Legal

Privacy Policy

August 26, 2026

This policy explains what we collect when you use our product, why we collect it, who we share it with, and the rights you have over it. We have tried to keep it readable. If anything here is unclear, please email us.

1. The short version

2. What we collect

Account information

When you sign in with Google we receive your email address, display name, and profile image from Google. We do not see or store your Google password.

Content you create

Resumes you upload or generate, job descriptions you paste, cover letters, application notes, and your profile photo if you upload one. We store this so you can reach it across sessions and so the AI features can work. We do not train AI models on this content.

Usage analytics

We capture product usage events — page views, button clicks, AI generation counts — through PostHog. These events carry no resume or job-description text: only counts, durations, file types and anonymous identifiers.

Only if you say yes. PostHog is not loaded at all until you accept on the banner. Not loaded and held back, but never started: no script, no request, no identifier. Declining is a complete answer and nothing else about the product changes.

Nothing else measures you. There is no second analytics tool that runs without asking: if you decline the banner, no analytics of any kind is collected in your browser.

The help assistant

When you ask the in-product assistant a question, we store the question on its own. Not your name, not your account, not your IP, not the answer, and not the rest of the conversation. It is kept for 30 days and then deleted. We do it so we can see which parts of the product people cannot work out, and it is stored with nothing attached so that it cannot later be connected to you.

The assistant is not given your account or your CV, so it cannot discuss them even if asked.

Billing data

When you buy credits or a pass, Ameriabank processes your card on its own payment page. We never see or store your card number, security code, or expiry date — you type them on the bank's page, not ours. What the bank returns to us afterwards, and what we keep on the order, is the last four digits of the card, the cardholder name as the bank holds it, the bank's reference number for the transaction, and its result codes. That is what lets us answer someone who says they paid and nothing happened.

Technical data

Standard server logs — IP address, user agent, request timestamps — for security and abuse prevention. Logs are retained for 30 days.

3. How we use it

4. Sub-processors

We rely on these services to run the product:

5. Retention

We keep your account data while your account is active. When you delete your account, we delete your resumes, applications, version history, notes and uploaded photos within 30 days. Payment records — the order, its amount, and the bank's references for it — are retained for seven years under applicable tax law, by us and by Ameriabank. Server logs are retained for 30 days.

We also keep encrypted off-database backups of the whole database for 90 days, so that a bad migration or a lost account is recoverable. Deleting something removes it from the live database on the timeline above; a copy can remain inside an encrypted backup until that backup expires, which is never more than 90 days after it was taken.

6. Your rights

Regardless of where you live, you can:

If you are in the European Economic Area, the UK, or Switzerland you additionally have the right to object to processing, the right to portability, and the right to lodge a complaint with your supervisory authority. Our lawful basis for processing is contract performance — running the product you signed up for — and legitimate interest in security and abuse prevention.

If you are in California you have rights under the CCPA and CPRA, including the right to know what we collect, the right to delete, the right to opt out of any sale or sharing of personal information, which we do not do, and the right to non-discrimination for exercising these rights.

To exercise any right, email us from the address on your account.

7. Cookies and local storage

We use a small number of cookies and one localStorage entry:

8. Where your data is processed

The server and the database are both in Germany: the application runs on Hetzner in Falkenstein, and the database is Neon in the eu-central-1 region, Frankfurt. For visitors in the European Economic Area, the primary processing of your account and your documents does not leave the EEA.

Some sub-processors listed in section 4 operate outside the EEA: Ameriabank in Armenia, and PostHog, Resend and the Google Gemini API. Armenia is not covered by an EU adequacy decision, so paying from the EEA means your card details are handled in Armenia by the bank that processes the payment. Transfers to the other three are covered by the Standard Contractual Clauses or an equivalent mechanism. Your CV is sent to only one of them, the Gemini API, and only for the specific request you asked for.

9. Children

The product is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

10. Security

All traffic is encrypted in transit with TLS 1.2 or later. Data is encrypted at rest in our database. We use industry-standard access controls. No system is perfectly secure — if we ever experience a breach affecting your data, we will notify you without undue delay.

11. Changes to this policy

We will update this page when we change how we handle data. Material changes will be announced by email to account holders at least 30 days before they take effect.