Privacy Policy
Effective: 19 February 2026 — Version 2026-02
1. Introduction
Aizumey (“we”, “our”, or “us”) operates the website and service available at aizumey.com (the “Service”). This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it.
This policy is designed to comply with the General Data Protection Regulation (“GDPR”, EU 2016/679), the UK GDPR, the California Consumer Privacy Act (“CCPA”, Cal. Civ. Code § 1798.100 et seq.) as amended by the CPRA, and other applicable privacy laws.
By using the Service, you confirm that you have read this policy and, where required, provided your consent via our consent gate.
2. Data Controller
The data controller responsible for your personal data is:
Aizumey
Email: contact@aizumey.com
If you are in the EU/EEA or UK and have questions about how we process your data, please contact us at the address above. We will respond within 30 days.
3. Data We Collect
3.1 Account Data (via Clerk)
When you register or sign in, Clerk (our authentication provider) collects and provides us with: your name, email address, and username. We store your Clerk user ID and username as your account identifier.
3.2 Profile Data
If you complete your profile, we store: first name, middle name, last name, email address, mobile phone number, and date of birth. This data is used to pre-fill your resumes and is stored in our database.
3.3 Resume Data
Resume content you create includes: full name, email, phone number, professional summary, work experiences (company, role, dates), education (institution, degree, dates), skills, portfolio URL, LinkedIn URL, and an optional profile photo.
You can choose to make a resume publicly accessible via a shareable link (/r/[id]). When a resume is public, its contents are visible to anyone with the link and are indexed by search engines. You can revoke public access at any time.
3.4 AI Interaction Data
When you use AI features (resume tips, cover letter generation, AI chat), your resume content and chat messages are sent to our AI backend service to generate responses. These messages are stored so you can continue conversations across sessions.
3.5 Cover Letters and Prompt Templates
Cover letters and custom prompt templates you create are stored in our database and associated with your account.
3.6 Usage and Analytics Data (optional consent)
With your consent, we use Vercel Analytics to collect anonymised page-view data (pages visited, referrer, country, device type). This data does not identify you personally. You may withdraw analytics consent at any time by contacting us.
3.7 Technical Data
We may record your IP address and browser user-agent at the time you provide consent, solely for audit and security purposes. Your IP is not used for profiling.
4. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)): Processing your account, profile, resume, cover letter, and AI interaction data is necessary to provide the Service you have requested.
- Consent (Art. 6(1)(a)): We rely on your explicit consent for optional analytics. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legitimate interests (Art. 6(1)(f)): We process minimal technical data (IP at consent time, user-agent) to maintain security, prevent fraud, and keep a verifiable consent audit trail. These interests do not override your rights.
5. How We Use Your Data
- To provide, operate, and improve the Service
- To generate AI-powered resume tips, cover letters, and chat responses
- To pre-fill resume fields from your profile
- To enable public resume sharing when you choose to make a resume public
- To send transactional emails related to your account (via Clerk)
- To maintain a consent audit trail as required by law
- To detect and prevent abuse, fraud, or security incidents
- To analyse aggregated, anonymised usage patterns (with consent)
We do not sell your personal data to any third party, and we do not use it for targeted advertising.
6. Third-Party Services and Data Sharing
We share data only with the sub-processors necessary to operate the Service:
| Processor | Purpose | Location |
|---|---|---|
| Clerk | Authentication and user management | USA (EU data centre available) |
| Neon (PostgreSQL) | Primary database hosting | AWS ap-southeast-1 |
| Supabase | Profile photo storage | AWS (region varies) |
| Vercel | Hosting, CDN, blob storage, analytics | Global edge network |
| Aizumey AI Backend | AI resume and cover letter generation | Render (USA) |
Each processor is bound by data processing agreements and may only process your data on our documented instructions. We do not share your data with any other third parties unless required by law.
7. International Data Transfers
Some of our sub-processors are based in the United States. Where personal data is transferred from the EU/EEA or UK to a third country, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK International Data Transfer Addendum as the appropriate transfer mechanism, or on the EU-US Data Privacy Framework where applicable.
8. Data Retention
- Account and profile data: Retained for as long as your account is active. If you request deletion, we will remove your data within 30 days.
- Resume and cover letter data: Retained until you delete the item or your account.
- AI chat session data: Retained for 12 months from the last message, then deleted.
- Consent records: Retained for 7 years as required for legal compliance and audit purposes, even after account deletion.
- Analytics data: Aggregated and anonymised; not tied to your account and not subject to deletion requests.
9. Cookies and Tracking
We use the following cookies:
| Cookie | Purpose | Type |
|---|---|---|
| __clerk_* | Authentication session management | Strictly necessary |
| __aizumey_cv | Records which policy version you consented to | Strictly necessary |
| __aizumey_ac | Stores your analytics consent preference | Functional |
| va-* (Vercel) | Anonymous page-view analytics | Analytics (consent required) |
Strictly necessary cookies cannot be disabled as the Service cannot function without them. You may withdraw analytics consent at any time by contacting contact@aizumey.com.
10. Your Rights
10.1 GDPR Rights (EU/EEA and UK residents)
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”) — request deletion of your data where it is no longer necessary, or where you withdraw consent.
- Data portability — receive your data in a structured, machine-readable format.
- Restriction — ask us to stop processing your data in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — withdraw any consent you have given at any time, without affecting prior processing.
- Lodge a complaint — complain to your national supervisory authority (e.g., the ICO in the UK, or your local EU DPA).
10.2 CCPA/CPRA Rights (California residents)
You have the right to:
- Know — request disclosure of the categories and specific pieces of personal information we have collected.
- Delete — request deletion of your personal information, subject to certain exceptions.
- Correct — request correction of inaccurate personal information.
- Opt-out of sale or sharing — we do not sell or share your personal information with third parties for cross-context behavioural advertising.
- Limit use of sensitive personal information — we do not use sensitive personal information beyond what is necessary to provide the Service.
- Non-discrimination — we will not discriminate against you for exercising any of these rights.
To exercise any of these rights, email contact@aizumey.com with the subject line “Privacy Request”. We will verify your identity and respond within 30 days (or 45 days for complex requests, with notice). There is no fee for reasonable requests.
11. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the version number and effective date at the top of this page. If you are a registered user, you will be shown the updated policy and asked to re-confirm your consent before you can continue using the Service.
13. Contact
For any privacy-related queries, requests, or complaints:
Email: contact@aizumey.com
We aim to respond to all enquiries within 30 days. If you are not satisfied with our response, you have the right to complain to your local data protection authority.