Privacy

What we keep, and for how long

A CV is one of the densest personal documents you own. This page says exactly what Atsy holds, who can read it, and how to remove it. No legal wall, no hedging.

What Atsy stores today

  • Your email address — so a sign-in code can reach you and you can come back to your results. Kept until you delete your account.
  • The country your request came from — used only to count where sign-ups come from.
  • Sign-in codes, stored as a one-way hash, deleted the moment they are used and expiring after ten minutes either way.
  • A salted hash of your IP address — never the address itself — purely to stop someone flooding the sign-in form.

Scanning is not live yet, so there is no CV, no file and no scan history in the system at all.

When scanning arrives, this is the deal

  • Your file is encrypted before it is stored, with a key held by the application, not by the storage.
  • The file is deleted automatically within 24 hours; the findings from it go after 30 days.
  • The text pulled out of your CV is never saved — only the findings, with short quotes so you can see what a fix refers to.
  • Nobody at Atsy can read your CV. There is no admin screen for it; the only view is yours, and a test in the build fails if that ever changes.
  • If you ask for AI-written suggestions, your name, email, phone, links and employers are removed before anything is sent, one bullet at a time. Scoring itself never uses AI.
  • Delete everything in your account, any time, immediately.

What Atsy never does

  • No advertising, no analytics, no tracking pixels, no third-party scripts — the only outside code on the whole site is Cloudflare's bot check on the sign-in form.
  • Your CV is never sold, shared, published, or used to train anything.
  • No recruiter, employer or agency has access to any of this.
  • No email from us except your sign-in codes and answers to feedback you send.
  • A copy of every email Atsy sends you also goes to the person who runs it, so that support questions can be answered and problems spotted. Sign-in codes are masked in that copy — it can never be used to get into your account.

Your rights, and how to use them

Atsy is run from New Zealand under the Privacy Act 2020, and follows the GDPR standard for anyone in the UK or EU. You can see everything held about you (the app is that view), correct it by signing in again with the right address, take it with you by downloading your report, and erase it in one click from your account screen. Erasure is immediate and irreversible.

Questions, or something you think is wrong here: reply to any Atsy email and it reaches a person.