Privacy Policy

Last updated: September 17, 2026

Letterin (working name) is an AI-assisted, modular, multilingual CV builder. This policy explains what data we process when you use the service, where it is stored, and what your rights are. Users in Turkey can find the detailed KVKK disclosure at /kvkk.

What data do we store?

We only keep the data the service needs to work:

  • Account details: your e-mail address and sign-in method (e-mail/password, Google or LinkedIn).
  • Your profile and CV data: name, contact details, work experience, education, skills, summary texts and — only if you add one — a photo.
  • Job postings you paste or read with the browser extension: stored so a tailored CV remains reproducible against the posting it was adapted to; they belong only to you.
  • Usage metrics: token counts and status records of AI calls (for fair use and future plan limits).
  • Where your account came from: the campaign tags in the link you first arrived on (those starting with utm_), whether you came from an ad click (only the name of the click identifier, never its value), the domain of the site that referred you, the first page you opened and the date. It is saved to your account once, to measure which promotion channels work, and is not shared with advertising platforms.

Where is it stored?

Your data lives in a Supabase (Postgres) database hosted on cloud infrastructure. Every table is protected by row-level security (RLS): you can only access your own rows. Supabase servers may be located outside Turkey; see the KVKK disclosure for details.

AI processing

When you start tailoring a CV to a job posting, scoring a posting against your CV, or importing an existing CV, the relevant text is sent to the configured AI providers. Currently OpenAI (GPT-4.1 mini) reads CVs and job postings and scores the match, and Google Gemini writes and rewrites text; both are reached through the OpenRouter API gateway. The architecture is provider-agnostic; if the models change, this page will be updated.

AI runs only on actions you initiate, and no suggestion is applied to your CV without your approval. Processing of the submitted text on the provider's side is subject to that provider's own data terms.

Browser extension

The Letterin browser extension (on the Pro plan) reads the job posting on the page you are viewing, and only when you click its icon. It reads that one tab: the text you selected on the page, the page's structured job-posting data (schema.org JobPosting), the visible text of its main content, and the page's address. It does not read other tabs, your browsing history, or pages you do not click it on, and it collects nothing in the background.

What it reads is sent only to your own Letterin account, where it is used to pick out the job posting and show it to you; nothing is stored at that step. When you score the posting against one of your CVs, save it, or add it to your application board, the posting text and its address are stored in your account like a posting you paste. A scored posting is kept so its analysis is not repeated, and it does not appear in your saved list. Scoring sends the posting and the CV you chose to the AI providers described above.

The extension does not collect recruiters' or anyone else's names or contact details, does not fill in forms or apply to jobs for you, and contains no advertising, analytics or tracking.

  • Connection key: created on your device for this browser. Our servers store only a one-way hash of it. "Disconnect" in the extension revokes the key, and you can revoke it any time in Letterin → Settings.
  • Last page read: the most recent page you asked it to read is kept in the browser's session storage and cleared when the browser closes.
  • Permissions: activeTab (the tab you click it on), scripting (to read that tab), sidePanel (to show its panel), storage (the key and the last page read), and access to letterin.app only. The extension has no permission for any job site.

Cookies

Authentication cookies that keep you signed in and a cookie that remembers your language preference are essential.

In addition, we use one measurement cookie (letterin_ft). It is set the first time you visit letterin.app in this browser and holds where that first visit came from (campaign tags, the name of a click identifier, the referring site's domain, the landing page, the date) together with a random identifier for this browser. It is our own cookie, read only by our server, never overwritten, and deleted after 180 days. If you create an account, its content is saved to your account once; the same identifier links the usage records of features you used without an account before signing up (for example, reading a CV) to your account.

We use no advertising or third-party tracking cookies, and we do not send this cookie's content to any advertising platform. You can delete or block cookies in your browser settings; the service keeps working.

Retention

Your data is kept for as long as your account exists. Records you delete are removed from your lists; when you delete your account, all of your data (profile, CVs, job postings, usage records) is permanently deleted.

Your rights

  • Access: learn what data of yours is held.
  • Export: download your CVs as PDF and your data in a structured format.
  • Rectification: update your data in the app at any time.
  • Deletion: delete individual records or your entire account.

Contact

For privacy questions: info@letterin.app.