CareerFast

Privacy Policy

Last updated: April 6, 2026

1. Data Controller

CareerFast is operated by Maxime Demoly, auto-entrepreneur, France. For any questions regarding your data, contact us at maxime.demoly@gmail.com.

2. What We Collect

Account data

Email address and full name (collected via Stripe Checkout at payment).

Profile data

Target role, location, languages, and skills (provided by you during onboarding).

LinkedIn data

If you provide your LinkedIn URL during onboarding, we scrape your public profile to extract: name, headline, work experience, education, skills, and languages. This is done once with your explicit consent and stored in your dedicated container.

Search criteria

Target roles, locations, salary preferences, contract types, sectors, job board selection, and language.

Resume

Uploaded by you as a PDF, or generated from your LinkedIn data (Pro plan).

Cover letter style

Optional: a sample cover letter you provide so the AI can match your writing style (Pro plan).

Application history

Jobs applied to, match scores, application status, and generated cover letters.

Payment data

Processed entirely by Stripe. We store your Stripe customer ID and subscription ID. We never store, see, or have access to your credit card numbers.

Communication data

Telegram chat ID (if you connect Telegram) and messages exchanged with Roger.

Technical data

One session cookie (cf_session): a JWT containing your user ID and email. HttpOnly, secure, 30-day expiry. Required for authentication. We do not use analytics cookies, tracking pixels, or third-party tracking scripts.

Job board credentials (optional)

If you provide login credentials for job boards (e.g., WTTJ, APEC), they are stored encrypted in your dedicated container. They are never stored in the central database and never accessible to other users or to us.

3. How We Use Your Data

  • To operate the service: scan job boards, evaluate matches, generate cover letters, and submit applications on your behalf.
  • To send transactional emails: welcome email, trial reminders, subscription confirmations, login codes.
  • To improve the service: aggregate and anonymized usage statistics, cost tracking.

We do NOT sell your data. We do NOT use your data for advertising. We do NOT share your data with data brokers.

4. Who We Share Data With

Employers

Your name, email, phone, resume, and cover letter are sent to employers as part of job applications. This is the core purpose of the service.

Stripe

Email and name for payment processing. Stripe is PCI-DSS compliant.

Anthropic (Claude AI)

Your profile summary, experience, skills, and job descriptions are sent to Anthropic's API for job evaluation and cover letter generation. Anthropic does not use API inputs for model training.

Resend

Email address for transactional email delivery (login codes, subscription notifications, application emails to employers).

Hetzner

Server hosting. Your dedicated container runs on Hetzner infrastructure.

LinkdAPI, WTTJ, APEC

Search keywords and location are sent for job search. No personal data is shared with these services.

Telegram

If you connect Telegram, your chat messages are routed through Telegram's servers.

5. Where Your Data Is Stored

  • Central database: Hetzner infrastructure (EU/US depending on deployment)
  • Your dedicated container: Hetzner VPS (Ashburn, Virginia, US)
  • Stripe: United States (PCI-DSS compliant)
  • Anthropic: United States

6. Data Retention

  • Active subscription: all data retained as long as your subscription is active.
  • After cancellation: full access until the end of your billing period. Then a 7-day read-only grace period to view and download your data.
  • After grace period: your server is permanently destroyed. All container data (profile, resume, applications, cover letters) is deleted. Your central database record is updated to reflect the closed account (email and name retained for billing records).
  • Account deletion: immediate. Stripe subscription canceled, server destroyed, database record deleted. All data permanently removed.
  • Onboarding data (non-converting): if you start onboarding but do not complete payment, your email and LinkedIn URL are retained for 30 days, then automatically deleted.

7. Your Rights (GDPR — European Union)

Under the General Data Protection Regulation, you have the right to:

  • Access: view all your data in the dashboard (profile, criteria, applications, cover letters, invoices).
  • Rectification: edit your profile, criteria, and resume at any time.
  • Erasure: delete your account (immediate and irreversible).
  • Data portability: download your applications (CSV/PDF), cover letters, and resume from the dashboard.
  • Objection: pause or cancel the agent at any time to stop processing.
  • Restriction: pause your subscription to temporarily stop all data processing.

To exercise any of these rights, contact us at maxime.demoly@gmail.com.

8. Your Rights (CCPA — California)

If you are a California resident, you have the right to:

  • Know what personal information we collect (described in this policy).
  • Request deletion of your personal information (account deletion).
  • Opt-out of the sale of personal information — we do not sell personal information.
  • Non-discrimination for exercising your privacy rights.

9. Cookies

We use a single session cookie (cf_session) for authentication. It is a JWT token containing your user ID and email, with a 30-day expiry. It is httpOnly (not accessible to JavaScript) and secure (HTTPS only in production).

We do not use analytics cookies, advertising cookies, or any third-party tracking technology.

10. Children

CareerFast is not intended for users under 18 years of age. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email. The "Last updated" date at the top reflects the most recent revision.

12. Contact

For any questions about this Privacy Policy or your data, contact: maxime.demoly@gmail.com