Overview
Your privacy is important. At Kazifi, a few fundamental principles guide everything in this policy:
- We are thoughtful about the personal information we ask you to provide and the information we collect about you through the operation of our Services.
- We store personal information only for as long as we have a reason to keep it.
- We aim to make it as simple as possible for you to control what is shared, what is kept private, and what is permanently deleted.
- We aim for full transparency on how we gather, use, and share your personal information.
This document is a real, binding promise about how we treat your data, not legal theatre. If anything here is unclear, write to hi@kazifi.co.
Who we are and what this policy covers
This Privacy Policy applies to information that we collect about you when you use kazifi.co and all of its subdomains and domain variants, together with the related applications and services (our "Services").
For the purposes of the GDPR, Kazifi is the data controller of the personal data described in this policy. You can reach us about any data-protection matter at privacy@kazifi.co.
Information you provide to us
The amount and type of information depends on the context and how you use the Services. Examples include:
- Account data: we require an email address (or an OAuth identifier) to create an account, and that's it. You may add more later, such as your name or an avatar, but it isn't required to create a Kazifi account.
- Content you create: resumes, cover letters, resignation letters, application notes, and LinkedIn drafts, including any biographical information you choose to put in them.
- Communications: information you provide when you respond to a survey or contact us about a support question.
- Billing data: handled by our payment processor. We see the plan and the invoice; we never see your card number.
Information we collect automatically
- Usage information: which features you open and aggregate actions you take (who did what, when), plus aggregate error logs and fair-use signals such as AI requests per day. We use this to provide the Services and understand how to make them better.
- Device information: general technical details such as screen size, browser, and device type, used to keep the product compatible and secure.
- Cookies and similar technologies: a small number of essential cookies for authentication and session safety, plus aggregate analytics that don't identify you. Please see our Cookie Policy for the full list.
Information we collect from other sources
If you create or log into your Kazifi account through another service (for example, Google or GitHub), we receive limited information from that service (such as a username and basic profile details) via that service's authorization procedures. What we receive depends on which service you use and the options it makes available.
How and why we use information
We use information about you for the purposes below:
- To provide the Services, for example, to set up and maintain your account and store your documents;
- To develop and improve the Services, for example, by adding features that help you create a resume or land a job more efficiently;
- To understand trends and how users interact with the Services, so we can make them easier to use;
- To monitor and prevent problems, protect the security of the Services, detect and prevent fraud and other illegal activity, and protect the rights and property of Kazifi and others; and
- To communicate with you, for example, about your account, important changes, or (if you've opted in) product updates.
Legal bases for processing (GDPR)
If you are in the EEA or the UK, the GDPR requires us to have a legal basis for each use of your personal data. We rely on:
- Performance of a contract: to create and run your account and provide the Services you ask for, including storing your documents and sending uploaded files to be scanned and parsed.
- Legitimate interests: to keep the Services secure, prevent fraud and abuse, and improve the product using aggregate, non-identifying signals, where those interests are not overridden by your rights.
- Consent: for optional things such as marketing email or non-essential analytics; you can withdraw consent at any time without affecting processing already carried out.
- Legal obligation: where we must process data to comply with the law.
What we don't do
- We do not train AI models on the contents of your documents.
- We do not sell or rent your data to recruiters, advertisers, or data brokers.
- We do not show your resume content to other users.
- We do not profile you for targeted ads.
AI providers
To generate text (rewrites, summaries, cover letters, interview prompts), we send the minimum necessary context to a third-party large-language-model provider. Today that's Anthropic, with a fallback to an OpenAI-compatible provider.
Providers process the request, return the response, and, per their enterprise terms, do not retain it for training. We rotate providers if their privacy posture changes.
Uploaded files & temporary processing
When you upload a document for us to import (typically an existing resume), we write it to a temporary, sandboxed location only for as long as it takes to scan it for malware and extract its text. This processing is quick and ephemeral: the uploaded file is deleted automatically as soon as extraction finishes or fails, and it is not added to long-term storage in its original form.
What persists afterwards is the extracted text and structured content, which becomes part of your documents and follows the retention rules below. We also use this extracted information to pre-fill your profile and account details during onboarding (for example, your name, contact details, work history, and skills) so you don't have to retype what's already in your resume. You can review, edit, or remove any of it. If a file fails the malware scan it is rejected and discarded, not processed.
The malware scan and text extraction run entirely on our own servers. Your uploaded file is not sent to any third party to be scanned or parsed. (Separately, once your content exists, certain AI features send text, never the original file, to a language-model provider when you ask for them; see AI providers.)
Retention
We keep your account and documents for as long as your account is active. If you delete the account, your data is removed within 24 hours from primary databases. Backups roll off within 30 days.
Files you upload for import are not part of this lifecycle. They are deleted immediately after processing; see Uploaded files & temporary processing above.
One narrow exception: when an account is deleted we retain an irreversible one-way cryptographic hash of the account's email address. We do not keep the email itself (the hash cannot be reversed to recover your address) and we use it for a single purpose: enforcing that introductory free credits are granted only once per person, so a deleted account can't be re-created to claim them again. It is never used for marketing, advertising, profiling, or sharing with anyone else.
Aggregate, fully anonymized analytics (e.g. "how many users used the resume builder this week") may be retained indefinitely.
Your choices
- Limit what you provide: you only need an email address to create an account. The rest is up to you. You can also browse much of the site without an account.
- Opt out of marketing email: follow the unsubscribe instructions in any promotional message, or toggle the setting in your account. We may still send essential account and legal notices.
- Cookies and "do not track": you can set your browser to reject cookies, with the caveat that some features may not work properly without them.
- Close your account: you can delete your account and all associated documents from Settings at any time.
Your rights
You can:
- Access all your data via a one-click export in Settings (PDF + DOCX + JSON).
- Correct anything by editing it in the app, or emailing us.
- Delete your account and all associated documents from Settings.
- Object to or restrict a specific processing, and request portability of your data, by emailing privacy@kazifi.co.
If you're an EU/UK resident, these mirror your GDPR rights, and you also have the right to lodge a complaint with your local data-protection supervisory authority, though we'd appreciate the chance to resolve it first. California residents have analogous rights under CCPA. We honour both without making you prove jurisdiction.
International data transfers
Because Kazifi is offered worldwide, information about you may be processed, stored, or accessed by us, our group, or our processors in countries outside your own, including outside the European Economic Area (EEA). Where we transfer personal information out of the EEA or UK, we put appropriate safeguards in place, such as European Commission-approved standard contractual clauses, so your information remains protected in accordance with this policy and applicable law.
Deleting your data
You can delete your account and all associated documents yourself from Settings. You can also ask us to delete your data by emailing privacy@kazifi.co, and we will action the request in line with the retention rules above.
Security
Encrypted in transit (TLS 1.2+) and at rest. Least-privilege access for engineers, two-factor required for everyone with database access. Full details on the Security page.
Children's data
Kazifi is intended for users who have reached the age of majority (or the minimum age required to consent to the processing of personal data) in their own jurisdiction. Where you have not reached that age, you may only use Kazifi with the consent and involvement of a parent or legal guardian.
We do not knowingly collect personal data from anyone below the applicable age without the required parental or guardian consent. If we learn that we have done so, we delete that data promptly.
Changes to this policy
We notify active users by email when this policy materially changes. The "Last updated" date at the top is authoritative; older versions are kept in the public changelog.
Contact
Questions about this policy or your data: hi@kazifi.co. Privacy-specific reports: privacy@kazifi.co. See the Contact page for everything else.