| TEST ENVIRONMENT -- test.1995.lol -- not the real site |
1995 Privacy Policy
Effective date: 2026-09-14. Version 2026-09-14.
|
1995 home | Terms of Service | The editor
This Privacy Policy explains what 1995 collects about you, why, who sees it, how long it is kept, and what you can do about it. It applies to the public home pages at https://1995.today/~username/, the editor at https://app.1995.today, and every email the service sends. It should be read together with the 1995 Terms of Service at https://1995.today/terms.html. The current version of this Policy is always at https://1995.today/privacy.html.
It is written for the person who uses the service. Where a legal term is needed, it is explained the first time it appears.
1. Who we are and how to reach us
1995 is operated by Undiscovered Tech, LLC (in this Policy, "1995", "we", "us" or "our"). For the purposes of the GDPR, the UK GDPR and similar laws, Undiscovered Tech, LLC is the controller of the personal data described in this Policy, which means we decide what is collected and why. To the extent the California Consumer Privacy Act applies to us, we are the business.
- Email: support@undiscoveredtech.com (put "Privacy" in the subject line so it is routed quickly)
- Postal address: 7824 Calico Flower Ave, Las Vegas, NV 89128, United States
Use the email address above for privacy requests, questions and complaints. Copyright infringement notices and counter-notices under the DMCA go to our designated agent, whose details are the same here and in Section 14.1 of the Terms of Service:
Copyright Agent, Undiscovered Tech, LLC
7824 Calico Flower Ave, Las Vegas, NV 89128, United States
Phone: 512-521-4106
Email: support@undiscoveredtech.com (put "Copyright" in the subject line)
[OWNER TO CONFIRM: register the same name, postal address, phone number and email with the U.S. Copyright Office DMCA Designated Agent Directory at dmca.copyright.gov, keep the registration current, and keep this copy and the one in Terms Section 14.1 identical. The safe harbor depends on it.]
The notice, counter-notice and repeat-infringer procedure is in the Terms of Service at https://1995.today/terms.html.
2. The short version
This summary is for orientation only. It is not binding. Sections 3 to 18 are the Policy; where this summary and those sections differ, the sections govern.
- Your page is public. All of it. Everything you publish on 1995 is a website on the open web, at a URL anyone can visit, copy, save, cache and index. That includes your username, your page content, your photos, your news posts, your friends list, approved guestbook entries and your hit count. It is your website and you are responsible for it. Once something is out, we cannot pull it back from other people's copies.
- Your first page goes live automatically the moment the AI finishes. You review it afterwards, not before.
- The first page is published without the contact-detail filter. If your resume contains an email address, phone number or address in its running text, the AI can copy it onto the first page. Check the page as soon as it is live.
- We collect what we need to run the service: your email address (there is no password), the resume you upload, the text and structured profile we extract from it, the site content you write, mail and guestbook entries sent to you, friend requests and blocks, and a small amount of technical data for rate limiting, abuse prevention and the hit counter.
- The text of your resume is sent to a third-party AI provider, Fireworks AI, to extract facts and draft your page copy. Your email address and username are not sent. The resume text goes as written, including any contact details you put in it.
- We will not use your resume for a job-search or recruiter product unless you opt in.
- We host on Amazon Web Services in the United States and use Cloudflare Turnstile to check that sign-ins and uploads come from a person.
- We do not sell your data. We do not share it with advertisers. We run no analytics or advertising cookies. Public pages set no cookies at all. The editor sets one strictly necessary session cookie.
- Free pages carry one advertising slot. Ad clicks are counted per campaign, not per person.
- Today we send three kinds of email: sign-in links, relays of mail sent to you through your page, and friend request notices, plus any service notice this Policy or the law requires. No newsletters.
- You can export your data as a JSON file and delete your account from the Account screen in the editor. Deletion removes your content from the live service, normally within minutes. Your username is held for 30 days, then released. Your account email record is held for 30 days, then removed. One internal lookup record keeps your former username; we remove your email address from that record by hand within 30 days of your deletion (Section 10.2). Some other copies last longer, and Sections 9 and 10 list them plainly.
- You must be at least 18, or the age of majority where you live, whichever is higher. The service is not for children, and we do not knowingly collect data from anyone under 13.
3. What is public
This is the most important section of this Policy. Read it before you upload.
3.1 Your page is a public website
When your page is published, 1995 writes static HTML files to a public web host at https://1995.today/~username/. Anyone on the internet can read them without an account. Your first page is published automatically. When your one AI generation finishes, the generated home page, your friends page, your resume page when your profile contains positions, education or skills, and any other page the generator creates (for example a news page) go live at https://1995.today/~username/ at once, with no separate publish step and before you have seen them. Uploading your resume is your instruction to publish what the AI produces from it. You agree to this in the Terms of Service (https://1995.today/terms.html), which you accept when you claim your username, before you can upload a resume. The agreement box on the username claim screen reads "I have read and agree to the Terms of Service, I have read the Privacy Policy, and I understand that everything I publish on 1995 is public", and the upload screen states again, above the file picker, that your page goes live at your address before you have seen it, with an "I understand" box you must tick before you can upload. If you do not want that draft public, open the editor as soon as the job completes and change or remove it, or delete your account.
There is no login, no privacy setting, and no "friends only" mode. Search engines and other crawlers can index your pages. Other people can copy, screenshot, archive, quote or cache them. You are the publisher of that website and you are responsible for what it contains. Read what the AI wrote as soon as it is live, and read what you add before you save it. If you would not want a stranger, a recruiter, or a future employer to see it, take it off. The Terms of Service describe your responsibilities in their own words.
3.2 What is on the public page
The following is public once it is published (your first version is published automatically, Section 3.1), and stays public until you change it, delete it, or delete your account:
- Your username and your page URL (https://1995.today/~username/). The URL is also part of every link, share image and friends list that points at you.
- Everything on your home page and any custom pages you create: headings, paragraphs, lists, tables, links, images, and any photo you upload (served at https://1995.today/~username/<id>.gif).
- Your resume page (https://1995.today/~username/resume/), generated whenever your profile has any positions, education or skills. It prints your name, headline, summary, location text, positions, education, skills, certifications, languages, interests and links.
- Your news page (https://1995.today/~username/news/) and every news post you have not marked as a draft. Post dates are real dates.
- Your friends page (https://1995.today/~username/friends/). A friends page is published for every site. It lists the username of every friend you have accepted, linked to their page. Friendships are therefore public in both directions, and the whole friends graph can be assembled by anyone who crawls it.
- Your guestbook, served from https://app.1995.today and linked from your page, readable by anyone without an account (Section 3.4). Only entries you have approved appear. An approved entry shows the signer's username linked to their page, or their profile display name if they have no username, or "A friend of the net" if they have neither, plus the entry text.
- Your hit counter, if your page includes one: a running count of views, with repeat views by the same visitor on the same day counted once (Section 4.10).
- A share image (https://1995.today/~username/og.png) generated from your stored profile and site, showing your name, page title, first paragraph and up to two positions. It can exist as soon as your profile has been generated.
- A footer with the real date your page was last updated.
- One advertising slot on each public page (Section 4.11). There is no setting to turn it off in the current version.
3.3 What is never printed on the page
Check the first generated page for contact details as soon as it is live, and remove any you find.
The email address and phone number fields of your profile are never printed on your public pages, whatever your resume contains, and the AI is instructed to leave phone numbers and street addresses out of everything else it writes. That protection covers those fields only. Contact details that end up in ordinary text, whether the AI copied them into your summary or home page copy or you typed them into a block, are covered only by the best-effort filter described below, which runs when you save in the editor and not on the first generated page, and they may appear on your page. Contact reaches you through the mail form on the app origin, and the sender must be a signed-in member.
