Privacy Policy

Last updated: August 25, 2025

GDPR Global CCPA/CPRA
Who we are
Data controller & contact

Utmosst ("we", "us", "our") operates utmosst.com and related services (the "Service").

Data Controller: Utmosst UG (haftungsbeschränkt), Cologne, Germany. If this entity name changes, the newest details in our legal imprint apply.

Contact: privacy@utmosst.com

What we collect
Categories of personal data
CategoryExamplesPurposeRetention
Account & IdentifiersName, email, password hash, user ID, auth provider IDsAccount creation, authentication, security, communicationsFor your account’s lifetime + up to 90 days after deletion for backups/logs
Profile & Job DataResumes/CVs, cover letters, LinkedIn import, job history, skills, preferencesGenerate documents, track applications, provide coaching & insightsUntil you delete the items or close your account
Content You ProvidePrompts, notes, goals, interview answers, attachmentsDeliver AI features and personalization you requestUntil you delete the items or close your account
Usage & Device DataIP, device/browser type, pages viewed, timestamps, performance/diagnosticsSecurity, analytics, service improvement, fraud preventionUp to 24 months (aggregated or anonymized thereafter)
PaymentsBilling name, email, subscription status (card data handled by our payment processor)Process payments, prevent fraud, manage subscriptionsAs required for accounting/tax and processor policies
SupportSupport tickets, chat messages, email threadsHelp you troubleshoot and resolve issuesUp to 24 months after ticket closure
How we use data
Purposes & legal bases (GDPR Article 6)
  • Provide the Service you request (create documents, track applications, coaching). Legal basis: Contract (Art. 6(1)(b)).
  • Improve & secure the Service (analytics, troubleshooting, preventing abuse). Legal basis: Legitimate interests (Art. 6(1)(f)).
  • Communicate about updates, security alerts, and transactional emails. Legal basis: Contract/legitimate interests.
  • Marketing (only with your consent where required; unsubscribe anytime). Legal basis: Consent (Art. 6(1)(a)).
  • Compliance with legal obligations (tax, accounting, law enforcement requests). Legal basis: Legal obligation (Art. 6(1)(c)).
AI & third‑party processing
Vendors and international transfers

To deliver AI features, we may process your prompts and content with reputable AI infrastructure providers (e.g., model hosts or API vendors). We use data processing agreements and, where transfers leave the EEA/UK, appropriate safeguards such as Standard Contractual Clauses.

We do not sell personal data. We share it only with processors acting on our instructions, or when required by law.

International users

We may process and store data in countries outside your own. Where we transfer personal data out of the EEA/UK, we rely on lawful transfer mechanisms (e.g., Standard Contractual Clauses) and implement appropriate safeguards.

Changes to this policy

We may update this policy to reflect changes to our practices, technologies, or legal requirements. We will post the updated version here and update the “Last updated” date. If changes are material, we will provide additional notice.