Privacy Policy

Last updated: 2 October 2026

Draft. This document is not yet in force and is published here for review only. It does not currently form a binding agreement.

Summary of key points

Plain-language overview. The detail is below, and the detail governs.


Contents

  1. Who we are
  2. Scope
  3. What data we collect
  4. Signing in with Google
  5. Why we process it, and our legal basis
  6. AI processing
  7. Who we share data with
  8. International transfers
  9. Cookies and tracking
  10. How long we keep data
  11. How we protect your data
  12. Data breaches
  13. Automated decision-making
  14. Your rights
  15. Marketing
  16. Age requirement
  17. Business transfers
  18. Changes to this policy
  19. Contact

1. Who we are

Trabalero ("Trabalero", "we", "us") is a job-application assistant consisting of a browser extension and a web dashboard.

The data controller responsible for your personal data is:

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy enquiries go to the contact address above.

2. Scope

This policy covers personal data processed through the Trabalero browser extension (Chrome and Firefox) and the Trabalero web dashboard and backend API.

It does not cover the job sites and applicant tracking systems (ATSes) you visit while using Trabalero. Those are independent controllers with their own policies, and what you submit to an employer is governed by that employer's policy, not ours.

We have no employer or recruiter side. Trabalero is used only by job seekers, for their own applications. We do not host employer accounts, we do not sell or expose candidate profiles to recruiters, and we never share your data with an employer — you do that yourself, by submitting an application on their site.

3. What data we collect

3.1 Account data

DataSourceWhy
Email addressYou, at signupAccount identity, authentication, service emails
Authentication credentialsPassword hash, or Google sign-in (see §4)Logging you in. We never see or store your password in readable form

3.2 Profile data

You enter this, or import it from a CV: first name, last name, email, phone number, postal address, city, state, postal code, country, LinkedIn URL, personal website URL, salary expectations, years of experience, work history, education history, skills, languages, and a free-text summary about yourself.

You may create several profiles. All of it is optional — Trabalero works with whatever subset you provide, though fill quality depends on it.

3.3 CV files

PDF or DOCX files you upload, stored in a private per-user bucket, together with text extracted from them. Extraction happens in your browser, not on our servers; the resulting text is stored so it can be reused without reprocessing the file.

3.4 Application tracking data

Company name, job title, job URL, a short excerpt of the job description, application date, status, your notes, and which profile you applied with.

3.5 Saved answers and cover letters

Questions encountered on application forms together with the answers you gave, so the same question can be filled next time; and cover letters you generate, polish, or write yourself.

3.6 Usage and billing data

Counts of the AI features you use, per pass and on the free tier (to enforce plan allowances); a timestamped log of AI requests (to enforce rate limits); a record of each AI request — the feature, the model, token counts, cost, timing and outcome, never the text you sent or got back (to monitor cost and fix faults); the passes you buy, with their purchase, end and refund dates; and the Stripe payment identifier of each purchase. We never receive or store card details — those go directly to Stripe.

3.7 Extension connection data

When you link the extension to your account we store when it connected and when it last synchronised, so the dashboard can show whether it is working.

3.8 Technical data collected automatically

When your browser or the extension contacts our servers, our hosting and database providers process standard connection data: IP address, request time, requested endpoint, and user-agent string (browser and operating system). This is ordinary server logging, used for security, abuse prevention and diagnosing faults — not for tracking or profiling.

When the dashboard hits an error, an error report goes to Sentry, our error reporter: the error and where in our code it happened, the page path (without its query string), browser and operating system, and the pages and buttons that led to it — never what you typed. Email addresses are masked before it leaves, and it carries no profile, CV, request contents, cookies or account identity. Sentry is set not to store IP addresses. It is used only to find and fix faults.

When the extension itself hits an error, it sends Sentry the error, where in the extension's own code it happened, the extension version and your browser — never the page's address or site, anything from your profile, or who you are. It sends these while you are signed in, or signed out only if you turn on "Send crash reports" in its Settings.

When you log in, sign up or ask for a password reset, Cloudflare Turnstile checks that you are a person and not an automated bot. It processes your IP address and technical details of your browser, such as its user-agent, to make that check; we receive only whether it passed. Cloudflare also uses these details, as a controller in its own right, to improve its bot detection — see Cloudflare's Turnstile privacy policy.

We do not collect precise location. An IP address can indicate an approximate region; we do not use it for that purpose.

3.9 Special category data — we exclude it by design

Some job applications ask questions that fall under Article 9 GDPR: racial or ethnic origin, health or disability status, religious belief, trade union membership, or sexual orientation. The voluntary equal-opportunity and diversity self-identification block is the common case.

