Privacy Policy

Last updated: 29 August 2026

1. What we collect

When you use atspass.com to analizar a CV, we collect the following data for the sole purpose of performing the analysis:

  • The text of your CV. The PDF or DOCX file you select is read locally in your browser and is never uploaded; only the extracted text is sent for analysis.
  • The job description text you provide
  • Your IP address (for rate limiting only)
  • Your email address (if you purchase credits or use paid analysis)

2. How we use your data

  • CV text & job description -sent to a third-party AI service to generate your ATS compatibility analysis. The data is processed in memory and is not stored on our servers after the request completes. The CV file itself never reaches our servers.
  • IP address -stored temporarily in an in-memory cache for up to one hour to enforce a rate limit of 5 analyses per hour. It is not written to disk or shared with third parties.
  • Email & credit balance -if you purchase credits, your email address and credit balance are stored in our database to track your remaining analyses.

3. Third-party processing

Your CV text and job description are sent to a third-party AI service for analysis. This provider processes data under their own privacy policy and data processing terms. If you would like details about our AI provider, please contact us.

Payments are processed by Stripe, a PCI-compliant payment processor. We do not store your card details. Stripe’s privacy policy applies to all payment transactions.

4. Data retention

We do not persist your CV, job description, or analysis results. All data is held in server memory only for the duration of the request and is discarded immediately after. Rate-limit records (IP address and request count) are held in memory for up to one hour and are lost on server restart.

If you purchase credits, your email address and credit balance are stored persistently in our database. Transaction records (purchase and usage) are also retained for accounting purposes.

5. Analytics

atspass.com uses Vercel Web Analytics to collect aggregate usage statistics such as page views, referrer, and general geographic region. It is cookieless: it sets no cookies on your device and assigns you no persistent identifier. Visitors are counted using a hash derived from the incoming request, which is rotated daily and cannot be used to follow you across sites or between visits.

We also record product events, so that we can see where the product works and where people give up: that a CV was selected or could not be read, that a job description was supplied, that an analysis was started, completed, or failed, that an upgrade prompt was shown or clicked, and that a document was downloaded.

Each is tagged with whether the visitor was on the free or paid tier, and with a plain descriptor where one is useful: the file extension (“pdf”), a reason code for a file we could not read (“scanned PDF”), and which part of the page a button sat in. Never the CV itself, its file name, the job description, your email address, or anything taken from them. These events are not tied to you.

  • We do not use analytics data for advertising or remarketing.
  • No personal data (such as your CV content, email address, or job description) is sent to our analytics provider.
  • Because our analytics provider sets no cookie and no identifier, there is nothing to opt out of. Blocking the script in your browser or an ad blocker prevents collection entirely.

Separately from the analytics provider, our own database keeps a dated record that an analysis ran, that one was refused for exceeding the free daily limit, and that a checkout was started, along with the number of tokens the AI models processed — which is how we know what a single analysis costs us to run. Free analyses are recorded with no identifier at all. They do carry one further number: how many analyses your browser has completed before this one, so that we can tell how many people run a single analysis from how many come back and refine. It is a count, not a name. Everyone at the same point in their own history sends the same number, it cannot be joined to any other record of yours, and it is capped so that a high count cannot become distinguishing on its own. A paid analysis and a checkout are recorded against the email address the credits belong to, because that is the address the balance is held under. Your CV and job description are not part of these records.

That count is kept by your browser, not by us. Alongside it your browser stores the scores of your recent analyses and a fingerprint of the job description, so that the results page can show you how a score has moved and only ever compares two analyses of the same job. All of it lives in your browser’s local storage on your own device, none of it is readable by another site, and clearing your site data deletes it. Neither your CV nor the job description itself is ever stored there.

Payment is handled via Stripe Checkout, which is an external redirect and does not set cookies on our domain.

6. Your rights

Under the UK GDPR and EU GDPR you have the right to:

  • Access -request confirmation of whether we process your personal data and obtain a copy.
  • Erasure -request deletion of your personal data. Because we do not store data beyond the request, there is nothing to delete, but you may still make a formal request.
  • Restriction & objection -object to or restrict processing of your data.
  • Portability -receive your data in a structured, machine-readable format.
  • Withdraw consent -you may withdraw your consent at any time by simply not submitting further analyses.

To exercise any of these rights, please contact us.

7. Lawful basis

We process your data on the basis of consent(GDPR Art. 6(1)(a)). You provide consent by clicking the “Puntúa mi CV” button to submit your CV for analysis. You may withdraw consent at any time by simply not submitting further analyses.

8. Security

All data is transmitted over HTTPS. CV text is sanitised on the server before being sent to the AI model. We do not store personal data on disk, reducing the risk surface of a data breach.

9. Browser extension

The ATS Pass browser extension is designed to keep your CV entirely on your own device. It works differently from the website:

  • Local storage only -the CV you save in the extension (uploaded PDF/DOCX or pasted text) is stored solely in your browser via chrome.storage.local. It never leaves your device and is never sent to our servers.
  • Local processing -the keyword match runs entirely in your browser. There is no AI, no server, and no network request involved in the match.
  • No collection -the extension does not collect, transmit, or sell any personal data, and it requires no account or sign-up.
  • Reading the job posting -when you click the extension icon, it reads the job description from the tab you are viewing in order to compare it against your saved CV. This text is processed locally and is not transmitted by the extension.
  • Handoff to atspass.com -if you choose to run a full analysis, the extension copies the job description to your clipboard and opens atspass.com. Any data you then submit on the website is covered by the sections above.

The extension requests only the permissions needed for this: access to the active tab to read the current job posting, local storage to save your CV, and clipboard access to hand the job description off to the website.

10. Changes to this policy

We may update this policy from time to time. The “last updated” date at the top of this page reflects the most recent revision.

11. Contact

If you have questions about this privacy policy or want to exercise your data rights, please reach out via our contact page.