Summary of key points
Plain-language overview. The detail is below, and the detail governs.
- We sell nothing and advertise nothing. No ad networks, no retargeting, no analytics trackers, no data brokers. There is no commercial reason for us to hold more of your data than the service needs.
- We don't watch you browse. The extension runs on job sites to find and fill form fields, but page content stays on your machine. The one exception is a list of the last 15 job postings you opened — title and link, so you can find them again — which you can delete at any time (§3.10).
- AI only runs when you press a button. Nothing is sent to an AI model automatically, and we send only what that one operation needs.
- We refuse diversity and disability questions. Equal-opportunity self-identification fields are detected and left for you to answer manually — never filled, never sent to AI, never stored.
- Your data is isolated per account at the database level. Other users cannot reach it, by construction rather than by policy.
- We never submit applications for you. You review and send every one.
- You can export or delete everything yourself, from the dashboard, at any time.
- We are established in Portugal and process your data under EU GDPR. Our database, storage and hosting, including the server that sends your AI requests, are all in the EU.
- Three things leave the EEA: the AI model provider (Anthropic, US) for operations you trigger, Stripe for payments, and Cloudflare's bot check when you log in or sign up.
Contents
- Who we are
- Scope
- What data we collect
- Signing in with Google
- Why we process it, and our legal basis
- AI processing
- Who we share data with
- International transfers
- Cookies and tracking
- How long we keep data
- How we protect your data
- Data breaches
- Automated decision-making
- Your rights
- Marketing
- Age requirement
- Business transfers
- Changes to this policy
- Contact
1. Who we are
Trabalero ("Trabalero", "we", "us") is a job-application assistant consisting of a browser extension and a web dashboard.
The data controller responsible for your personal data is:
- Controller: [YOUR FULL LEGAL NAME / COMPANY NAME]
- Address: [REGISTERED ADDRESS]
- Country of establishment: Portugal
- Contact for privacy matters: [PRIVACY CONTACT EMAIL]
- Registration number (if applicable): [NIPC / NIF]
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy enquiries go to the contact address above.
2. Scope
This policy covers personal data processed through the Trabalero browser extension (Chrome and Firefox) and the Trabalero web dashboard and backend API.
It does not cover the job sites and applicant tracking systems (ATSes) you visit while using Trabalero. Those are independent controllers with their own policies, and what you submit to an employer is governed by that employer's policy, not ours.
We have no employer or recruiter side. Trabalero is used only by job seekers, for their own applications. We do not host employer accounts, we do not sell or expose candidate profiles to recruiters, and we never share your data with an employer — you do that yourself, by submitting an application on their site.
3. What data we collect
3.1 Account data
| Data | Source | Why |
|---|---|---|
| Email address | You, at signup | Account identity, authentication, service emails |
| Authentication credentials | Password hash, or Google sign-in (see §4) | Logging you in. We never see or store your password in readable form |
3.2 Profile data
You enter this, or import it from a CV: first name, last name, email, phone number, postal address, city, state, postal code, country, LinkedIn URL, personal website URL, salary expectations, years of experience, work history, education history, skills, languages, and a free-text summary about yourself.
You may create several profiles. All of it is optional — Trabalero works with whatever subset you provide, though fill quality depends on it.
3.3 CV files
PDF or DOCX files you upload, stored in a private per-user bucket, together with text extracted from them. Extraction happens in your browser, not on our servers; the resulting text is stored so it can be reused without reprocessing the file.
3.4 Application tracking data
Company name, job title, job URL, a short excerpt of the job description, application date, status, your notes, and which profile you applied with.
3.5 Saved answers and cover letters
Questions encountered on application forms together with the answers you gave, so the same question can be filled next time; and cover letters you generate, polish, or write yourself.
3.6 Usage and billing data
Counts of the AI features you use, per pass and on the free tier (to enforce plan allowances); a timestamped log of AI requests (to enforce rate limits); a record of each AI request — the feature, the model, token counts, cost, timing and outcome, never the text you sent or got back (to monitor cost and fix faults); the passes you buy, with their purchase, end and refund dates; and the Stripe payment identifier of each purchase. We never receive or store card details — those go directly to Stripe.
