Last updated · version 2026-07-26

Privacy Policy

This policy explains what areito does with your personal data. It covers the whole service at areito.me.

The short version: we collect what the service needs to work, we share it with three suppliers who help run it, we never sell it or hand it to advertisers, and you can delete all of it yourself at any time.

Who is responsible

areito is the data controller for your personal data. For anything in this policy — questions, requests, complaints — contact privacy@areito.me.

What we collect

Account details

Your email address, your chosen username, and your password, which is stored only as a one-way hash that cannot be reversed back into the password. We also keep timestamps: when the account was created, when you last used it, when your email address was verified, when you last changed your password, and when you accepted our terms and which version.

Profile content

Whatever you choose to enter, which for a CV is usually a lot: your name and professional title, a summary, a photograph, your nationality and any work permits, your contact email and phone number, your street address, postcode, city and country, links to your social profiles, and the substance of your career — roles, employers, dates, education, skills, languages, projects, publications, presentations, awards, certificates, courses, memberships, volunteering, interests, blog posts, referees, and recommendations.

Almost all of this is optional. Only your email address and username are actually required. If you would rather your home address were not in our database, leave it out — a CV rarely needs one.

Files you upload

Images and documents you upload, plus the smaller preview copies we generate from images automatically.

Documents you send to CV import

If you use CV import, the CV you upload is processed to extract its contents. See "Who we share data with" below — this is the one feature that sends your data outside our own systems.

Technical data

Our server records requests it receives: the IP address, the time, the page or API path, the response status, and the browser's user-agent string. This is ordinary server logging, and it is also how we enforce rate limits that stop one person from hammering the service — those limits are keyed to your account when you are logged in, and to your IP address when you are not.

Analytics

We run our own analytics on our own server. It records the page visited, the referring site, rough screen size, and a country derived from the IP address, which is not stored. It sets no cookies, assigns you no identifier, and cannot follow you to any other website. We use it to see which parts of the service get used, nothing more.

Cookies and local storage

We use no tracking or advertising cookies. To keep you signed in, the site stores login tokens in your browser's local storage; this is strictly necessary for the service to function, and clearing your browser data signs you out.

Why we are allowed to use it, legally

  • To perform our contract with you — running your account, storing your profile, generating CVs, and serving your published portfolio. Without this data there is no service to provide.
  • Our legitimate interests — keeping the service secure and available, preventing abuse, taking backups, and understanding usage through the privacy-preserving analytics described above. We have weighed these against your privacy and kept the data involved to a minimum.
  • Legal obligations — where we must retain or disclose something by law.

Who we share data with

We do not sell your personal data, share it with advertisers or data brokers, or use it to train machine-learning models. It goes to three suppliers who process it on our instructions, and nowhere else:

  • Hostinger — hosts the server the service runs on, and sends our transactional email (address verification, password resets, invitations). All of your data sits on infrastructure they provide.
  • Anthropic — only when you use CV import. The document you upload is sent to Anthropic's API, where a Claude model reads it and returns structured data. Anthropic processes API data on our behalf, does not use it to train its models, and retains it only briefly for abuse monitoring. If you would rather no third party saw your CV, do not use CV import — enter your details manually instead. Every other feature works without it.
  • Our backup storage provider — a cloud object-storage service that holds the encrypted-in-transit daily backups described below.

We may also disclose data where the law compels us to, or where it is necessary to establish or defend a legal claim.

Transfers outside the UK

Anthropic is based in the United States, so a CV you send to CV import is processed there. That transfer relies on the safeguards UK and EU data protection law requires for international transfers — standard contractual clauses in Anthropic's data processing terms. Everything else stays on European infrastructure.

What becomes public

Your portfolio is private until you publish it. When you do, the sections you have chosen to show become visible to anyone with the link, without logging in, and search engines may index and cache them.

That cached copy is the part worth understanding: once a page has been public, unpublishing removes it from our servers but cannot remove it from third-party caches and archives, which are outside our control. Please decide with that in mind what belongs on a public page — we would suggest not your home address or phone number.

How long we keep it

  • Your account and profile — until you delete them. We do not expire idle accounts.
  • After you delete your account — your profile, uploads, and published pages are removed from the live service immediately and permanently. There is no recycle bin and we cannot restore them.
  • Backups — we back up the database and uploaded files once a day to off-site storage, and each backup is deleted 30 days after it is made. So for up to 30 days after you delete your account, your data still exists in backups we hold but do not use. It then disappears as those backups age out. We restore from a backup only to recover from a failure, never to bring back a deleted account.
  • Server logs — no longer than 30 days.
  • Verification and password-reset links — the stored token expires within hours and is discarded once used.
  • Analytics — aggregate counts only, with nothing that identifies a person.

Your rights

Under UK GDPR — and EU GDPR if you are in the EU — you can ask us to:

  • Give you a copy of the personal data we hold about you, in a portable format. Your profile is exportable from the app at any time without asking us.
  • Correct anything inaccurate. You can edit your profile directly.
  • Delete your data. Deleting your account does this in full; ask us if you want anything else erased.
  • Restrict or object to our processing of it.
  • Object to processing we base on legitimate interests, as described above.

Email privacy@areito.me and we will respond within one month. There is no charge.

If you are unhappy with how we have handled your data you can complain to the UK's Information Commissioner's Office at ico.org.uk. If you are in the EU, you may complain to your own country's data protection authority instead. We would appreciate the chance to put things right first.

Data about other people

Profiles often contain other people's details — a referee's phone number, a named recommendation. If you are in there because someone else put you there and you want it removed, email privacy@areito.me and we will deal with it, whether or not you have an account.

How we protect it

Traffic is encrypted in transit with HTTPS. Passwords are stored as bcrypt hashes, never in a readable form — we could not tell you your password if you asked. Changing your password invalidates every existing session. Publishing, CV import, and uploads require a verified email address. Uploads are size- and type-checked before being stored. No system is perfectly secure, but data is kept to the minimum the service needs.

If something goes wrong

If a breach occurs that is likely to affect your rights, we will tell you without undue delay, describe what happened and what data was involved, and notify the Information Commissioner's Office within 72 hours as the law requires.

Children

The service is for working professionals and is not intended for under-16s. We do not knowingly collect their data; tell us if you believe we have.

Changes to this policy

If we change this policy substantively we will publish it with a new date and notify account holders by email or in the app. We will not quietly start using your data for something this policy does not describe.


Questions about either document? Email privacy@areito.me.