When you save your profile, site content, news posts, mail, guestbook entries and friend-request notes, we run a filter before storing them that removes text that looks like an email address, phone number or postal address and replaces it with "[removed]". Links to email addresses (mailto:) are refused outright.
This filter is a best effort. It uses patterns and can miss things, particularly numbers without context, spaced-out or unusual formats, and some international formats. It is not a substitute for your own judgement. If you type personal information into your page and it gets through, it is public, and you are responsible for it.
3.4 Public forms on the app origin
The "Send me mail", guestbook and "Be my friend" pages are served from https://app.1995.today. The guestbook page and the friend-request page can be read by anyone. The mail form asks visitors who are not signed in to sign in first.
3.5 We cannot recall public content
Once a page has been served, copies may exist in browser caches, search-engine indexes, web archives and on other people's computers. When you edit or delete content, or delete your account, we update or remove our copy and ask our content delivery network to drop its cached copies. We cannot make anyone else delete theirs, we cannot remove your page from search engine results or web archives, and we do not promise that a change propagates immediately. In particular, the share image at https://1995.today/~username/og.png is cached for up to 24 hours, so link previews on other sites can show the previous version for up to a day after you edit or delete. Do not publish anything you would not be comfortable seeing on the open internet indefinitely.
3.6 After deletion, the URL still exists
When you delete your account, your pages are removed and replaced with a plain notice reading "This home page has been removed." at https://1995.today/~username/. That notice can stay indefinitely. Thirty days after deletion your username becomes available again, once our database's expiry process releases the hold, normally within a few days of the 30-day mark, and another person may claim it and publish at the same URL.
3.7 What other members can see about you
- When you send mail through someone's page, the recipient sees your username (or "A 1995 member" if you have none), your display name and your message. Your email address is not shown to them, is not stored with the message, and is not used as the reply address; replies go back through the Mail screen in the editor.
- When you sign a guestbook, the owner and, if they approve the entry, the public see your username or display name. Your email address is stored with the entry so that you can find and export your own entries. It is not shown on the public page, it is not shown on the owner's moderation screen, and it is not included in the owner's JSON data export of their guestbook, which is stripped of it before the file is built. The owner sees your username only.
- When you send a friend request, the recipient sees your username and your note, on the site and in the notification email.
- When you become friends, your username appears on the other person's public friends page and theirs on yours.
- When you block someone, they are not told, and if someone blocks you, you are not told. Neither of you can then send the other mail, sign the other's guestbook or send a friend request; the blocked person sees the same response as if their message had been delivered. You accept this in the Terms of Service (https://1995.today/terms.html), which state that messages, guestbook entries and friend requests may not be delivered and that the service will not tell you why.
4. What we collect and why
This section lists what we collect. We have tried to make it complete, and if we find that we have left something out we will add it here. Not listed individually are the operational records our hosting provider keeps about how the service runs, such as metrics and change streams, which do not identify you beyond what Sections 4.12 and 9.3 describe. Where a category comes from another member (for example, mail sent to you), we say so.
4.1 Email address
- What: the email address you sign in with. It is your account identifier. There is no password.
- Why: to send you sign-in links, to relay mail sent through your page, to notify you of friend requests, to identify your account for support, export and deletion, and to enforce our rules (a banned address stays on record so it cannot re-register).
- Detail: an account record is created the first time a sign-in link is requested for an address, before the link is clicked. It holds the email address, an internal account identifier, the date it was created, whether the one free generation has been used, which version of the Terms of Service and this Policy you agreed to and when you agreed (recorded when you tick the agreement box on the username claim screen or when you re-accept an updated version) and, if applicable, moderation status and email-delivery status (Sections 4.14 and 8.4). If you ask for a link and never use it, the record still exists. To remove it, sign in and delete the account, or email us (Section 11). If someone else entered your address and you never asked for a link, you do not need to sign in to have the record removed: email us from that address and we will delete it, unless the record carries a ban (Section 4.14) or a bounce or complaint mark (Section 8.4), which we keep for the reasons given there.
4.2 Username
- What: the username you claim. It becomes part of your public URL and is published on every page, link and list that points at you.
- Why: to address your site and to identify you to other members.
- Detail: usernames cannot be changed in the current version of the service. Friendships and blocks use your internal account identifier rather than your username, so that a username claimed by someone else later does not inherit them.
4.3 Your resume and what we extract from it
- What: the file you upload (PDF, DOCX or TXT, up to 5 MB); the plain text we extract from it (truncated at 60,000 characters); and the structured profile the AI produces from that text (name, headline, summary, location, positions, education, skills, interests, certifications, languages, links, a persona label such as "engineer" or "designer" that selects your template, and first-person home page copy). Alongside the profile we store provenance data: which file it came from, a checksum, the model and prompt version used, token counts, latency, cost, and a grounding score that measures how much of the profile could be matched back to your source text. You cannot edit the provenance fields.
- Why: to build your page, to let you correct and edit the result, and to allow re-extraction with an improved prompt or model later without asking you to upload again. If we re-run extraction, your resume text is sent to the AI provider again as described in Section 6.2, and we will update this Policy and tell you before doing so.
- Detail: the file is uploaded from your browser straight to a private storage bucket. The file and the extracted text are stored privately for as long as your account exists, are never published, never emailed, and never included inline in your export (the export contains a short-lived download link instead). If you want the original file and the extracted text deleted while keeping your page, email us at support@undiscoveredtech.com from your account address and we will delete them by hand; your profile and page are unaffected, though your export's resume download link will no longer work, in production the prior versions of those files expire automatically 30 days later as described in Section 9.3, and you would need to upload again for any future re-extraction feature. We do not currently use your resume for any purpose other than generating and maintaining your page. We will not use your resume, extracted text or profile for any other purpose, including a job-search directory, recruiter access, matching or similar products, unless you opt in to that use. We will update this Policy before offering such a feature, and not opting in will not affect your page. The extracted text is sent to a third-party AI provider; see Section 6. LinkedIn import works only from a PDF you export yourself; we never fetch linkedin.com. Uploading a resume also creates a job record (status, timestamps and any error) that we use to show you progress and debug failures.
4.4 Site content, news posts and photos
- What: everything you write in the editor, stored as structured data and published as HTML: your home page and custom pages, your news posts (including drafts, which are stored but not published), and any GIF photos you upload (up to 200 KB each).
- Why: to render and publish your site, and to enforce the limits of 100 images and 10 MB per site.
- Detail: photos exist in two places, the private data store and the public web host. We also keep usage counters for your account: number of images, bytes of assets and bytes of published HTML. Everything here is public once it is published (Section 3). Saving in the editor stores your latest copy and Publish rebuilds the public page from it, but Publish is not the only thing that does: posting news that is not a draft, accepting a friend request, ending a friendship, blocking or being blocked, a reinstatement after a takedown, and our own re-rendering for a template or core-element change all rebuild the public page from whatever you last saved, with no Publish step. The share image is drawn from the saved copy directly. Treat a saved change as publishable at any moment; the editor is not a private draft space. Terms of Service Sections 4.4 and 4.6 say the same.
4.5 Mail sent through your page
- What: when a signed-in member uses the mail form on your page, we store the message (after the contact filter), the sender's display name and username, the time, and whether you have opened it (the Mail screen marks messages read).
- Why: to deliver the mail, to show you your inbox, and to enforce daily sending limits.
