Privacy Policy

Last updated: 12 August 2026

This policy explains what personal data Aptora processes when you use the service, why we process it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR). We only process the data we need to run the service, and we keep our infrastructure and primary database in the European Union.

1. Who is responsible

The controller responsible for processing your personal data is:

Lasse Borchard

Cloudsurf IT Consulting (sole proprietorship)

Elisabethstr. 1 84570 Annabrunn Germany

aptora@cloudsurf.digital

2. What data we process, why, and on what legal basis

We process the following categories of personal data:

Account & identity

Data:
Name, email address, profile photo, workspace/organisation membership and the identifier assigned by our authentication provider.
Purpose:
To create and secure your account, sign you in and manage team access.
Legal basis:
Performance of a contract (Art. 6(1)(b))

Profile & CV content

Data:
Everything you add to a profile or CV: name, contact details, address, work and education history, skills, languages, projects, links, and any references or testimonials you enter about other people.
Purpose:
To store, edit, render and export your CVs and profiles — the core purpose of the service.
Legal basis:
Performance of a contract (Art. 6(1)(b))

Jobs & applications

Data:
Job postings you save or forward, and the applications you create — including the recipient contact name and email address an application is addressed to.
Purpose:
To match jobs to your profile and help you compose and track applications.
Legal basis:
Performance of a contract (Art. 6(1)(b))

Inbound emails

Data:
Everything sent or forwarded to your personal Aptora address: the full message (headers, sender, subject, body, attachments) and delivery metadata. This includes mail that is not a job alert — we cannot tell before it arrives.
Purpose:
To show your messages in Aptora and, for mail from job portals we recognise, to extract the job postings it contains. Extraction uses pattern rules, our own models and our AI provider. Extracted job postings become part of Aptora's shared job pool and can be matched to other users; the stored job posting carries no link to you or your mailbox. Mail that does not come from a recognised portal is stored for you to read, but is not analysed for job content and is never shared with other users.
Legal basis:
Performance of a contract (Art. 6(1)(b))

Payment data

Data:
Subscription records and the customer identifier assigned by our payment provider. Card details are handled by the payment provider — we never see or store them.
Purpose:
To process payments for paid plans and to meet accounting obligations.
Legal basis:
Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))

Connected AI tools (MCP)

Data:
Records of AI clients (e.g. Cursor, Claude) you connect via our OAuth flow, and the access tokens issued to them.
Purpose:
To let an AI assistant you authorise create and manage your profiles on your behalf, and to let you review and revoke that access.
Legal basis:
Performance of a contract (Art. 6(1)(b))

Usage statistics

Data:
Aggregate visit counts and viewing time for CV share links. We deliberately do not record visitors' IP addresses, user agents or referrers.
Purpose:
To show you how often a shared CV link was opened and for how long.
Legal basis:
Legitimate interest in basic, privacy-preserving analytics (Art. 6(1)(f))

Visibility in talent search

Data:
When your profile is delivered, opened, shortlisted or contacted in Aptora's talent search, we log the acting team, the acting user, your profile, the kind of access and the time.
Purpose:
Transparency towards you as the person concerned — you can see these accesses, on paid personal plans with the name of the acting company — and protection against abuse and unfair use of the search. Users of the talent search become visible to candidates as their team, never as an individual person. Records are kept for 12 months and then deleted.
Legal basis:
Legitimate interest (Art. 6(1)(f)) — transparency and abuse prevention

3. AI processing

Aptora uses AI to make sense of unstructured content — extracting a structured CV from a PDF you upload, parsing job postings (including those in emails that reach your inbound address from job portals we recognise), detecting skills and ranking how well a job fits your profile. To do this, the relevant content (for example a CV file, a job posting, or the text of a job-portal email) is transmitted to our AI provider, Anthropic, and processed on their infrastructure in the United States. Mail that does not come from a recognised job portal is not sent to our AI provider for job extraction. The AI output is a suggestion that you remain in control of. We do not use your data to train any AI model, and Anthropic states that data submitted through its API is not used to train its models.

