Privacy Policy
How Kitsuno handles your data. GDPR compliant, zero tracking, full transparency.
Last updated: March 20, 2026 · Effective immediately
The short version: Kitsuno collects only what's needed to run your job search. We don't track you, don't sell your data, don't show ads, and don't use your career data to train AI models. You can export or delete everything at any time.
1. Who we are
Kitsuno is operated by SF4L S.R.L., a company registered in Romania (CUI 49409572, J2024000638403), with its registered office at Șoseaua Nicolae Titulescu Nr. 10, Bl. 20, Sc. A, Et. 9, Ap. 41, Sector 1, București, Romania.
For any privacy-related questions, contact us at hello@kitsuno.ai.
2. What data we collect
2.1 Account data
When you create an account, we collect your email address, name, and authentication credentials. If you sign in via a third-party provider (Google or LinkedIn), we receive your name and email from that provider.
2.2 Career data (your "career library")
You provide this voluntarily to power your job search:
- Work experience, education, skills, and certifications
- Uploaded CVs, work examples, testimonials, and other evidence
- Job search preferences: target roles, keywords, locations, work modes
- Search profile configurations and scoring weights
Your career data belongs to you. We process it solely to operate your job search. We never sell it, share it with advertisers, or use it to train AI models.
2.3 Job search activity
As Kitsuno operates your job search, we store:
- Jobs found, scores, and match details
- Generated documents (CVs, cover letters, emails)
- Application status and follow-up actions
- Conversations with Kitso (your AI career agent)
2.4 Waitlist data
If you join the waitlist before creating an account, we collect your email address, IP address (for abuse prevention), and any UTM parameters from the referring link.
2.5 Technical data
We store minimal technical data required for security and operations: IP addresses in server logs (retained for 30 days), user agent strings, and login timestamps.
2.6 What we don't collect
Kitsuno does not use cookies for tracking. We do not use analytics services. We do not embed tracking pixels, social media widgets, or advertising scripts. The only browser storage we use is localStorage for your light/dark theme preference.
3. Why we process your data (legal basis)
| Purpose | Legal basis (GDPR) |
| Operating your job search and generating applications | Contract performance (Art. 6(1)(b)) |
| Account creation and authentication | Contract performance (Art. 6(1)(b)) |
| Email notifications and digests | Contract performance (Art. 6(1)(b)) |
| Waitlist registration | Consent (Art. 6(1)(a)) |
| Security, fraud prevention, abuse detection | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
4. Third-party processors
We use a limited number of third-party services to operate Kitsuno. Each processes only the minimum data required for its function:
| Service | Purpose | Data processed | Location |
| Hetzner | Server hosting | All application data (encrypted at rest) | Germany 🇩🇪 |
| OVHcloud | AI scoring & extraction | Job descriptions, anonymized profile context | France 🇫🇷 |
| Nebius | AI document generation, chat & scoring | Career context for document generation, chat messages, job descriptions | Finland 🇫🇮 (EU) |
| Groq | AI inference fallback & voice transcription | Career context, chat messages, voice audio | United States 🇺🇸 * |
| Resend | Email delivery | Email address, message content | United States 🇺🇸 * |
| Telegram | Push notifications (opt-in) | Telegram user ID, notification content | Various |
| Google Fonts | Typography | IP address (standard web request) | United States 🇺🇸 * |
| ElevenLabs | Voice synthesis (interview coaching) | Text to be spoken (career context) | United States 🇺🇸 * |
| Creem | Payment processing (Merchant of Record) | Email, subscription tier, payment metadata | Estonia 🇪🇪 |
| SambaNova, Cerebras, Cloudflare | AI inference (scoring cascade) | Job descriptions, anonymized profile context | United States 🇺🇸 * |
| Cloudflare CDN | JavaScript library delivery | IP address (standard web request) | United States 🇺🇸 * |
* International transfers: Where data is processed outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or the service provider's adequacy certification. Groq, Resend, ElevenLabs, SambaNova, Cerebras, and Cloudflare process data under SCCs. Creem operates under EU jurisdiction (Estonia). Nebius processes data in Finland (EU) with zero-retention inference and SOC 2 Type II / ISO 27001 certification. We are evaluating self-hosting fonts to eliminate this third-party dependency.
5. AI processing
Kitsuno uses AI models to score job matches, generate tailored documents, and power the Kitso career agent. Important details:
- No model training: Your data is never used to train or fine-tune AI models. All AI calls are inference-only.
- Context isolation: Each AI request contains only the context needed for that specific task. Your full career library is never sent in a single request.
- Human review: All AI-generated documents (CVs, cover letters, emails) require your review and approval before any action is taken.
- Transparency: Every AI action is logged. You can track each job through every stage — from discovery and scoring to drafting and application — and see what Kitso did and why.
6. Data retention
| Data | Retention |
| Account & career data | Until you delete your account |
| Generated documents | Until you delete them or your account |
| AI conversation history | Until you delete it or your account |
| Server logs (IP, user agent) | 30 days |
| Waitlist entries | Until beta launch or upon request |
| Deleted account data | Immediately and permanently removed |
7. Your rights
Under the GDPR, you have the following rights. To exercise any of them, email hello@kitsuno.ai. We respond within 30 days.
- Access — Request a copy of all data we hold about you
- Rectification — Correct inaccurate data
- Erasure — Request deletion of your data ("right to be forgotten")
- Portability — Export your career library in machine-readable format (JSON)
- Restriction — Request we limit processing of your data
- Objection — Object to processing based on legitimate interest
- Withdraw consent — Where processing is based on consent (e.g. waitlist), withdraw at any time
You also have the right to lodge a complaint with the Romanian data protection authority (ANSPDCP) at www.dataprotection.ro.
8. Data export & deletion
You can export your entire career library, configuration, and application history at any time from your dashboard in JSON format. To delete your account and all associated data, use the account settings page or email us. Deletion is immediate and permanent.
9. Security
We protect your data with encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. Our infrastructure is hosted on dedicated servers in Germany with no shared tenancy.
10. Children
Kitsuno is designed for professionals and is not directed at anyone under 16. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email to registered users. The "last updated" date at the top reflects the most recent revision.