- Detail: the relayed email is sent from our noreply address, names the sender by username only, and links to your Mail screen, where you can reply. Neither party's email address is shown to the other. Messages received before 2026-09-14 may still hold the sender's address in our database; it is no longer displayed or exported and is removed when your account is deleted. A message you send lives in the recipient's account, not yours; if you delete your account, messages you sent stay in the recipients' inboxes. If your address has bounced or complained (Section 8.4), the message is still stored in your inbox but no email is sent.
4.6 Guestbook entries
- What: entries written on your guestbook (the signer's username and display name, the signer's account email address, the entry text after the contact filter, a moderation status of pending, approved or hidden, and timestamps), and a reverse index of entries you have written on other pages.
- Why: to let you moderate your guestbook (approve, hide, delete) and to let signers find and export their own entries.
- Detail: the signer's email address is stored with the entry so that the signer can find and export their own entries and so that we can find them; on account deletion we remove the index that lets us find them, but the address remains on each entry. It never leaves our systems as the page owner's data: it is not shown on the public page, not shown on your moderation screen, and not included in your JSON data export of your guestbook (Section 11), which carries the signer's username and display name only. Every new entry starts as pending and appears nowhere until you approve it. Hidden and pending entries are kept until you delete them. If you delete your account, entries you wrote on other people's guestbooks remain there; they are part of that page owner's guestbook and under that owner's control once left.
4.7 Friend requests, friendships and blocks
- What: friend requests you send and receive (who sent it, who received it, an optional note of up to 200 characters after the contact filter, the status, and timestamps); accepted friendships, mirrored on both accounts; and blocks you create (the blocked account's identifier and username, the time, and an optional reason of up to 200 characters that is stored only on your side). Being blocked by someone creates a record on your account naming the blocker's identifier and username but not their reason; it is never shown to you.
- Why: to run the friends feature, to publish your friends page, and to stop people you have blocked from reaching you.
- Detail: requests that were declined, cancelled or accepted are kept as records. If you block someone, they can no longer send you mail, sign your guestbook or ask to be your friend, and you can no longer do those things to them either; a block cuts off contact in both directions. To protect people who block for their own safety, a blocked person is shown the same response as anyone else and is never told that a block exists; nothing is stored, sent or counted. Blocking is not retroactive: content already left on your page stays until you remove it. Your block list is private to you, and the list of who has blocked you is never shown to anyone, including you. If you delete your account, the copies of these records stored on your friends' and blockers' accounts are not removed by the deletion job (Section 10.2).
4.8 Usage limits and usage counters
- What: whether your one free AI generation has been used; your image count and site size; the status of your generation job; your page view count; and short-lived daily counters keyed by your email address or username: messages sent, messages sent to a given recipient, messages received, guestbook signatures made, guestbook signatures on a given page, friend requests sent, and friend-request notification emails sent.
- Why: to enforce the one free generation, the storage caps (100 images and 10 MB per site) and the daily limits, which keep the service affordable and reduce spam: 10 messages sent per day, 3 per day to the same recipient, 10 received per day, 5 guestbook signatures per day and 1 per guestbook per day, and 20 friend requests per day.
- Detail: each daily counter expires within two days.
4.9 IP address and user agent, briefly
We use your IP address in three places, and in each case we keep it only briefly or not at all:
- Sign-in rate limiting. We count sign-in link requests per IP address in hourly buckets (20 per hour) and per email address (5 per hour). Each bucket expires one hour after it is written.
- Bot check. When you ask for a sign-in link or start a resume upload, we send your IP address to Cloudflare together with the Turnstile token so Cloudflare can verify it (Section 7.3).
- Hit counter. Described in Section 4.10. The counter discards the IP address after hashing.
The IP address is not otherwise stored by the application. Separately, infrastructure access logs record the IP address and user agent of every request; see Section 4.12.
4.10 Hit counter (no IP address stored)
- What: when anyone views a page that includes a hit counter, we compute a one-way hash of a secret daily salt, the viewer's IP address and the viewer's browser user agent, and keep only a truncated version of that hash for 24 hours against the page owner.
- Why: so the same viewer is not counted twice in one day.
- Detail: the IP address and user agent are discarded after hashing and are never stored or logged by the counter. The hash is designed so that the IP address cannot be recovered from it. At most, someone holding that day's secret salt could confirm whether a specific IP address and browser pair they already knew had visited that day, and because the salt changes daily, hashes from different days cannot be linked. The public number is the page's running count of views. The request for the counter image passes through our CDN like every other request and appears in the CDN access logs described in Section 4.12; the counter itself stores nothing but the hash.
4.11 Advertising slot
- What: every public page carries one advertising slot. It is the only script on a free page. It fetches a small file naming the current creative and click link, both served from our own host, not from any ad network. When a visitor clicks an advertisement, we increment a click counter for that campaign and redirect them to the advertiser's page.
- Why: to report clicks, and in future impressions, to advertisers in aggregate.
- Detail: click counts are per campaign, not per person. Like every request, the click request appears in the CDN access logs described in Section 4.12 with the visitor's IP address; we do not join those logs to the click counter or to any person. The redirect withholds the referring page and is marked not to be cached, so the advertiser does not learn whose page the click came from. Once redirected, you are on the advertiser's site, which sees your visit as any website does and is governed by its own privacy policy. We store no per-visitor advertising data in our database, build no ad profiles, and do not target advertisements by viewer. We intend to count impressions in aggregate from our own infrastructure access logs (Section 4.12). We do not use an advertising network today and intend to sell advertisements directly. We reserve the right to introduce an advertising network in the future; if we do, we will update this Policy before any visitor data reaches that network.
4.12 Server and CDN access logs
- What: our content delivery network (Amazon CloudFront) writes standard access logs for requests to https://1995.today and https://app.1995.today, and our storage buckets write server access logs. These are AWS-defined formats that include the requester's IP address, user agent, referrer, the path requested, the query string and the time. Because a sign-in link is a URL with a token in its query string, a used sign-in link (which expires within 15 minutes) can appear in these logs. Our application code also writes structured logs containing usernames, request paths, status codes, job status, generation cost, grounding scores and error class names. Our application logs are written not to include email addresses, secrets, sign-in tokens, full session identifiers or the content of your resume; the worker logs only the source type and the size of the text.
- Why: security, abuse investigation, debugging, and aggregate advertising impression counts.
- Detail: we cannot narrow the fields in the CDN standard log format. The logs are stored in a private bucket. Retention is described in Section 9.3.
4.13 Session data
- What: when you sign in we create a session record holding a random session identifier, your email address and the creation time, and we set one cookie (Section 5). We also keep an index of your sessions.
- Why: so the editor knows who you are, and so we can sign you out everywhere.
- Detail: sessions last 30 days unless you sign out or your account is suspended, banned or deleted, all of which revoke every session.
4.14 Moderation and administrative records
- What: a small number of administrators, identified by an allow-list of email addresses, can look up an account by username and see its email address, moderation status and reason, whether the free generation was used, account creation date, last sign-in (as far back as 30 days), number of active sessions, and counts of messages, assets, views and storage used. When an administrator suspends, bans or reinstates an account, we record the action, the reason given, the timestamp and the administrator's email address, both on the account and in an audit log.
- Why: to enforce the Terms of Service, to defend against claims, and to keep a ban effective.
- Detail: the audit log is kept for 24 months after the action, then expired automatically by the database, because it is the only record of why an action was taken if that action is later challenged. A ban deliberately does not delete the account, so that the address cannot register again.
