SatoriBack home

Privacy Policy

Updated: 2026-08-07

This policy explains what data Satori collects, why, who it may be shared with and in what form, how long it is kept, and what you can do about it. We tried to write it concretely rather than in boilerplate: everything below matches what the product actually does.

1. Who we are

Satori (withsatori.com) is a platform that helps you build a path into a new professional role. We are the controller of your personal data and decide how it is processed. For anything data-related, contact us at info@withsatori.com.

2. What we collect

2.1. Account data. Email, an encrypted (hashed) password, name, interface language, account creation date, email verification date, last sign-in date. We never store your password in readable form and cannot read it.

2.2. Your professional profile. The resume text you upload (kept as your Master CV), the skills extracted from it, your current role, years of experience, target roles, preferred cities and work format, answers to a short questionnaire, and any text you write about yourself by hand.

2.3. Product activity. The journeys and goals you create, skills-gap results, generated learning modules, your attempts and scores, saved vacancies and their statuses (saved, applied, and so on), and resumes generated for a specific vacancy.

2.4. Conversations with the assistant. The messages you send to the in-app AI mentor and its replies.

2.5. Technical data. IP address, browser type and version, device and screen characteristics, system language, referrer, request time; page views, clicks and taps inside the app; errors and server response codes. This is recorded on our own infrastructure.

2.6. Payments. The fact and contents of a purchase, tier, amount, transaction identifier, promo code applied, credits granted. We never receive or store your card details — payment happens on the payment provider's side.

3. Why we use it

  • To deliver the service you came for: parse your resume, find the gap between your profile and your target role, build a path, match vacancies, generate a tailored resume. Legal basis: performance of our contract with you.
  • To keep the service running and secure: troubleshooting, preventing abuse and automated attacks, enforcing limits. Legal basis: our legitimate interest in operating the service safely.
  • To improve the product: understanding where people get stuck, which prompts fail, how accurately the system scores a match. Legal basis: legitimate interest — aggregated and de-identified data is enough for this, and that is what we aim to work with.
  • To send service email — verification, password reset, important changes to the service.

We do not make legally significant decisions about you automatically. Match scores are a recommendation inside the product, not a hiring decision.

4. AI processing

Resume parsing, gap analysis, and generation of modules and resumes run through third-party LLM APIs — currently DeepSeek. This means the text of your resume and your messages to the assistant are sent to that provider for processing. We send only what a given operation requires, and we do not send your email or payment data there.

Please do not put information in your resume that must not reach external services: medical data, other people's personal data, or a previous employer's trade secrets. If we change LLM provider, we will update this section.

5. Who we share data with

5.1. Vendors acting on our behalf. LLM API providers (section 4), infrastructure and hosting, service email delivery, and — if we enable them — web analytics services. They receive only what their function requires, act on our instructions, and may not use your data for their own purposes.

5.2. Job sources. To find vacancies for you, we send search queries built from your profile — role title, city, keywords — to external job aggregators. Neither your resume, nor your email, nor your name is sent there.

5.3. Aggregated and de-identified data — partners, investors, research. To develop the product, raise funding, and report to partners, grant bodies and investors, we prepare and share statistics and de-identified data: user counts and their trend, step-by-step conversion, distribution of roles, cities and industries, matching quality, typical skills gaps, and generalised examples and quotes not tied to any individual. Such materials are prepared so that no specific person can be identified from them. Partners and investors do not get access to your resume, your conversations with the assistant, or your email.

5.4. Legal and financial advisers. As part of investment due diligence, an audit, or legal support, we may provide a limited set of data to advisers and prospective investors — strictly to the extent needed for the review, and only under written confidentiality.

5.5. Change of business ownership. If the service is sold, reorganised, or merged with another company, user data transfers to the new owner along with the service. We will give notice in advance, and this policy continues to apply until it is replaced.

5.6. When the law requires it, or in response to a lawful request from a competent authority.

5.7. What we never do. We do not sell your personal data. We do not send your resume to employers or recruiters without a deliberate action by you. We do not make your profile public.

6. Analytics, cookies and session recording

6.1. First-party analytics. We record in-app activity on our own servers (section 2.5) and store it separately from the main database. The visit counter is also our own service on the same machine, not a third-party product. This data is never sold and is used only to operate, troubleshoot and improve the service.

