This policy explains what TrackMyself collects, why we collect it, who else can see it, and how to get it back or deleted. It describes what the software actually does, not what we might do one day.
TrackMyself operates TrackMyself and decides how your data is handled — in data protection terms, we are the controller. For any privacy question or request, write to privacy@trackmyself.app.
Account details. Your name, email address, and either a password (stored only as a bcrypt hash — we never see the original) or a Google account identifier. If you sign in with Google we also store the profile picture URL Google gives us. We record your role and plan.
Application records. Whatever you enter about the jobs you apply for: company, role, platform, status, dates, salary, contact details, job post links, notes, and any attachments you add.
Interview records. Stage names, statuses, scheduled dates, feedback and notes.
CV profile. The details you enter in the CV builder. Depending on which formats you use, this can include your address, date of birth, nationality and photograph, because the Europass and Lebenslauf formats expect them. These fields are optional — the ATS CV never prints them.
Documents you upload. CVs, resumes, cover letters, certificates, a profile picture and a cover image. These are stored in our database.
Technical data. Standard server and hosting logs, including IP address and browser type, kept for security and troubleshooting.
We do not sell your personal data, and we do not use it to train AI models.
We use a small number of service providers. They act on our instructions and may not use your data for their own purposes.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel Inc. | Application hosting and content delivery | Request logs, IP address |
| MongoDB Atlas | Database hosting | All account and application records |
| Google LLC | Optional sign-in with Google | Name, email address, profile picture |
| Anthropic PBC | AI CV tailoring and banner drafting (Premium, on request only) | The CV text and job description you submit for that request |
| Google LLC (Gemini API) | Fallback AI CV tailoring when the primary provider is unavailable (on request only) | The CV text and job description you submit for that request |
| Hugging Face | Delivers the background-removal model file to your browser | None — the model is downloaded to you; your images are never sent |
Content you send to the AI features is used to answer that one request. It is not used to train models.
Your applications and documents are private to your account. Other ordinary users cannot see them.
Administrative roles exist so the platform can be maintained. Accounts with editor, administrator or superadministrator permissions can see application records across the platform, and can see which users hold CV documents together with counts and storage sizes. Administrators can change a user's role or plan, and can edit or delete application records. Permissions are configurable, and every administrative action is checked on the server.
We set no advertising or analytics cookies, which is why you are not asked to consent to any.
Account and application data is kept while your account exists. There is no automatic expiry and we do not delete inactive accounts on your behalf.
Pausing. You can put your account on hold from your profile page. Pausing freezes application tracking — nothing can be added or edited — while leaving every record readable and the CV builder, document library and browser tools working. Pausing deletes nothing and changes nothing about what we hold; it is a state you can leave again with one click. An administrator can also pause an account where the service is being misused.
Deletion. You can erase your account yourself, at any time, from your profile page — no request to us, no waiting period. You confirm by typing DELETE and, if your account has a password, by entering it. This removes the account record together with every application, interview record, reminder, CV profile and uploaded document attached to it, in a single operation. It is immediate and cannot be undone, so export anything you want to keep first. Superadministrator accounts are the one exception and must be removed by another superadministrator, because self-deletion would lock the platform. An administrator deleting an account from the dashboard erases the same records.
Backups and server logs may retain copies for a short period before they age out.
Depending on where you live, you may have the right to:
Much of this you can do yourself: edit or delete any application, remove any uploaded document, export your CV as a Word file, pause your account, or delete the account and everything in it from your profile page. For anything else, email privacy@trackmyself.app and we will respond within 30 days.
Passwords are hashed with bcrypt and never stored in readable form. Sessions use signed tokens. Every route that returns your data checks your identity on the server and scopes the query to your account.
No service can promise perfect security. Use a strong, unique password, and be careful about the personal detail you put into free-text notes.
Our hosting and database providers operate globally, so your data may be processed outside your country. Where data protection law requires it, transfers rely on the appropriate safeguards those providers offer, such as standard contractual clauses.
TrackMyself is not intended for anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
If this policy changes we will update the date at the top of the page, and give notice in the service where the change materially affects you. Our Terms & Conditions apply alongside this policy.
Questions about this document? Write to hello@trackmyself.app. Read this alongside our Terms & Conditions and Privacy Policy.