Privacy Policy
Last updated: 2026-09-18
This Privacy Policy explains how Hennadii Shvedko ("we", "us") collects, uses, and protects your personal data when you use our service. We act as a data controller for your account data and as a data processor for the freelance marketplace data you instruct us to fetch on your behalf. We comply with the EU General Data Protection Regulation (GDPR).
1. Data we collect
- Account data: name, email address, hashed password, plan, and consent timestamps.
- Billing data: handled by our payment processor (Stripe); we never store full card numbers.
- Configuration: search profiles, AI instructions, notification preferences, and encrypted third-party API tokens (e.g. your Upwork OAuth tokens), stored encrypted at rest.
- Marketplace data: job postings and related information fetched from Upwork on your instruction. This may include client information sourced from Upwork.
- Usage and diagnostic data: logs needed to operate, secure, and debug the service.
2. How we use your data
We process your data to provide the service (job scoring, cover-letter drafting, notifications), to bill you, to secure the platform, and to comply with legal obligations. AI scoring and generation are performed via our AI sub-processors. We do not sell your personal data.
3. Legal bases
We rely on performance of a contract (providing the service you signed up for), legitimate interests (security, fraud prevention, service improvement), consent (marketing emails, which you may withdraw at any time), and legal obligation (tax and accounting records).
4. Retention
Account and configuration data are kept while your account is active. Marketplace data sourced from Upwork is automatically deleted within 24 hours in line with Upwork's API Terms of Service; it is either re-fetched on demand or purged. Operational logs are retained for a limited period and then deleted. When you delete your account we erase your full data graph (see section 7).
5. Sub-processors
We share data with the third-party processors listed on our Sub-processors page, each bound by appropriate data-protection terms and, where applicable, EU Standard Contractual Clauses for transfers outside the EEA.
6. International transfers
Some sub-processors are located outside the EEA. Where that is the case, transfers are safeguarded by Standard Contractual Clauses or an equivalent adequacy mechanism.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to certain processing. You can exercise the right to data portability (a full machine-readable export, free of charge) and the right to erasure directly from your account's Privacy settings. You may also lodge a complaint with your local supervisory authority.
8. Security
We encrypt secrets at rest, restrict access on a need-to-know basis, and monitor for errors and abuse. To report a vulnerability, see our security policy.
9. Contact
For privacy questions or to exercise your rights, contact our Data Protection Officer at hennadii.shvedko@shvedko.dev.
Hennadii Shvedko
Hennadii Shvedko
Max-Born-Ring 59
37077 Göttingen
Germany