This notice explains how and why data is processed in free and paid product flows and how long it is retained.
Notice version: 2026-09-24.product-measurementWe process the CV you upload and personal data contained in it, the job posting you paste, language and role choices, analysis and draft results, account and security records, consent choices, and—if you use paid features—order and payment-status data. A CV may contain special-category data; remove information that is unnecessary for the service before uploading.
Processing directly necessary to form or perform a contract may be used to provide the requested analysis, account, and purchased service; legitimate interests balanced against your fundamental rights may support security and abuse prevention; legal obligations may support payment, accounting, and authority requests. Marketing relies on separate, optional consent where required.
Data is collected electronically through upload and text fields, account and payment forms, technical security records created while you use the service, and provider flows you choose to use.
To assess how site actions work and where users stop progressing in aggregate, we use a random 30-minute first-party session marker, a broad traffic source, device category, and event time. We count arrivals, form starts, analyses, package views, and payment steps. These event records do not include raw ad-click identifiers, full referring addresses, CV/job-posting content, email addresses, or IP addresses. Events are retained for up to 90 days and the administration dashboard is restricted to authorized accounts. These product events are not sent to advertising networks or used to build profiles across sites.
Advertising measurement with Google Ads and Google Tag Manager starts only with your affirmative permission in cookie preferences. Before consent, or if you reject it, the Google tag does not load and this integration sends no measurement requests to Google. If you allow it, your IP address, browser and device information, page information, ad-click identifiers, and related cookies may be sent to Google to measure advertising performance. For real purchases with verified payment and credit delivery, the order identifier, amount, and currency are sent to Google for conversion measurement; test payments are excluded. We do not add CV or job-posting content, analysis results, or contact details to advertising measurement data. Advertising personalization and remarketing are disabled. Refusing optional measurement does not prevent you from using free or paid services.
Use “Cookie preferences” at the bottom of the page to change or withdraw permission. Your choice is saved in this browser with a validity of 180 days. Withdrawal stops further measurement; it does not retroactively delete information already sent to Google. Google may also process transferred information on servers outside Türkiye. Its data use and cookie durations are explained in the Google sources below and our Cookie Policy.
In local review mode, records stay in this running server’s temporary memory and are linked to a random HttpOnly ownership cookie in your browser. Local AI mode uses the same temporary storage; extracted CV and posting text is sent to Gemini for structured analysis and application-draft generation after direct personal identifiers are masked. A model draft is stored only after server-side schema, source-reference, and grounding checks pass. If all three validation attempts fail, a deterministic safe draft is built from validated evidence. When production services are enabled, files are held in private R2 storage and records in Neon.
Guest results are retained for 24 hours and content linked to a verified account for 30 days by default. You can delete a record earlier from the result or dashboard. At expiry, CV/posting sources, file metadata including the original filename and hash, analyses, application drafts, and their account links are deleted from the database; the R2 object is removed through a durable deletion queue. Order, contract-acceptance, and credit records may be retained separately for applicable legal or financial obligations, with their application-content link removed.
Limited to the relevant purpose, Gemini may support analysis and drafting, Cloudflare R2 private file storage, Neon database services, Inngest job execution, PayTR payments, and Clerk account verification and session management. Payment or identity services are not involved unless you use the related feature. Data is disclosed to competent authorities only where legally required.
For rights available under Article 11 of the Turkish Personal Data Protection Law—including information, access, correction, deletion or destruction, learning recipients, objecting to solely automated results, and seeking compensation—send a sufficiently identifying request to the legal contact below. Marketing permission remains separate from analysis access.
Official basis: KVKK transparency obligation and Article 11 rights