4.15 Support and legal correspondence
- What: emails you send us and our replies, copyright notices and counter-notices, and any privacy request and the information we need to verify it.
- Why: to respond to you, to keep a record of what was agreed, and to establish, exercise or defend legal claims.
4.16 What we do not collect
We do not collect payment information (there is nothing to buy), passwords, precise location, device identifiers beyond the browser user agent described in Sections 4.10 and 4.12, contacts or biometric data. We use no analytics, error-reporting, session-replay or advertising trackers on either the public site or the editor, and no social plug-ins. The editor does not use browser local storage or session storage. We do not scrape LinkedIn or any other site on your behalf.
5. Cookies and similar technologies
5.1 One strictly necessary cookie, on the editor only
The only cookie 1995 sets is a session cookie named __Host-sid on https://app.1995.today. It identifies your signed-in session. It is HttpOnly (scripts cannot read it), Secure (sent only over HTTPS), SameSite=Lax, and expires after 30 days. Its value is a random identifier plus a cryptographic signature so that it cannot practically be forged. It is strictly necessary to operate the editor, so consent is not required for it and it cannot be disabled while you are signed in. Because of its name prefix, it can only ever be set on the app origin. Signing out deletes the session on our side and clears the cookie.
5.2 No cookies on public pages
Public pages at https://1995.today set no cookies. The hit-counter image and the advertising slot are plain requests to our own host; neither sets or reads a cookie, and neither loads anything from a third party.
5.3 No analytics or advertising cookies
None set by 1995, anywhere. The Turnstile widget on the editor (Section 5.4) is the one third-party component and is governed by Cloudflare's policy. Because we set only a strictly necessary cookie, we do not show a cookie banner and do not ask for cookie consent.
5.4 Cloudflare Turnstile
The editor loads Cloudflare's Turnstile bot-check widget from challenges.cloudflare.com on the sign-in screen and before a resume upload. The widget runs in your browser, and what it collects there, including any cookies or storage it uses, is governed by Cloudflare's privacy policy, not ours. See Section 7.3. The public site loads nothing from third parties.
6. How the AI processing works
6.1 What happens
- Our servers extract plain text from your uploaded file using ordinary, non-AI tools, and truncate it at 60,000 characters.
- That text is embedded in a fixed prompt and sent as a single chat-completion request to Fireworks AI (https://fireworks.ai), a third-party model-hosting provider. The prompt instructs the model to extract facts without inventing or embellishing, and specifies a schema the answer must follow. If the first answer does not fit the schema, the same request is sent once more with the validation errors attached. That is at most two requests per generation.
- The model returns structured data, a persona label that selects your template, and short first-person home page copy written in the voice of a 1995 personal home page.
- Our servers run a non-AI check that every company, title, school, degree, date, skill and certification the model returned closely matches text in your resume, using an approximate comparison, and drop anything that does not match. This check can let through small errors and can drop correct items. The match ratio is stored as the grounding score. The home page copy is not checked this way, which is one reason you must read it as soon as it goes live.
- The generated site is published immediately at your public URL. You then get the editor to correct anything that is wrong; your corrections replace the live page when you save and republish.
You get one free AI generation per account; publishing and editing afterwards make no AI calls. We keep your resume text so that we can re-run extraction with an improved prompt or model (Section 4.3). If we do, your resume text is sent to the AI provider again under Section 6.2, and we will update this Policy and tell you before doing so; we will not re-run it in a way that changes your published page without telling you first.
6.2 What Fireworks AI receives
The resume text, embedded in our prompt, and nothing else about you: not your email address, not your username, not your account identifier, not your IP address. The resume text itself is sent as extracted, without redaction, so any personal information in your resume (your name, phone number, address, references, and anything else you wrote) reaches Fireworks AI. Do not upload a resume containing information you are not prepared to share with that provider. If you are in the EEA, the UK or Switzerland and do not accept this, do not upload a resume (Section 13.3).
Your resume may name other people, such as references. Remove their contact details before you upload; we do not filter the file before it is sent. We process any such details only as part of your resume text, we never contact those people, and the filter in Section 3.3 removes contact details when you save your profile in the editor.
6.3 What we keep about the request
We store, on your profile, the model identifier, prompt version, token counts, latency, cost and grounding score (Section 4.3).
6.4 Retention on Fireworks AI's side
Our request to Fireworks AI does not set any retention, zero-retention or no-training option, and we rely on the provider's published API data terms for what happens to the text afterwards. We do not control how long Fireworks AI retains request inputs or outputs, or whether it uses them to improve its services; that is governed by Fireworks AI's own terms and privacy policy, published on its website (https://fireworks.ai), which you should read before uploading. We make no claim in either direction about how long they keep it, because we have not verified it. We do not currently have a way to ask Fireworks AI to delete past requests when you delete your account; whatever their own terms provide applies to those. [OWNER TO CONFIRM: before launch, confirm a data processing agreement with the provider and a no-training / no-retention setting, then restate this section with what is actually configured. Remove this bracket before publishing.] We reserve the right to change the model or provider; if we do, we will update this Policy.
6.5 Accuracy and human review
The AI output is a draft. It can be wrong, incomplete or oddly phrased. You receive the editor afterwards and are responsible for reviewing and correcting your page as soon as it is generated and at any time afterwards, because the first version is published without your review, and for what remains on your page after you have had the chance to fix it. The generation makes no decision about you that has legal or similarly significant effects; it only proposes content that you control.
7. Third parties: processors and other recipients
We do not sell personal information, and we do not share it for cross-context behavioural advertising. No advertising network receives personal data from us. The providers that handle your data are listed below. AWS and Cloudflare act as our processors; Fireworks AI's status is explained in Section 7.2.
7.1 Amazon Web Services (AWS), United States, region us-east-1
All hosting, storage, database, queueing, logging and email delivery run on AWS in the us-east-1 (Northern Virginia) region. Services used include S3 (file storage), CloudFront (content delivery), Lambda and API Gateway (application code), DynamoDB (database), SQS (job queue), SES and SNS (email sending and delivery events), Systems Manager Parameter Store and Secrets Manager (secrets), Route 53 (DNS) and CloudWatch (application logs). AWS processes this data on our behalf to provide those services.
7.2 Fireworks AI (independent recipient)
Fireworks AI receives the extracted resume text, embedded in our prompt, to perform the AI extraction and copywriting described in Section 6. It receives no account data. We rely on the provider's published API data terms for how that text is handled; we have not separately agreed terms that bind it to process the text only on our instructions, so we list it here as a recipient that processes the text under its own published terms rather than as a processor acting on our behalf. [OWNER TO CONFIRM: before launch, put a data processing agreement in place with Fireworks AI and enable a no-training / no-retention setting if the provider offers one, then move this entry to Section 7.1's treatment and update Sections 6.4 and 13.3. Remove this bracket before publishing.] If we put a data processing agreement in place, we will update this section and Section 13.3.
7.3 Cloudflare Turnstile
We use Cloudflare Turnstile to tell humans from bots on sign-in requests and resume uploads. Two things happen: your browser loads Cloudflare's widget script on those screens (so Cloudflare sees your browser's request, as any embedded script provider does), and our server sends the widget's response token together with your IP address to Cloudflare to verify it. Your email address is not sent to Cloudflare. What the widget collects in your browser is described in Cloudflare's privacy policy.
7.4 Recipients who are not processors
- Other members receive your data as described in Section 3 (public pages and what other members can see) and Section 4 (mail, guestbook, friend requests).
- Advertisers receive only aggregate click counts and, in future, aggregate impression counts per campaign. They receive no personal data from us.