Trabalero detects these questions and refuses to process them. When the extension finds one, it marks the field "answer manually" and stops there:

You answer those questions yourself, on the employer's own site, and nothing about them passes through us. We hold no Article 9 data about you from application forms, so no Article 9 processing condition is engaged.

The detection is intentionally broad: if it is unsure, it excludes. The cost of over-matching is one question you type yourself.

One limit you should know about. A CV you upload may contain special category information incidentally — a religious institution in your education history, a disability disclosure, trade union involvement. We cannot detect that inside free text. If your CV contains such information and you use the CV analysis feature, that text is sent to our AI provider along with the rest of the CV. If this concerns you, remove those details from the CV you upload. You can delete any CV at any time from the dashboard.

3.10 Recently visited job postings

The extension keeps a list of the last 75 job postings you opened, so you can find your way back to one you did not apply to yet. For each we record the job title, company name, page URL and the time you opened it — never the content of the page.

This is recorded only on pages that identify themselves as a job posting in their own published page data (the JobPosting markup search engines read). Ordinary web pages, and job sites you merely browse without opening a posting, produce no entry.

The list is always kept in your browser. If you have connected the extension to an account it is also saved to that account, so the dashboard can show it on your other devices. The account keeps the newest 300; an older entry is erased as newer ones arrive. If you have not connected the extension, it never leaves your machine.

You can delete any single entry, or the whole list, from the dashboard and from the extension at any time. Deleting an entry on the dashboard erases the record — we keep no note that it existed.

3.11 What the extension does not send us

This is central to how Trabalero is built, so we state it explicitly.

The extension runs on the pages you visit in order to find and fill form fields. The content of those pages is not transmitted to us, with two exceptions, both following an action you take:

We do not log your general browsing history or the sites you visit. The one record we keep of pages you have merely looked at is the recently-visited list described in §3.10 — job postings only, title and link only, and deletable by you.

3.12 What we never do

3.13 Problem reports

When you use "Report a problem" in the extension or the dashboard, we receive what you wrote and the kind of problem. From the extension we also receive its version and, if you leave it ticked, the site's name (never the full address). After an Autofill you can also include technical details: how many fields were found and filled, and the label, state and type of each field left open — never what is in them or anything from your profile.

Signed in, the report is linked to your account. Signed out, it is linked to no one; we keep a keyed hash of your IP address with it only to limit how many reports one connection can send a day, and erase that hash within two days.

4. Signing in with Google

If you choose Google sign-in, Google tells us your name, email address and Google account identifier so we can create and authenticate your account. We do not receive your Google password, and we request no access to Gmail, Google Drive, contacts, or any other Google service.

Google's own handling of the sign-in is governed by Google's privacy policy. You can disconnect Trabalero from your Google account at any time in your Google security settings; you will then need another sign-in method.

5. Why we process it, and our legal basis

PurposeDataLegal basis (Art. 6 GDPR)
Provide the account and the serviceAccount, profile, CV, application dataContract — Art. 6(1)(b)
Fill forms and reapply saved answersProfile, saved answersContract — Art. 6(1)(b)
AI features you triggerProfile, CV text, job description, questionsContract — Art. 6(1)(b)
Enforce plan limits, rate limits, prevent abuse, monitor AI cost and faultsUsage counters, AI call log, AI request recordLegitimate interests — Art. 6(1)(f): keeping the service viable, preventing cost abuse and fixing faults
Take payment, manage passes and refundsEmail, Stripe payment id, passesContract — Art. 6(1)(b); legal obligation for invoicing — Art. 6(1)(c)
Security, abuse prevention, fault diagnosisTechnical data and the bot check (§3.8), problem reports (§3.13)Legitimate interests — Art. 6(1)(f)

Special category data (Art. 9): not applicable — we exclude it rather than process it. See §3.9.

6. AI processing

AI features are never automatic. Nothing is sent to an AI system unless you click a control asking for it. When you do:

FeatureWhat is sent
Answer application questionsThe questions from the form, the job description, and your active profile
Analyse a CVThe extracted text of the CV you selected
Generate a cover letterYour active profile and the job description — your previously saved cover letter is deliberately excluded
Polish your own cover letterYour active profile and the cover letter text you supplied
Rewrite or review a saved cover letterThe text of the saved cover letter you selected

These requests pass through our backend, which authenticates you and applies your plan's limits, then go directly from our server to our AI model provider (§7). We send only what the requested operation needs. Raw CV files are never sent — only text already extracted in your browser.

