Privacy Policy
Last updated: May 1, 2026
1. Introduction
Matcher.Work ("we", "our", or "us") operates the Matcher.Work Chrome Extension and website at matcher.work. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
By using Matcher.Work, you consent to the data practices described in this policy. If you do not agree, please discontinue use of the service.
2. Data We Collect
We collect the following categories of data:
- Account data: email address and Firebase UID used for authentication and token management.
- CV content: the text of your CV, stored encrypted in Firestore and never shared with third parties beyond our AI provider for analysis.
- Ideal Job Profile (IJP): your career goals, work preferences, salary expectations, and values — stored in Firestore and used solely for job matching.
- Job analysis results: match scores, strengths, gaps, and recommendations generated for each job posting you analyze. Cached for up to 80 days.
- Token purchase history: records of purchases processed through Stripe, including package type and timestamp. No payment card data is stored by us.
- Usage analytics: anonymized behavioral events (e.g., "analysis performed", "CV generated") collected via PostHog, hosted on EU servers. Session recordings may capture UI interactions with inputs masked.
3. How We Use Your Data
- To provide AI-powered job matching and document generation features.
- To generate tailored CVs and cover letters matched to specific job postings.
- To process token purchases and maintain your balance via Stripe.
- To improve our product through aggregated, anonymized usage analytics.
- To send transactional emails and — if you subscribed — a weekly newsletter via Resend.
4. Third-Party Services
We use the following third-party services to operate Matcher.Work:
- Google Gemini API: job description text is sent for AI analysis. Google does not use this data to train models under the API terms.
- Stripe: payment processing for token purchases. Subject to Stripe's Privacy Policy.
- PostHog: product analytics hosted on EU servers (
eu.i.posthog.com). Data retained for 90 days. Session recordings are enabled with all form inputs masked. Subject to PostHog's Privacy Policy. - Resend: transactional and newsletter email delivery. Subject to Resend's Privacy Policy.
- Firebase (Google Cloud): authentication, database storage, and Cloud Functions. Subject to Google Cloud's Privacy Policy.
5. Data Sharing
We do not sell your personal data. We do not share your data with advertisers or marketing partners. Data is shared only with the service providers listed in Section 4, strictly to operate and improve Matcher.Work.
6. Data Retention
- Account data (CV, IJP, token balance): retained until you request account deletion.
- Job analysis cache: automatically deleted after 80 days.
- Analytics data: retained for 90 days on PostHog EU servers.
- Backup data: retained for up to 30 days on Firebase.
- Newsletter subscriber data: retained until unsubscribe request.
7. Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you have the right to:
- Access a copy of your personal data in JSON format.
- Delete your account and all associated data.
- Export your CV, IJP, and job history as JSON.
- Opt-out of analytics by contacting us or using your browser's Do Not Track setting.
- Withdraw consent at any time without affecting prior processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email contact@matcher.work.
8. Security
- All data is transmitted over HTTPS / TLS.
- CV and IJP data is encrypted at rest in Firestore.
- Firebase security rules restrict access to authenticated users' own data only.
- We conduct regular security reviews of our infrastructure.
9. Cookies & Tracking
- PostHog analytics cookies: used to track anonymous usage patterns and session recordings. You may opt out via the cookie banner or by contacting us.
- Firebase authentication tokens: stored in browser local storage to maintain your session.
- We do not use advertising cookies or cross-site tracking pixels.
10. Children's Privacy
Matcher.Work is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact us at contact@matcher.work and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or a notice on the extension dashboard. The effective date at the top of this page will always reflect the most recent version.
12. Contact
For privacy questions or requests, contact us at: contact@matcher.work