Tawori website & web app
Privacy policy
Effective 9 September 2026 · Version 2026-09-09.2
This policy explains how your information is handled when you visit Tawori, request beta access or use its web workspace to organise job applications, work on your CV and prepare for interviews.
The main points: you provide CVs, job descriptions, links and other application information through the web app. Saving a pasted job description starts AI extraction through our server and AI providers. Other AI features process the relevant content when you request them. Saved content and AI interaction records remain on the server until deleted as described below. Signing out or clearing your browser does not delete your cloud workspace.
For a copy of your data, deletion, or a privacy question, email airaamane.pro@gmail.com. You can use this route even if an in-app account control is unavailable.
1. Who is responsible
Tawori is operated by Abdellah Iraamane, based in Ireland ("Tawori", "we", "us"). We are the data controller for the processing described in this policy. Contact us at airaamane.pro@gmail.com; you do not need a Tawori account to make a privacy request.
This policy covers the website and web app. The browser-extension project has been discontinued. The versioned AI processing notice records further details of AI processing; older notices may describe discontinued features. This privacy policy reflects the current product scope. Reading it does not itself give consent to optional processing.
2. Information we process
- Account and sign-in information: your email address, name or display name, authentication identifier, email-verification status, preferences, consent choices and account/activity timestamps. WorkOS handles authentication and sign-in sessions.
- Beta requests: the name, email address, phone number, job-seeker status and reason you submit, together with the request date. These are separate records from a signed-in workspace.
- CVs and workspace content: uploaded CVs, extracted text, contact and career information, edits and version history, application records, notes, job descriptions and links, salaries, locations, interview preparation, answers and design-practice content you choose to provide.
- Job descriptions and links you provide: text you paste or enter, saved job/application URLs, job title, employer, location, salary and other posting details, including information extracted from that text by AI. Submitted text may include recruiter or other professional contact details. We obtain this information from your submissions, which may contain material published by employers, recruiters or job boards, and keep submission and processing records.
- AI interaction records: submitted content and context, the request sent to the AI service, original and processed responses, model and timing information, errors and retries. These can contain personal information from your CV, job posting, notes or answers.
- Technical and usage information: request identifiers, requested paths, timestamps, response status and processing duration; authentication, abuse-prevention and security records; and the IP address, browser/device and request information processed by hosting and authentication services. Optional product events record steps, outcomes and account/workspace identifiers, without free-text CVs, job descriptions or notes.
- Support correspondence: your contact details, messages and any attachments you send us. Please do not send passwords, authentication tokens or unnecessary sensitive documents.
Some career documents reveal health, disability, religion or other sensitive information, or contain other people's details. Please omit information that is unnecessary for your application and avoid uploading confidential employer material. Only submit content you are entitled to use, and do not supply another person's private information unless you are entitled to do so. If a user's submission includes your information and you are not a Tawori user, you can contact us to exercise your rights.
3. How information reaches Tawori
You add job information through the web app. When you save a pasted job description, its text is sent over HTTPS to the Tawori backend and through OpenRouter to its model providers to extract and organise the job details. The submission, result and processing history are associated with your workspace. You can also enter or edit application details and links yourself.
The web job-entry form does not read an open job-board tab or import that page's HTML and browsing metadata. Links and other information included in text you submit may still be stored and processed with that text. Company-aware interview preparation can use web research through Exa, as described in section 5.
Browser storage supports sign-in, preferences, recovery drafts and cached workspace content. Authentication/session information may be held in browser storage or cookies, depending on the sign-in configuration. Removing local data may sign you out or discard unsaved work. The public demo keeps its sample workspace separately in your browser; it does not sync that workspace to a signed-in account.
Earlier extension testing: if you previously submitted information through a test version of Tawori Job Saver, discontinuing that project does not automatically delete those records. Any retained job content, URLs, posting/contact details and technical capture records remain covered by the retention and deletion provisions below and the use, sharing and human-access restrictions in the earlier privacy policy. This change does not permit new uses of that information.