3.7 Extension connection data
When you link the extension to your account we store when it connected and when it last synchronised, so the dashboard can show whether it is working.
3.8 Technical data collected automatically
When your browser or the extension contacts our servers, our hosting and database providers process standard connection data: IP address, request time, requested endpoint, and user-agent string (browser and operating system). This is ordinary server logging, used for security, abuse prevention and diagnosing faults — not for tracking or profiling.
When the dashboard hits an error, an error report goes to Sentry, our error reporter: the error and where in our code it happened, the page path (without its query string), browser and operating system, and the pages and buttons that led to it — never what you typed. Email addresses are masked before it leaves, and it carries no profile, CV, request contents, cookies or account identity. Sentry is set not to store IP addresses. It is used only to find and fix faults.
When the extension itself hits an error, it sends Sentry the error, where in the extension's own code it happened, the extension version and your browser — never the page's address or site, anything from your profile, or who you are. It sends these while you are signed in, or signed out only if you turn on "Send crash reports" in its Settings.
When you log in, sign up or ask for a password reset, Cloudflare Turnstile checks that you are a person and not an automated bot. It processes your IP address and technical details of your browser, such as its user-agent, to make that check; we receive only whether it passed. Cloudflare also uses these details, as a controller in its own right, to improve its bot detection — see Cloudflare's Turnstile privacy policy.
We do not collect precise location. An IP address can indicate an approximate region; we do not use it for that purpose.
3.9 Special category data — we exclude it by design
Some job applications ask questions that fall under Article 9 GDPR: racial or ethnic origin, health or disability status, religious belief, trade union membership, or sexual orientation. The voluntary equal-opportunity and diversity self-identification block is the common case.
Trabalero detects these questions and refuses to process them. When the extension finds one, it marks the field "answer manually" and stops there:
- it is never filled from your profile;
- it is never sent to our AI provider, even if you use AI answering for the rest of the form;
- your answer is never saved to your stored answers, so it is never reapplied to a later application and never reaches our database.
You answer those questions yourself, on the employer's own site, and nothing about them passes through us. We hold no Article 9 data about you from application forms, so no Article 9 processing condition is engaged.
The detection is intentionally broad: if it is unsure, it excludes. The cost of over-matching is one question you type yourself.
One limit you should know about. A CV you upload may contain special category information incidentally — a religious institution in your education history, a disability disclosure, trade union involvement. We cannot detect that inside free text. If your CV contains such information and you use the CV analysis feature, that text is sent to our AI provider along with the rest of the CV. If this concerns you, remove those details from the CV you upload. You can delete any CV at any time from the dashboard.
3.10 Recently visited job postings
The extension keeps a list of the last 75 job postings you opened, so you can find your way back to one you did not apply to yet. For each we record the job title, company name, page URL and the time you opened it — never the content of the page.
This is recorded only on pages that identify themselves as a job posting in their
own published page data (the JobPosting markup search engines read). Ordinary
web pages, and job sites you merely browse without opening a posting, produce no
entry.
The list is always kept in your browser. If you have connected the extension to an account it is also saved to that account, so the dashboard can show it on your other devices. The account keeps the newest 300; an older entry is erased as newer ones arrive. If you have not connected the extension, it never leaves your machine.
You can delete any single entry, or the whole list, from the dashboard and from the extension at any time. Deleting an entry on the dashboard erases the record — we keep no note that it existed.
3.11 What the extension does not send us
This is central to how Trabalero is built, so we state it explicitly.
The extension runs on the pages you visit in order to find and fill form fields. The content of those pages is not transmitted to us, with two exceptions, both following an action you take:
- a short job description excerpt, when you save an application or ask for AI help on a posting;
- the text of unanswered questions on a form, when you click to have them answered by AI.
We do not log your general browsing history or the sites you visit. The one record we keep of pages you have merely looked at is the recently-visited list described in §3.10 — job postings only, title and link only, and deletable by you.
3.12 What we never do
- We do not sell or rent your personal data.
- We do not buy personal data, scrape public profiles, or acquire data about you from data brokers, marketing partners, or social networks.
- We do not run advertising, retargeting, or third-party analytics.
