education College Scorecard, and Maryland apprenticeship listings. No personal information is sent to these sources.
Retention & deletion
Account and career data is kept while the account is active and while the school's program continues. You can delete your own reflections, goals, applications, and saved items at any time. Account deletion requests are honored except where a school or law requires retention. Security and audit records, and email suppression records for people who unsubscribed or bounced, are kept longer because they exist to protect accounts and honor opt-outs. Aggregate, de-identified reporting may remain after individual data is removed.
Privacy requests
Students, families, staff, and partners can request a copy of their data, a correction, or deletion using our request form. We confirm receipt by email and aim to respond within 30 days. Where a school provided the data, we coordinate with the school before acting.
Reporting a security issue
Good-faith security research is welcome. Report findings through the request form using "Report a security issue," and include enough detail to reproduce. Please do not access, modify, or retain other people's data, avoid automated scanning that degrades the service, and give us reasonable time to remediate before public disclosure. We do not pursue researchers who follow these guidelines.
Your choices
- Update or remove information from your profile at any time, including your resume.
- Withdraw an application from the tracker.
- Reduce or disable environmental animations from your profile preferences.
- Unsubscribe from non-essential emails using the link in any message; account and security emails still send.
- Request access, correction, or deletion through the request form.
Shared responsibility
- The platform provider operates the underlying hosting, database, authentication, and storage infrastructure.
- Oveus Career Accelerator configures the application controls, access policies, role boundaries, and content described on this page.
- Schools and staff are responsible for the accuracy of roster data they upload and for using student information only to support students.
- Employers are responsible for accurate, lawful postings and for handling applicant information appropriately.
- Account holders are responsible for keeping their credentials secure and their information accurate.
Contact
Questions about this page, your data, or a security concern? Use the request form and we'll route your request to the right person. Please include enough detail for us to find your account without sharing your password.
We do not claim compliance with SOC 2, ISO 27001, HIPAA, PCI DSS, or any other certification or regulatory framework, and nothing on this page should be read as such a claim. This page describes our current practices and may change as the platform evolves.