- Administrators, as described in Section 4.14. Every administrative action is logged with the administrator's identity. Whoever operates our infrastructure can, by the nature of the job, access stored data. We limit that access to what is needed to run the service and, where anyone other than the operator has it, require the same confidentiality this Policy describes.
- The operator's own mailbox receives raw bounce and complaint notifications from AWS SES in production; those notifications include the affected email address (Section 8.4).
- Copyright complainants and the people they complain about. If we receive a copyright infringement notice about your page, we may forward it to you, including the complainant's name and contact details. If you send us a counter-notice, the law (17 U.S.C. 512(g)(2)(B)) requires us to forward it to the person who made the original complaint. A counter-notice must contain your name, address and telephone number, so those reach the complainant, as does any email address you include. We keep notices, counter-notices and a record of which accounts they concerned for as long as we need them to handle repeat complaints and to defend claims.
- Law enforcement, regulators or courts: we may disclose personal information if we believe in good faith that it is required by law, subpoena, court order or a lawful request by a public authority; to enforce the Terms of Service; or to protect the rights, property or safety of 1995, our members or the public.
- A successor, if 1995 is sold, merged, reorganised or financed, in which case this Policy continues to apply to the transferred data until it is changed, and we will give you notice.
8. Emails we send
All email is sent from a noreply address at our domain through Amazon SES. Today the service sends three kinds of transactional email and no marketing email. We may additionally send service notices required by this Policy or by law (for example a material change to this Policy or a security incident), and we will not send anything else without your consent. Every message carries a footer saying why you received it. There is nothing to unsubscribe from: each email is triggered by something you or another member did, so there is no unsubscribe link. To stop mail relays and friend request notices, block the sender or delete your account. You can also email support@undiscoveredtech.com from your account address asking us to stop relaying mail or sending friend-request notices to you, and we will honour that within 10 business days (owner to confirm the manual process, since the service has no per-feature opt-out setting); your inbox in the editor will still show messages. If we ever introduce optional or promotional email, we will ask for your consent first and include a working opt-out in every such message.
8.1 Sign-in links
When a sign-in link is requested for your address we send one email containing a link that expires in 15 minutes. We store only a one-way hash of the link's token, together with your email address and an optional return path, for 15 minutes. A link is single-use, but the same link is honoured again for 60 seconds after first use so that mail scanners that pre-open links do not lock you out. You only receive these when someone requests one for your address; the response to a request is always the same, so nobody can learn from it whether an address has an account. If you did not request one, ignore it.
8.2 Mail relays
When a signed-in member sends you mail through your page, we forward the message to your account address with the subject "[1995] Mail from <sender> via your home page". The relayed email is sent from our noreply address, names the sender by username only, and links to your Mail screen, where you can reply. Neither party's email address is shown to the other. Messages received before 2026-09-14 may still hold the sender's address in our database; it is no longer displayed or exported and is removed when your account is deleted. Limits: 10 messages per recipient per day, 10 per sender per day, and 3 per sender to the same recipient per day. To stop mail from a particular member, block them; to stop all of it, delete your account.
8.3 Friend-request notices
When a member asks to be your friend we send one email with the subject "[1995] <username> wants to be your friend", the sender's username, their optional note, and links to your Friends and Mail screens. At most one such email is sent per sender-recipient pair per day. Block the sender to stop notices from them.
8.4 Bounces and complaints
If a message to your address hard-bounces, or if you mark one as spam and your mail provider reports it to us, we record that status against your address and stop sending all further email to it, including sign-in links, which means you will no longer be able to sign in from that address. This is silent: the sign-in form still says to check your email, but no email goes out, and the person who triggered the mail is not told. The mark has no expiry of its own. It is stored on the same record as your account: if you delete your account, it is removed with that record 30 days later (Section 9.2); for an address that never had an account, it is kept until you ask us to remove it. If you believe your address was suppressed in error, write to support@undiscoveredtech.com from another address and we will consider it; we may decline to lift a suppression caused by a spam complaint. While your address is suppressed you cannot sign in, so the export and deletion controls on the Account screen are unavailable to you; write to us and we will verify you another way and act on your request (Section 11). In production, the raw bounce and complaint notification, which includes the affected address, is also delivered to the operator's mailbox at support@undiscoveredtech.com.
9. How long we keep data
9.1 Active accounts
Everything in Section 4 that belongs to your account is kept for as long as your account exists, including your original resume file and the extracted text. There is no automatic expiry of your resume, profile, pages or posts. The exceptions are these short-lived items:
- Sign-in link token (stored only as a hash): 15 minutes.
- Sign-in rate-limit counters (per email address and per IP address): 1 hour.
- Hit-counter viewer hash (no IP address): 24 hours.
- Daily usage counters (mail, guestbook, friend requests): 2 days.
- Friend-request pair lock (one pending request per direction): 30 days.
- Session: 30 days, or earlier on sign-out or revocation.
- Queued background jobs, including the account deletion job: deleted once the job has run, normally within minutes; an unprocessed job is discarded after 4 days, or after 14 days if it fails repeatedly.
Account record created by a sign-in request that was never completed: kept until the address holder signs in and deletes the account or asks us to remove it (Sections 4.1 and 11).
One further point: the profile and site documents written at generation time are stored as a file copy as well as in the database. Editor saves update the database copy; the file copy is rewritten only by a generation run. So text you later edit out in the editor can persist in the generation-time file copy until your account is deleted.
9.2 Deleted accounts
- Your published pages, profile, site, news posts, photos, uploaded resume, extracted text, received mail, received guestbook entries, friendships, requests, blocks, job records, usage counters and hit-counter data are removed from the live service by a background job that normally completes within minutes; if the job queue is backed up it can take longer. In production, prior versions of your files remain in the private store and expire automatically 30 days after your deletion; see Section 9.3.
- Your username is held for 30 days so that it cannot be claimed by someone else immediately after you delete. This hold does not restore your account or content; deletion is final as soon as the background job runs (Section 9.3). After 30 days the hold is released by our database's expiry process, normally within a few days of the 30-day mark, and the username becomes available to anyone.
- Your account email record is held for 30 days as a deletion marker and is then removed automatically by our database's expiry process, normally within a few days of the 30-day mark. During those 30 days it still carries the email address and other account attributes.
- Section 10 lists what the deletion process does not reach.
9.3 Backups, versioning and logs
We want to be precise here, because this is where "deleted" can mean less than people assume.
- File storage versioning: in production, our private data store keeps prior versions of stored objects for recovery. The deletion process removes the current version of your files (original resume, extracted text, profile and site copies, photos), normally within minutes, and they are no longer accessible through the service. The prior versions expire automatically 30 days after they stop being current, which for a deletion means 30 days after your deletion; a storage lifecycle rule does this, not a person, and the same rule removes the delete marker left behind. We can also remove them sooner if you ask. We do not use those prior versions to run the service, and access to them is limited to the operator.
- Database recovery data: the production database has point-in-time recovery enabled, which lets us restore it to any moment within AWS's rolling recovery window. We do not configure that window; it is AWS's own, 35 days at the effective date. Deleted items therefore remain restorable for up to that period after deletion. Our test and staging databases have point-in-time recovery turned off. The database also emits a change stream that AWS retains for about 24 hours; nothing reads it today, but it briefly holds the prior contents of changed and deleted records.
- Application logs (which our logging rules keep free of email addresses) are retained for 90 days (three months) in production, and 30 days in our test and staging environments.
