Privacy Policy
Effective 2026-08-26Last updated 2026-09-22
Scope and product template status
Ganlik is a resume- and cover-letter tailoring MVP. This Privacy Policy is an EU/GDPR-oriented transparency notice describing personal-data handling as implemented in the current application code and configuration surface. It is a product transparency template requiring counsel review; it does not claim GDPR/CCPA compliance, certifications, adequacy, or that every processor contract has been verified.
Effective date: 2026-08-26. Last updated: 2026-09-22.
Controller and contact
Ganlik is the product data controller for personal data processed through this application as described here. This notice does not invent a registered legal-entity name, company registration number, postal address, or a named supervisory privacy contact, because those operator identity details are not established in repository configuration.
You can contact the controller / privacy contact through the Contact Us form at /contact. Submissions are delivered by server-side email to a fixed operator inbox configured in the deployment environment; the sender’s email is used only as Reply-To. This page does not publish a support mailbox address.
Operator full legal name and postal address remain production-launch configuration and legal blockers that must be completed before treating this notice as launch-ready. Until then, this page intentionally omits fabricated identity or address details.
Data categories, purposes, lawful bases, and retention
The following matrix summarizes the main processing categories for this MVP. Detailed behavior follows in later sections. Counsel should confirm every lawful-basis label for the launch jurisdiction.
| Data category | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Clerk identity, session, and account management | Authenticate you, create and maintain your signed-in session, and scope product records to your Clerk user id. | Contract (providing the authenticated service you request). | While your account exists; Delete account and data removes product data then deletes the same Clerk user so the identity and session end. |
| Resume files / parsed resume, job descriptions, job URLs, application metadata, notes, and interviews | Create and manage owner-scoped applications and resume library entries, ingest resumes and job postings, and support your application workflow. | Contract (providing resume/JD tailoring and application tools). | Until you delete the application or library entry, or confirm Delete account and data (subject to generation finishing barriers). Guest DOCX bytes and pasted JD text stay in the current browser tab only. |
| AI inputs and validated outputs | Run resume tailoring and cover-letter generation and store only schema-validated structured suggestions/letters plus review decisions. | Contract (delivering the AI-assisted features you request). | Ganlik persists validated structured results on your owner-scoped records until application or account deletion. OpenAI provider abuse-monitoring logs may retain prompts/responses up to 30 days by default (see AI processing). |
| Document conversion and download | Generate tailored DOCX on demand and, when configured, convert DOCX to PDF via CloudConvert for download. Authenticated owners can also download DOCX/PDF for a saved library resume version using the same structured template as the live editor preview (no credits). | Contract (providing downloadable documents you request). | Ganlik generates DOCX/PDF bytes on demand and does not persist generated PDF bytes as durable application or library blobs. CloudConvert receives temporary conversion payloads on the EU API host; exact provider-side deletion timing is not verified in this repository. |
| Credits, Stripe Checkout orders, and payment reconciliation | Enforce integer credit costs, fulfill one-time credit pack purchases, and keep a minimal payment/credit audit trail. | Contract (billing and credit ledger for the service) and, where applicable, legal obligation (Dutch accounting/tax record-keeping). | Active credit balance while the account exists. Minimal purchase-order / credit-ledger / credit-account rows may be retained up to 7 years after deletion for Dutch accounting, fraud prevention, and charge reconciliation. |
| Support and Contact Us submissions | Receive and respond to inquiries sent through the /contact form. | Responding to your request (steps needed to handle the inquiry; contract where it relates to your account or service). | Delivered by server-side SMTP to the configured operator inbox (Reply-To set to your email). This repository does not implement an automatic mailbox deletion job. |
| Abuse prevention, security, and fraud controls | Rate-limit expensive endpoints, resist abuse, and protect service integrity. | Legitimate interests (security, abuse prevention, and fraud controls). | Per-scope limiter buckets use short hit windows (default 60 seconds unless overridden server-side) and are cleaned when expired; owner-scoped limiter rows are also removed on Delete account and data. Raw IP addresses are not persisted (HMAC-hashed subjects for guest/IP scopes). |
| Privacy-minimized operational analytics | Measure allowlisted operation success/failure rates and coarse active usage for operator service reporting (no resume/JD/prompt content). | Legitimate interests (operating and improving reliable service). | Owner identifiers on analytics events are cleared on Delete account and data; anonymized/non-owner operational events may remain for service reporting. |