6.2. Cookies we set. There are three, and this is the complete list:

  • vr_vidanalytics. A random browser identifier that lets us tell a returning visit from a new one and build visit statistics. Set by our own counter, lasts up to 400 days. It contains no name, no email and nothing from your resume.
  • NEXT_LOCALEfunctional. Remembers the interface language you picked so you do not have to switch it every time.
  • satori_dlstrictly necessary. A one-off permission to download the resume you just generated; it lives for 60 seconds and disappears.

We set no advertising cookies and nothing that follows you across other sites. One clarification: your sign-in is not kept in a cookie but in your browser's local storage — that is where the session token lives, and in guest mode it disappears when you close the tab.

How to refuse them. Cookies are controlled in your browser settings: you can delete them, block them for a specific site, or open the site in a private window so they vanish on close. Ad blockers stop them too. The honest consequences: without vr_vid the service works in full, you simply count as a new visitor every time; without NEXT_LOCALE you will pick your language on each visit; without satori_dl a generated resume file will not download. Clearing your browser's local storage will sign you out.

6.3. Third-party trackers: there are none right now. As of 2026-08-07 the site runs no third-party analytics counter, advertising pixel or session-recording service.

What used to run. From 17.07 to 07.08.2026 the pages carried a tag-manager container belonging to a partner on a test advertising campaign, and through it three third-party services. We name them explicitly, because for those three weeks they saw what real visitors did:

  • Microsoft Claritysession replay and heatmaps: playback of how a person moved through the page, where they tapped and scrolled. It is the most sensitive of the three, and the previous version of this policy did not mention it — we are correcting that now. Microsoft's terms: privacy.microsoft.com.
  • Google Analytics 4 — visit and in-app event statistics. Google's terms: policies.google.com/privacy; you can opt out of Google Analytics measurement in every browser with their add-on: tools.google.com/dlpage/gaoptout.
  • Meta Pixel — the Facebook/Instagram advertising pixel: it recorded page views and the fact of registration to measure the campaign. Meta's terms: facebook.com/privacy/policy.

On 07.08.2026 we removed that container, and all three services with it, from every page of ours. Data they collected during that period is held by Microsoft, Google and Meta under their own retention rules — we cannot delete it on your behalf, but you can: each of the three explains at the links above how to request access or erasure. If we ever enable our own equivalent tools, we will name them in this section and ask for your consent before switching them on where the law requires it.

7. How long we keep data

  • Account and profile data — for as long as your account exists. After a deletion request we remove it within 30 days.
  • Guest sessions (using the product without registering) — deleted automatically shortly after they end, together with everything created in them.
  • Technical activity logs — up to 90 days, then deleted.
  • Payment records — for as long as accounting and tax law requires, even after the account is deleted.
  • Aggregated de-identified metrics — indefinitely; they are no longer personal data.

8. Your rights

Wherever you are, you can:

  • find out exactly what data we hold about you and get a copy of it;
  • correct inaccurate data — most of the profile is editable in the app;
  • delete your account and data;
  • restrict or object to processing;
  • withdraw consent where processing relies on consent;
  • complain to the data protection authority in your country.

To exercise any of these, write to info@withsatori.com. We respond within 30 days. California residents: we collect identifiers and internet activity information within the meaning of the CCPA/CPRA, and we do not sell or share it as those terms are defined by that law.

9. Security and where data lives

Data is stored on our own server in the European Union, and the connection to the site is encrypted. Passwords are kept only as an irreversible hash. Only the founders of the service have access to the database. Sending data to the LLM provider and, where needed, to other vendors may mean processing outside your country — we choose providers that maintain an adequate level of protection.

No system is perfectly secure. If a breach occurs that puts your rights at risk, we will notify you and the supervisory authority within the timeframes set by law.

10. Children

The service is intended for adults building a career. We do not knowingly collect data from anyone under 16. If you believe a child has given us their data, write to info@withsatori.com and we will delete it.

11. Changes to this policy

We update this policy whenever what the product does with data changes. The date of the last update is shown at the top. We will announce material changes by email to the address on your account, or with a prominent notice in the app.

Automated emails (verification, password reset) are sent from noreply@withsatori.com. Any data question, access or deletion request: info@withsatori.com.

Satori — an adaptive path to your next role