Privacy Policy

Last updated 4 May 2026

The legal version

wathafak ("we", "us", "our") is a CV-tailoring and application-tracking service operated by the wathafak team. This Privacy Policy describes how we collect, use, store, and disclose Personal Data when you use our website and services (the "Service"). It applies to data of users in the European Economic Area, the United Kingdom, the Kingdom of Saudi Arabia, and elsewhere. By using the Service you confirm you have read this Policy. For questions, contact privacy@wathafak.com.

What it actually means

We help you tailor CVs to job postings. This page explains what data we hold, why, and how to get rid of it. Plain English on the right, formal stuff on the left.

1. Who we are

The data controller is the wathafak team. Where required by law, an EU representative and a KSA local representative will be designated and listed on this page once appointed. Contact for all data-protection matters: privacy@wathafak.com.

We're a small team running wathafak. Email privacy@wathafak.com for anything privacy-related.

2. What we collect

(a) Account identifiers: email address and authentication identifier issued by the sign-in provider. (b) CV Content: documents you upload (PDF, DOCX) or text you paste, the extracted plain text, and the structured representation we generate from them. CVs frequently contain Personal Data including name, contact details, employment history, education, and may contain Special Category data such as nationality, gender, or photographs. (c) Job Descriptions: text or URLs you submit, and the structured fields we extract. (d) Application records: tailored CV variants, cover letters, match scores, status, notes, follow-up timestamps. (e) Service logs: per-request identifiers, model name, latency, and error context retained for security and audit. (f) Product analytics: page views and event identifiers via PostHog, stored only with your explicit consent.

Your email, your CV file and the text inside it, the job postings you give us, and what you do with them. Plus boring server logs so we can debug. Analytics tracking only fires if you say yes to the cookie banner.

3. How we use it

We process Personal Data on the lawful bases of (i) performance of a contract (operating the Service you requested), (ii) legitimate interest (security, fraud prevention, product improvement at aggregate level), and (iii) consent (optional analytics cookies). Specifically: rendering and persisting your CV; sending CV and JD content to AI sub-processors to generate tailored variants, match scores, gap analyses, and cover letters; tracking application status; producing exports; sending operational emails (e.g. password recovery). We do not engage in automated decision-making producing legal effects.

We use your data to run the product: read your CV, read the job posting, tailor a version, write a cover letter, export the docs, track applications. We don't run black-box decisions on you.

4. AI sub-processors

CV Content and Job Descriptions are transmitted to large language model providers (currently Anthropic, OpenAI, and OpenRouter, collectively the "AI Sub-processors") via authenticated API calls solely to generate the tailored output you requested. We have agreements in place that prohibit training on your content where supported by the provider; where the provider does not offer that guarantee, we do not use them for your content. We retain a request identifier and model name for audit. We do not transmit Personal Data outside the scope of fulfilling a specific user request.

Your CV and JD go to AI providers (Anthropic, OpenAI, OpenRouter) so they can generate the output. They're contractually blocked from training on your stuff. We log a request ID so we can trace problems.

5. Sharing and disclosure

We do not sell, rent, or trade Personal Data. We share data only with: (i) the AI Sub-processors listed in Section 4, (ii) infrastructure sub-processors who host or transmit data (cloud storage, database, email delivery, error monitoring), (iii) the authentication provider (Ory) for sign-in flows, (iv) competent authorities when legally compelled by valid order under applicable law, and (v) successors in the event of a merger or acquisition, subject to equivalent privacy protections. We never share your data with advertisers or data brokers.

We don't sell your data. The only people who see it are the AI providers, our hosting providers, the auth provider, and lawyers if a court orders us to.

6. Retention

Account data and content remain in your account until deletion. Upon deletion of an individual record (CV, job, application), the record is removed from active databases immediately and purged from backups within thirty (30) days. Upon account deletion, all associated content is removed within thirty (30) days, except where retention is required by law (e.g., financial records related to billing, retained for the statutory period). Server logs are retained for ninety (90) days for security and debugging, after which they are deleted or fully anonymised. Aggregated, non-identifying analytics may be retained indefinitely.

Your stuff stays until you delete it. Deleting an item removes it within 30 days, including from backups. Deleting your whole account removes everything within 30 days. Server logs go after 90 days.

7. Your rights

You have the right to access, rectify, erase, restrict processing, object to processing, and request portability of your Personal Data. EU/UK residents may lodge a complaint with their supervisory authority (in the EU, the Data Protection Authority of your member state; in the UK, the ICO). KSA residents may contact the Saudi Data and Artificial Intelligence Authority (SDAIA). You may exercise these rights from in-app settings or by emailing privacy@wathafak.com. We respond within thirty (30) days. There is no charge for reasonable requests.

You can see, fix, export, or delete your data — from settings or by emailing us. EU/UK/KSA folks can also complain to their data regulator if we mess up. We reply within 30 days, free.

8. Security

We employ industry-standard technical and organisational measures including encryption in transit (TLS 1.2+ exclusively), encryption at rest for stored files, network isolation of databases and object storage from the public internet, role-based access for our team, audit logging of administrative actions, malware scanning on uploaded files, and authenticated download proxies. Authentication and session management are delegated to Ory Kratos. We do not process payment card data; payment processing, where applicable, is delegated to a PCI-DSS compliant provider.

We use HTTPS, encrypt files at rest, scan uploads for malware, lock down the database, and let Ory handle logins. Cards are never on our servers — payment runs through a PCI-compliant processor.

9. Cookies and tracking

We use strictly necessary cookies (authentication session, CSRF token, language preference) without prior consent under the legitimate-interest basis. Optional analytics cookies (PostHog) are set only after explicit consent through the cookie banner; consent may be withdrawn at any time. We do not use third-party advertising cookies, cross-site tracking pixels, or remarketing tags. The full cookie inventory is available on request.

Strictly-needed cookies (login, language) load right away. Analytics cookies wait for you to click 'allow' in the banner. No ad trackers, ever.

10. International transfers

Data may be transferred to and processed in jurisdictions outside the EEA, UK, or KSA, including the United States, where AI Sub-processors and certain infrastructure providers operate. Such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission and equivalent UK and KSA mechanisms where required, alongside supplementary measures including encryption and access controls. A list of sub-processors and their processing locations is available on request.

Some of our suppliers (the AI providers, our hosting) are in the US. We use the standard EU/UK contractual safeguards plus encryption to keep that legit. Email us if you want the full sub-processor list.

11. Children

The Service is not directed to or intended for individuals under the age of sixteen (16). We do not knowingly collect Personal Data from children. If we discover that we have collected Personal Data from a child, we will delete it promptly. If you are a parent or guardian and believe your child has provided us data, contact privacy@wathafak.com.

wathafak is for grown-ups looking for jobs. We don't want kids' data. If we somehow ended up with some, we'll delete it.

12. Changes to this Policy

Material changes will be communicated in-app and to the email associated with your account at least fourteen (14) days before they take effect. Non-material changes (typographical fixes, clarification of existing meaning) take effect immediately and are reflected by the "Last updated" date. Continued use of the Service after the effective date constitutes acceptance.

We give 14 days' notice for any meaningful change. Small fixes go in immediately. The 'Last updated' date at the top is always current.

13. Contact

Data Protection Contact: privacy@wathafak.com. For complaints we have not resolved, EU residents may contact their national supervisory authority, UK residents may contact the Information Commissioner's Office (ico.org.uk), and KSA residents may contact the Saudi Data and Artificial Intelligence Authority (sdaia.gov.sa).

Email privacy@wathafak.com. If we don't fix it, you can complain to your country's data regulator.