- We do not use your content to train AI models, and our AI provider does not train on data submitted through our account.
- We do not submit job applications on your behalf.
3.13 Problem reports
When you use "Report a problem" in the extension or the dashboard, we receive what you wrote and the kind of problem. From the extension we also receive its version and, if you leave it ticked, the site's name (never the full address). After an Autofill you can also include technical details: how many fields were found and filled, and the label, state and type of each field left open — never what is in them or anything from your profile.
Signed in, the report is linked to your account. Signed out, it is linked to no one; we keep a keyed hash of your IP address with it only to limit how many reports one connection can send a day, and erase that hash within two days.
4. Signing in with Google
If you choose Google sign-in, Google tells us your name, email address and Google account identifier so we can create and authenticate your account. We do not receive your Google password, and we request no access to Gmail, Google Drive, contacts, or any other Google service.
Google's own handling of the sign-in is governed by Google's privacy policy. You can disconnect Trabalero from your Google account at any time in your Google security settings; you will then need another sign-in method.
5. Why we process it, and our legal basis
| Purpose | Data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Provide the account and the service | Account, profile, CV, application data | Contract — Art. 6(1)(b) |
| Fill forms and reapply saved answers | Profile, saved answers | Contract — Art. 6(1)(b) |
| AI features you trigger | Profile, CV text, job description, questions | Contract — Art. 6(1)(b) |
| Enforce plan limits, rate limits, prevent abuse, monitor AI cost and faults | Usage counters, AI call log, AI request record | Legitimate interests — Art. 6(1)(f): keeping the service viable, preventing cost abuse and fixing faults |
| Take payment, manage passes and refunds | Email, Stripe payment id, passes | Contract — Art. 6(1)(b); legal obligation for invoicing — Art. 6(1)(c) |
| Security, abuse prevention, fault diagnosis | Technical data and the bot check (§3.8), problem reports (§3.13) | Legitimate interests — Art. 6(1)(f) |
Special category data (Art. 9): not applicable — we exclude it rather than process it. See §3.9.
6. AI processing
AI features are never automatic. Nothing is sent to an AI system unless you click a control asking for it. When you do:
| Feature | What is sent |
|---|---|
| Answer application questions | The questions from the form, the job description, and your active profile |
| Analyse a CV | The extracted text of the CV you selected |
| Generate a cover letter | Your active profile and the job description — your previously saved cover letter is deliberately excluded |
| Polish your own cover letter | Your active profile and the cover letter text you supplied |
| Rewrite or review a saved cover letter | The text of the saved cover letter you selected |
These requests pass through our backend, which authenticates you and applies your plan's limits, then go directly from our server to our AI model provider (§7). We send only what the requested operation needs. Raw CV files are never sent — only text already extracted in your browser.
Our AI model provider does not use data submitted through our account to train their models.
7. Who we share data with
We do not sell your personal data. We share it only with providers who process it on our behalf, under contract, as needed to run Trabalero:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, CV file storage | EU |
| Vercel | Dashboard and API hosting | EU |
| Anthropic (Claude) | AI model provider — processes the content in §6 | United States |
| Stripe | Payment processing and VAT calculation | EU/US; a controller in its own right for payment data |
| Sentry | Error reports from the dashboard and the extension (§3.8) | EU (Germany) |
| Cloudflare | Bot check on log in, sign up and password reset (§3.8) | Global network; United States company; a controller in its own right for improving its bot detection |
We use no product-analytics or advertising service. If we introduce one, we will add it to the table above, update this policy, and notify you under §18 before it takes effect.
We may also disclose data where legally required (court order, lawful request from a public authority), or to establish, exercise or defend legal claims.
8. International transfers
Our database, file storage and hosting, including the server that sends your AI requests, are all in the European Union.
Three transfers leave the EEA:
- Anthropic (United States) — for the AI operations you explicitly trigger (§6).
- Stripe — for payment processing, where some processing may occur in the United States.
- Cloudflare — for the bot check when you log in, sign up or reset your password (§3.8).
These are made under Chapter V GDPR safeguards: Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You may request a copy of the relevant safeguards using the contact details in §1.
