Skip to main content

Privacy Policy

Last updated: August 2, 2026

1. Who We Are

Aycabtu (aycabtu.com) is an AI-powered job application assistant that helps you create tailored resumes, cover letters, and interview preparation materials. In this policy, "we", "us" and "our" refer to Aycabtu.

Aycabtu is established in Ravenswaaij, the Netherlands, registered with the Dutch Chamber of Commerce under number 42115703, VAT identification number NL003323176B81.

Questions about this policy and requests concerning your data: privacy@aycabtu.com. We are not required to appoint a data protection officer and have not appointed one; that address is the contact point for all privacy matters.

2. Two Services, Two Roles

Aycabtu consists of two parts. Which rules apply depends on which part you use.

Aycabtu for job seekers. You create an account yourself and use the service for your own applications. Here Aycabtu determines the purpose and means of the processing and acts as controller.

Aycabtu for employers. Your employer takes out the service to build a pay structure and to compile pay statistics. Here your employer is the controller and Aycabtu is a processor acting on their instructions, under a data processing agreement.

Sections 3 and 4 describe what we process in both parts. Section 8 explains where to send a request about your data if you use Aycabtu through your employer.

3. What Data We Collect

Account information

  • Name and email address
  • Password (stored as a one-way hash, so we cannot read it)
  • Profile picture (optional)

You can also log in without a password using a one-time sign-in link we send to your email address.

Job application data

  • Documents you upload (LinkedIn exports, existing resumes, PDFs, personality test results, certificates)
  • Job descriptions you enter
  • AI-generated resumes, cover letters, and interview tips
  • Resume feedback requests: a resume you upload for analysis (ATS match score, general quality feedback, or rejection analysis) together with the related job description, and the AI feedback we return
  • Resume tailoring data: an existing resume and a target job description, and the tailored result
  • Salary Check data: your role, sector and salary details, and the AI assessment of whether your pay is in line with the market
  • Salary negotiation data: role, years of experience, current and offered salary, negotiation situation, and AI-generated counter-offer advice
  • Career Discovery data: the answers you provide about your profile, and the AI-suggested roles
  • Ghost Job Check and AI Risk Audit data: the job posting or role you submit, and the AI assessment
  • Recruiter email content you paste into the Reply Coach, and AI-generated response advice
  • Referral outreach data: the contact name and company you enter, and the AI-generated outreach message (this concerns a third party, see "Third-party data" below)
  • Evidence links: URLs you choose to add to support claims on your resume (for example a GitHub repository or portfolio page), which can be shown on an optional verification page

Third-party data

Some features process limited data about a third party that you provide:

  • Interviewer Research: you provide the name and employer of your interviewer. We use Claude AI's web search to look up publicly available information about that person (e.g. LinkedIn profile, company bio) and store the result to generate personalised interview tips.
  • Referral Outreach: you provide the name and company of a contact in your network so we can draft a personalised outreach message. We do not look this person up online; we only use what you enter.

This data concerns a third party and is processed on the basis of legitimate interest (Art. 6(1)(f)). It is used solely to help you prepare your application and is deleted when you delete the related item or your account.

Pay structure & job evaluation (employer tools)

On our pay-transparency tools (including the employers.aycabtu.com workspace and the employer vacancy checks) you enter job profiles, vacancy texts and role descriptions to build a defensible pay structure or to benchmark a vacancy. This is your own business content describing roles, not salary data about identifiable individuals. We send it to Claude AI (with web search for market calibration) to generate the analysis, grading and substantiation, and store the result in your account.

Pay data (employer tools)

This part works differently from what you may be used to, and that is a deliberate choice.

The payroll file an employer loads is processed entirely in the user's own browser. Averages, medians and group distributions are calculated on the device itself. The file is not sent to our systems and we do not store it.

Only aggregated outcomes per job group and gender reach our systems, and there are two kinds:

  • Group sizes, the number of men and women per job group, are always sent. They contain no pay information and no individual can be derived from them: we receive no names and cannot tie a tally to a person.
  • Pay outcomes carry two thresholds. An average is only sent when the underlying group contains at least three people. A median needs at least five, because a median over three people is the middle person's exact pay while an average over three is nobody's pay. Outcomes for smaller groups stay available locally only. Where suppressing one group would make an adjacent group identifiable after all, that group is withheld too.

