Privacy Policy
A résumé is one of the most revealing documents a person owns — where you have worked, what you earn by implication, where you studied, sometimes your address and nationality. This page says exactly what Pássaro holds, why, for how long, and who else it passes through.
1.Who is responsible
- Controller
- Igor Ilin
- Address
- ul. Straganiarska 20/22 lok. 35, 80-837 Gdańsk, Poland
- Contact
- support@passaro.ai
There is no data protection officer: the service is too small to require one. Privacy questions go to the contact address above and are answered by a person.
2.What we hold
| Data | Why we have it | Legal basis |
|---|---|---|
| An account identifier issued by our sign-in provider | To know which profile is yours. It is the only thing our account record holds — see section 3 for what it does not hold | Performance of the contract |
| Your Base Profile: name, headline, location, summary, work history with employers and dates, education, skills, languages | It is the material every analysis and every generated résumé is written from | Performance of the contract |
| The contact details printed on your résumé: typically a phone number, an e-mail address, a city, sometimes a profile link | They have to appear in the document we generate for you. They come from the CV you imported, or from what you typed into the profile — not from registration | Performance of the contract |
| Résumé text you upload or paste, while an import is in progress | To turn it into a profile you can then correct | Performance of the contract |
| Job descriptions you save, and the vacancies you are pursuing | To judge the fit and tailor a résumé to a specific posting | Performance of the contract |
| Match analyses and generated résumés, including profile links recorded for tracked generated statements | They provide the requested analysis and document, and let you inspect the profile records linked to tracked statements | Performance of the contract |
| Counts of what you have used this month | To apply the allowances your plan includes | Performance of the contract |
| Subscription and payment metadata: plan, status, period, the identifier Paddle gave your customer record | To know what you are entitled to, and to answer billing questions | Performance of the contract; legal obligation for accounting records |
| Hashed identifiers for rate limiting on public endpoints | To stop one visitor from consuming the free analysis capacity meant for everyone | Legitimate interest in keeping the service available |
We do not ask for anything in the special categories the law protects — health, religion, trade union membership, ethnicity, political opinions. But a CV sometimes mentions them in passing: a disability, a religious employer, a union role. We store your CV as you gave it, so if such a detail is in there we are holding it, on the basis that you chose to put it in a document you asked us to work from. You can remove it from the profile at any time, and it will then not appear in anything we generate.
3.What we do not hold
Worth stating explicitly, because these are the things people reasonably assume are being collected:
- No sign-in credentials, and no e-mail address of your own. Authentication is handled by Clerk; our account record contains an identifier and three timestamps, and nothing else. The e-mail we can write to you at lives with Clerk, not with us. (An e-mail address printed on your résumé is a different thing, and it is in section 2.)
- No card details. Payment happens inside Paddle; we never see a card number and could not charge you ourselves.
- No analytics, no tracking pixels, no advertising identifiers, no third-party scripts on any page. Nothing is measuring your visit.
- No raw IP addresses. The rate limiter stores a one-way hash of the request's identity and nothing that can be turned back into an address.
- No résumé text from an anonymous match score. Before you register, the public analysis keeps only a hash of what you pasted, its length and the resulting findings. The text itself stays in your own browser, and never reaches our database.
None of this makes the rest anonymous, and it would be convenient but untrue to say so. A profile carrying your name, your employers and their dates identifies you whether or not an e-mail address sits beside it, and the identifier our records use can be resolved back to you through the sign-in provider. What we hold is a small amount of personal data about a person we can identify — which is why the rest of this page exists.
4.What the model sees
Producing an analysis or a résumé means sending the relevant text — your profile projection, the job description, the résumé being imported — to our model provider, OpenAI, through its API. It is sent to be processed and the result comes back; it is not used to train models, which OpenAI is contractually bound not to do for API traffic.
Nothing about you is used to make an automated decision with legal or similarly significant effect. A match score is a suggestion shown to you, on your own data, at your own request. No employer receives anything from us, and we evaluate no one on anybody else's behalf — a deliberate boundary, recorded as a decision rather than left to drift.
5.Who else processes it
| Provider | What it does | What reaches it |
|---|---|---|
| Clerk | Sign-in, sessions, account e-mails | Your e-mail address and password, which are held there rather than by us, and authentication metadata |
| Neon | The database | Everything in section 2 except card details |
| Render | Runs the backend | Data in transit while a request is being served |
| Vercel | Serves the web interface | Requests and their metadata |
| Paddle.com Market Ltd | Sells the subscriptions, invoices, refunds | Name, e-mail, billing country and tax details you give at checkout |
| OpenAI | The language model | The text described in section 4 |
Our database currently runs in a United States region, so the data in section 2 is stored outside the EU, as is processing by Clerk, Paddle and OpenAI. Each of these providers offers a data processing agreement and a transfer mechanism for European personal data; collecting and naming those agreements here is part of launch preparation and this section will be completed with them. There are no other processors — no e-mail marketing tool, no analytics provider, no error monitoring service.
6.How long we keep it
- Your profile, vacancies, analyses and generated résumés: for as long as your account exists. Stopping a paid plan does not delete anything.
- Résumé text held for an import in progress: until the import is confirmed or you replace it, and in any case only while the account exists.
- Billing records: as long as accounting law requires them to be retained, which is longer than the account itself.
- Rate-limiting hashes: they are only consulted within a rolling window measured in hours. They are not yet purged automatically afterwards, which is a gap we are closing; they contain no identifying data in the meantime.
7.Your rights
You can ask us to:
- tell you what we hold about you, and give you a copy
- correct anything that is wrong — most of it you can edit directly in the profile screens
- delete your account and its contents
- export your data in a machine-readable form
- restrict or object to processing based on legitimate interest
Write to the contact address in section 1. We answer within 30 days. There is no charge, and no reason has to be given.
Deleting the account removes the rows in section 2 that belong to it; the database is structured so that they go with it rather than being left behind. Two honest caveats: a self-service delete button does not exist yet, so the request above is handled by a person; and database backups are retained for a period after deletion, so a copy may persist there briefly before rotating out.
If you think we have handled your data badly, you can complain to the data protection authority in your country. We would rather you told us first, but that is your right and not conditional on us.
8.How it is protected
- Everything travels over HTTPS, and the database requires an encrypted connection.
- Every request for your data is authenticated, and every user-owned record is checked for ownership before it is read or written — not merely filtered in the interface.
- Model API keys are held server-side only and never reach the browser.
- Uploaded files are size-limited, checked by content rather than by their name, parsed in memory and discarded. The file name is never used as a path on disk.
To report a security problem, use the security contact on the contact page. We will not pursue anyone who reports a genuine vulnerability in good faith.
10.Changes to this policy
If we start collecting something new, use a new processor, or change why we hold something, this page changes first and the date at the bottom moves. A change that materially affects you is announced by e-mail rather than left here to be discovered.
Last reviewed 10 October 2026. Questions about this document go to Contact.