Privacy Policy

Last updated: April 26, 2026

1. Who We Are

Aycabtu (aycabtu.com) is an AI-powered job application assistant that helps you create tailored resumes, cover letters, and interview preparation materials. In this policy, "we", "us" and "our" refer to Aycabtu.

2. What Data We Collect

Account information

  • Name and email address
  • Password (stored as a one-way hash — we cannot read it)
  • Profile picture (optional)

Job application data

  • Documents you upload (LinkedIn exports, existing resumes, PDFs)
  • Job descriptions you enter
  • AI-generated resumes, cover letters, and interview tips
  • Salary negotiation data: role, years of experience, current and offered salary, negotiation situation, and AI-generated counter-offer advice
  • Recruiter email content you paste into the Reply Coach, and AI-generated response advice

Interviewer research data

When you use the Interviewer Research feature, you provide the name and employer of your interviewer. We use Claude AI's web search to look up publicly available information about that person (e.g. LinkedIn profile, company bio) and store the result to generate personalised interview tips. This data concerns a third party and is processed on the basis of legitimate interest (Art. 6(1)(f)). It is used solely to help you prepare for your interview and is deleted when you delete your account.

Session & security data

  • IP address of each login session
  • Browser user agent of each login session

We store this data to secure your account (e.g. to detect suspicious logins) and to comply with legal obligations. It is deleted when you log out.

Payment data

Payments are processed by Stripe. We store only a reference to your Stripe payment (amount and credits purchased). We never see or store your full card details.

Analytics data

We use Umami, a privacy-friendly, open-source analytics tool that we self-host on our own servers in the Netherlands. Umami does not use cookies, does not track you across websites, and does not collect any personally identifiable information. Analytics data is aggregated and never linked to your account. No data is sent to third parties.

3. Why We Process Your Data

Purpose Legal basis (GDPR)
Providing the service (generating documents) Performance of contract (Art. 6(1)(b))
Account security (IP / user agent per session) Legitimate interest (Art. 6(1)(f))
Processing payments Performance of contract (Art. 6(1)(b))
Analytics (Umami — self-hosted, no cookies, no PII) Legitimate interest (Art. 6(1)(f))
Researching interviewers via web search to generate personalised interview preparation Legitimate interest (Art. 6(1)(f))
Sending a follow-up email after an ATS check if no resume has been generated (to help you get the most out of the service) Legitimate interest (Art. 6(1)(f))
Legal obligations Legal obligation (Art. 6(1)(c))

4. Third-Party Services

We share data with the following third parties only to the extent necessary to deliver our service:

  • Anthropic (Claude AI) — your uploaded documents and job descriptions are sent to Anthropic's API to generate content. Anthropic does not use API data to train its models. Anthropic's privacy policy applies: anthropic.com/privacy
  • Stripe — payment processing. Stripe's privacy policy: stripe.com/privacy
  • Umami — privacy-friendly analytics, self-hosted on our own servers in the Netherlands. No data is sent to third parties. Open-source: umami.is
  • Mailtrap — transactional email delivery (password resets, confirmations).

We do not sell your data to third parties.

5. How Long We Keep Your Data

  • Account data — kept until you request deletion of your account.
  • Session data (IP address, user agent) — deleted when you log out.
  • Generated documents — kept until you delete them, or until your account is deleted.
  • Payment records — kept for 7 years to comply with tax regulations.
  • Interviewer research profiles — deleted when you delete your account.

6. Your Rights (GDPR)

If you are in the European Economic Area, you have the following rights:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interest.
  • Restriction — request that we limit processing of your data.

To exercise any of these rights, including account deletion, you can use the Settings page in your account or contact us at privacy@aycabtu.com. We will respond within 30 days.

7. Cookies

We use a single session cookie (session_id) to keep you logged in. This cookie is strictly necessary for the service to function and does not track you across other websites.

Umami does not set any cookies.

8. Security

We take appropriate technical measures to protect your data, including HTTPS encryption in transit, hashed passwords, and access controls. No system is 100% secure; if you discover a vulnerability please contact us responsibly at privacy@aycabtu.com.

9. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email or by a prominent notice on our website. The "last updated" date at the top of this page always reflects the most recent version.

10. Contact

Questions or requests regarding this policy:

Email: privacy@aycabtu.com