- CDN and storage access logs (which contain IP addresses, user agents, referrers, paths and query strings) expire automatically 90 days after they are written; a storage lifecycle rule does this. We use them only for security, abuse investigation and aggregate advertising counts, we do not use them to identify individual visitors except to investigate abuse or a security incident, and access to them is limited to the operator.
- Queue messages, including the account-deletion message that carries your username and email address, are deleted once the job has run, normally within minutes; an unprocessed message is discarded after the AWS default of 4 days, and one that repeatedly fails processing is held in a dead-letter queue for up to 14 days.
- The moderation audit log (Section 4.14) is kept for 24 months after the action, then expired automatically by the database, because it is the only record of why an action was taken if that action is later challenged.
- Email suppression records (Section 8.4): kept for as long as the address has no account or the account exists, because they exist to stop us contacting you. If you delete your account, the mark is stored on the same record as your account and is removed with it after the 30-day hold; a bounce or complaint that arrives during that hold lands on the expiring record and is removed with it. For an address that never had an account, the mark is kept until you ask us to remove it.
- Records of yours held in other members' accounts (mail you sent, guestbook entries you wrote, and the mirror halves of friendships, requests and blocks): kept until that member deletes them or deletes their account (Section 10.2).
- Support and legal correspondence: for as long as needed to handle the matter and meet legal obligations.
We use backups only to recover from a failure of the service, not to restore an account at a former owner's request. If a service-wide recovery ever brought back data that had been deleted, we would run the deletion again.
10. Deleting your account, and what deletion does not reach
10.1 How to delete
In the editor, open the Account screen, type your username (or your email address if you never claimed a username) to confirm, and submit. Every session is revoked immediately, your username and email record are marked as deleted, and a background job removes your content, normally within minutes, replaces your pages with the "This home page has been removed." notice, and clears the CDN cache. If you never claimed a username, the email record is marked deleted and your sessions are revoked, but no background job runs and there is nothing to unpublish: guestbook entries you signed and mail you sent from that account remain in the owners' data, and the index linking those guestbook entries to your address is not removed. Email us if you want it removed. Any live session can perform this action; there is no second confirmation by email, so keep your sessions secure and sign out of shared computers. You can also ask us to delete your account by emailing support@undiscoveredtech.com from your account address.
If your account has been suspended or banned, you cannot sign in, export or delete through the editor. Write to the address shown on the suspension notice (support@undiscoveredtech.com) from your account address and we will handle the export or deletion by hand; a ban keeps the email record so that the address cannot register again (Section 4.14).
10.2 What deletion does not reach
We want you to know exactly what stays. Some of this is by design and some is a limitation we are telling you about honestly. We list it so that you can decide what to post. After you delete your account:
- Mail you sent to other members stays in their inboxes, with your display name and username as they were when you sent it. It is stored as their mail and is under their control.
- Guestbook entries you wrote on other people's pages stay in their guestbooks. It is part of their guestbook and under their control once you have signed it. If you had claimed a username, the index linking those entries to your address is removed; if you had not, it is not (Section 10.1). Your email address stored with those entries is not shown on the public page, not shown on the owner's moderation screen, and not included in the owner's JSON data export of their guestbook (Section 4.6): the owner sees your username only.
- The other half of each friendship, friend request and block stored on the other person's account keeps your internal account identifier and a snapshot of your username. Your username therefore still appears as a link on a former friend's friends page, pointing at the removal notice, until that person unfriends you; republishing their page does not remove it. Once your username becomes available again (Section 3.6), that link points at whoever claims the name next.
- One internal lookup record mapping your internal account identifier to your former username is kept so that other members' friend and block records keep pointing at the right account rather than at whoever claims your old username next. In the current version that record also still carries your email address. The address is not needed for that purpose and we do not use it. We treat your account deletion as your request to remove the address from that record, and we remove it by hand within 30 days of deletion without a further request from you.
- If your account was banned, the email record is kept indefinitely so that the address cannot register again.
- The moderation audit log (24 months), application logs (90 days) and access logs (90 days) are not rewritten; each expires on its own schedule (Section 9.3).
- Email suppression records (Section 8.4) on your address are removed with your account record after 30 days, unless your account was banned and the email record is kept.
- Prior file versions, database recovery data and queue messages in production remain as described in Section 9.3.
- The "This home page has been removed." notice at your old URL can remain indefinitely.
- Copies that other people or services made of your public pages are outside our control (Section 3.5).
If you want us to review any of these residual records in your case, write to support@undiscoveredtech.com.
10.3 Suspension and takedown are not deletion
If we suspend or ban an account under the Terms of Service, we overwrite every HTML page under its username with a "This home page is not available." notice, delete the main photo at https://1995.today/~username/photo.gif from the public host, and revoke every session, but we do not delete the account's data, so that a mistaken suspension can be reversed by re-rendering. A takedown does not reach anything else. Other images you uploaded, at https://1995.today/~username/<id>.gif, remain publicly served. The share image at https://1995.today/~username/og.png is rendered from the stored profile and site, which a takedown does not change, so it can continue to show your name, page title, first paragraph and positions while the account is suspended. Your guestbook page and friend-request page are served from the app origin and stay readable, as does your hit counter image and its count. Terms of Service Section 13.2 lists the same two sets. Data is deleted only when you delete the account or when we decide to delete it under the Terms of Service.
11. Your rights and how to exercise them
You have these rights regardless of where you live. Sections 12 and 13 add rights specific to California and to the EEA, UK and Switzerland. You can do most of this yourself in the editor at https://app.1995.today. If you cannot sign in because your account is suspended or banned (Section 10.1) or your address is suppressed (Section 8.4), use the email route below.
- Access and portability: open the Account screen and choose Export. You receive a file named 1995-<username>.json containing your account record (email, account identifier, username, whether the free generation was used, and the version and date of the terms you accepted), your profile, your site, mail you received (up to 1,000), guestbook entries you received (up to 1,000, each carrying the signer's username and display name but never the signer's email address, which is stripped before the file is built, Section 4.6) and entries you wrote elsewhere, your uploaded-asset metadata, your friendships, your friend requests in and out with all statuses, the blocks you made, the extraction metadata, and a download link for your original resume that is valid for 5 minutes. The export does not include your news posts (email us and we will send them to you as a JSON file), the extracted text file, job records, usage or view counters, your session list, or administrative records; email us if you need any of those. It also does not include the list of members who have blocked you. We do not disclose that list to anyone, including in response to an access request, because it is another person's data and disclosing it could put them at risk; the law allows us to withhold it on that ground.
- Correction: edit your profile, site and posts in the editor at any time and republish. The extraction provenance fields cannot be edited, and you cannot change your username in this version.
- Deletion: use the Account screen as described in Section 10.
- Withdrawing and objecting: because nearly all processing is necessary to provide a service you asked for, the way to withdraw is to delete the content or the account. You can delete individual news posts and guestbook entries on your page, unfriend, unblock, and unpublish by removing content and republishing. Photos can be replaced by uploading a new image under the same id. Photos and inbox messages, like everything else in your account, are removed when you delete your account, and you can ask us by email to remove individual items. Where we rely on legitimate interests (Section 13.2), you can object by email; where you dispute accuracy, you can ask us to pause use while we check.
- Restricting who reaches you: block a member and they can no longer mail you, sign your guestbook or send you friend requests.
