Ssartori

Privacy

Privacy notice

Draft for operator review · September 28, 2026

This is not a final privacy notice. Before public signup, the operator must add the legal entity and jurisdiction, verified privacy contact, retention/deletion rules, and confirmed processor and transfer details. Obtain suitable legal review.

Information handled

An account contains an email address and account identifier managed by Supabase Auth. If you complete a profile, Sartori stores the job-search preferences you enter. Older profiles may retain a name and an email copy created before this audit; new signups no longer ask for a name or copy the email into account preferences. Searches can create saved job-match records. You may optionally upload a resume; its file and filename are stored in private, account-scoped Supabase storage. Sartori does not currently parse resumes, generate CVs, submit applications, or take payments.

How the information is used

Profile preferences are used to compare role, skill, and location keywords with listings retrieved from the Arbeitnow public job feed. The current match score is keyword overlap, not an AI or suitability assessment. Sartori reads the public feed from its server; it does not send your uploaded resume to the feed. If you choose to open an employer listing, that employer's site handles any information you submit there under its own terms and privacy notice.

Storage and access

Account and job-search records are held in the configured Supabase project. Optional resume files use a private bucket with user-scoped access policies; they are not published as public links. Supabase's current project region, applicable transfer safeguards, retention settings, and contractual processor terms must be confirmed by the operator before this notice is finalized. Local browser-only demo state is used only in development and is not the production account store.

Cookies, analytics, and security

Supabase Auth uses session mechanisms needed to sign in and keep an account session. No analytics or advertising tracker is currently integrated. Cloudflare may process connection and security metadata when the public domain is served through its network; the operator must review and describe the final Cloudflare configuration and applicable provider terms before launch. Access is protected with Supabase authentication and database/storage access policies, but no online service can promise zero risk.

Retention, access, and deletion

The Settings page can record an account-deletion request in the account database. Submitting this request does not immediately delete the account or uploaded files and does not trigger an email or automated processing. An authorized operator must review and process it through secure administrative tools; a public contact address and retention/deletion process, including backup handling, remain to be provided before public signup. The draft notice is not a substitute for that process.

This draft was prepared from the current product behavior, not from legal advice. Operator contact and production publication checklist remain outstanding.