| Optional product feedback and referrals | Record voluntary product feedback you submit, and operate the optional invite/referral reward program when you share an invite link. | Voluntary user action: legitimate interests in improving the product from feedback you choose to send; contract for the invite/reward program when you use it. This MVP does not implement a separate GDPR consent/withdrawal control for these features. | Until Delete account and data (feedback rows, referral codes, and referral relationships are purged with product data). Opaque referral invite cookies are temporary browser cookies. |
| Job recommendations (configured job sources) | On demand, derive bounded search keywords from your selected library resume’s professional content, then send those keywords plus your selected country/city filters to configured job-search providers (Job Opportunities API, Arbeitnow for supported markets, Adzuna, and optional regional Jooble) so the product can return, deduplicate, and rank public job listings for you to review. One successful daily free match (Amsterdam calendar day) returns the highest-ranked result from the last 30 days without a credit charge. Full match reserves 1 credit and returns up to 10 results; the credit is finalized only for a successful non-empty matched result, while failed, timed-out, invalid, or empty searches restore the reservation. When you choose Add to dashboard, Ganlik persists that listing’s title, company, plain-text job description, and apply URL as a new owner-scoped application (using your selected library resume) so you can continue in Dashboard/Tailor workflows without another search charge. | Contract (providing the authenticated job-search feature you request). | Ganlik does not persist provider search result lists or match scores for this MVP. Derived keywords and location filters are sent transiently to each configured provider for the request only. If you Add to dashboard, the job title, company, description text, and apply URL are stored on your application like other job materials until you delete that application or your account. Adzuna and Jooble may process outside the EEA under their terms; transfer safeguards are operator verification tasks. |
| Account/product deletion and retained financial records | Honor Delete account and data / application deletion while retaining the minimum financial audit records needed for accounting and fraud integrity. | Legal obligation and legitimate interests where appropriate (Dutch accounting/tax retention, fraud prevention, charge reconciliation), alongside contract performance for deletion itself. | Product content is removed per implemented delete paths. Minimal Stripe purchase-order / credit-ledger / credit-account rows may remain up to 7 years and do not keep resume or job-description content. |
Processing categories, purposes, lawful bases, and retention periods
Legitimate interests and your right to object
Where this notice relies on legitimate interests, the interests pursued are: (1) protecting the service against abuse, fraud, and security threats through rate limiting and related controls; (2) operating privacy-minimized service analytics so operators can keep the product reliable; and (3) retaining minimal financial/audit records needed for charge reconciliation and fraud prevention after product deletion, alongside legal accounting duties where they apply.
You may object to processing based on legitimate interests via the Contact Us form at /contact. An objection does not automatically mean the interest always overrides your rights, or that every request will succeed—Ganlik will consider your objection and any compelling grounds or legal duties that apply. Deletion and financial-retention limits described below may still apply.
Sensitive user content
Resumes, job descriptions, job URLs, AI-generated tailoring suggestions, accept/reject review decisions, and cover-letter content are sensitive user content. Treat them as private career materials. The product stores structured forms of this content on owner-scoped application records and owner-scoped resume library entries after you authenticate; it does not treat them as public.
What the product collects
Authentication identity from Clerk (the signed-in owner id used to scope application, resume library, and credit records). Account profile details shown in Clerk-hosted UI are processed by Clerk according to Clerk’s own terms and privacy materials.
Application records owned by your Clerk user id may include: job URL; original resume file name; optional reference to a library resume id when an application resume was copied from your library; optional owner-editable application stage (draft, applied, recruiter screen, interview, assessment, offer, rejected, or withdrawn; unset until you choose one); optional owner-editable priority (low, medium, or high); optional plain-text application notes; optional interview records (round label, scheduled time, contact details, notes, next step); stage-change history used for your application analytics; parsed resume JSON (plain text, section/paragraph structure, and—for supported uploads—a bounded, sanitized Word formatting template with preview metadata); resume byte-size and MIME metadata; job description plain text and source/status metadata (manual paste or URL fetch); optional job title/company fields; AI tailoring status, validated structured suggestions, and review decisions; cover-letter status and validated structured letter JSON; and related timestamps/attempt identifiers used for idempotency and lifecycle control.