- By email: for anything you cannot do in the app, or if you cannot sign in, write to support@undiscoveredtech.com. To protect your data we will verify that you control the account email address, normally by replying to that address or by sending a sign-in link to it (unless the address is suppressed under Section 8.4 or the account is suspended or banned, in which case we will agree another method with you), before acting. If you cannot use that address, tell us and we will find another way to verify. We will respond within the time the applicable law allows: within one month if you are in the EEA, the UK or Switzerland, and within 45 days if you are a California resident, in each case extendable as that law permits, and we will tell you if we need an extension. Otherwise we aim to respond within 45 days. We do not charge for requests unless they are manifestly excessive. We may decline requests that are manifestly unfounded, excessive, or that would require us to disclose another person's data, and we will explain why.
- Authorised agents: you may have someone make a request for you if they can show your written authorisation; we may still verify your identity directly.
We will not discriminate against you for exercising any of these rights.
12. California residents (CCPA/CPRA)
This section applies to residents of California, to the extent the California Consumer Privacy Act as amended by the California Privacy Rights Act applies to 1995, and supplements the rest of this Policy.
12.1 Categories of personal information collected in the last 12 months
- Identifiers: email address, username, internal account identifier, IP address (rate limiting, Turnstile verification and access logs).
- Personal information as described in Cal. Civ. Code 1798.80(e): your name and any other details in your resume and page content.
- Professional or employment-related information: positions, employers, titles, dates, skills and certifications, from your resume and your edits.
- Education information: schools, degrees and dates, from your resume and your edits.
- Geolocation data: the location text in your resume and profile (for example a city or region). We collect no precise geolocation.
- Internet or other electronic network activity: access logs, session records, usage counters and hashed hit-counter markers.
- Audio, visual or similar information: photos you upload.
- Inferences: the persona label the AI assigns to select your template, and the AI-drafted copy derived from your resume.
- Content of communications: mail, guestbook entries, friend-request notes and support correspondence.
- Sensitive personal information: we do not ask for any, and we ask you not to include any in your resume or page. If your resume contains it and you upload it, it is sent to the AI provider as written (Section 6.2), may appear on the page that is published automatically when generation completes (Section 3.1), and is otherwise processed only to generate and maintain your page. We do not use it to infer characteristics about you. Remove it from the file before uploading if you do not want that.
12.2 Sources
You (your uploads and edits), other members (mail, guestbook entries, friend requests, blocks), and automatic collection by our infrastructure (access logs, counters).
12.3 Purposes
Providing and maintaining your page and account, communicating with you about it, preventing abuse and enforcing limits, security, debugging, counting advertising impressions and clicks in aggregate, and complying with law.
12.4 Disclosures for a business purpose
We disclose personal information to the service providers in Section 7 (AWS, Cloudflare) for the purposes described there. Resume text is disclosed to Fireworks AI, which may process it under its own terms (Sections 6.4 and 7.2). We have not sold personal information in the preceding 12 months and do not sell it. We have not shared personal information for cross-context behavioural advertising and do not do so. We have no actual knowledge that we sell or share the personal information of consumers under 16.
By category: identifiers (email address, username, IP address): AWS; Cloudflare (IP address and Turnstile token from our server, plus whatever its widget collects in your browser, Section 7.3); other members (username publicly); authorities on lawful request. Personal, professional and education information, geolocation text and inferences (resume, profile, page content): AWS; Fireworks AI (resume text); the public (whatever you publish). Internet activity (access logs, session records, counters): AWS only. Audio or visual information (photos): AWS and the public. Content of communications (mail, guestbook entries, friend-request notes): AWS; the member you sent them to; the public where the recipient approves a guestbook entry. Support and legal correspondence: authorities where required, and copyright complainants as described in Section 7.4. Advertisers receive only aggregate counts, which are not personal information.
12.5 Your rights
You have the right to know what personal information we collect, use, disclose, and sell or share (we sell and share none); to access it and receive a copy; to delete it; to correct it; to limit the use of sensitive personal information (we do not use it beyond what is necessary to provide the service); and not to be discriminated against for exercising these rights. We will not deny you the service, charge a different price, or provide a different level of service because you exercised a right. Exercise them as described in Section 11. Because we do not sell or share personal information, there is no opt-out to offer and nothing for a Global Privacy Control signal to switch off; we treat such a signal as consistent with what we already do. Because your public pages are public by your design, deleting your account removes our copies as described in Sections 9 and 10 and cannot reach copies others have made.
12.6 Retention
By category: identifiers: while the account exists, then 30 days (email record) or, for the internal lookup record, until we remove the address by hand within 30 days of deletion (Section 10.2); IP addresses: 1 hour (rate limiting), 24 hours as a hash (hit counter), and in access logs as stated in Section 9.3. Personal, professional, education, geolocation text, inferences, audio or visual: while the account exists, then removed within minutes, subject to Section 9.3. Internet activity: sessions 30 days, counters 1 hour to 2 days, access logs as stated in Section 9.3. Content of communications: while the recipient's account exists (Section 10.2). Support and legal correspondence: as stated in Section 9.3. Sections 9 and 10 give the full detail.
13. EEA, UK and Swiss residents (GDPR, UK GDPR and FADP)
This section applies if you are in the European Economic Area, the United Kingdom or Switzerland.
13.1 Controller
Undiscovered Tech, LLC, contact details in Section 1. We have not appointed a data protection officer, and we have not appointed a representative in the EU or the UK (owner to confirm with counsel whether Article 27 requires one; if it does, name the representative here). Contact us directly at the addresses in Section 1.
13.2 Legal bases
- Performance of a contract (Article 6(1)(b)): creating your account, sending sign-in links, processing your resume to generate your page (including the AI step in Section 6), hosting and publishing your page, relaying mail, storing and moderating guestbook entries, and delivering friend requests, and providing export and deletion.
- Legitimate interests (Article 6(1)(f)): rate limiting, bot checks, blocking, moderation and audit records, ban records, keeping an internal identifier-to-former-username lookup after deletion so that other members' friend and block records stay attached to the right account rather than to the next holder of the username, keeping mail you sent and guestbook entries you wrote in the recipient's own records after you delete your account, because those records belong to the recipient's account and removing them would alter another member's data without their knowledge, keeping the mirror halves of friendships, requests and blocks on other members' accounts so that their block and friend lists keep working, bounce and complaint suppression, security and access logging, debugging, aggregate advertising measurement, backups, and defending legal claims. Our interest is in running a safe, working and financially viable service; we have limited the data involved (for example, the hit counter hashes and discards IP addresses) and you can object as described below.
- Special categories of data (Article 9): we do not ask for health, religious, ethnic, political, trade-union, sexual-orientation or similar data. If your resume or page contains it, we rely on your explicit consent, which you give by uploading a file or saving content that contains it after reading this Policy, and on the fact that you have chosen to make it public on your page (Article 9(2)(a) and (e)). You can withdraw that consent by removing the content or deleting your account. Remove such details from the file before uploading if you do not want them processed or published.
- Data about people who are not members (visitors' IP addresses in access logs and the hashed hit counter, and people named in members' content) is processed on the legitimate-interest basis above or as part of the member's own content. We cannot notify those people individually; this Policy is our notice to them, and they have the rights in Section 13.4.
- Legal obligation (Article 6(1)(c)): responding to lawful requests and keeping records we are required to keep.
- Consent (Article 6(1)(a)): apart from the explicit consent described under Article 9 above, we do not currently rely on consent for anything and send no optional or promotional email. If we introduce any, we will ask for your consent and you can withdraw it at any time.
13.3 International transfers
1995 is operated from the United States, and we are established only there.
