Skip to main content

Privacy Policy

This privacy policy explains which personal data we process when you use Resume Copilot, for what purposes, on what legal basis, and for how long.

Summary

We store your CV, job ads, and account data on Supabase servers in Frankfurt. Generated text is produced by Vertex AI in the EU with training opt-out enforced. We do not sell your data and we do not train any model on your inputs.

Controller

The controller under Art. 4(7) GDPR is Gendron Himmels AI Innovations GbR, Bürgerstraße 1, 22081 Hamburg, Germany, represented by its partners Patrick Gendron and Robin Himmels. Email: team@resumecopilot.de.

Data protection officer

We have not appointed a data protection officer, as the statutory thresholds do not currently apply. For any privacy-related matter, reach us at the address above or through our contact form.

Data we process

Account data (email, language preference), application data (your master CV including any profile photo embedded in it, uploaded job ads, generated CVs and cover letters, and intermediate parsed forms we cache to speed up tailoring), and technical telemetry needed to operate the service (error reports, request logs with PII scrubbed).

Profile photos in your CV

If the CV you upload includes a profile photo, we extract that image and store it on our Supabase servers in Frankfurt alongside the source CV. The photo shares the same retention as the CV it came from. You can hide the photo on any individual tailored CV before exporting, and when you delete your account the photo is removed together with the rest of your CVs within 30 days.

Cached AI inputs and outputs

To avoid re-parsing the same content on every tailoring, we cache derived forms of your uploaded data — for example a structured JSON representation of your master CV. These intermediate caches follow the same retention as the source they were derived from: they are deleted when you delete the source CV, and removed within 30 days when you delete your account.

Special categories of personal data

Tailoring a CV does not require any special categories of personal data within the meaning of Art. 9(1) GDPR (such as health or disability status, religion, trade-union or political-party membership, or ethnic origin). If the CV you upload nonetheless contains such information — for example a note about a disability or a profile photo — we process it solely to provide the service you requested. The legal basis is your explicit consent under Art. 9(2)(a) GDPR, which you give by deliberately uploading and tailoring that content. You may remove such information before uploading, and a profile photo can additionally be hidden per tailored CV.

Purpose and legal basis

We process your data (a) to provide the CV and cover-letter tailoring service you requested and to manage the contract and your account (Art. 6(1)(b) GDPR); (b) to process payments for paid credit packs (Art. 6(1)(b) GDPR); (c) to keep the service secure, stable, and protected against abuse (Art. 6(1)(f) GDPR — legitimate interest in reliable, abuse-resistant operation); (d) for lightweight product analytics via PostHog, solely on the basis of your consent (Art. 6(1)(a) GDPR); and (e) to answer enquiries submitted through the contact form (Art. 6(1)(b) or (f) GDPR).

Subprocessors

We use carefully selected subprocessors: Supabase (database and storage, EU/Frankfurt), Vercel (hosting, EU), Google Vertex AI (text generation, EU, no training), Trigger.dev (background-job orchestration, USA — IDs-only payloads), Resend (transactional email, USA), Stripe (payment processing), PostHog (product analytics, EU cloud, with consent only), and Sentry (error monitoring). Transfers to the USA are explained in the following section.

International data transfers (USA)

Some of the providers we use process data in the USA, a third country without a general adequacy decision. Appropriate safeguards under Art. 44 et seq. GDPR are in place for these transfers.

Trigger.dev (background jobs): We use Trigger.dev — which runs its cloud infrastructure in the USA — to orchestrate background jobs such as generating export PDFs and running scheduled deletion tasks. The transfer is safeguarded by the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). We generally send Trigger.dev no CV or other content data: jobs carry only anonymous identifiers (IDs); the actual content is loaded from our Frankfurt servers at runtime, processed in memory, and then discarded. A residual, technically unavoidable risk remains that operational and log data (e.g. run logs with IDs and timestamps) are retained in the USA for the duration of run logging (up to 30 days by default); we have deliberately assessed and accepted this residual risk, as the data contains no plain-text content.

