RS Works

← All posts

Blog

What happens to your participants' data when you use an AI resume tool

Andrea Gerson

What happens to your participants' data when you use an AI resume tool

When a resume goes into most AI tools, the participant's personal information travels with it. Name, address, phone number, full work history, and on some tools date of birth and nationality get sent to a third-party AI model for processing. Where that information goes next, how long it is kept, and whether it is used to train future models depends entirely on the tool. Many do not tell you, and most participants never think to ask.

For an individual choosing a consumer app, that trade might be acceptable. They are deciding for themselves. A program is deciding on behalf of people who did not get asked, and often on behalf of people for whom exposure carries real consequences.

Why this weighs more for workforce populations

The people moving through workforce programs are frequently the people with the most to lose from careless data handling. Returning citizens, immigrants, survivors, and public benefit recipients are not in a strong position to absorb a privacy failure. When a program adopts a tool, it inherits that tool's data practices for every person on the caseload at once. Data privacy stops being optional the moment you are responsible for hundreds of records instead of your own.

Two separate risks worth naming

The first risk is where the data goes. Every general-purpose model routes prompts through the provider's servers. If a coach pastes a participant's resume into a consumer chatbot, that resume now sits in infrastructure the program does not control and cannot audit.

The second risk shows up on the document itself. In our benchmark, one popular tool placed the candidate's date of birth and nationality directly on the finished resume. Those two fields hand a hiring manager exactly what they need to screen someone out by age or national origin, and the participant would have no idea it happened. A tool can protect a database perfectly and still expose someone through the file it hands back.

The questions to ask any vendor

Ask whether participant data is sent to an external AI model, and if so, which one. Ask whether that is disclosed to participants before their information is processed. Ask whether the data is retained or used for training, and for how long. Ask who inside and outside the organization can see it. A vendor who handles workforce data well will have clear answers ready. A vendor who treats the question as a nuisance is telling you something.

The standard for a program is higher

An individual can weigh privacy against convenience and make their own call. A program cannot make that call for an entire caseload and hope no one notices. The right default is a tool that keeps participant information out of third-party models and off the parts of the document where it can be used against the person. That is the standard we hold ourselves to, and it is a fair one to hold any tool to before it touches your participants' data.

More from the blog