Privacy Policy

Last updated: September 21, 2026

Letterin (working name) is an AI-assisted, modular, multilingual CV builder. This policy explains what data we process when you use the service, where it is stored, and what your rights are. Users in Turkey can find the detailed KVKK disclosure at /kvkk.

What data do we store?

We only keep the data the service needs to work:

  • Account details: your e-mail address and sign-in method (e-mail/password, Google or LinkedIn).
  • Your profile and CV data: name, contact details, work experience, education, skills, summary texts and — only if you add one — a photo.
  • Job postings you paste or read with the browser extension: stored so a tailored CV remains reproducible against the posting it was adapted to; they belong only to you.
  • Usage metrics: token counts and status records of AI calls (for fair use and future plan limits).
  • Where your account came from: the campaign tags in the link you first arrived on (those starting with utm_), whether you came from an ad click (only the name of the click identifier, never its value), the domain of the site that referred you, the first page you opened and the date. It is saved to your account once, to measure which promotion channels work, and is not shared with advertising platforms.

Where is it stored?

Your data lives in a Supabase (Postgres) database hosted on cloud infrastructure. Every table is protected by row-level security (RLS): you can only access your own rows. Supabase servers may be located outside Turkey; see the KVKK disclosure for details.

AI processing

When you start tailoring a CV to a job posting, scoring a posting against your CV, or importing an existing CV, the relevant text is sent to the configured AI providers. Currently OpenAI (GPT-4.1 mini) reads CVs and job postings and scores the match, and Google Gemini writes and rewrites text; both are reached through the OpenRouter API gateway. When an English CV is scored against an English posting, the match verdicts are made by TypeSafe (Jev), which receives only the CV's lines and the requirements extracted from the posting. The architecture is provider-agnostic; if the models change, this page will be updated.

AI runs only on actions you initiate, and no suggestion is applied to your CV without your approval. Processing of the submitted text on the provider's side is subject to that provider's own data terms.

Browser extension

The Letterin browser extension (on the Pro plan) reads the job posting on the page you are viewing, and only when you click its icon. It reads that one tab: the text you selected on the page, the page's structured job-posting data (schema.org JobPosting), the visible text of its main content, and the page's address. It does not read other tabs, your browsing history, or pages you do not click it on, and it collects nothing in the background.

What it reads is sent only to your own Letterin account, where it is used to pick out the job posting and show it to you; nothing is stored at that step. When you score the posting against one of your CVs, save it, or add it to your application board, the posting text and its address are stored in your account like a posting you paste. A scored posting is kept so its analysis is not repeated, and it does not appear in your saved list. Scoring sends the posting and the CV you chose to the AI providers described above.

The extension does not collect recruiters' or anyone else's names or contact details, does not fill in forms or apply to jobs for you, and contains no advertising, analytics or tracking.

  • Connection key: created on your device for this browser. Our servers store only a one-way hash of it. "Disconnect" in the extension revokes the key, and you can revoke it any time in Letterin → Settings.
  • Last page read: the most recent page you asked it to read is kept in the browser's session storage and cleared when the browser closes.
  • Permissions: activeTab (the tab you click it on), scripting (to read that tab), sidePanel (to show its panel), storage (the key and the last page read), and access to letterin.app only. The extension has no permission for any job site.

Saving to and importing from Google Drive

On the Pro plan you can save a CV you built to your Google Drive in one click, with the editor's "Save to Drive" button. It runs only when you click it and it is entirely optional: you can always download the same file and upload it yourself. The file goes from your browser straight to Google; our servers are not an intermediary in that transfer.

Anyone with an account can import a CV from their Drive with "Pick from Drive" on the master profile. Google's own file picker opens, and Letterin gets access only to the file you choose. That file then takes the same path as a CV you upload from your device: it is sent to our servers, read with the AI processing described above, and you decide what is written to your profile.

To offer these, Google's sign-in script loads with the master profile page, and in the editor only when you open the Drive menu; the file picker loads only when you click "Pick from Drive".

  • The only permission we ask for is "drive.file": Letterin can see only the files it created itself and the file you choose in Google's picker. The rest of your Drive is closed to us — we cannot list, read or search your files.
  • The access token lives in your browser tab's memory and is gone after about an hour, or when you close the tab. It never reaches our servers, is never written to our database, and does not appear in your account export. You can withdraw the permission at any time in your Google Account's security settings.
  • Saved files go into a "Letterin" folder created in the root of your Drive. Saving the same CV again does not create a second copy: it updates the contents of the file we saved before. The files are yours and stay in your Drive even if your subscription ends.
  • We use this access only to save the file and to import the file you choose: never for advertising, profiling, transfer to third parties, or model training.

Cookies

Authentication cookies that keep you signed in and a cookie that remembers your language preference are essential.

In addition, we use one measurement cookie (letterin_ft). It is set the first time you visit letterin.app in this browser and holds where that first visit came from (campaign tags, the name of a click identifier, the referring site's domain, the landing page, the date) together with a random identifier for this browser. It is our own cookie, read only by our server, never overwritten, and deleted after 180 days. If you create an account, its content is saved to your account once; the same identifier links the usage records of features you used without an account before signing up (for example, reading a CV) to your account.

We use no advertising or third-party tracking cookies, and we do not send this cookie's content to any advertising platform. You can delete or block cookies in your browser settings; the service keeps working.

Retention

Your data is kept for as long as your account exists. Records you delete are removed from your lists; when you delete your account, all of your data (profile, CVs, job postings, usage records) is permanently deleted.

Your rights

  • Access: learn what data of yours is held.
  • Export: download your CVs as PDF and your data in a structured format.
  • Rectification: update your data in the app at any time.
  • Deletion: delete individual records or your entire account.

Contact

For privacy questions: info@letterin.app.