Resume library entries owned by your Clerk user id may include: a user-editable alias; the original uploaded file name; optional parent/version metadata for immutable saved versions (parent resume id, version number); an optional Master Resume flag (at most one per owner); an allowlisted ATS template id used by the structured editor preview and version downloads; parsed resume JSON (plain text, section/paragraph structure, and—for supported uploads—a bounded, sanitized Word formatting template with preview metadata); resume byte-size and MIME metadata; upload-attempt identifiers; and related timestamps. Library entries are not applications. Saving structured edits creates a new version and does not mutate the source entry or application snapshots.
Credit account balance, immutable credit ledger entries (amounts, balances, entry types including trial, purchase, referral_reward, reserve, finalize, and refund; attempt ids; idempotency keys; optional application id references; and verified Stripe Checkout Session references on purchase rows), and credit purchase-order records used for Checkout idempotency and fulfillment audit.
Referral records: each authenticated owner may have one opaque invite code and invite link (`/?ref=<code>`). When a friend follows that link, a same-origin HttpOnly referral cookie may store the opaque code temporarily (never owner ids or secrets). After signup, the product may bind the new verified Clerk user to at most one inviter and later record pending/qualified/rewarded/rejected referral status with audit timestamps and the server-fixed reward amount. Invitee email addresses and names are not stored on referral rows and are not shown in inviter dashboards—only aggregate pending/successful/credits-earned counts.
Optional product feedback: authenticated owners may voluntarily submit sentiment and an optional short reason; feedback is owner-scoped and deleted with Delete account and data.
Abuse-control records: per-scope rate/concurrency buckets keyed by a pseudonymous subject key. Authenticated limits use the Clerk owner id. Unauthenticated/IP-scoped limits use an HMAC-hashed trusted client IP combined with a guest scope id. Raw IP addresses are not persisted.
Privacy-minimized operations analytics events may record allowlisted operation tokens, result tokens, coarse error categories, durations, and optional owner ids for distinct active-usage counts—never resume/JD/letter content, filenames, URLs, email, IP, prompts/outputs, stack traces, secrets, or raw error strings.
Before signup, limited guest tailor continuity metadata (resume file name, job URL, a boolean flag that a manual job paste was provided, and an unguessable claim token) may be held in the browser’s sessionStorage, and the claim token alone may appear in the same-origin Clerk return URL. Guest DOCX bytes and pasted job description text are held only in the current browser tab’s memory for the shortest practical period (tab/session lifetime as implemented) and are never written to sessionStorage, localStorage, cookies (except the opaque referral invite cookie described above), Clerk metadata, URLs, logs, or unauthenticated server persistence. Processing and AI generation begin only after authentication; signup does not spend credits.
DOCX binaries and generated files
Uploaded Word (.docx) source bytes are parsed in memory on the server and are not persisted as the original file blob. For supported uploads, the product stores a bounded, allowlisted, sanitized formatting template (styles, paragraph/run properties, numbering, and safe internal package parts) plus structured plain text and preview metadata needed to render and regenerate documents. Macros, embedded active content, and external relationships are removed and are not retained. Unsupported or oversized templates fall back to text-only parsing while still storing plain text.
Tailored resume and cover-letter .docx downloads are generated on demand in memory from reviewed/validated structured content and any retained safe formatting template on authenticated download routes. Generated DOCX bytes are not stored as durable application blobs. When PDF download is configured, CloudConvert receives temporary DOCX bytes for conversion on the EU API host (`eu-central.api.cloudconvert.com` by default); Ganlik does not persist generated PDF bytes as durable application blobs. Exact CloudConvert provider-side deletion timing is not verified in this repository and remains a pre-production vendor-contract verification item.
Concrete retention periods
Browser-only guest DOCX bytes and pasted job description text: current browser tab / in-memory session lifetime as implemented; they are not written to durable browser or server storage.
Account, application, resume library, product feedback, and referral product data: retained until you delete the relevant records or confirm Delete account and data, matching the implemented delete paths (application deletion, unreferenced library deletion, and whole-account purge).
