Legal
Privacy Policy
Last updated: 28 mai 2026
1. Data controller
The controller of personal data is ProfilUp, publisher of the service available at profilup.co.
DPO contact: contact@profilup.co
2. Data we collect
We collect the following data depending on how you use the Service:
2.1 Account data
- Last name, first name, email address (upon registration)
- Google identifier (sign-in via Google OAuth)
- Profile photo and LinkedIn identifier (if you link your LinkedIn account from the dashboard)
- Registration date and last login date
2.2 LinkedIn profile data
- Professional headline, summary, work experience, skills, education
- This data is provided by you, either directly or via import
- It is not retained beyond the time needed for optimization, unless you save it to your dashboard
2.3 Usage data
- Results of analyses and generated scores
- Optimization history (retained in your account)
- Subscribed plan and payment history (excluding banking data)
2.4 Technical data
- IP address, browser type, operating system
- Pages visited and session duration (via server logs)
- Theme preference (stored locally in your browser)
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provision of the optimization service | Performance of contract |
| Account management and authentication | Performance of contract |
| Payment processing (via Stripe) | Performance of contract |
| Sending transactional emails | Performance of contract |
| Service improvement and statistics | Legitimate interest |
| Marketing communications (if consent given) | Consent |
| Compliance with legal obligations | Legal obligation |
4. Sub-processors and transfers
We use the following sub-processors, with whom we have signed GDPR-compliant data processing agreements:
- Supabase — database hosting and authentication (servers located in the EU)
- Stripe — payment processing (PCI-DSS certified, transfers to the United States governed by standard contractual clauses)
- Anthropic / OpenRouter — AI processing of profile text (data submitted is not used to train the models)
- Vercel — application hosting (global CDN, data processed in the EU for European users) and anonymous audience measurement (Vercel Analytics, no cookies or individual identifiers — exempt from consent under CNIL recommendations)
- PostHog — product analytics (usage events such as "optimization started", "job scan performed") hosted on PostHog's European instance (Frankfurt, Germany). No cookies or local storage are used, IP addresses are not collected, and cross-site tracking is disabled. Legal basis: legitimate interest (service improvement).
- Enrichlayer — public extraction of LinkedIn profile data when you provide a LinkedIn URL. Only publicly accessible data from your profile is retrieved.
- Firecrawl — extraction of content from public job postings (LinkedIn, Indeed, Welcome to the Jungle, careers sites) when you provide us with a job posting URL.
- Adzuna — aggregator of public job listings used for the Job Radar and Spontaneous Applications features. No personal data is transmitted to Adzuna.
- Upstash (Redis) — rate limiting (anti-abuse) on API calls. Temporary storage of your hashed IP address for a few minutes.
No personal data is sold to third parties.
5. Data retention period
- Active account data: retained for the entire duration of the account
- Data after account deletion: deleted within 30 days
- Billing data: 10 years (legal accounting obligation)
- Technical logs: 12 months maximum
- Browsing session data: 90 days
6. Your rights (GDPR)
In accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679), you have the following rights:
- Right of access — obtain a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data
- Right to data portability — receive your data in a structured format
- Right to object — object to processing for marketing purposes
- Right to restriction — request temporary suspension of processing
- Right to withdraw consent — at any time, with no retroactive effect
To exercise these rights, contact us at contact@profilup.co. We will respond within a maximum of 30 days.
You also have the right to lodge a complaint with the CNIL (the French Data Protection Authority).
7. Cookies and local storage
ProfilUp uses minimal storage:
- Supabase session cookies — necessary for authentication, expire when the session ends
- localStorage — theme — stores your light/dark preference locally in your browser, with no transmission to our servers
- localStorage — optimization profile — temporary backup of the analyzed profile (resume text or LinkedIn data) to prevent data loss in case of accidental navigation. Stored only in your browser.
- localStorage — application tracker — locally stores the list of jobs added to your Kanban board and dismissed applications, so you find them again on your next visit. No data is sent to the server.
Audience measurement (Vercel Analytics) — We use Vercel Analytics to count page views and traffic sources in a strictly anonymous manner. This tool does not set any cookies, does not create any individual identifier, and does not allow tracking a visitor across sessions or sites. It is exempt from consent requirements under CNIL recommendations regarding exempt audience-measurement tools (Article 82 of the French Data Protection Act).
Product analytics (PostHog) — We use PostHog (European instance, Frankfurt) to understand which features are used and to detect production errors. The configuration in place ensures:
- no cookies or local storage set on your browser (in-memory persistence only)
- no collection of IP addresses
- no session recording (session replay disabled)
- no automatic capture of clicks or input (autocapture disabled)
- respect for the "Do Not Track" signal sent by your browser
When you are signed in, your actions (optimization started, job scan, letter generated, payment) are linked to your account identifier to measure service performance. You can disable this measurement at any time using the button below — your choice is stored locally in your browser:
We do not use advertising cookies, third-party marketing trackers, or individualized behavioral analytics tools such as Google Analytics.
8. Security
We implement appropriate technical and organizational measures to protect your data:
- TLS/HTTPS encryption on all communications
- OAuth 2.0 authentication via Google, or a magic link sent by email (your credentials never pass through our servers)
- Database-level security rules (Supabase Row Level Security)
- Data access limited to employees who need it
- No storage of banking data (delegated to Stripe, PCI-DSS certified)
9. Minors
The Service is intended for individuals aged 16 and over. We do not knowingly collect data concerning minors under 16. If you are a parent and believe your child has provided us with data, please contact us at contact@profilup.co.
10. Changes to this policy
We may update this policy as the Service or applicable regulations evolve. Any substantial change will be notified to you by email or via a notice banner on the Service, at least 7 days before it takes effect.
11. Contact
For any question regarding this policy or your personal data:
- Email: contact@profilup.co