4. Purposes and legal bases
| Purpose | Legal basis under the GDPR |
|---|---|
| Create and maintain your account; save jobs and workspace content; perform the AI operations you request; provide exports and ordinary support. | Performance of our agreement with you, or steps you request before entering it (Article 6(1)(b)). |
| Review your beta request and contact you about the requested access. | Steps at your request before entering an agreement. Managing invitation capacity and preventing duplicate or abusive requests also serves our legitimate interests (Article 6(1)(f)). |
| Organise limited recruiter/professional information contained in job descriptions submitted by users. | Our and our users' legitimate interests in keeping relevant application information together, balanced against the rights of the people named in a posting. Their data is not processed on the basis of a contract with them. |
| Secure and maintain the service, investigate failures or abuse, and evaluate whether features operate correctly. | Our legitimate interests in a reliable and secure service, balanced against your rights. Full-content diagnostic records are restricted to these purposes and are not used to train models. |
| Collect optional account-linked product-usage events. | Your consent (Article 6(1)(a)). You can decline or withdraw through Data & privacy without losing the core service. |
| Understand website traffic through Vercel Web Analytics. | Our legitimate interests in understanding and maintaining the website, using the limited analytics described below. This is separate from optional account-linked product events. |
| Respond to privacy requests, comply with applicable law, and establish, exercise or defend legal claims. | Legal obligations (Article 6(1)(c)) and, for appropriate claims handling, legitimate interests. |
We use only information relevant to the purpose and consider the effect on you when relying on legitimate interests. You can object to that processing. A general agreement to use AI does not authorise unrelated uses or replace any additional legal condition required for special-category information.
The current forms do not submit when fields marked required are left blank. If you cannot or do not want to provide a requested detail, contact us to discuss another way to handle your request. Providing optional workspace content and analytics consent is your choice. A beta request does not automatically subscribe you to promotional email.
AI scores and suggestions help you review your own application. Tawori does not make an employer's hiring decision about you or use these scores to make a solely automated decision with legal or similarly significant effects. Review generated information before using it.
5. Providers and sharing
We use service providers to operate Tawori. Their access depends on the feature you use:
| Provider or service | Role and information involved |
|---|---|
| Vercel | Website hosting and Web Analytics; web requests, URLs and technical visitor information. |
| Railway, including Railway Buckets | Application servers, database, file storage and scanning infrastructure; account/workspace data, uploads, AI interaction records and operational requests. |
| WorkOS | Account authentication, sessions and verification; identity/contact details and sign-in/security information. Any identity provider you choose also processes information under its own notice. |
| OpenRouter and its routed Google Gemini model providers | Requested AI extraction, drafting, comparison and feedback; submitted content and relevant workspace context. The actual hosting provider can vary with routing and availability. See OpenRouter's model-provider directory and subprocessor information. |
| Exa, through OpenRouter | Web research for company-aware interview preparation; relevant company/role search queries and search results when that feature is used. |
| Google Fonts requests on the website and email sent to our Gmail support address; font-request metadata or the support correspondence you send. |
Requested AI calls are made under Tawori's service account. We request OpenRouter endpoints that support zero data retention and deny provider data collection. This is not a promise that every provider keeps no operational, security or billing metadata. Tawori itself retains the interaction records described here. We do not use your content to train AI models.
Vercel describes its Web Analytics as cookie-free and based on short-lived request-derived identifiers. It can collect page paths, referrers, approximate country and browser/device information. The in-app product-analytics switch controls our account-linked events; it does not control this separate website analytics service. See Vercel's analytics explanation. This privacy-policy page does not load an analytics script or external fonts.
We may disclose relevant information when legally required or necessary to investigate abuse, protect rights or obtain professional advice, with access limited to what is needed. The earlier restrictions preserved in section 3 still apply to any data from extension testing. We do not sell your personal information or disclose your private workspace to employers or job boards as part of saving a job. If you export and share an application yourself, its recipient's handling is outside Tawori's control.
6. International processing
Tawori is operated from Ireland, but its providers and their subprocessors may process information outside Ireland and the European Economic Area, including in the United States. Choosing an EU server region does not ensure that authentication, AI, support and other provider processing remain in the EU.
We use standard self-service provider accounts. Railway's data-processing terms, WorkOS's data-processing terms and the Vercel data-processing terms for our Pro hosting plan are incorporated into their service agreements and include European Commission Standard Contractual Clauses for applicable transfers. These clauses impose contractual safeguards on recipients outside the EEA. A separate individually signed document is not the only way these terms take effect.
AI provider arrangements are still being verified. OpenRouter's current published commercial-use terms incorporate its DPA, which includes Standard Contractual Clauses. We have not yet confirmed the version applicable to our existing account or that its permitted data categories cover identifiable CV and employment information. We therefore cannot currently confirm the contractual safeguards for all AI processing described in this policy. We will update this section when that review is resolved; this notice does not establish that the outstanding arrangements are compliant.
Contact airaamane.pro@gmail.com for details of the providers and safeguards applicable to your processing, or to request a copy of relevant safeguards with confidential information removed where necessary. We do not describe Tawori as an EU-only storage or processing service.
7. Retention
Retention depends on the type of record. Deleting a visible item and deleting all historical copies of its content are different operations.
