5 Files and what you sent
Tiago Águeda edited this page 2026-09-20 12:23:51 +02:00

Files and what you sent

Two different things live here, and the difference matters.

Files you already had

Documents → Files

Upload PDFs, Word documents, certificates, portfolio pieces — anything written outside Postulo. A CV a designer made for you belongs here, not in the CV builder.

Versions. When you upload a replacement, name the file it supersedes. Postulo numbers the new one automatically and keeps the old file: superseded versions are shown greyed out rather than deleted. You applied with that old version, and the record of what you sent has to stay true.

The upload limit is 20 MB per file.

Say which language it is in. The upload form asks, and leaves the answer blank until you give one: Postulo has never read the file, so it does not guess. A file whose language nobody has stated says language not said on the list, which is a prompt rather than a complaint — nothing else depends on it, and a German certificate is better unlabelled than labelled English. Once said, the flag stands beside the file wherever it appears, and the answer travels with any copy sent to a store.

What you sent

Documents → Sent documents

Whenever you export a CV, download a report, or record what you sent with an application, Postulo stores:

  • the PDF exactly as it was rendered at that moment,
  • the text it was built from, and
  • a checksum of the file.

These are never regenerated. Edit the CV afterwards as much as you like; the snapshot does not move.

This is the feature you will not appreciate until an interviewer asks about something on your CV three months and eleven revisions later. The stored text matters as much as the PDF, because a PDF is awkward to search and impossible to diff.

To record a set: open an application and choose Record what you sent. Pick a CV, a cover letter and any files you already had. Postulo renders the first two as they stand, attaches everything to the application, and notes it on the timeline.

A snapshot outlives what it was sent with. Delete the application, the listing or even the whole company, and the PDFs stay where they are, still naming the role and the employer they went to. That is the point of a snapshot: the evidence is not a side effect of the records around it. Deleting any of those does say, before it happens, how many applications, timeline entries, interviews and reminders go with it — and how many sent documents are kept.

A snapshot keeps the language it was sent in. It is frozen with the PDF, like the text and the checksum, and for the same reason: the CV it came from can be rewritten into another language afterwards, or deleted outright, and what an employer received is still what it was. A report is kept in the language you were reading Postulo in when you pressed Download, because that is the language it was printed in.

An uploaded file cannot be swapped. Once a file is here, its bytes never change: editing it changes the title, the kind and the notes only. A new version is a new upload that marks the old one as superseded, so an application that says it sent something still means the file it actually sent. Every upload is checksummed when it arrives.

Not everything you send is a file. A portfolio, a profile or a video CV is an address, and those live on your career record as links. Record what you sent offers them beside your CV, your letter and your files, and the ones you tick are attached to the application and named on the timeline. A link that did not answer when it was last checked says so wherever it appears.

Keeping copies elsewhere

Everything above lives in Postulo's own private media, and always will: that is where rendering, downloads, the export and the review of what you sent read from, and none of it needs a network. A document store is somewhere that receives copies — a Paperless-ngx archive, say, through the postulo-paperless plugin.

Once the operator has installed a store plugin, add it under Settings → Connections. The form ends with a switch per kind of document — CV, cover letter, certificate, portfolio, report, reference, other — so you can send the paperwork and keep the rest at home. An email is not a kind, deliberately: what is worth keeping of one — the text as sent, frozen — is what a letter's snapshot already is, and a message a transport carries is not a document. From then on every new document is queued for the store and the scheduler sends it on its next pass, a few minutes later. Each document shows how that went, beside its name:

  • archived — with a link to it in the store, when the store has one;
  • waiting to be sent — the scheduler has not been round yet;
  • failed: … — with the reason; Postulo tries again with a growing wait, six times, then leaves it to you;
  • not accepted — the store declined that kind of document.

Send to stores now under a document tries at once, and gives a copy that gave up its attempts back. Send everything on the connection queues every document you already had before the store existed. Nothing is ever sent twice to the same store, and nothing is ever deleted from a store: an archive is for keeping.

The references — where each copy went — travel in your export, so a restored instance still knows where its copies are even before you recreate the connection.

Each copy is filed under the language of the document, never the language you happen to read Postulo in — a French CV archived as English is a French CV you will not find again. A file nobody has stated a language for is sent without one, and the store files it by its own rules.

Privacy

Uploaded documents contain your address, your phone number and your full employment history. Postulo treats them accordingly:

  • Media is never served by the web server. Files are delivered only through a view that has already established who is asking. A file belonging to someone else is not merely refused — it is not found.
  • Downloads are sent with Cache-Control: private, no-store, so they do not linger in a shared cache.
  • Stored paths are checked on every request to confirm they resolve inside the media directory.
  • Deleting a document deletes its file, once the change is committed and no other record points at the same file. "Deleted" means deleted, not hidden.

Documents deleted before that was true left their files behind, and a restore from an older archive can bring more. To find them:

uv run manage.py prune_media              # lists what no record points at, deletes nothing
uv run manage.py prune_media --remove     # deletes those files

It lists by default because the failure mode of the other default is somebody's CV. Files that a document, an avatar or a company logo points at are never touched.

If you put a reverse proxy in front of Postulo, do not add a location block serving MEDIA_ROOT. It would bypass every one of those checks. If you want the proxy to do the work of sending bytes, use POSTULO_MEDIA_ACCEL_PREFIX instead, which hands over only after Postulo has authorised the download. See Configuration.