Privacy Policy
Last updated: 2026-05-21
1. Who we are
Lurien ("Lurien") provides a CV-tracking and AI feedback service. All data is hosted in the EU (Frankfurt). We are the data controller for account data and the data processor for view-tracking data on behalf of our users.
2. What we collect
- Account data: email, hashed password, name.
- Uploaded files: PDF CVs you upload, stored encrypted in the EU.
- View data: when a recruiter opens your link, we log open time, hashed IP, approximate city, browser type, and page-dwell time.
- Usage: minimal product analytics — feature usage, no third-party trackers.
3. What we do NOT collect
- Raw IP addresses — only SHA-256 hashed.
- Mouse movements, keystrokes, browser fingerprints.
- Any data outside the EU. No US transfer.
4. Your rights (GDPR Articles 15–22)
- Access — request a copy of your data.
- Erasure — delete your account and all linked data instantly.
- Portability — export your data as JSON.
- Rectification — update any inaccurate data.
- Object — to specific processing (e.g. marketing).
To exercise these rights, email privacy@lurien.app or use the Account → Delete button in your dashboard.
5. AI processing
When you use the AI CV review or cover letter feature, your CV text (with national IDs, IBANs, phone numbers and emails automatically masked) is sent to our AI provider (DeepSeek). The provider does not retain your data after generation. PII never leaves our EU server.
6. Cookies
We use only essential cookies (session, language preference, cookie consent state). No marketing or third-party tracking cookies.
7. Data retention
Account data is kept while your account is active. Upon deletion, all your data is removed within 24 hours. We keep an anonymised audit row (no PII) for compliance.
8. Contact
For privacy questions: privacy@lurien.app