The employer therefore remains the only holder of the individual pay data. Anyone who wants to verify this can watch their own browser's network traffic while the file is being processed. We provide a data flow diagram and an explanation of how it works on request.

Session & security data

  • IP address of each login session
  • Browser user agent of each login session

We store this data to secure your account (e.g. to detect suspicious logins) and to comply with legal obligations. A session is removed when you log out, and sessions that go unused for 30 days are deleted automatically by a daily clean-up.

Free tools without an account

Some tools can be used without creating an account, including the free ATS check, the salary check, the vacancy compliance check and the employer vacancy check. For these tools we process:

  • The content you submit (for example the resume, job posting or vacancy text), which is sent to Claude AI to produce the result
  • Your IP address, which we store temporarily and in a limited form to prevent abuse and enforce daily usage limits

If you later create an account and claim a result (for example via a sign-in link after a free ATS check), that result is linked to your new account. Otherwise this data is not tied to an identified user.

Payment data

Payments are processed by Stripe. We store only a reference to your Stripe payment (amount and credits purchased). We never see or store your full card details.

Analytics data

We use Umami, a privacy-friendly, open-source analytics tool that we self-host on our own servers in the Netherlands. Umami does not use cookies, does not track you across websites, and does not collect any personally identifiable information. Analytics data is aggregated and never linked to your account. No data is sent to third parties.

4. Why We Process Your Data

Purpose Legal basis (GDPR)
Providing the service (generating documents) Performance of contract (Art. 6(1)(b))
Account security (IP / user agent per session) Legitimate interest (Art. 6(1)(f))
Processing payments Performance of contract (Art. 6(1)(b))
Analytics (Umami, self-hosted, no cookies, no PII) Legitimate interest (Art. 6(1)(f))
Researching interviewers via web search to generate personalised interview preparation Legitimate interest (Art. 6(1)(f))
Sending a follow-up email after an ATS check if no resume has been generated (to help you get the most out of the service) Legitimate interest (Art. 6(1)(f))
Generating pay structures and job evaluations from the role descriptions you provide (employer tools) Performance of contract (Art. 6(1)(b))
Compiling pay statistics per job group from the aggregates calculated in your own browser (employer tools) Performance of contract (Art. 6(1)(b)), on the instructions of your employer as controller
Operating free tools without an account, including preventing abuse and enforcing daily usage limits (IP address) Legitimate interest (Art. 6(1)(f))
Legal obligations Legal obligation (Art. 6(1)(c))

5. Use of Artificial Intelligence

Aycabtu uses AI to generate resumes, cover letters, interview tips, resume feedback, salary checks and negotiation advice, reply coaching, career suggestions, job and vacancy checks, and employer pay structures. In compliance with the EU AI Act (Regulation (EU) 2024/1689), we inform you of the following:

  • All documents and content generated through this service are produced by AI (Anthropic Claude) based solely on the documents and information you provide.
  • Some features use Claude AI's web search to look up publicly available information (for example to research a named interviewer, calibrate a pay structure against the market, or check a vacancy). Where this is done it is described in this policy.
  • Aycabtu does not make automated decisions about you as a candidate. We help you present yourself; employers make their own decisions.
  • You remain in full control: AI output is always shown to you before use, and you can edit, discard, or not use it.
  • The AI generates content strictly based on the documents and information you provide. It is instructed not to invent or fabricate information.

6. Third-Party Services

We share data with the following third parties only to the extent necessary to deliver our service:

  • Anthropic (Claude AI): we extract the text from the documents you upload on our own servers and send only that text, together with the job description, to Anthropic's API to generate content. Your original files are never sent to Anthropic, and neither is any photo they contain. Anthropic does not use API data to train its models, and deletes inputs and outputs within 30 days of receipt. Anthropic's privacy policy applies: anthropic.com/privacy
  • Stripe: payment processing. Stripe's privacy policy: stripe.com/privacy
  • Umami: privacy-friendly analytics, self-hosted on our own servers in the Netherlands. No data is sent to third parties. Open-source: umami.is
  • Mailtrap (Railsware Products Studio LLC): transactional email delivery (password resets, confirmations, sign-in links). Receives your name and email address.

