Controller
The data controller responsible for processing on this website is:
Maven Webcraft
Berlin, Germany
Email: info@mavenwebcraft.com
See the Impressum for full provider details.
What we process
| Category | Data | Purpose | Legal basis |
|---|---|---|---|
| Account | Email address, password hash, verification status; with Google sign-in: name and profile email from Google | Account creation, login, credit balance | Art. 6(1)(b) GDPR |
| Uploaded evidence | CV / resume documents (PDF, DOCX, TXT, MD), public profile URLs you provide | One-time profile synthesis | Art. 6(1)(b) GDPR |
| Derived profile | Structured skills, experience, seniority, target description, with PII masked | Job discovery and ranking | Art. 6(1)(b) GDPR |
| Search records | Queries, ranked results, timestamps (newest 25 kept) | Search history feature | Art. 6(1)(b) GDPR |
| Payments | Credit purchases via Stripe; we store only the purchase record, never card data | Billing | Art. 6(1)(b), (c) GDPR |
| Technical | Session cookie, request metadata required for security | Session integrity, abuse prevention | Art. 6(1)(f) GDPR |
How AI processing works
Artificial intelligence is used to synthesize your profile, plan search queries, and rank vacancies. Before any of your text reaches a model provider:
- PII is masked locally and names, email addresses, phone numbers, and postal addresses are replaced with placeholders on our infrastructure first.
- Raw files are never retained. Uploaded documents are parsed in a temporary workspace that is deleted when processing completes.
- No key exposure. Inference runs through our managed configuration; you never provide or see provider API keys.
The model pipeline receives de-identified evidence only. Your identity exists solely in your account record, which is encrypted at rest and keyed to your user ID.
Recipients & processors
- Appwrite for authentication, account data, and encrypted session state.
- Stripe for payment processing for credit top-ups. Stripe acts as an independent controller for payment data; card details are entered on Stripe-hosted surfaces only.
- AI model providers receive masked, de-identified profile text for synthesis and ranking.
- Google only when you choose "Continue with Google" (OAuth2 sign-in).
Where processors act on our behalf, data processing agreements pursuant to Art. 28 GDPR are in place or being finalized. Transfers outside the EU/EEA rely on adequacy decisions or standard contractual clauses.
Retention
- Raw uploads: deleted immediately after parsing and not retained at all.
- Profile and search history: retained while your account exists, to support your workflow; the history holds your newest 25 searches.
- Billing records: retained for the statutory retention period (up to 10 years under German commercial and tax law).
- Account deletion: profile, history, and state are erased upon verified deletion request.
Cookies & local storage
We use a single session cookie to keep you signed in and bind searches to your account. It carries no tracking identifier, is not used for advertising, and expires when your session ends. No third-party tracking cookies are set.
Your rights
Under the GDPR you have the right to:
- Access (Art. 15) and obtain a copy of the data we hold about you.
- Rectification (Art. 16) and correct inaccurate data.
- Erasure (Art. 17) and delete your account, profile, and history.
- Restriction (Art. 18) and objection (Art. 21) to limit or object to processing.
- Portability (Art. 20) and receive your data in a structured, machine-readable format.
- Complaint (Art. 77) and lodge a complaint with a supervisory authority.
To exercise any of these rights, email info@mavenwebcraft.com from your account address. We respond without undue delay, within one month at the latest.
Changes to this policy
We update this policy when our processing changes. Material changes are announced in the app before they take effect; the version and date at the top of this page always reflect the current state.