Our AI model provider does not use data submitted through our account to train their models.

7. Who we share data with

We do not sell your personal data. We share it only with providers who process it on our behalf, under contract, as needed to run Trabalero:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, CV file storageEU
VercelDashboard and API hostingEU
Anthropic (Claude)AI model provider — processes the content in §6United States
StripePayment processing and VAT calculationEU/US; a controller in its own right for payment data
SentryError reports from the dashboard and the extension (§3.8)EU (Germany)
CloudflareBot check on log in, sign up and password reset (§3.8)Global network; United States company; a controller in its own right for improving its bot detection

We use no product-analytics or advertising service. If we introduce one, we will add it to the table above, update this policy, and notify you under §18 before it takes effect.

We may also disclose data where legally required (court order, lawful request from a public authority), or to establish, exercise or defend legal claims.

8. International transfers

Our database, file storage and hosting, including the server that sends your AI requests, are all in the European Union.

Three transfers leave the EEA:

These are made under Chapter V GDPR safeguards: Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You may request a copy of the relevant safeguards using the contact details in §1.

9. Cookies and tracking

The dashboard sets only the cookies strictly necessary to keep you signed in. We use no advertising cookies, no tracking pixels, no web beacons, and no third-party analytics.

Because we do not track you across sites, there is nothing for a Do Not Track or Global Privacy Control signal to switch off — the behaviour those signals ask for is our default.

The browser extension stores data on your own device (your profiles, saved answers, and a session token) so it can work offline and without re-fetching. That storage is local to your browser and is not a tracking mechanism.

10. How long we keep data

DataRetention
Account, profile, CV, application, answer and cover-letter dataUntil you delete it, or delete your account
Recently visited job postings (§3.10)Until you delete the entry or clear the list, it falls outside the newest 300, or you delete your account
Deleted accountErased on request; see §14
Usage counters and AI call log[12] months, for limit enforcement and abuse prevention
AI request record (§3.6)90 days, then folded into daily totals per feature and model that no longer identify you
Server logs (§3.8)[30] days
Error reports (§3.8)Up to 90 days, in Sentry
Problem reports (§3.13)3 months, or until you delete your account if sooner. The IP hash on a signed-out report: under two days
Billing and invoicing recordsAs required by Portuguese tax law (currently 10 years), even after account deletion

Deleting your account removes your profiles, CVs, stored CV files, applications, saved answers, cover letters, recently-visited history and usage records. Legally-mandated billing records are the exception.

11. How we protect your data

No system is perfectly secure, and we cannot guarantee absolute security.

12. Data breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Portuguese supervisory authority within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will also notify you directly and without undue delay, under Article 34.

13. Automated decision-making

We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you for advertising.

Trabalero's AI features generate draft content for you to review — suggested answers, cover letters, and CV observations. They do not evaluate, score, or rank you, and they make no decision about you. Employers may make automated decisions in their own hiring processes; that is outside our control and governed by their policies.

14. Your rights

Under GDPR you have the right to:

Access, rectification, portability and erasure are available to you directly in the dashboard at any time. For anything else, contact [PRIVACY CONTACT EMAIL]. We respond within one month, as Article 12(3) GDPR requires.

If you believe we have handled your data unlawfully, you may complain to:

Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134 – 1.º, 1200-651 Lisboa, Portugal www.cnpd.pt

You may also complain to the supervisory authority where you live.

15. Marketing

We send service emails necessary to run your account — sign-in, billing, security, and material changes to this policy or the Terms. You cannot opt out of these while you hold an account, because they are part of providing the service.

16. Age requirement

Trabalero is for adults. You must be at least 18 years old to create an account. The service is not directed at children and we do not knowingly collect data from anyone under 18.

If we discover that an account belongs to someone under 18, we will terminate it immediately and delete the associated personal data, without notice. See Terms of Service §3 and §13.

If you believe a person under 18 has provided us with personal data, contact [PRIVACY CONTACT EMAIL] and we will delete it.

17. Business transfers

If Trabalero is involved in a merger, acquisition, or sale of assets, your data may transfer to the acquiring party. We will notify you before that happens and before your data becomes subject to a different privacy policy, and you will have the opportunity to delete your account first.

18. Changes to this policy

We may update this policy as the service changes. Material changes will be notified by email or in the dashboard before they take effect. The "last updated" date at the top always reflects the current version.

19. Contact

Questions about this policy or your data: [PRIVACY CONTACT EMAIL]

Terms of Service Home