Privacy Policy

Effective date: June 2026  ·  Applies to: the Skills Excavator tool at skills.fionaliang.au

This policy explains what personal information is collected when you use the Skills Excavator, how it is used, and what your rights are. It is written to be read — not buried.

The short version: You share career stories. Those stories are used to generate your skills profile and are read by Fiona. Your data is stored securely, never sold, and never used to train AI models. You can ask for your data to be deleted at any time.

Who is responsible for your data

Fiona Liang, operating as fionaliang.au, is the data controller. If you have any questions about this policy or want to exercise your rights, contact Fiona at hello@fionaliang.au.

What we collect and why

Information When Why
Email address Before you begin To send your session link, deliver your PDF skills summary, and allow Fiona to follow up
Name Before you begin To personalise the conversation and your output
Your conversation messages During the session The stories you share are the product — they are used to generate your skills profile and are read by Fiona
Voice transcripts (if you use voice input) During the session, only if you choose voice Same as conversation messages. Audio is never stored — only the text transcript.
Your skills profile (structured output) At the end of your session Delivered to you as a PDF; retained by Fiona as a record
Session metadata Throughout To allow you to resume your session if you close the tab; for product improvement

What we do not collect: audio recordings, payment information, location data, or device fingerprints.

Your consent

Before the conversation begins, you are shown a summary of what will be collected and asked to tick a box confirming you understand and agree. The session does not start without this.

Your consent covers: collection of your email and name; collection of the stories you share; Fiona reading those stories and your skills output; sending your PDF to your email; and Fiona's own follow-up.

Your consent does not cover: AI model training (explicitly excluded — see below), sale or transfer of your data to any third party, or any marketing beyond Fiona's own practice.

Who sees your information

Information Who can see it
Email and name Fiona (via session notification email)
Your stories Fiona (via session notification email). This is disclosed in the consent statement before you share anything.
Skills profile You (on-screen and PDF); Fiona (via notification email)
Session metadata Fiona (via database dashboard); the system only

No other parties receive your data. There is no third-party CRM integration.

Third-party services used

The tool relies on four third-party services to function:

  • Supabase — stores all data (email, messages, skills output) in a managed database hosted on Amazon Web Services in the United States. Data is encrypted at rest and in transit. Supabase privacy policy.
  • Anthropic (Claude API) — the AI that guides the conversation and generates your skills profile. Your conversation content is sent to Anthropic's API to generate responses. Anthropic's terms of service state that API inputs are not used to train their models. Anthropic privacy policy.
  • Resend — sends your session link email and your PDF. Your email address is passed to Resend for delivery only. Resend privacy policy.
  • Vercel — hosts the tool and provides anonymous, cookieless usage analytics (such as page views and how visitors arrive). This measures overall usage only; it does not use cookies, does not track you across other websites, and is never linked to your stories or your skills profile. Vercel privacy policy.

Data is stored on US-based servers. If you are located in the European Union, please note that your data will be transferred to and stored in the United States.

How long we keep your data

Your data is retained for 24 months from your last activity. After that, your email and name are removed, your conversation messages are deleted, and only anonymous session metadata (counts and dates, no identifiable content) is kept for product improvement purposes.

Your rights

You have the right to:

  • Access your data — request a copy of what we hold about you
  • Correct inaccurate information
  • Delete your data — we will remove your email, name, stories, and skills output within 30 days of your request

To exercise any of these rights, email hello@fionaliang.au. We will respond within 30 days.

Security

Your data is protected by:

  • Encryption at rest (AES-256) and in transit (HTTPS) — enforced by Supabase and Vercel
  • Row-level security — the database is configured so each user's data can only be accessed by requests authenticated to that user
  • Time-limited, single-use session links — your magic link expires after 7 days and cannot be used twice
  • No API keys or secrets in source code — all credentials are stored as encrypted environment variables

Australian Privacy Act

This tool is designed to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988. The consent statement, data minimisation, and deletion process are designed to meet APP 3 (collection), APP 5 (notification), APP 6 (use and disclosure), APP 11 (security), APP 12 (access), and APP 13 (correction and deletion).

Changes to this policy

If this policy changes in a way that affects how your data is used, we will update this page and note the new effective date at the top. We will not apply changes to data collected under a previous version of this policy without seeking fresh consent where required.

Contact

Questions, requests, or concerns: hello@fionaliang.au