Privacy Policy

Last updated: March 20, 2026

1. Introduction

Tuelio ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at tuelio.com and related services.

2. Information We Collect

Account information: When you register, we collect your email address, name, and optionally a profile photo. If you sign in with Google or LinkedIn, we receive your public profile information from those providers.

CV content: The personal and professional information you enter into your CVs (work experience, education, skills, etc.) is stored securely in our database.

Payment information: Payment processing is handled entirely by Stripe. We do not store your credit card details. We receive your subscription status and billing history from Stripe.

Usage data: We collect anonymized usage analytics (page views, feature usage) through PostHog. We track AI feature usage (token counts) to enforce plan limits.

Technical data: IP address, browser type, device type, and operating system — collected automatically for security and performance monitoring.

3. How We Use Your Information

  • To provide and maintain the Tuelio platform
  • To generate and render your CVs as PDFs
  • To power AI features (your CV content is sent to Anthropic's Claude API for AI-assisted writing and optimization)
  • To process payments and manage subscriptions via Stripe
  • To send transactional emails (account confirmation, password reset, billing receipts)
  • To improve our product through anonymized analytics
  • To enforce usage limits and prevent abuse

4. Third-Party Services

We use the following third-party services that may process your data:

  • Supabase — Authentication, database, and file storage (hosted in EU)
  • Anthropic (Claude API) — AI-powered CV writing and optimization. CV content sent to Claude is not used to train their models.
  • Stripe — Payment processing and subscription management
  • Vercel — Web application hosting
  • PostHog — Product analytics (anonymized)
  • Sentry — Error monitoring

5. Data Retention

We retain your account data and CV content for as long as your account is active. When you delete your account, all associated data (profile, CVs, subscription records, AI usage logs, uploaded files) is permanently deleted from our systems within 30 days.

6. Your Rights

You have the right to:

  • Access your personal data — export all your data as JSON from Settings
  • Rectify inaccurate data — edit your profile and CVs at any time
  • Delete your data — delete your account from the Profile page
  • Port your data — download all your data in a machine-readable format
  • Object to processing — contact us to opt out of specific processing activities

7. Security

We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, secure authentication via Supabase Auth, and regular security audits. All payment data is handled by PCI-compliant Stripe infrastructure.

8. Cookies

We use essential cookies for authentication and session management. Analytics cookies (PostHog) are used to understand how the platform is used. You can disable non-essential cookies in your browser settings.

9. Contact

For privacy-related questions or to exercise your data rights, contact us at privacy@tuelio.com.