Privacy policy
Last updated Aug 21, 2026
This notice explains what personal data OfferCompass processes, why, on what legal basis, who else sees it, how long it is kept and what you can require of us. It is written to be read rather than to be survived, but nothing has been left out to achieve that.
Who is responsible
The controller within the meaning of Art. 4(7) GDPR is Sven Güttner, Walter-Hohmann-Straße 19, 45128 Essen, Germany.
Data protection enquiries: support@offercompass.app. We have not appointed a data protection officer, as we do not meet the thresholds in Art. 37 GDPR or §38 BDSG. Your enquiry is answered by the controller personally.
What we process, why, and on what legal basis
Each category below is processed for the stated purpose only. Where the basis is Art. 6(1)(b) GDPR, providing the data is necessary to perform the contract and the service cannot be delivered without it.
- Account data (email address, name where given, profile image URL, authentication identifiers) — to create and operate your account. Art. 6(1)(b) GDPR. We never receive or store your password.
- Document content (resumes, cover letters, resignation letters, their settings and version history) and files you upload for import — to store, render, score, export and version the documents you create. Art. 6(1)(b) GDPR.
- Profile photographs, where you choose to upload one, including the automated image checks and the AI review — to provide the photo feedback feature you invoked. Art. 6(1)(b) GDPR. A photograph is not processed for any purpose other than returning that feedback to you, and never for identification, biometric analysis or profiling.
- AI generation inputs and outputs (the text you submit and what is returned) — to produce the output you asked for. Art. 6(1)(b) GDPR.
- Billing data (plan, subscription status, payment and customer identifiers, invoice records) — to bill you and to meet accounting and tax obligations. Art. 6(1)(b) and Art. 6(1)(c) GDPR.
- Usage records (credits consumed in the current period, feature use needed to enforce plan limits) — to operate the plan you are on. Art. 6(1)(b) GDPR.
- Server and security logs (IP address, request metadata, timestamps) — to keep the service available, diagnose faults and defend against abuse. Art. 6(1)(f) GDPR; our legitimate interest is the security and integrity of the service.
- Measurement data, and only if you consented to it (pages viewed, the referring page, the approximate region derived from your IP address, browser and device type) — to see which pages and guides are actually useful. Art. 6(1)(a) GDPR for the processing and §25(1) TDDDG for the storage on your device. Withdrawable at any time from "Cookie settings" in the footer, without giving a reason and without affecting anything measured before you withdrew.
- Correspondence you send us, including support requests and anything filed through the cancellation form — to answer you and, for cancellations, to comply with §312k BGB. Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f) GDPR.
Who else processes it
We use the following processors under Art. 28 GDPR data processing agreements, each with access limited to what its function requires. We do not sell personal data, disclose it to data brokers, or share it with recruiters or employers.
- Cloudflare, Inc. — hosting, database, object storage, content delivery, headless browser rendering and the Workers AI inference behind every AI feature. Inference runs on Cloudflare's own infrastructure; your text is not used to train models.
- Clerk, Inc. — authentication, session management and account administration.
- Stripe Payments Europe, Ltd. — payment processing and subscription billing. Card details are entered on their systems and are never transmitted to or stored by us.
- Google Ireland Limited — website analytics (Google Analytics 4), and only for visitors who consented to it. Nothing reaches Google from a visitor who declined, or who has not answered yet.
Transfers outside the EEA
Cloudflare and Clerk are established in the United States, Stripe processes through its Irish and United States entities, and Google Ireland Limited transfers onward to Google LLC in the United States, so processing may take place there or in other third countries. Those transfers are safeguarded by the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, supplemented where applicable by the provider's certification under the EU–US Data Privacy Framework (Art. 45 GDPR).
You may request a copy of the safeguards relied on for any specific transfer by writing to support@offercompass.app.
How long it is kept
Documents, uploads and account data are kept until you delete them or delete your account, at which point they are removed immediately rather than queued. Deletion is irreversible and we cannot recover a deleted document for you.
Invoices and the accounting records attached to them are retained for ten years under §147 AO and §257 HGB, and cannot be deleted on request before that period expires; they are restricted from all other processing in the meantime under Art. 18 GDPR.
Cancellation filings and their confirmations are retained for three years, the regular limitation period under §195 BGB, because they are evidence of when a contract ended.
Server and security logs are retained for no longer than 30 days and are then deleted or irreversibly aggregated.
Analytics records held by Google are configured for the shortest retention period Google offers, two months, and expire automatically after that. Cloudflare Web Analytics is aggregated and carries no identifier that could be traced back to you.
Automated decision-making
The ATS score is a deterministic rule-based calculation performed on your own document at your request. It produces advice for you and is not used to make any decision about you, so it is not automated decision-making within the meaning of Art. 22 GDPR. We do not profile you, score you as a candidate, or share any assessment of you with a third party.
Job matching compares a document you choose against postings you searched for. The result is a suggestion shown to you and nothing else acts on it.
Your rights
Under the GDPR you have the following rights, which we honour without charge and without asking why:
- Access to the personal data we hold about you and the information in this notice (Art. 15).
- Rectification of inaccurate data and completion of incomplete data (Art. 16).
- Erasure, subject only to the retention obligations set out above (Art. 17).
- Restriction of processing (Art. 18).
- Portability — a machine-readable export of everything you created, available immediately from your settings without asking us (Art. 20).
- Objection at any time to processing based on our legitimate interests, including profiling based on them (Art. 21).
- Withdrawal of any consent you have given, at any time, without affecting the lawfulness of processing carried out before you withdrew it (Art. 7(3)).
Job postings in the index
The job search indexes openings published by employers through their own applicant tracking systems. Those postings are not your personal data, but they occasionally contain someone else's — a named hiring manager, a direct line. We process that on the basis of Art. 6(1)(f) GDPR, our legitimate interest in operating a job search, balanced against a limited and public disclosure that the publisher chose to make.
If you find personal data in an indexed posting that should not be there, write to support@offercompass.app and we will remove it.
Security
Data is encrypted in transit and at rest. Access to production systems is limited to the people who operate them. We are a small operation and will not claim certifications we do not hold; if you need a formal security review for an employer or an institution, ask and you will get an honest description of what exists.
Changes to this notice
Where a change materially affects how we process your data, we will tell you before it takes effect rather than relying on you noticing the date at the top of this page.