Privacy Policy
Lumyhired processes CVs. This page says exactly what we do with them.
Last updated: 13 September 2026
Summary of key points
- Who we are. Lumyhired is operated by a France-registered sole trader who is the data controller. Full legal identity is in our mentions légales; reach us through the contact page.
- What we process. Your account details, your CV and its contents, job descriptions you paste, your searches and applications, and technical/usage data. Your CV is the most sensitive of these.
- Why. To run the service you asked for, take payment, and keep the service secure. We do not sell your data and do not use your CV to train AI models.
- Who else sees it. A small set of processors (hosting, database, payments, AI generation) act on our instructions — listed in section 4.
- Your control. You can access, correct, export or permanently delete your account and data yourself, at any time (sections 9 and 11).
- No ad tracking. Strictly-necessary cookies plus cookieless, anonymous audience measurement by default; masked session replay only if you opt in — no advertising cookies and no cross-site tracking (section 5).
Contents
- Who is the data controller
- What information we collect
- How we use it, and on what legal basis
- Who else processes your data
- Cookies and tracking
- AI-powered features
- Signing in with Google
- International transfers
- How long we keep it
- How we keep it safe
- Your rights, deletion and export
- People data (recruiters, hiring managers, company officers)
- Children
- Changes to this notice
- Contact
1. Who is the data controller
Lumyhired is operated by an individual entrepreneur (entrepreneur individuel) registered in France, who is the data controller for the processing described here. As French law requires, the operator’s full legal identity, registration number and address are published in our mentions légales. For any question about your data, or to exercise the rights below, use our contact page.
2. What information we collect
Information you give us:
- Account data — email address and authentication identifiers, so you can sign in.
- CV content — the résumé you upload or build, and everything in it. This routinely includes your name, contact details, employment history and education, and may include date of birth or nationality if you put them in your CV. Please don’t include special-category data (health, religion, etc.) — we don’t need it.
- Job descriptions you paste in for tailoring, and your search preferences (target roles, location, filters).
- Application tracking data — the roles you save and the stage each application has reached.
- Billing data — handled by our payment processor. We do not store your card number.
Information collected automatically:
- Usage data — which metered actions you take and when, so we can enforce plan limits and understand what to improve.
- Technical & security signals — your IP address is used transiently to rate-limit and protect accounts, and appears in our host’s server logs; we do not store it in our own database. Basic diagnostics/error data help us fix problems.
3. How we use it, and on what legal basis
- To provide the service (tailoring, ATS audits, job search, tracking) — performance of our contract with you, GDPR Art. 6(1)(b).
- To take payment — performance of the contract.
- To keep the service secure (rate limiting, abuse prevention) and to improve it — our legitimate interest, Art. 6(1)(f).
- To meet legal obligations (e.g. keeping accounting records) — Art. 6(1)(c).
We do not sell your data, and we do not use your CV to train AI models.
4. Who else processes your data
We use the following processors. Each acts on our instructions under a data-processing agreement.
- Supabase, Inc. (United States) — database and authentication. Your account and CV content are stored here with row-level security.
- Railway Corp. (United States) — application hosting and server logs.
- Stripe, Inc. (United States, with an EU entity in Ireland) — payment processing. We never see or store your card number.
- Google (Gemini API) (United States) — the AI that generates tailored CV content. We use the paid API tier; your prompts and CV text are not used to train Google’s models.
- OpenRouter, Inc. (United States) — AI fallback when the primary model is unavailable. We send requests with prompt data collection denied.
- PostHog (United States region) — product analytics and, only if you opt in, masked session replay. By default it runs in a privacy-first, cookieless mode that records anonymous page views only: it sets no cookies, stores nothing on your device, creates no user profile, and your IP address is discarded. If you accept analytics in the consent banner, it additionally records how you interact with the app (a “session replay”) using persistent cookies — with every form field and all on-screen text in your CV, application and account areas masked, so it never captures readable personal information. Because PostHog is hosted in the United States, this is an international transfer (see section 8).
For the optional people- and company-lookup features, a search query containing only a company name and city — never your CV — is sent to whichever of these public sources answers: Google Custom Search, Brave Search and DuckDuckGo (all United States), GitHub, Inc. (United States), and recherche-entreprises.api.gouv.fr (the French public company register, France).
Several of these providers are established outside the EU — see section 8 on international transfers. We do not use any email-marketing processor and we run no advertising or marketing services. Our only analytics tool is PostHog (United States), which is cookieless and anonymous by default and adds masked session replay only with your consent, described in section 5.
