Privacy Policy

A résumé is one of the most revealing documents a person owns — where you have worked, what you earn by implication, where you studied, sometimes your address and nationality. This page says exactly what Pássaro holds, why, for how long, and who else it passes through.

1.Who is responsible

Controller
Igor Ilin
Address
ul. Straganiarska 20/22 lok. 35, 80-837 Gdańsk, Poland
Contact
support@passaro.ai

There is no data protection officer: the service is too small to require one. Privacy questions go to the contact address above and are answered by a person.

2.What we hold

DataWhy we have itLegal basis
An account identifier issued by our sign-in providerTo know which profile is yours. It is the only thing our account record holds — see section 3 for what it does not holdPerformance of the contract
Your Base Profile: name, headline, location, summary, work history with employers and dates, education, skills, languagesIt is the material every analysis and every generated résumé is written fromPerformance of the contract
The contact details printed on your résumé: typically a phone number, an e-mail address, a city, sometimes a profile linkThey have to appear in the document we generate for you. They come from the CV you imported, or from what you typed into the profile — not from registrationPerformance of the contract
Résumé text you upload or paste, while an import is in progressTo turn it into a profile you can then correctPerformance of the contract
Job descriptions you save, and the vacancies you are pursuingTo judge the fit and tailor a résumé to a specific postingPerformance of the contract
Match analyses and generated résumés, including profile links recorded for tracked generated statementsThey provide the requested analysis and document, and let you inspect the profile records linked to tracked statementsPerformance of the contract
Counts of what you have used this monthTo apply the allowances your plan includesPerformance of the contract
Subscription and payment metadata: plan, status, period, the identifier Paddle gave your customer recordTo know what you are entitled to, and to answer billing questionsPerformance of the contract; legal obligation for accounting records
Hashed identifiers for rate limiting on public endpointsTo stop one visitor from consuming the free analysis capacity meant for everyoneLegitimate interest in keeping the service available

We do not ask for anything in the special categories the law protects — health, religion, trade union membership, ethnicity, political opinions. But a CV sometimes mentions them in passing: a disability, a religious employer, a union role. We store your CV as you gave it, so if such a detail is in there we are holding it, on the basis that you chose to put it in a document you asked us to work from. You can remove it from the profile at any time, and it will then not appear in anything we generate.

3.What we do not hold

Worth stating explicitly, because these are the things people reasonably assume are being collected:

  • No sign-in credentials, and no e-mail address of your own. Authentication is handled by Clerk; our account record contains an identifier and three timestamps, and nothing else. The e-mail we can write to you at lives with Clerk, not with us. (An e-mail address printed on your résumé is a different thing, and it is in section 2.)
  • No card details. Payment happens inside Paddle; we never see a card number and could not charge you ourselves.
  • No analytics, no tracking pixels, no advertising identifiers, no third-party scripts on any page. Nothing is measuring your visit.
  • No raw IP addresses. The rate limiter stores a one-way hash of the request's identity and nothing that can be turned back into an address.
  • No résumé text from an anonymous match score. Before you register, the public analysis keeps only a hash of what you pasted, its length and the resulting findings. The text itself stays in your own browser, and never reaches our database.

None of this makes the rest anonymous, and it would be convenient but untrue to say so. A profile carrying your name, your employers and their dates identifies you whether or not an e-mail address sits beside it, and the identifier our records use can be resolved back to you through the sign-in provider. What we hold is a small amount of personal data about a person we can identify — which is why the rest of this page exists.

4.What the model sees

Producing an analysis or a résumé means sending the relevant text — your profile projection, the job description, the résumé being imported — to our model provider, OpenAI, through its API. It is sent to be processed and the result comes back; it is not used to train models, which OpenAI is contractually bound not to do for API traffic.

Nothing about you is used to make an automated decision with legal or similarly significant effect. A match score is a suggestion shown to you, on your own data, at your own request. No employer receives anything from us, and we evaluate no one on anybody else's behalf — a deliberate boundary, recorded as a decision rather than left to drift.

5.Who else processes it

ProviderWhat it doesWhat reaches it
ClerkSign-in, sessions, account e-mailsYour e-mail address and password, which are held there rather than by us, and authentication metadata
NeonThe databaseEverything in section 2 except card details
RenderRuns the backendData in transit while a request is being served
VercelServes the web interfaceRequests and their metadata
Paddle.com Market LtdSells the subscriptions, invoices, refundsName, e-mail, billing country and tax details you give at checkout
OpenAIThe language modelThe text described in section 4

Our database currently runs in a United States region, so the data in section 2 is stored outside the EU, as is processing by Clerk, Paddle and OpenAI. Each of these providers offers a data processing agreement and a transfer mechanism for European personal data; collecting and naming those agreements here is part of launch preparation and this section will be completed with them. There are no other processors — no e-mail marketing tool, no analytics provider, no error monitoring service.

6.How long we keep it

  • Your profile, vacancies, analyses and generated résumés: for as long as your account exists. Stopping a paid plan does not delete anything.
  • Résumé text held for an import in progress: until the import is confirmed or you replace it, and in any case only while the account exists.
  • Billing records: as long as accounting law requires them to be retained, which is longer than the account itself.
  • Rate-limiting hashes: they are only consulted within a rolling window measured in hours. They are not yet purged automatically afterwards, which is a gap we are closing; they contain no identifying data in the meantime.

7.Your rights

You can ask us to:

  • tell you what we hold about you, and give you a copy
  • correct anything that is wrong — most of it you can edit directly in the profile screens
  • delete your account and its contents
  • export your data in a machine-readable form
  • restrict or object to processing based on legitimate interest

Write to the contact address in section 1. We answer within 30 days. There is no charge, and no reason has to be given.

Deleting the account removes the rows in section 2 that belong to it; the database is structured so that they go with it rather than being left behind. Two honest caveats: a self-service delete button does not exist yet, so the request above is handled by a person; and database backups are retained for a period after deletion, so a copy may persist there briefly before rotating out.

If you think we have handled your data badly, you can complain to the data protection authority in your country. We would rather you told us first, but that is your right and not conditional on us.

8.How it is protected

  • Everything travels over HTTPS, and the database requires an encrypted connection.
  • Every request for your data is authenticated, and every user-owned record is checked for ownership before it is read or written — not merely filtered in the interface.
  • Model API keys are held server-side only and never reach the browser.
  • Uploaded files are size-limited, checked by content rather than by their name, parsed in memory and discarded. The file name is never used as a path on disk.

To report a security problem, use the security contact on the contact page. We will not pursue anyone who reports a genuine vulnerability in good faith.

9.Cookies and local storage

Pássaro sets no analytics or advertising cookies, and therefore asks for no cookie consent. What it does store in your browser, and why each item is necessary, is listed on the cookies page.

10.Changes to this policy

If we start collecting something new, use a new processor, or change why we hold something, this page changes first and the date at the bottom moves. A change that materially affects you is announced by e-mail rather than left here to be discovered.

Last reviewed 10 October 2026. Questions about this document go to Contact.