Resend (transactional email): We use Resend — which runs its infrastructure in the USA — to send transactional email (e.g. sign-in / magic-link messages or replies to contact enquiries). The transfer is doubly safeguarded: Resend is certified under the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR), supplemented by the Standard Contractual Clauses under Art. 46(2)(c) GDPR. We send Resend only the data needed for delivery — your email address and the subject and body of the relevant transactional email, or a magic-link token. CV content is never sent via Resend.

Google Sign-In (optional): If you choose "Continue with Google" instead of an email address and password, Google confirms your identity to us and sends us your name, your email address and, where available, your profile picture. We receive nothing else — Google never sends us your contacts, your calendar or any other Google data, and we never send Google your CV. For this sign-in step Google acts as an independent controller under its own privacy policy and will know that you signed in to Resume Copilot. Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR), supplemented by the Standard Contractual Clauses under Art. 46(2)(c) GDPR. The legal basis is Art. 6(1)(b) GDPR (performance of a contract), because you chose this way of signing in. Signing in with an email address and password remains available and involves Google in no way.

Automated processing and AI

Your CV and cover letter are tailored using a large language model (Google Vertex AI, Gemini 2.5) operated in the EU region europe-west1. Google contractually does not use your inputs to train models (training opt-out is configured). For abuse and safety monitoring, Google may log inputs for an unspecified period. There is no solely automated decision within the meaning of Art. 22 GDPR producing legal or similarly significant effects: every AI suggestion is shown to you, can be edited by you, and is only applied after you confirm it. You retain full control over the content.

Cookies and analytics

We use strictly necessary cookies only for sign-in and your active session; the legal basis for storing or accessing information on your device is §25(2)(2) TDDDG, and for the processing Art. 6(1)(f) GDPR. The anonymous-trial cookie is functional and not used for tracking. For product analytics we use PostHog (EU cloud) — but only with your prior consent (Art. 6(1)(a) GDPR, §25(1) TDDDG). PostHog is not loaded and no analytics data is collected before you consent. You can reject consent with one click in the cookie banner and withdraw a granted consent at any time, with effect for the future, via the “Cookie settings” link in the footer; the lawfulness of processing carried out before withdrawal remains unaffected.

Session recordings

Under the same consent you give in the cookie banner, PostHog (EU cloud) also records how you move through the site: pointer movement, clicks, scrolling and page changes. These recordings contain nothing readable. Every text node and every form field is replaced with a placeholder inside your browser before anything is transmitted — PostHog never receives the original characters. Your CV, your cover letter, your application photo and your signature are excluded from the recording entirely and appear only as an empty area. Nor do we record the data your browser exchanges with our servers in the background, technical log output, or embedded payment fields. The sole purpose is to spot usability problems in our interface; the legal basis is your consent (Art. 6(1)(a) GDPR, §25(1) TDDDG). If you reject in the cookie banner or withdraw your consent, no recording takes place.

Payment processing (Stripe)

Paid credit packs are processed through Stripe. Stripe processes payment and customer data (e.g. email address, payment-method metadata, transactions) as an independent controller under its own privacy policy and statutory retention obligations, in particular under commercial and tax law. Our legal basis is Art. 6(1)(b) GDPR (performance of a contract). When you delete your account we remove the mapping between your account and your Stripe customer record; the Stripe record itself is subject to Stripe's regulatory retention periods.

Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) to processing based on Art. 6(1)(f) GDPR. Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR). A message via our contact form is enough to exercise these rights; you can also start access and erasure from within your account. Independently, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information (Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit); you may also contact the authority of your habitual residence.

Retention

We keep personal data only as long as necessary for the respective purposes. Anonymous trial data (uploaded CV, extracted profile photo, parsed JSON form, pasted job ad, and rate-limit counters) is deleted automatically within 24 hours of the anonymous session expiring. Account data and content stored in your account are kept until you delete your account, after which they are removed from live systems and backups within 30 days. Error reports (Sentry) are deleted after 90 days; server request logs contain only pseudonymous request identifiers. Payment data is subject to statutory retention periods (see Payment processing).

Contact for privacy matters

Use our contact form for any privacy-related request — we typically respond within one business day.

Open the contact form

Last reviewed: 2026-08-27