Privacy Policy
Last updated: 21 July 2026
This policy explains what personal data Aptora processes when you use the service, why we process it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR). We only process the data we need to run the service, and we keep our infrastructure and primary database in the European Union.
1. Who is responsible
The controller responsible for processing your personal data is:
Lasse Borchard
Cloudsurf IT Consulting (sole proprietorship)
Elisabethstr. 1 84570 Annabrunn Germany2. What data we process, why, and on what legal basis
We process the following categories of personal data:
Account & identity
- Data:
- Name, email address, profile photo, workspace/organisation membership and the identifier assigned by our authentication provider.
- Purpose:
- To create and secure your account, sign you in and manage team access.
- Legal basis:
- Performance of a contract (Art. 6(1)(b))
Profile & CV content
- Data:
- Everything you add to a profile or CV: name, contact details, address, work and education history, skills, languages, projects, links, and any references or testimonials you enter about other people.
- Purpose:
- To store, edit, render and export your CVs and profiles — the core purpose of the service.
- Legal basis:
- Performance of a contract (Art. 6(1)(b))
Jobs & applications
- Data:
- Job postings you save or forward, and the applications you create — including the recipient contact name and email address an application is addressed to.
- Purpose:
- To match jobs to your profile and help you compose and track applications.
- Legal basis:
- Performance of a contract (Art. 6(1)(b))
Inbound emails
- Data:
- Job-alert emails you forward to your personal Aptora address, including the full message (headers, sender, body) and delivery metadata.
- Purpose:
- To parse job postings out of the emails you send us and turn them into structured jobs.
- Legal basis:
- Performance of a contract (Art. 6(1)(b))
Payment data
- Data:
- Subscription and purchase records and the customer identifier assigned by our payment provider. Card details are handled by the payment provider — we never see or store them.
- Purpose:
- To process payments for paid plans and one-off purchases and to meet accounting obligations.
- Legal basis:
- Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Connected AI tools (MCP)
- Data:
- Records of AI clients (e.g. Cursor, Claude) you connect via our OAuth flow, and the access tokens issued to them.
- Purpose:
- To let an AI assistant you authorise create and manage your profiles on your behalf, and to let you review and revoke that access.
- Legal basis:
- Performance of a contract (Art. 6(1)(b))
Usage statistics
- Data:
- Aggregate visit counts and viewing time for CV share links. We deliberately do not record visitors' IP addresses, user agents or referrers.
- Purpose:
- To show you how often a shared CV link was opened and for how long.
- Legal basis:
- Legitimate interest in basic, privacy-preserving analytics (Art. 6(1)(f))
3. AI processing
Aptora uses AI to make sense of unstructured content — extracting a structured CV from a PDF you upload, parsing job postings, detecting skills and ranking how well a job fits your profile. To do this, the relevant content (for example a CV file or a job posting) is transmitted to our AI provider, Anthropic, and processed on their infrastructure in the United States. The AI output is a suggestion that you remain in control of. We do not use your data to train any AI model, and Anthropic states that data submitted through its API is not used to train its models.
4. Who we share data with
We do not sell your personal data. We share it only with the service providers (subprocessors) we rely on to run Aptora, each bound by a data processing agreement and permitted to use the data only to provide their service to us:
- Amazon Web Services (AWS) — Cloud hosting and email intake (compute, storage, inbound email). Our infrastructure runs in the eu-central-1 (Frankfurt) region. (EU (Frankfurt) — AWS is a US company)
- Neon — Managed PostgreSQL database — our primary data store. (EU (aws-eu-central-1))
- Clerk — Authentication, session and organisation management (account identity). (USA)
- Anthropic (Claude) — AI model provider. We send CV files and job postings to Anthropic's API to extract structured data, detect skills and rank matches. Anthropic states that data submitted through its API is not used to train its models. (USA)
- Voyage AI — Optional text-embedding provider used for semantic skill matching, only when that feature is enabled. (USA)
- Stripe — Payment processing for paid plans and purchases. (USA / EU)
- Cloudflare — DNS for our domains. DNS records are not proxied, so page traffic does not flow through Cloudflare. (USA / global)
Separately, if you connect an external AI tool through our MCP/OAuth flow, that tool receives the data needed to perform the actions you authorise. You can review and revoke those connections at any time under Settings.
5. International data transfers
Our hosting and primary database are located in the European Union (Frankfurt). Some of our providers (Clerk, Anthropic, Voyage AI, Stripe and Cloudflare) are based in or transfer data to the United States. Where personal data is transferred outside the EU/EEA, the transfer is safeguarded by the European Commission's Standard Contractual Clauses and, where applicable, the provider's certification under the EU–US Data Privacy Framework.
6. How long we keep your data
We keep your personal data for as long as your account is active and you use the service. You can delete individual CVs, applications and connected tools yourself at any time. When you ask us to delete your account, we delete or anonymise your personal data unless we are legally required to keep it (for example, payment records retained to meet accounting and tax obligations). Access tokens for connected AI tools expire automatically — access tokens after one hour and the underlying connection after 30 days unless renewed.
7. Cookies
Aptora uses only strictly necessary cookies. These are the session cookies set by our authentication provider (Clerk) to keep you signed in and maintain your workspace context. We do not use any advertising, marketing or third-party analytics cookies, and there is therefore no tracking that would require a consent banner.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data deleted (Art. 17);
- restrict or object to processing (Art. 18 and 21);
- receive your data in a portable, machine-readable format (Art. 20);
- withdraw any consent you have given, with effect for the future (Art. 7(3)).
To exercise any of these rights, contact us using the details in section 1. You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Ansbach; you may also complain to the authority in the EU member state of your residence or place of work.
9. Data security
We protect your data with appropriate technical and organisational measures, including encryption in transit, hashing of sensitive credentials, encryption of stored secrets, and access controls that limit who can reach your data. No online service can be guaranteed to be completely secure, but we work to protect your information and to keep these measures up to date.
10. Children
Aptora is not directed at children. You must be at least 16 years old to use the service. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy as the service evolves or the law changes. When we make material changes we will update the "last updated" date above and, where appropriate, notify you in the app.