Data you send us. When you sign in, upload a resume or write anything on the service, you send that data directly from your own device to a controller established outside the EEA, the UK and Switzerland. That is direct collection by a controller outside your region, not an onward transfer between two organisations, and Chapter V of the GDPR (including the Article 49 derogations) is not what we rely on for it. The safeguards that apply to it are our own commitments in this Policy: the purposes in Section 4, the legal bases in Section 13.2, the retention periods in Section 9, the security measures in Section 15, and the rights in Sections 11 and 13.4, which we honour wherever you live. This Policy is our notice under Articles 13 and 14 of where your data is processed.
Onward disclosures to our providers. What we then pass to the providers in Section 7 is a transfer to a processor, and each one is covered as follows. The United States has no general adequacy decision from the European Commission, the UK or Switzerland, but the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Data Privacy Framework provide adequacy for United States organisations certified under them; the current list is at https://www.dataprivacyframework.gov.
- Amazon Web Services (hosting, storage, database, queueing, logging, email delivery): where AWS is listed as certified under those frameworks, we rely on that certification; where it is not, we rely on the Standard Contractual Clauses incorporated into the AWS customer agreement's data processing addendum.
- Cloudflare (Turnstile bot check): the same two-step position, certification where Cloudflare is listed, otherwise the Standard Contractual Clauses in Cloudflare's data processing addendum.
- Fireworks AI (the extracted resume text only, Section 6.2): we have not confirmed a framework certification, and Section 7.2 explains the basis on which the text is processed today.
[OWNER TO VERIFY each provider's DPF listing at https://www.dataprivacyframework.gov before publishing and at each revision, record which of the two bases actually applies to each provider, and name the Standard Contractual Clauses module and the data processing addendum for any provider that is not listed. Remove this bracket before publishing.]
If a listing lapses we will update this section. You can ask us at the address in Section 1 for a copy of the safeguards that apply.
13.4 Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability (the JSON export in Section 11 is our portability format, together with any news posts we send you on request), and objection (including to any processing based on legitimate interests), and the right to withdraw consent where processing is based on consent. Exercise them as described in Section 11.
Right to object. You may object at any time, on grounds relating to your particular situation, to any processing we base on legitimate interests (Section 13.2). Email support@undiscoveredtech.com with "Objection" in the subject line. We will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EEA member state, the UK or Switzerland where you live, work, or where you believe an infringement occurred. In the UK that is the Information Commissioner's Office. In Switzerland it is the Federal Data Protection and Information Commissioner (FDPIC). We would appreciate the chance to address your concern first, but you are not required to contact us before complaining.
13.5 Automated decision-making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. The AI generation produces a draft page that you review and control. Moderation decisions are made by people.
13.6 Public pages and your rights
Once your page is published, other people and services may copy or index it. We will act on erasure requests for what we hold, but we cannot compel third parties who copied your public content to erase it. Section 3 explains this in detail.
13.7 Whether you must give us data
You are not under any legal obligation to give us personal data. An email address is required to create an account; without one there is no account. Uploading a resume is required for the one AI generation; without it we cannot generate a page from your resume. Everything you add to your page beyond that is your choice, and you may leave it out.
14. Children
1995 is not directed at children. You must be at least 18 years old, or the age of majority where you live if that is higher, to use the service (see the Terms of Service). We do not knowingly collect personal information from anyone under 13, and we do not knowingly allow anyone under 18 to create an account. If you believe a child under 13 has provided us with personal information, or that an account belongs to someone under the minimum age, email support@undiscoveredtech.com and we will delete the account and its data promptly. We may lower the minimum age in a future version of the Terms of Service; if we do, this section will be updated to match.
15. Security
We take reasonable measures appropriate to a small, free service:
- All traffic is redirected to HTTPS, TLS 1.2 or newer is required, and HTTP Strict Transport Security is enabled with a one-year term, subdomains included, and preload.
- The session cookie is HttpOnly, Secure, SameSite=Lax, host-locked to the editor origin, and its value is signed with HMAC-SHA256 and verified in constant time. Sessions are stored server-side and are revoked on sign-out, suspension, ban and deletion. If the signing secret is unavailable the service refuses to operate rather than fall back.
- Sign-in tokens are stored only as one-way hashes and expire in 15 minutes.
- State-changing requests must come from the editor's own origin; cross-origin requests are rejected.
- Content Security Policies are applied to public pages, the editor and the app-origin forms; public pages cannot load third-party scripts or images. API responses are never cached and carry no referrer.
- Secrets (session signing key, Turnstile key, AI provider key, counter salt) are stored in AWS Systems Manager Parameter Store as encrypted SecureStrings and read at runtime; none are in code.
- Each application component runs under a least-privilege role; for example, the API's role can write and read only the resume and photo prefixes of the private bucket. Every web-facing function checks a shared origin secret before doing anything, so requests cannot bypass the CDN.
- Storage buckets block all public access and are encrypted at rest with S3-managed keys; public pages are served only through the CDN; the private data store is reachable from the browser only through short-lived signed upload links.
- Our logging rules forbid writing email addresses, tokens or full session identifiers to application logs, and we treat any that reaches a log through an error as something to remove.
- Deployments use short-lived credentials from AWS IAM Identity Center.
No system is perfectly secure. We cannot guarantee that unauthorised access, loss or disclosure will never happen. If we learn of a breach affecting your personal data we will notify you and any regulator as applicable law requires. You are responsible for keeping control of the email account you sign in with, because anyone who can read that inbox can sign in as you.
16. Do Not Track and similar signals
We do not respond to browser "Do Not Track" signals, because there is no tracking to disable: we do not track visitors across sites, run no analytics, set no advertising cookies, and do not sell or share personal information for advertising. Your browser's signal does not change how the service works. Global Privacy Control signals are addressed in Section 12.5.
Other than the Cloudflare Turnstile widget on the editor's sign-in and upload screens (Section 5.4), whose collection is governed by Cloudflare's privacy policy, we do not allow third parties to collect personally identifiable information about your online activities over time and across different websites through the service. That widget is the only third-party code that runs in your browser.
17. Changes to this Policy
We may change this Policy as the service changes. When we do, we will post the new version at https://1995.today/privacy.html with a new effective date and version string. For material changes that reduce your rights or expand what we collect or share, we will email your account address before the change takes effect, unless your address is suppressed under Section 8.4, and we will post the change at https://1995.today/privacy.html on the same day. When a new version of the Terms of Service or this Policy applies, the editor asks you to read and accept it before you can claim a username, upload a resume, save, publish, post news, send mail, sign a guestbook or send a friend request again; your page stays online and you can still export or delete your account from the Account screen while you decide. If you do not agree, delete your account. Where the law requires your consent we will ask for it and the change will not apply to you until you give it. Earlier versions are available on request. Any change to the commitment in Section 4.3 (no job-search, recruiter or similar use of your resume, extracted text or profile without your opt-in) is a material change and will be handled under this section, with your opt-in required before any such use of data collected under this version.
18. Contact
Questions, requests or complaints about privacy:
Undiscovered Tech, LLC
7824 Calico Flower Ave, Las Vegas, NV 89128, United States
Email: support@undiscoveredtech.com (put "Privacy" in the subject line)
Write to us about anything in this Policy, to exercise a right, to report a privacy concern, or to ask us to review data that deletion does not reach (Section 10.2). Related document: the Terms of Service at https://1995.today/terms.html. This Privacy Policy is published at https://1995.today/privacy.html.
Governing law and venue for disputes arising under this Policy are set out in the Terms of Service and follow the law of Nevada (owner to confirm; Nevada is the owner's likely choice), without prejudice to any mandatory protection you have under the law of the place where you live.
1995 home | Terms of Service | The editor
Best viewed with any browser. No cookies on this page.