9. Cookies and tracking
The dashboard sets only the cookies strictly necessary to keep you signed in. We use no advertising cookies, no tracking pixels, no web beacons, and no third-party analytics.
Because we do not track you across sites, there is nothing for a Do Not Track or Global Privacy Control signal to switch off — the behaviour those signals ask for is our default.
The browser extension stores data on your own device (your profiles, saved answers, and a session token) so it can work offline and without re-fetching. That storage is local to your browser and is not a tracking mechanism.
10. How long we keep data
| Data | Retention |
|---|---|
| Account, profile, CV, application, answer and cover-letter data | Until you delete it, or delete your account |
| Recently visited job postings (§3.10) | Until you delete the entry or clear the list, it falls outside the newest 300, or you delete your account |
| Deleted account | Erased on request; see §14 |
| Usage counters and AI call log | [12] months, for limit enforcement and abuse prevention |
| AI request record (§3.6) | 90 days, then folded into daily totals per feature and model that no longer identify you |
| Server logs (§3.8) | [30] days |
| Error reports (§3.8) | Up to 90 days, in Sentry |
| Problem reports (§3.13) | 3 months, or until you delete your account if sooner. The IP hash on a signed-out report: under two days |
| Billing and invoicing records | As required by Portuguese tax law (currently 10 years), even after account deletion |
Deleting your account removes your profiles, CVs, stored CV files, applications, saved answers, cover letters, recently-visited history and usage records. Legally-mandated billing records are the exception.
11. How we protect your data
- Every record is bound to your account and isolated at the database level by row-level security, so one user's data cannot be read by another.
- CV files sit in a private bucket, reachable only through short-lived signed links issued to you.
- The extension holds your session token in extension-only session storage, which is not reachable by any web page — including the job sites the extension runs on.
- Secret keys (AI provider, database service key, payment keys) exist only on our server, never in the extension or the browser.
- All traffic is encrypted in transit (HTTPS).
No system is perfectly secure, and we cannot guarantee absolute security.
12. Data breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Portuguese supervisory authority within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will also notify you directly and without undue delay, under Article 34.
13. Automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you for advertising.
Trabalero's AI features generate draft content for you to review — suggested answers, cover letters, and CV observations. They do not evaluate, score, or rank you, and they make no decision about you. Employers may make automated decisions in their own hiring processes; that is outside our control and governed by their policies.
14. Your rights
Under GDPR you have the right to:
- Access your data — the dashboard exports everything we hold about you as JSON, on demand.
- Rectify inaccurate data — editable directly in the dashboard.
- Erase your data — the dashboard deletes your account and cascades deletion across all your records and files.
- Restrict or object to processing based on legitimate interests.
- Data portability — the JSON export serves this purpose.
- Withdraw consent where processing relies on consent, without affecting processing already carried out.
Access, rectification, portability and erasure are available to you directly in the dashboard at any time. For anything else, contact [PRIVACY CONTACT EMAIL]. We respond within one month, as Article 12(3) GDPR requires.
If you believe we have handled your data unlawfully, you may complain to:
Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134 – 1.º, 1200-651 Lisboa, Portugal www.cnpd.pt
You may also complain to the supervisory authority where you live.
15. Marketing
We send service emails necessary to run your account — sign-in, billing, security, and material changes to this policy or the Terms. You cannot opt out of these while you hold an account, because they are part of providing the service.
16. Age requirement
Trabalero is for adults. You must be at least 18 years old to create an account. The service is not directed at children and we do not knowingly collect data from anyone under 18.
If we discover that an account belongs to someone under 18, we will terminate it immediately and delete the associated personal data, without notice. See Terms of Service §3 and §13.
If you believe a person under 18 has provided us with personal data, contact [PRIVACY CONTACT EMAIL] and we will delete it.
17. Business transfers
If Trabalero is involved in a merger, acquisition, or sale of assets, your data may transfer to the acquiring party. We will notify you before that happens and before your data becomes subject to a different privacy policy, and you will have the opportunity to delete your account first.
18. Changes to this policy
We may update this policy as the service changes. Material changes will be notified by email or in the dashboard before they take effect. The "last updated" date at the top always reflects the current version.
19. Contact
Questions about this policy or your data: [PRIVACY CONTACT EMAIL]