Privacy policy
We take your privacy seriously. Here's exactly what we collect, why, and how you stay in control.
Last updated: May 8, 2026
1. Who we are
Similator Pro (hereafter "we", "the Service") is an AI-powered resume optimization tool designed to pass Applicant Tracking Systems (ATS). The service is published from France and intended for job seekers worldwide.
Data controller: The Similator Pro team
Contact email: contact@similator-pro.com
2. Data we collect
2.1 Data you provide directly
- User account: email address, name (optional), hashed password (never in plaintext), creation date, last login date.
- Sign in with Google: email, full name, profile picture (URL), unique Google identifier ("sub"). No other access right is requested from your Google account.
- Resume and job offer content: the text of your resume and the job offer that you paste into the tool. PDF/DOCX parsing happens in your browser — the original file never leaves your machine.
2.2 Data collected automatically
- Essential technical cookies: session cookie (HttpOnly, HMAC-signed) to keep you logged in. Required for the service to operate.
- Anonymized analytics (only with your consent): visit statistics via Vercel Analytics — pages visited, browser, country. No raw IP address, no cross-site fingerprinting.
3. Processing purposes
Your data is only processed to:
- Provide the service (ATS analysis, scoring, content generation)
- Maintain your account and analysis history
- Improve the service (aggregated and anonymized analysis)
- Security (fraud detection, abuse prevention)
We never sell your data. We never use it for advertising purposes.
4. Subprocessors and transfers
To provide the service, we rely on these technical subprocessors (all GDPR-certified or Privacy Shield successor compliant):
- Vercel Inc. (USA) — web hosting. Data: pages served, ephemeral IPs for security.
- Supabase Inc. (USA / EU) — PostgreSQL database. Data: your account, analysis history.
- Anthropic PBC (USA) or OpenAI Inc. (USA) — only when you click "Rewrite": the text of your resume/offer is sent for AI generation. Neither Anthropic nor OpenAI uses your data to train their models under their paid APIs ("zero data retention" policy available on request).
- Google LLC (USA) — only if you choose Google sign-in. Strict minimum needed to authenticate.
All transfers outside the EU are framed by the European Commission's Standard Contractual Clauses (SCC).
5. Retention period
- Active user account: as long as you use it. Complete deletion on simple request to the contact email.
- Inactive account: automatic deletion after 24 months without login.
- Resumes and analyses: kept as long as your account exists, deletable at any time from your dashboard.
- Technical logs: 30 days maximum.
6. Your rights (GDPR)
You have the following rights at any time:
- Access: get a copy of all data concerning you
- Rectification: correct inaccurate data
- Erasure (right to be forgotten): complete and permanent deletion
- Portability: retrieve in a structured format (JSON)
- Objection: refuse certain processing
- Restriction: temporarily suspend a processing
To exercise a right, write to contact@similator-pro.com. We respond within 30 days maximum.
If we don't comply, you can file a complaint with the CNIL (French data protection authority): cnil.fr/en/plaintes.
7. Cookies
See our cookie policy for full details.
8. Security
- Passwords hashed with scrypt (cost factor 16384)
- HMAC-SHA256-signed sessions, cookies HttpOnly + Secure + SameSite=Lax
- HTTPS mandatory (HSTS preload)
- Strict security headers (X-Frame-Options, X-Content-Type-Options, etc.)
- Regular security audits
In the event of a security incident affecting your data, we will notify you within 72 hours in compliance with GDPR.
9. Changes
This policy may evolve. Any substantial modification will be notified by email at least 30 days before entry into force. Minor changes (corrections, clarifications) are published with the update date at the top of this page.
10. Contact
For any question regarding your data: contact@similator-pro.com