4. Who we share data with

We do not sell your personal data. We share it only with the service providers (subprocessors) we rely on to run Aptora, each bound by a data processing agreement and permitted to use the data only to provide their service to us:

  • Amazon Web Services (AWS) Cloud hosting and email intake (compute, storage, inbound email). Our infrastructure runs in the eu-central-1 (Frankfurt) region. (EU (Frankfurt) — AWS is a US company)
  • Neon Managed PostgreSQL database — our primary data store. (EU (aws-eu-central-1))
  • Clerk Authentication, session and organisation management (account identity). (USA)
  • Anthropic (Claude) AI model provider. We send CV files and job postings to Anthropic's API to extract structured data, detect skills and rank matches. Anthropic states that data submitted through its API is not used to train its models. (USA)
  • Voyage AI Optional text-embedding provider used for semantic skill matching, only when that feature is enabled. (USA)
  • Stripe Payment processing for paid plans. (USA / EU)

Separately, if you connect an external AI tool through our MCP/OAuth flow, that tool receives the data needed to perform the actions you authorise. You can review and revoke those connections at any time under Settings.

5. International data transfers

Our hosting and primary database are located in the European Union (Frankfurt). Some of our providers (Clerk, Anthropic, Voyage AI and Stripe) are based in or transfer data to the United States. Where personal data is transferred outside the EU/EEA, the transfer is safeguarded by the European Commission's Standard Contractual Clauses and, where applicable, the provider's certification under the EU–US Data Privacy Framework.

6. How long we keep your data

We keep your personal data for as long as your account is active and you use the service. You can delete individual CVs, applications and connected tools yourself at any time. When you ask us to delete your account, we delete or anonymise your personal data unless we are legally required to keep it (for example, payment records retained to meet accounting and tax obligations). Access tokens for connected AI tools expire automatically — access tokens after one hour and the underlying connection after 30 days unless renewed.

7. Cookies and consent

We only set cookies and comparable storage the way you decided. Strictly necessary cookies are exempt from consent (§ 25(2) TDDDG); everything else is only set after your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). Your decision is stored for six months, after which we ask again.

Necessary (always on)

Without these the service does not work: you cannot stay signed in, and the app cannot render in your language and time zone. They are set without consent and cannot be switched off.

CookiePurposeStorage periodProvider
__session, __client_uatSign-in session and workspace context; the same provider may set further session cookies.session, up to 12 monthsClerk, Inc., USA
NEXT_LOCALEThe interface language you chose.12 monthsAptora (1st party)
NEXT_TIMEZONEYour time zone, so dates and times are shown as they are where you are.12 monthsAptora (1st party)
rf_inbox_noticeRemembers that you acknowledged the inbox notice, so it is not shown again.12 monthsAptora (1st party)
rf_consentYour decision on this page — which categories you allowed, and when. Contains no identifier.6 monthsAptora (1st party)

Analytics (only with consent)

Anonymised reach and usage measurement, so we learn which parts of Aptora are used and where people get stuck. We currently use no analytics cookies at all — the category exists so that nothing can be loaded before you have allowed it. Should we introduce a tool, it will be named here, kept for at most 12 months, and only loaded after your consent.

You can change or withdraw your consent at any time with effect for the future — as easily as you gave it, via “Cookie settings” in the footer of every page or here:

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have your data deleted (Art. 17);
  • restrict or object to processing (Art. 18 and 21);
  • receive your data in a portable, machine-readable format (Art. 20);
  • withdraw any consent you have given, with effect for the future (Art. 7(3)).

To exercise any of these rights, contact us using the details in section 1. You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Ansbach; you may also complain to the authority in the EU member state of your residence or place of work.

9. Data security

We protect your data with appropriate technical and organisational measures, including encryption in transit, hashing of sensitive credentials, encryption of stored secrets, and access controls that limit who can reach your data. No online service can be guaranteed to be completely secure, but we work to protect your information and to keep these measures up to date.

10. Children

Aptora is not directed at children. You must be at least 16 years old to use the service. We do not knowingly collect personal data from children.

11. Changes to this policy

We may update this policy as the service evolves or the law changes. When we make material changes we will update the "last updated" date above and, where appropriate, notify you in the app.