OpenAI API: According to OpenAI’s official API Data Controls documentation, API data is not used to train or improve models unless the API customer explicitly opts in. If the operator has not opted in, API data follows that default no-training rule. This repository does not prove the current OpenAI account or project data-sharing opt-in state, so this notice does not claim that the operator’s live setting is known or verified—operators must verify and document that setting before production. Default abuse-monitoring logs may include prompts and responses and can be retained up to 30 days unless longer retention is legally required or reasonably necessary to protect OpenAI’s services or third parties. Chat Completions has no application-state retention by default, subject to documented exceptions. This repository does not prove Zero Data Retention (ZDR) or Modified Abuse Monitoring approval for this project, so this notice does not claim ZDR.
CloudConvert: temporary conversion via the configured EU API host; Ganlik does not persist generated PDF bytes. Exact provider-side deletion timing/contract terms are not verified here—treat confirmation of that timing as a pre-production vendor-contract verification item rather than an invented number.
Contact email: messages are delivered to the configured operator mailbox over SMTP (intended for a Gandi mailbox when CONTACT_SMTP_* points at mail.gandi.net). No enforced automatic mailbox deletion job exists in this codebase; retention follows the operator’s mailbox process until a documented procedure is established.
Abuse limiter: hit windows default to 60 seconds per scope unless overridden by server env; expired idle buckets are cleaned opportunistically, and owner-scoped limiter rows are removed on account deletion.
Operations analytics: owner identifiers remain until account deletion, then are cleared; anonymized/non-owner operational events may remain for service reporting.
Financial and accounting records: minimal Stripe purchase-order / payment-reconciliation records and immutable credit ledger entries, plus the credit-account parent row structurally required for those records, may be retained for up to 7 years where needed for Dutch accounting and tax record-keeping (aligned with Dutch Tax Administration guidance on retention of business administration), fraud prevention, charge reconciliation, and balance integrity.
How the product uses data
To authenticate you, create and show owner-scoped applications and resume library entries, ingest resumes and job descriptions, run AI tailoring and cover-letter generation, record accept/reject decisions, generate on-demand downloads (including CloudConvert PDF conversion when configured), enforce integer credit costs, fulfill one-time credit pack purchases, operate the referral invite program (opaque invite links, binding, and inviter reward grants), collect optional product feedback, limit abuse of expensive endpoints, support Contact Us inquiries, record privacy-minimized operational analytics, delete application private content when you request application deletion, delete unreferenced library resumes when you request library deletion, and delete your account product data plus Clerk sign-in identity when you confirm Delete account and data.
Recipients and processors
Clerk — authentication identity and session management. Receives account credentials/profile data you enter in Clerk-hosted flows and the stable user id used for owner scoping. Clerk may process data outside the EEA according to Clerk’s own terms; this repository does not treat regional residency or a signed DPA/SCC as verified.
Neon (PostgreSQL) — primary application database via DATABASE_URL. Stores owner-scoped applications, resume library content, credits/purchase orders, referrals, feedback, abuse-limiter rows, and operations analytics events. Neon may process outside the EEA depending on the configured project; residency and DPA/SCC status are not asserted from this repository alone.
Vercel — application hosting and request routing for this deployment. Processes HTTP request traffic needed to deliver the app. Vercel may process outside the EEA; hosting-region and DPA/SCC verification are operator pre-production tasks.
OpenAI (OpenAI-compatible Chat Completions API as configured) — AI provider. Receives resume- and job-derived prompt context needed to produce structured suggestions or letters. See AI processing for training and abuse-monitoring retention. OpenAI may process outside the EEA; this notice does not claim EU-only processing or verified SCCs from repo evidence.
CloudConvert — DOCX→PDF conversion when configured. Receives temporary DOCX bytes and returns PDF bytes via the EU API host configured for this project (`eu-central.api.cloudconvert.com` by default). Exact provider retention timing is unverified; DPA/SCC status is an operator verification task.
Stripe — Checkout and webhooks for one-time credit pack purchases. Receives payment and checkout details needed to charge and reconcile orders. Stripe may process outside the EEA under Stripe’s terms; card data is handled by Stripe, not stored as full PAN data in Ganlik product tables.
Configured SMTP / email provider (Gandi when CONTACT_SMTP_HOST is set to a Gandi mailbox host such as mail.gandi.net) — delivers Contact Us messages to the fixed operator inbox. Receives message content and Reply-To addressing needed to deliver mail. International transfer posture depends on the configured provider; not verified as EEA-only from this repository.
Adzuna — Job Search API used only when you run Job recommendations from the authenticated dashboard. Receives derived search keywords (from professional resume content such as recent role titles and skills, after stripping contact details as far as the parser structure permits) and your selected country/city filters — not the resume document, full resume text, or personal/contact fields. Returns public job listing metadata for on-demand display. When you Add to dashboard, Ganlik stores selected listing fields on your application; Adzuna is not called again for that add. Adzuna may process outside the EEA under Adzuna’s terms; DPA/SCC verification is an operator task.
Jooble — optional regional Job Search API used only where the relevant country key is configured and you run Job recommendations. Receives the same derived search keywords and selected country/city filters as Adzuna — not the resume document, full resume text, or personal/contact fields. Returns public job listing metadata for transient, deduplicated display. Jooble may process outside the EEA under Jooble’s terms; DPA/SCC verification is an operator task.
Job Opportunities API — public job-listing API used when you run Job recommendations. Receives derived search keywords and selected country/city/date filters — not the resume document, full resume text, or contact fields. Returns employer-direct listing metadata for transient, deduplicated display. Provider terms, processing locations, and DPA/SCC posture remain operator verification tasks.
Arbeitnow — public job-board API used for supported German and UK searches. Ganlik fetches a public page and filters it server-side using derived keywords, selected city, and date range; the resume document and contact fields are not sent. Provider terms, processing locations, and DPA/SCC posture remain operator verification tasks.
Processor Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), EU–US Data Privacy Framework certifications, adequacy reliance, and regional residency claims are not treated as completed facts in this notice unless confirmed by repository configuration or official contract evidence held by the operator.
International transfers
Some providers named above may process personal data outside the European Economic Area (EEA).
Where a provider’s contract actually includes them, applicable safeguards may include an adequacy decision and/or Standard Contractual Clauses (SCCs). This transparency notice does not assert that every listed processor’s DPA/SCC pack has been reviewed or signed for this project.
Processor DPA/SCC verification is an operator pre-production compliance task. Unverified safeguards are not presented here as completed.
Authentication (Clerk)
Sign-in and sign-up are provided by Clerk. Dashboard routes and application mutation/download APIs require a Clerk session. Application rows, resume library rows, credit accounts, purchase orders, and referral records are keyed to Clerk’s stable user id (owner-scoped). Referral eligibility uses trusted Clerk Backend account creation time and primary-email verification status (no Clerk webhook is required for this MVP). Authenticated owners can confirm Delete account and data from the Your data surface; after owner-scoped product data is purged in the database, the product calls Clerk’s Backend API to delete that same signed-in user so the identity and session end.
AI processing
Resume tailoring and cover-letter generation send resume- and job-derived content to the configured OpenAI-compatible Chat Completions API (credentials such as AI_API_KEY stay on the server and must not use a NEXT_PUBLIC_ prefix) so the product can provide AI-assisted suggestions and letters. Only schema-validated structured results are persisted by Ganlik—not raw provider transcripts. That does not mean prompts are never stored anywhere: OpenAI may retain prompts/responses in default abuse-monitoring logs as described below, and Ganlik stores validated structured outputs on your application records.
According to OpenAI’s official API Data Controls documentation (https://platform.openai.com/docs/guides/your-data): API data is not used to train or improve models unless the API customer explicitly opts in. If the operator has not opted in, API data follows that default no-training rule. This repository does not prove the current OpenAI account or project data-sharing setting, so this notice does not claim that Ganlik’s live opt-in or opt-out state is known. Operator verification and documentation of the actual account/project data-sharing setting is required before production (see production legal blockers). Default abuse-monitoring logs may include prompts and responses and are retained up to 30 days unless longer retention is legally required or reasonably necessary to protect OpenAI’s services or third parties. Chat Completions has no application-state retention by default, subject to documented exceptions. This project’s configuration does not prove Zero Data Retention (ZDR) or Modified Abuse Monitoring approval, so this notice does not claim ZDR.
Distinguish Ganlik persistence (owner-scoped validated suggestions/letters until you delete them) from OpenAI provider retention (default abuse monitoring up to 30 days, plus any longer retention OpenAI documents for legal/protection needs). The exact model and base URL follow server environment configuration (default base URL targets api.openai.com when configured).
AI output can be incomplete or incorrect; see the Terms. AI suggestions assist you in preparing materials and do not make employment decisions about you, and are not solely automated decisions producing legal or similarly significant effects within this product.
Job URL retrieval
You may paste a job description manually or ask the product to fetch a public HTTP(S) job URL stored on your application. Fetching uses a pinned, SSRF-resistant transport with bounded timeouts, redirects, and response size. Fetched HTML is not rendered or stored as markup; only normalized plain text and safe metadata are retained. Job fetch configuration does not use a scraping API key.
Job recommendations (multiple providers)
When you use Jobs in the signed-in dashboard, Ganlik derives a bounded search phrase from the professional content of one owner-scoped library resume you select (for example recent role titles and skills). Contact-oriented fields such as email, phone, and URLs are stripped as far as the parsed resume structure permits. That phrase plus your selected location filters and posting-date filter are sent to configured job-search providers: Job Opportunities API, Arbeitnow for supported German and UK searches, Adzuna, and optional regional Jooble. The resume document itself and personal/contact details are not uploaded to these providers.
Lawful basis for this processing is contract (providing the authenticated job-search feature you request). Job Opportunities API, Arbeitnow, Adzuna, and configured Jooble regional endpoints are recipients/processors of transient query parameters or public request traffic and may process outside the EEA; international-transfer safeguards and each provider’s DPA/SCC status are operator verification tasks, not completed facts from this repository.
Ganlik does not persist Adzuna search result lists or match percentages for this MVP: listings are shown for the current request only unless you explicitly choose Add to dashboard. That action creates an owner-scoped application with the listing’s title, company, plain-text job description, and apply URL plus a snapshot of the library resume you selected on Jobs — the same first-party application fields used elsewhere in the dashboard. Match percentages describe resume-to-posting relevance only and are not a prediction of hiring outcomes; they are not stored on the application. You control this processing by choosing whether to run a search, which resume and filters to use, whether to add a listing to your dashboard, and by deleting applications, library resumes, or using Delete account and data when you no longer want the underlying content available.
One successful daily free match, measured by the Europe/Amsterdam calendar day, returns the highest-ranked job from postings in the last 30 days and does not use a credit. A full matched-job search costs 1 credit only when a non-empty validated result set is returned and may return up to 10 jobs with selectable posting-date filters. Provider failures, timeouts, invalid responses, and empty results do not consume the daily free match and are not charged or restore the reserved credit. Adding an already returned job to Dashboard does not use another credit.
Payments and credits (Stripe)
Credit units are server-authoritative integers, not currency. CV generation costs 2 units; cover-letter generation and a successful non-empty full matched-job search each cost 1 unit. The single daily free match does not use a credit. A one-time MVP trial grant may initialize a new owner’s balance (default 5 units unless overridden server-side).
One-time credit packs are purchased through Stripe Checkout in payment mode. The client submits only a pack id and purchase-attempt id; amounts, currency, Price IDs, and success/cancel URLs are server-derived. Credits are granted only after the Stripe webhook verifies the paid session against the persisted order—never from browser redirects alone. Stripe processes card and checkout details under Stripe’s own terms.
Referral rewards: an authenticated owner may share a unique invite link. When a genuinely new friend follows that link, signs up with Clerk, verifies email, and completes their first successful CV generation, the inviter receives a one-time server-fixed grant of 20 credits recorded as a distinct referral_reward ledger entry. The invitee receives no referral credits. Self-referral, duplicate invitees, legacy accounts outside the short signup window, and client-authored reward amounts are rejected.
Storage (Neon / Postgres) and hosting (Vercel)
Application, resume library, credit, purchase-order, referral, product feedback, operations analytics, and abuse-limiter data are persisted in PostgreSQL via Neon as configured by DATABASE_URL. The application is delivered through Vercel hosting and ordinary network providers that terminate TLS and route traffic. This template does not invent a specific cloud region, certification, or verified subprocessor contract beyond what the repository configures.
Application deletion, resume library deletion, account deletion, and retained audit records
From an application detail page, an authenticated owner can confirm deletion of that application. Deletion is owner-scoped: it removes the applications row and private content stored on it (parsed resume JSON/text, any retained sanitized formatting template and preview metadata, job description text/metadata, AI tailoring suggestions, review decisions, and cover-letter JSON). Uploaded DOCX source file bytes were never stored as blobs. Application deletion does not cascade-delete resume library entries.
From the resume library page, an authenticated owner can confirm deletion of a library resume. Deletion is owner-scoped and blocked while any owned application still references that library entry, or while child versions still point at it as their family root, so applications, suggestions, cover letters, credit records, generated history, and version chains are not cascade-deleted. Missing or foreign library ids are treated as already absent (idempotent). When deletion proceeds, it removes the library row’s parsed resume JSON/text and sanitized formatting template metadata.
Deletion of an application is blocked briefly while CV or cover-letter generation is provisional (status generating, including staged output awaiting credit finalize/promote), with a generic “Generation is finishing; try again shortly.” response.
From the Your data page (linked from Privacy and the signed-in dashboard), an authenticated owner can confirm Delete account and data. The confirmation flow requires typing DELETE and affirming understanding of retained financial records. Server-side deletion uses only the Clerk session user id—never a client-supplied owner id. In one database transaction the product purges owner-scoped non-required product data: applications and their dependent interview/stage/notes/suggestion/review/cover-letter content, resume library records and artifacts, product feedback, referral codes and referral relationship rows, abuse-limiter rows keyed to that owner, and owner identifiers on non-financial operations analytics events. After that database cleanup succeeds, the product deletes the same Clerk user so the sign-in identity and session end. If database cleanup fails, the Clerk identity is left unchanged. If Clerk deletion fails after database cleanup, the product does not restore deleted content; retrying is safe and idempotent.
Minimal Stripe purchase-order / payment-reconciliation records and immutable credit ledger entries, plus the credit-account parent row structurally required for those records, may be retained after application deletion or Delete account and data for up to 7 years where needed for Dutch accounting and tax record-keeping (aligned with Dutch Tax Administration guidance on retention of business administration), fraud prevention, charge reconciliation, and balance integrity. Those retained records do not keep resume text, job description text, generated CV/cover-letter content, notes, feedback, or other application private content—ledger applicationId values may remain only as orphan UUIDs without a foreign key. This Privacy Policy is a transparency statement describing implemented behavior and requires counsel review; it does not claim blanket GDPR compliance or that every retention choice is finally settled for every jurisdiction.
Data-subject rights
Subject to applicable law, you may request access, correction, deletion, restriction of processing, data portability, and objection to processing based on legitimate interests. Where processing genuinely relies on consent, you may withdraw consent without affecting the lawfulness of processing before withdrawal. Exercising these rights will not cause retaliation in the form of degrading core account access beyond what is technically required to honor the request.
Submit privacy requests through the Contact Us form at /contact. We aim to respond within one month under the GDPR response target, subject to lawful extensions where permitted.
You have the right to lodge a complaint with the Dutch Autoriteit Persoonsgegevens. Official complaint information: https://autoriteitpersoonsgegevens.nl/klachten
Legal retention duties (including up to 7-year financial/accounting records) and identity verification needs may limit or shape how a request can be fulfilled. Some requests may require confirming you control the relevant account before action is taken.
Security, breach posture, and automated decisions
The codebase uses owner scoping, server-only secrets, webhook signature verification, abuse limiting, SSRF-resistant job fetching, and TLS-terminated hosting as implemented. This template does not claim formal security certifications, guaranteed uptime, absolute confidentiality against all threats, or that every third-party processor’s controls are verified here.
If a personal-data breach occurs that requires notification under applicable law, the operator intends to follow those notification duties; this notice does not invent a separate public breach portal.
AI suggestions assist you in drafting application materials. They do not make employment decisions about you and are not solely automated decisions with legal or similarly significant effects inside this product.
Your choices
You can avoid uploading resumes or pasting job text you do not want processed. You can use manual job description paste instead of URL fetch. You can accept or reject individual AI suggestions before download. You can delete individual applications when generation is not provisional. You can rename or delete unreferenced resume library entries. You can choose whether to run Job recommendations, which library resume and location/language filters to use, whether to Add to dashboard, and you can refrain from searching. You can open Your data from Privacy or the signed-in dashboard and confirm Delete account and data to purge product data and close the Clerk sign-in identity, subject to the minimal financial retention described above.
You can reach the operators through the Contact Us form on this site (/contact). Submissions are delivered by server-side email to a fixed operator inbox configured in the deployment environment; the sender’s email is used only as Reply-To. This page does not publish a support mailbox address.
Changes
If product behavior changes, this template should be updated to match the code. The last-updated date above reflects the current documented revision of this copy. Material changes should be reflected here before relying on the notice for a new release.