5. Cookies and tracking
By default we use only strictly-necessary cookies — the ones that keep you signed in (set by our authentication provider) and a couple of short-lived functional cookies (e.g. a subscription-sync marker and a password-recovery flag). We also store your theme and language choice in your browser’s local storage. Analytics and session-replay cookies are set only if you opt in (see below).
For product analytics we use PostHog (United States region). By default it runs in a privacy-first, cookieless mode: it counts anonymous page views to help us understand which pages are useful, sets no cookies and stores nothing on your device (the anonymous identifier exists only in the page’s memory and is gone when you close the tab), it creates no user profile, and your IP address is discarded. In this default mode it falls within the CNIL exemption for audience measurement, so no consent is required.
If you opt in through the consent banner, we additionally enable persistent analytics and session replay — a masked recording of how you move through the app, used only to find and fix usability problems. It uses cookies (which is why it needs your consent), and it is configured so that all form fields and all on-screen text in your CV, application and account areas are masked: it records the shape of your interactions, never readable personal data. You can decline, and declining keeps only the cookieless anonymous mode above.
We do not use advertising or marketing cookies, web beacons, or cross-site trackers. Because there is no industry standard for “Do Not Track” signals we do not respond to them — but we do not track you across sites in the first place.
6. AI-powered features
Audits, tailored CVs, cover letters and outreach messages are produced by AI models run by our providers: primarily Google (Gemini API) on the paid tier, with OpenRouter as a fallback (requests sent with prompt data-collection denied). To generate your output, the relevant CV text and job description are sent to that provider. Your input and the output are not used to train their models, and we do not use them to train any model of our own. Review AI output before you rely on it — it can contain mistakes.
7. Signing in with Google
If you sign in with Google, we receive only your basic profile — name, email address and avatar — to create and secure your account. We request the default sign-in scopes only. We do not access your Gmail, Drive, Calendar or contacts, and we never read your email.
8. International transfers
Our hosting, database, payment and AI providers are established in the United States (Stripe also has an EU entity in Ireland), so your data may be processed there. Where a provider is outside the EU/EEA, the transfer relies on the European Commission’s Standard Contractual Clauses or an equivalent safeguard. The French company-register lookup is processed in France.
9. How long we keep it
Account and CV data are kept for as long as your account exists. Delete your account and we delete them, except billing records we must keep for statutory accounting periods. Scraped job listings are cleared within a few days unless you save them. Server logs held by our host (Railway) are retained for a rolling short window — around 30 days — and then discarded.
10. How we keep it safe
Data is stored with row-level security scoped to your account, access is restricted, and transport is encrypted. No system is perfectly secure, so we cannot guarantee against every threat — but we design for least access and keep sensitive material (like your CV) confined to the processing that produces your results.
11. Your rights, deletion and export
Under the GDPR you may request access, correction, erasure, restriction, portability, and you may object to processing based on legitimate interest. Write to our contact page. You also have the right to complain to the CNIL (cnil.fr).
Delete your account yourself, any time: open Billing & subscription and use the “Danger zone — Delete my account” section. Deletion is permanent and immediate: it removes your profile, CVs, adaptations, searches and application goals, and cancels any active subscription. We keep only the billing records the law requires.
Export: to receive a copy of your data in a portable format, write to our contact page and we will send you an export.
12. People data (recruiters, hiring managers, company officers)
To help you find who to contact at a company, Lumyhired builds a small directory of people connected to the companies you search. These people did not sign up for the service.
- Source — public search results and the French company register (recherche-entreprises.api.gouv.fr). We do not scrape private or logged-in pages.
- Legal basis — our legitimate interest in helping job-seekers reach the right contact, GDPR Art. 6(1)(f).
- What we store — name, public headline or role, profile URL, and city. Nothing that is not already public.
- Retention — kept only while the entry stays relevant to a search and refreshed from the public source; removed on request.
If you are listed and would rather not be, you can object at any time under Art. 21: use the removal form at /people/remove, or write to our contact page. We record the request, stop showing the entry, and delete it.
13. Children
The service is for people aged 18 or over. We do not knowingly collect data from anyone under 18. If you believe a minor has given us data, reach us through our contact page and we will delete it.
14. Changes to this notice
We may update this notice as the service or the law changes. We revise the “Last updated” date above and, for material changes, give reasonable notice. Please review it from time to time.
15. Contact
For any privacy or data-protection request, use our contact page. The operator’s full legal identity and postal address are in the mentions légales.