Recipient viewing activity
When a recipient opens a portfolio room, Crit may record the room opened, pages viewed, approved images opened fullscreen, approximate device type, and time spent. Location is recorded only when the deployment explicitly trusts its Cloudflare proxy headers.
The candidate sees delivery and viewing signals for rooms they created.
Private hiring decisions
Organization notes, ratings, assignments, and stages are visible only to active members of that hiring workspace. Crit does not include those fields in candidate analytics, campaign records, or delivery notifications.
Portfolio and account files
Portfolio PDFs, generated image crops, and CVs are stored privately. Recipient access uses revocable room secrets. Validated portfolio bytes are moved to a content-addressed object so an earlier upload URL cannot replace the reviewed file.
Saved product interest
When a candidate saves a paid package, Crit records the account, package, lifecycle state, and timestamps so the choice survives a later session and aggregate demand can be measured. Saving is not an order, payment, price reservation, or queue priority. It is not marketing consent and does not subscribe the account to email.
A candidate can withdraw the saved interest. A later verified purchase marks the matching record converted, and deleting the account removes the record.
Campaign email delivery
For a candidate-confirmed email campaign, Crit sends the approved message, candidate reply address, and private room address to the verified recruitment email stored in the purchased directory revision. Crit stores an immutable recipient snapshot and provider message identifier, but does not store the decrypted private room address in the campaign message ledger.
Delivery providers may return accepted, delivered, delayed, bounced, failed, suppressed, opened, clicked, or complaint events. Crit keeps the events needed for campaign status, abuse prevention, support, and billing evidence.
Deletion
Deleting an account transactionally revokes its recipient links and removes candidate records before private storage cleanup starts. A durable deletion job retries portfolio, crop, and CV cleanup after interruptions; reviewer membership snapshots are anonymized.
Retention
Crit keeps account and portfolio data while the account is active. Raw viewing events are deleted after 30 days.
Encrypted database and private-file recovery copies are deleted after 14 days. Account data removed from the live service may remain in those protected backups until that backup window expires.
Access boundary
A room secret grants access to one recipient portfolio. An authenticated organization membership grants access to that organization's submission records.