Privacy Policy
Effective Date: 5 September 2026 • Version 2.0
1. Data Processing Scope & Application Telemetry
JLG Technology LLC ("JLG Technology", "we", "us", or "our") develops professional career intelligence, document engineering, and developer tools. Our applications—including Career Asset Engine and Slimrell—collect technical runtime diagnostics and telemetry necessary for application stability, performance optimization, algorithmic fairness evaluation, and API service delivery:
- Client-Side System Diagnostics: The client application includes an active telemetry service that captures essential device metadata, including operating system name and version, physical hardware model, total RAM, CPU architecture, network connectivity state, and installed client version.
- Backend Analytics & Service Ingestion: The FastAPI cloud gateway ingests operational telemetry, including user activity events, AI token consumption records, client context state, and billing ledger transaction records (
POST /api/v1/analytics/activity). - Audit & Algorithmic Fairness Monitoring: Search and matching queries pass through audit middleware (
fairness_middleware.py) that logs demographic and experience tier distribution data to verify algorithmic fairness and mitigate bias in career matching.
2. Information We Collect on This Web Hub
Because JLG Tech Hub functions primarily as an informational hub and native software distribution showcase, data collection on this website is minimal and restricted to:
- Voluntary Inquiries: Name, organization, email address, and encrypted inquiry payloads submitted through our direct contact modal.
- Technical Infrastructure Logs: Standard web traffic records (IP addresses, user agent strings, request paths, and timestamps) captured by Netlify for edge security, rate-limiting, and DDoS mitigation.
- Admin Session Authentication: Encrypted session tokens and Google OAuth identity markers strictly used by authorized administrators.
3. Cloud-Assisted AI, On-Device Regex Redaction & Privacy Proxy
Career Asset Engine operates on a hybrid client/cloud architecture designed for maximum user sovereignty and transparency:
- Cloud-Assisted Model Inference: Semantic vector embeddings are generated on the backend via GCP Vertex AI (
text-embedding-004). Complex profile classification and resume tailoring execute via leading cloud LLMs (Gemini 2.0 Flash, Vertex AI, Claude) over an encrypted, privacy-preserving proxy gateway. - On-Device Regex-Based Token Sanitization: Before outbound transmission, client-side pattern matching (
pii_sanitizer.dart) parses and replaces sensitive identifiers (phone numbers, email addresses, SSNs, and street addresses) with structured redaction tokens (such as[REDACTED_PHONE_CONTACT]and[REDACTED_CANDIDATE_EMAIL]). - Client-Side Vector Ranking & Local Persistence: Vector similarity search, scoring, and cosine matching execute directly on your physical device (
semantic_matcher.dart). Resumes, profile data, and generated artifacts are encrypted at rest locally using SQLCipher AES-256. - BYOK & x402 Micropayments: Users can Bring Your Own Key (BYOK) or settle per-request compute via Base L2 / HTTP 402 gasless micro-payments, removing centralized billing trackers and data aggregation.
4. Cryptographic Proofs & Blockchain Transparency
When utilizing on-chain micro-settlement (USDC via x402) or cryptographic agreement verification on Base L2, challenge proofs and payment transactions are settled on-chain. Plaintext documents, financial records, and personal identities are never written to public ledgers.
5. Cookies & Local Storage
This website uses strictly necessary functional tokens for interface preferences and administrative authentication. We do not use third-party tracking pixels, advertising identifiers, or cross-site behavioral telemetry.
6. Third-Party Services & Integrations
External services (such as Google OAuth SSO for internal operators, Netlify hosting, and GitHub repository hosting) maintain independent privacy policies. JLG Technology does not grant third parties access to customer data or local application stores.
7. Data Security & Storage Standards
We enforce strict industry encryption benchmarks:
- Transport layer encryption utilizing TLS 1.3 for all web interactions.
- SQLCipher 256-bit AES encryption for native desktop local storage keystores.
- Zero centralized plaintext custody of customer cryptographic keys or secrets.
8. Your Rights (GDPR / CCPA / CPRA)
Under applicable global privacy laws, you maintain the right to inspect, correct, or request deletion of any communication data you have voluntarily submitted to us. We never sell or monetarily trade personal information.
9. Legal Inquiries & Privacy Contact
If you have questions regarding this Privacy Policy or wish to exercise data rights, contact us at: