← CV Tailor

Privacy policy

Last updated: 28 September 2026

1. Who is responsible

The controller under the GDPR is Nestor Iriondo, Kiefholzstraße 16, 12435 Berlin, Germany. Email: hello@nestoririondo.com. There is no data protection officer, as none is required.

2. Your account

We store your name, email address, a hashed password (not the password itself) and your sign-in sessions, including the IP address and browser of each session. If you sign in with Google, Google sends us your name, email address and profile picture link; we receive no password and nothing else from your Google account. Purpose: providing the service you signed up for. Legal basis: Art. 6(1)(b) GDPR (contract). A session ends when you sign out or after 7 days without use. Everything else is kept until you delete your account.

You need an email address to use the service. Everything else you enter is up to you.

3. Your CV, profile and applications

We store what you enter or import: CVs and profile facts (possibly with a photo), job postings, generated CVs and their versions, applications and your job search settings. Purpose: providing the service. Legal basis: Art. 6(1)(b) GDPR. Kept until you delete it or your account.

A CV can contain sensitive information (for example about health or religion). The service doesn't need any and doesn't ask for it; if you enter such information anyway, it is processed only to do what you ask with it (Art. 9(2)(a) GDPR), and you can remove it at any time.

Each account has its own database on a server in Germany. To run the service, the operator can see each account's details (email, sign-up and last sign-in, signed-in devices) and how many CVs, applications and job matches it has, but not their content.

4. AI processing

When you import a CV, generate or revise a CV, or rate job matches, the relevant profile facts and job texts are sent to Anthropic (Claude), which processes them for us as a processor under a data processing agreement. Contact details are not sent for job ratings. Anthropic does not use this data to train its models and deletes it within 30 days, unless it is needed to enforce its usage policy. Legal basis: Art. 6(1)(b) GDPR. The results are suggestions: nothing is sent to an employer, and no decision about you is made automatically within the meaning of Art. 22 GDPR.

We record each AI operation (its kind, time, tokens used and cost) to enforce your plan's limits and keep costs under control. Legal basis: Art. 6(1)(b) and (f) GDPR; our legitimate interest is preventing abuse of the free trial. After you delete your account, these records are kept under an internal id, without your email address or any content.

5. Free trial

To give each email address one free trial, we store a keyed hash of your email address, not the address itself. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is preventing the trial from being reset by signing up again. The hash stays after you delete your account, for as long as a free trial is offered.

6. Payments

Pro is sold by Polar Software Inc. as merchant of record: Polar processes the payment, invoices and taxes, and receives the payment details and billing address you enter at checkout. We never see your card. Polar tells us only whether your subscription is active and its billing period, which we store as your plan. Legal basis: Art. 6(1)(b) GDPR. Polar is responsible for its own processing; see polar.sh/legal/privacy. Polar keeps invoices as long as tax law requires.

7. Emails

We send emails about your subscription (for example when an introductory offer or Pro is about to end) through Resend, which sends them for us as a processor. We store which of these emails were sent, so none goes out twice. Legal basis: Art. 6(1)(b) GDPR. We send no newsletters or advertising.

8. Feedback

If you send feedback from the app, we store your message, its type, your plan and, if you leave that box ticked, the path of the page you were on (for example /applications/…, not its content). Your email address is stored with it only if you tick "It's OK to email me". Legal basis: Art. 6(1)(f) GDPR (improving the service) and, for the email address, your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time by writing to us. When you delete your account, your feedback is kept without anything that links it to you.

9. Security and abuse protection

To stop mass sign-ups, the number of new accounts per IP address is limited; the IP address is kept for that purpose for up to one day. The server may also record technical request data (IP address, time, requested address, browser) in logs to detect and fix attacks and errors; these logs are deleted after at most 14 days. When something fails, our server sends an error report to PostHog: the error message and technical trace, the page path without its parameters, the affected function and, for errors in your browser, the browser type. No IP address, account or cookie is included; your browser never contacts PostHog. Error reports are deleted after at most 12 months. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is a secure, working service.

10. Job boards and job pages

The job search queries public job boards (Bundesagentur für Arbeit, Arbeitnow) with your search keywords and location. When you add a posting by its link, our server opens that page. No profile data is sent in either case, and the sites see our server, not your device.

11. Cookies and browser storage

We set two cookies: the sign-in session cookie and one that remembers the interface language you chose (kept for a year). In your browser's storage we remember your light/dark choice, which language suggestions you have answered and which draft you had open. All of these are strictly necessary for features you use, so they need no consent (§ 25(2) TDDDG). There is no advertising, analytics or third-party tracking.

12. Recipients and transfers outside the EU

Where data goes to the USA, the transfer is based on the EU Commission's adequacy decision for the EU-U.S. Data Privacy Framework if the recipient is certified, and otherwise on the EU standard contractual clauses (Art. 46(2)(c) GDPR). You can ask us for a copy of the safeguards.

13. Your rights

You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16) or erased (Art. 17), to restrict its processing (Art. 18), to receive it in a portable format (Art. 20), and to withdraw any consent with effect for the future (Art. 7(3)). You can edit everything in the app at any time and delete your account and all its data in Settings; deletion is immediate, and backups are overwritten within 30 days. Deleting your account also ends a paid subscription. For anything else, write to us.

Right to object (Art. 21 GDPR): where we process your data based on legitimate interests (Art. 6(1)(f)), you can object at any time for reasons arising from your particular situation. We then stop, unless we can show compelling legitimate grounds or need the data to establish, exercise or defend legal claims.

You can also complain to a data protection supervisory authority, in particular the one where you live or work.

14. Changes

We update this policy when the service changes. The date at the top shows the current version.