Privacy policy
Effective date: 7 September 2026
Last updated: 7 September 2026
Who operates this service
HR Assistant is a personal proof of concept, not a commercial product. It is operated by Sam Dengler, reachable at samdengler@gmail.com.
Signing in
Sign-in uses Google through Amazon Cognito. Google returns an ID token carrying the account's email address, name, and subject id; the page uses that token for the account menu and never sends it to the chat backend. Only the access token travels with a chat request. The page keeps a refresh token in the browser's IndexedDB storage so a reload keeps the session signed in; the token is rotated each time it is used and is cleared on sign out.
Conversations
Each conversation is written to a private Amazon S3 bucket as a thread record: the messages exchanged, the run and trace identifiers, timing information, and a keyed hash of the account's subject id rather than the id itself. Records expire automatically 30 days after they are last written. Reading a record requires a separate, restricted role set up for that purpose; ordinary operation of the service never reads them.
Replies and the model
Replies are generated by an Anthropic Claude model running on Amazon Bedrock, with retrieval from a knowledge base of AWS documentation. Amazon Bedrock's published policy is that it does not use customer content to train its models; that is AWS's stated policy, not a claim this service can independently verify.
Feedback votes
A thumbs up or thumbs down on a reply is sent to a feedback API and stored as a business event in a Dynatrace tenant, carrying the run id, trace id, thread id, message id, and the vote. The event carries no account identifier.
Page monitoring
The page loads Dynatrace Real User Monitoring from the site's own origin. It reports page performance, errors, and which feature flags were active, as session properties. It does not identify a visitor by account unless a configuration switch, currently off, is turned on.
Backend logs and traces
The chat backend's gateways and runtime log requests to Amazon CloudWatch for 30 days, and traces are forwarded to the same Dynatrace tenant. These records carry request and trace identifiers.
Local chat history
A browser-local chat history feature exists behind a flag that is currently off. When it is on, chats are kept only in the browser's IndexedDB storage and can be cleared from the page at any time.
Advertising, sale of data, and cookies
The service carries no advertising and does not sell data. The page itself sets no cookies. Cognito's hosted sign-in page and Google may set cookies of their own during sign-in, outside this page's control.
Network and infrastructure logging
Requests pass through AWS WAF and Amazon CloudFront, which log request metadata such as IP address and user agent as part of how those AWS services operate.
Changes to this policy
Changes to this policy are announced by updating the date at the top of this page.
Contact
Questions about this policy can be sent to samdengler@gmail.com.