- Browser drafts and cached content
- Recovery drafts, preferences and cached workspace content can remain in the browser until cleared by the app or through browser controls. Clear this browser removes the local workspace data described in section 8. Unsaved local drafts may be lost when browser storage is cleared.
- Saved workspace content and job submissions
- We retain content so you can return to your workspace, including versions, original submitted job text and historical processing records, until you request the relevant deletion. Removing a job or application does not necessarily remove its original submission or AI interaction history; workspace deletion or a specific privacy request covers those additional records. The same applies to any retained submissions from earlier extension testing.
- CV originals and temporary imports
- Successfully imported PDF originals are retained for source preview until the source resume is deleted. Temporary failed or expired imports are scheduled for cleanup; their usual processing expiry is 24 hours. Extracted text may remain in your CV and AI records after temporary import material is removed.
- AI interaction history
- Submitted inputs, requests, responses and retry/error records are retained with the workspace for troubleshooting and evaluation. They currently have no separate automatic time-based expiry. They are removed with workspace deletion or handled through a specific deletion request, subject to any applicable legal exception.
- Exports and account-deletion records
- Generated account-export archives normally expire after 24 hours; the download screen shows the applicable expiry. Account-deletion receipt links expire seven days after creation; expired receipt records are subsequently cleaned up once processing has finished. A hashed identity marker used to prevent accidental recreation following deletion is retained for 30 days.
- Optional product analytics
- Account-linked product events expire after 365 days and are removed by scheduled cleanup or workspace deletion. Withdrawing consent stops new events; it does not itself erase previously collected events. You may request their deletion separately.
- Beta requests and support
- We keep requests while reviewing access, managing an invitation or handling related follow-up, and correspondence while resolving the issue and any necessary follow-up or dispute. These records do not have an automatic workspace-linked expiry. Ask us to remove them when no longer needed; deleting your workspace alone does not delete a beta request or an email conversation.
- Security records, provider logs and backups
- Records needed for security, abuse investigation, legal duties or claims can remain separately for those purposes. Providers may retain their own operational records under their terms. Backup copies may remain until their applicable rotation or deletion cycle; we do not promise immediate removal from every backup when an item is deleted. Contact us for the applicable retention details.
8. Deletion and your choices
In the web app, open your account menu and Data & privacy for available export, browser-clear, workspace-deletion, account-deletion and optional analytics controls. If a control is unavailable or a request fails, email airaamane.pro@gmail.com. Include the email associated with your account and what you want us to do; do not send your password.
- Clear this browser removes local drafts/cache, not cloud records.
- Sign out does not request server-side deletion.
- Workspace deletion covers the workspace's saved content, original job submissions and related AI records, including any earlier extension submissions; it is different from deleting your sign-in identity.
- Account deletion also requires removing the account identity. Tell us if your request should include beta applications, support correspondence or information outside the workspace.
We may need to verify your identity proportionately before disclosing or deleting information. Deletion can be limited where continued retention is required by law or justified for legal claims or another applicable exception. We will explain any refusal or limitation. Do not assume a request has completed until you receive its result or confirmation.
9. Your rights
Depending on the circumstances, you can request access to your personal information, correction, erasure, restriction of processing, and portability of information processed automatically on the basis of consent or contract. You can object to processing based on legitimate interests and to direct marketing. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing.
We normally respond within one month. Where the law permits an extension because of complexity or the number of requests, we will tell you within that first month and explain why. Requests are generally free of charge, subject to the limited exceptions in data-protection law.
You can complain to Ireland's Data Protection Commission, or the supervisory authority where you live or work. You do not have to contact us first, although we welcome the chance to address a concern.
10. Access and security
We use HTTPS, authenticated workspace access and upload-validation/scanning controls to protect information. Authorised operators and service providers may access information as needed to operate the service, investigate security issues or handle support, subject to applicable access and purpose restrictions. The earlier restrictions preserved in section 3 still apply to any data from extension testing. Technical restrictions on a trace viewer do not mean that no infrastructure administrator can access stored information.
No internet service can guarantee absolute security. Keep your account secure, use a trusted device and contact us promptly if you suspect unauthorised access.
11. Children
Tawori is intended for adults managing their own job applications, not for children under 18. If you believe a child has provided information, contact us so we can assess and handle it appropriately.
12. Changes to this policy
We will update the effective date and version when this policy changes. We will provide an appropriate notice of material changes and seek fresh consent where legally required. A new policy does not retrospectively change the choices you made or authorise a new purpose for earlier data.
Version 2026-09-09.2 reflects the decision to discontinue the browser-extension project and describes web-app submissions. The previous privacy policy (2026-09-09.1) remains available for reference.