Privacy
Candidate personal data never reaches the AI model, and is never stored in raw form. When you paste a CV or upload a file, our own server extracts the text and redacts it before anything is written to a database: names become [NAME_1], emails become [EMAIL_1], and phone numbers, addresses and account identifiers are removed outright.
Who we are, and how to reach us
politehr.me is run by a very small team, and [email protected] reaches it. That is the address for a question about this notice, for any of the rights below, and for anything you would like deleted. The legal entity behind the service and its registered address are not published here yet; that is a gap we know about, and the address above answers in the meantime.
The promise this whole product is built around
Only redacted text is stored. The uploaded file itself is parser input and is never kept, and nothing that has not been through the redaction reaches a database or a model.
Immediately before every model call the assembled prompt is scanned again, and if any personal data is found the call is aborted rather than sent. Candidate names are the one exception to removal: they are kept encrypted, and only so a letter can address a person instead of a placeholder. They are decrypted when the letter is shown to you, never when it is sent to the model. Logs carry counts and types — never content, never a name, never a filename.
Two roles, and which one is whose
For the candidate data you paste, you are the controller and we are the processor: we handle it to produce the letter you asked for, on your instruction, and for nothing else. For your own account — your email address, your threads, your balance — we are the controller. That line decides who a candidate should ask about what, and it is why the terms put the lawful basis for pasting a CV on your side of it.
Nothing here decides anything about a person
The model writes a message about a decision you have already made. It does not score, rank, filter or evaluate candidates, and no automated decision with a legal or similarly significant effect is made here about anybody. The short version: this is a writing tool that happens to sit next to hiring, not a hiring tool.
What we hold about you
Your account: the email address, name and avatar Google gives us when you sign in. Your work: threads, the redacted text in them, thread settings and usage counters. Your purchases: which pack, how many requests, the amount, and the transaction id from our payment provider — never your email address, name, postal address or card details, which we neither receive nor ask for. And your IP address, used briefly to apply the rate limits and not stored against your account.
Why we hold it, and on what basis
To provide the service you asked for, which is the contract between us: your account, your threads, your letters, your balance. To keep the service working and un-abused, which is our legitimate interest: the anonymous identity, the rate limits, and error monitoring. To take payment and keep the records that go with it, which is that same contract plus our payment provider’s own legal obligations. And, if analytics is ever switched on, your consent — given or refused in the cookie settings, and changeable at any time.
Who else sees any of it
Google, for signing in. Google Gemini, which receives the redacted prompt text and never raw personal data. Paddle, which takes the payment and receives a price id and an internal identifier from us and nothing else. Sentry, which receives scrubbed error reports. And our hosting provider, which runs the servers. If product analytics is ever enabled, the vendor is named here in the same change that switches it on.
Where it goes
Some of those companies are outside the European Economic Area, mostly in the United States. Those transfers rest on the European Commission’s standard contractual clauses, which is the mechanism that keeps the data under European protection once it has left.
How long we keep it
Threads on an anonymous identity are deleted after 14 days. Threads on an account are deleted after 90. Purchase records last as long as the account does. Deleting your account deletes all of it immediately, including any unspent balance. Our payment provider keeps its own transaction records for as long as its tax obligations require, which is not something we can shorten on your behalf.
Your rights
You can ask for access to what we hold, for it to be corrected, for its erasure, for its processing to be restricted, and for a portable copy; and you can object to processing we do on the basis of legitimate interest. Where we rely on consent you can withdraw it at any time, without that affecting anything already done with it. Deleting your account from the menu is the fastest erasure there is, and [email protected] does the rest. You also have the right to complain to your data protection supervisory authority — though we would rather you told us first.
If you are a candidate
If your CV was pasted here by somebody else, write to [email protected]. We will usually hold nothing but redacted text and an encrypted name, and we will say so plainly rather than pretend to a file we do not have. Because the recruiter is the controller of that data, we will pass your request on to them as well.
Children
The service is not for people under 16 and is not directed at them. If you believe a child has used it, write to us and the account goes.
Changes to this notice
When this notice changes we update this page and date it, and a material change is announced rather than slipped in. If a change adds a purpose that needs your consent, you are asked again before anything new happens.