Rtbha· رتبها

Privacy policy

Last updated 2026-05-04

This Privacy Policy explains what information Rtbha ("we", "us") collects when you use the service, how we use it, and the choices you have. We try to keep this short and concrete.

What we collect

Account data. When you sign in, we store your email address (used for the magic-link login) and a unique account identifier in our database. We do not collect a password — authentication is via single-use email links only.

Resume content. When you upload a resume, the file is stored in our object storage (Cloudflare R2) and the parsed structured profile is stored in our database (MongoDB). The original file is deleted automatically when you replace your resume or delete your account.

Job descriptions. Job descriptions you paste or fetch are stored alongside the analyses you create. They remain accessible only to you.

Generated artifacts. Tailored CVs, cover letters, and interview prep packs you generate are stored in our object storage so you can re-download them. They are deleted when you delete the analysis or your account.

Usage events. We record cost and model metadata for each AI call (without storing the prompt or response content) so we can enforce monthly cost limits. We never store the body of your resume or job descriptions in usage logs.

Cookies. We set one essential cookie for authentication (the session token). When you visit a public page that displays advertising, we may also set advertising cookies subject to your consent.

What we do with it

  • Run the AI pipelines that produce your analyses and artifacts.
  • Display your history and settings to you.
  • Enforce per-account rate limits and the monthly cost cap.
  • Send you the magic-link sign-in email via SMTP2GO.

We do not sell your data. We do not share resume content, job descriptions, or generated artifacts with anyone other than the third-party processors listed below, who act on our behalf.

Third-party processors

  • MongoDB — primary database for accounts, resumes, analyses.
  • Cloudflare R2 — object storage for uploaded resumes and generated artifacts.
  • SMTP2GO — sends authentication and password-reset emails.
  • Anthropic, Google AI, DeepSeek — process the text content of your resume and job descriptions to produce analyses. These calls do not include your email address; we send only the content needed for the specific pipeline.
  • Upstash Redis — sliding-window rate limiting (does not store content).

Each of these is bound by their own privacy commitments and contracts. We send only the data they need to perform the specific function, and we delete inputs as soon as the response is received.

Data retention

  • Account, resume, and analysis data is retained until you delete it via the Settings page.
  • Authentication tokens expire 10 minutes after issue.
  • Magic-link tokens expire 10 minutes after issue.
  • Usage events are retained for 90 days for cost tracking.

When you delete your account, we delete your account record, all uploaded resumes, all analyses, all generated artifacts, all skill explanations, and all usage events on a best-effort basis. Some operational logs may persist for up to 30 days.

Your rights

You can:

  • Access all data we hold about you via the dashboard, history, and settings pages.
  • Replace your resume or generated artifacts at any time.
  • Delete your account and all associated data via Settings → Delete account.
  • Contact us at the email below for any request that the in-product flows don't satisfy.

If you are in the EU/UK and want to exercise rights under GDPR (access, rectification, deletion, portability, restriction, objection), email us; we'll respond within 30 days.

Children

The service is not directed at users under 16. We don't knowingly collect data from anyone under that age.

Changes to this policy

We may update this policy. The "Last updated" date at the top reflects the most recent change. If we make a change that materially reduces your rights, we will notify users by email at the address on file.

Contact

For privacy questions, write to privacy@rtbha.com (replace with the production address you publish).