We do not sell your data to third parties, and we do not share it with anyone for advertising purposes. Individual pay data is never passed to any of these providers: it does not leave the employer's own browser, as described in section 3.

Business customers: the same providers, with the data each one receives, where it is processed and which transfer safeguard applies, are set out in our subprocessor list. That page also states how a change of subprocessor is announced and how you can object to one.

International transfers

Our own servers are located in the Netherlands, and our encrypted backups are stored in the European Union (Frankfurt, Germany). Some of the third parties above are established in the United States, which means some of your personal data is transferred outside the European Economic Area:

  • Anthropic: the text extracted from your documents, and the job description. Transferred under the Standard Contractual Clauses approved by the European Commission, which are incorporated into Anthropic's Data Processing Addendum and form part of the commercial terms we have accepted.
  • Stripe: payment reference data. Stripe, Inc. is certified under the EU-U.S. Data Privacy Framework, the European Commission's adequacy decision for transfers to the United States, and additionally applies the European Commission's Standard Contractual Clauses through its Data Transfers Addendum.
  • Mailtrap (Railsware Products Studio LLC): your name and email address. Railsware Products Studio LLC is certified under the EU-U.S. Data Privacy Framework, the European Commission's adequacy decision for transfers to the United States.

You can request a copy of the safeguards that apply to these transfers by contacting us at privacy@aycabtu.com.

7. How Long We Keep Your Data

  • Account data: kept until you request deletion of your account.
  • Session data (IP address, user agent): removed when you log out, and in any case once the session has gone unused for 30 days, after which a daily automated clean-up deletes it.
  • Generated documents (resumes, cover letters, feedback, pay structures, and other AI output): kept until you delete them, or until your account is deleted.
  • Text sent to the AI service: Anthropic deletes the text we send and the output it returns within 30 days of receipt. During that period it may be accessed by Anthropic for safety and security purposes. It is not used to train their models. Your original uploaded files are never sent to them at all.
  • Payment records: kept for 7 years to comply with tax regulations.
  • Third-party data (interviewer research, referral outreach): deleted when you delete the related item or your account.
  • Free tools without an account: IP-based usage counters are kept only as long as needed to enforce daily limits and are then deleted; submitted content that is not claimed by an account is not retained as identified personal data.
  • Evidence links: kept until you remove them or delete the related resume.
  • Job profiles and aggregated pay outcomes (employer tools): kept until the employer deletes them or until the agreement ends. The underlying payroll file never reaches us and is therefore not retained by us at all.
  • Encrypted backups: kept for 30 days from the moment the data enters the backup, after which they are removed automatically.

8. Your Rights (GDPR)

If you are in the European Economic Area, you have the following rights:

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate data.
  • Erasure: request deletion of your data ("right to be forgotten").
  • Portability: receive your data in a machine-readable format.
  • Objection: object to processing based on legitimate interest.
  • Restriction: request that we limit processing of your data.

To exercise any of these rights, including account deletion, you can use the Settings page in your account or contact us at privacy@aycabtu.com. We will respond within 30 days.

If you use Aycabtu through your employer, address your request to your employer: they are the controller for that part of the service. If we receive such a request directly, we forward it to them within five working days and do not handle it independently.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl.

One practical note on erasure: when you delete a document or your account, we remove it from our own systems straight away. The text we previously sent to our AI service is deleted by them within 30 days of when it was sent, which we cannot speed up. Nothing further is retained after that.

9. Cookies

We use a single session cookie (session_id) to keep you logged in. This cookie is strictly necessary for the service to function and does not track you across other websites.

Umami does not set any cookies.

10. Security

We take appropriate technical measures to protect your data, including HTTPS encryption in transit, hashed passwords, and access controls. No system is 100% secure; if you discover a vulnerability please contact us responsibly at privacy@aycabtu.com.

11. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email or by a prominent notice on our website. The "last updated" date at the top of this page always reflects the most recent version.

12. Contact

Questions or requests regarding this policy:

Email: privacy@aycabtu.com