Privacy
What we collect, where it lives, and how to make us delete it.
Lynceus reads company careers pages and matches what it finds against your CV. That needs your CV, so this page explains exactly what happens to it. Most of our users are in the EU, so we have written this to the GDPR's standard whoever you are.
What we collect
Your account. An email address, and either a password (stored only as a hash, never in a form we can read) or a Google account identifier if you signed in that way.
Your CV. You upload a file; we extract the text from it and parse that into structure — job titles, skills, years. The uploaded file itself is not kept. It is read in memory and discarded once the text is out. We store the extracted text and the parsed structure, because those are what matching actually reads. There is no file of yours on any storage bucket, because we do not use one.
What you do here. Searches you run, the roles you save or dismiss, applications you track, and your chat threads with the search agent. Saved so the product works on your second visit rather than starting over.
We do not ask for, and have no use for, your address, your phone number, your date of birth, or any of the special categories the GDPR treats separately — health, ethnicity, religion, politics. If your CV happens to contain something in that last group, it lands in the extracted text along with everything else; we do not seek it out or act on it.
Where it is stored
In one PostgreSQL database, on a server we rent and administer in the EU. Not in a third-party data warehouse, not in an analytics product, and not on object storage — there is no second copy in another provider's system to reason about.
Who else processes it
Two AI providers, acting as processors on our instructions: OpenAI and Groq. They receive the text of your CV when it is first parsed, and job descriptions plus your search terms when matching and drafting run. They do not receive your email address, your password, or your application history.
This is worth being plain about, because it is the one place your CV text leaves our server. We use their standard API endpoints, which are not used to train their models. If that is not acceptable to you, do not upload a CV — the rest of the product works without one.
Beyond those two: an email provider, to send you the mail you ask us to send. That is the whole list. We have no advertising partners and no data buyers, and we do not sell or rent anything about you to anyone.
Cookies
One cookie: refreshToken, which keeps you signed in. It is HttpOnly and Secure, so no script on the page can read it, and it exists purely so you are not logged out every fifteen minutes.
There are no advertising cookies, no analytics cookies, and no third-party trackers on this site or in the app. Nothing here is measuring you for anyone else's benefit, which is also why you have not been shown a consent banner — we have nothing to ask consent for.
The app also keeps one item in your browser's local storage: the id of a search that is still running, so a page refresh does not lose it. It never leaves your browser.
Security
Everything between you and us travels over TLS, and so does everything between us and the AI providers. Passwords are hashed. Access to the server is restricted to key-based administrator login.
We would rather be exact than reassuring: the database is protected by those access controls rather than by database-level encryption at rest. If that matters to your decision, it should be a fact you have rather than one you assume.
How long we keep it
Your account data stays until you ask us to delete it. If an account goes unused for two years we will delete it, after writing to the address on it first.
Job listings are not personal data and are kept as long as they are useful. Server logs, which contain IP addresses, are kept for 30 days for debugging and abuse handling, then rotated out.
Your rights
Under the GDPR you can ask us to:
- Show you what we hold — a copy of your account, CV text, parsed profile and activity.
- Correct it — your parsed profile is editable in the app; anything else, ask.
- Delete it — your account and everything attached to it.
- Take it elsewhere — the same copy, in a machine-readable format.
- Object, or withdraw consent — including deleting your CV while keeping the account.
Deletion is currently done by asking us rather than by pressing a button: email privacy@trylynceus.com from your account address and we will remove your account, your CV text, your parsed profile and your activity within 30 days, and confirm when it is done. We are building the self-service version; until it exists we are not going to claim it.
If you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first.
Early access
Lynceus is in early access and changing weekly. If we change how your data is handled in a way that matters, we will email account holders rather than quietly editing this page and hoping nobody re-reads it.
Contact
privacy@trylynceus.com for anything on this page.