Privacy policy
Last updated 4 October 2026
Clever Candidate keeps your job search in one place. This page explains which personal data it stores, why, for how long, and what your rights are. In short: we store what you put in so the app can work for you. We don't sell your data or use it for advertising, and there are no tracking or advertising cookies.
Who is responsible
The operator of this installation hasn't entered their name and address yet (settings LEGAL_NAME, LEGAL_ADDRESS and LEGAL_EMAIL).
Write to this address with any question about your data.
Your account
When you sign up we store your name, your e-mail address and your password. The password is stored only as a hash (bcrypt), so nobody can read it, not even us. We also store your workspace and role, when you signed up and last logged in, and whether you confirmed your e-mail address.
Why: to give you your account (Art. 6(1)(b) GDPR).
Your CV, jobs and files
Clever Candidate stores what you enter: personal details for your CV (which may include a photo, your address, date and place of birth and nationality), work history, projects, education, certificates, languages and skills; letter templates and files you upload; the jobs you save, with their status, notes, reminders and history; and the companies you apply to. When you save a job from a link, our server fetches that page to read the posting.
Why: this is the service you use (Art. 6(1)(b) GDPR). Photo, birth date and nationality are optional: add only what you want employers to see.
Who sees it: only you. If you belong to a workspace, for example of a career service, its owners and admins see your name, e-mail address, role, when you last logged in, and how many jobs you saved, applied for and got interviews for, but not the jobs, CV, letters or files themselves. Platform administrators can look at your account to help you when you ask for support.
E-mails you send through Clever Candidate
When you apply by e-mail, we store the e-mail (recipients, subject, text and the names of the attached files) with the job, so you can see what you sent. It goes out through your own mailbox if you connected one (we store its password encrypted), or else through our mail server, with your name as the sender and replies going to you.
To stop misuse of our mail server, we count e-mails per sender and recipient. For that we keep a fingerprint (hash) of each recipient's address, not the address itself, for 8 days. Every e-mail names its sender and lets the recipient refuse further e-mails sent through Clever Candidate; refusals are kept as a fingerprint, too. If an e-mail can't be delivered, we read the delivery report from our mailbox to tell you why. Delivery reports are kept for up to a year.
Why: to send your applications (Art. 6(1)(b) GDPR) and to protect recipients and our mail server from spam (Art. 6(1)(f) GDPR). The people you write to receive your e-mail and files; we use their address only to deliver it.
Payments
Workspace plans are paid through Stripe. You enter your payment details on Stripe's pages; we never see your card number. Stripe tells us your customer and subscription number, the plan, whether payments went through, and the amounts and numbers of your invoices, which we store with the workspace.
Why: to sell and bill the plan (Art. 6(1)(b) GDPR) and to keep the records the law requires (Art. 6(1)(c) GDPR).
Cookies
We only use cookies the app needs to work. There are no tracking, analytics or advertising cookies, and our pages load no scripts, fonts or images from other sites.
- session: keeps you logged in, for 30 days or until you log out.
- flash: shows a message after an action, for 1 minute.
These cookies are strictly necessary, so they need no consent.
Server logs and security
Our server records each request: time, page, result and your IP address, to find errors and fend off attacks. The log is limited in size: old entries are overwritten by new ones, and it is cleared when the app is updated. To limit login and sign-up attempts, the server also counts requests per IP address for up to an hour.
Why: to keep Clever Candidate secure and working (Art. 6(1)(f) GDPR).
How long we keep data
- Your data stays until you delete it, or your account.
- Deleted jobs and companies go to Deleted, where you can restore them.
- Deleting your account signs you out and hides your data. It is kept, so the platform admin can restore your account if you change your mind. Ask us (address above), and we erase it for good.
- Daily backups are kept for 31 days, with a copy on a separate backup server. Erased data is gone from them once the last backup holding it has been replaced.
- Sessions end after 30 days, password reset links after an hour, confirmation links after a day, and invitations after 7 days.
Who else gets data
Your data is kept on our server and our backup server. Service providers who run these servers or deliver our e-mail for us process data only on our behalf and as we instruct them. Stripe receives data as described above. We don't give your data to anyone else, unless the law obliges us to.
Your rights
Under the GDPR you can ask us at any time to tell you which data we have about you (Art. 15), to correct it (Art. 16), to erase it (Art. 17), to limit its use (Art. 18), or to give it to you in a common format (Art. 20). You can object to processing based on our legitimate interests (Art. 21). Write to the address above. Much of this you can do yourself: change or delete anything in the app, download your CV as a PDF, or delete your account in Settings.
You can also complain to a data protection supervisory authority, in particular in the EU country where you live or work.
Changes
When this policy changes, the date at the top changes. Before we use your data in a new way, we ask you.