Archived policy. This version was superseded on 9 September 2026 after the browser-extension project was discontinued. Read the current privacy policy. The original policy text is preserved below for reference.

Tawori & Tawori Job Saver

Privacy policy

Effective 9 September 2026 · Version 2026-09-09.1

This policy explains how your information is handled when you visit Tawori, request beta access, use your workspace or save a job with the Tawori Job Saver Chrome extension.

The main points: the extension previews the job you choose; choosing Save to Tawori sends captured content and URLs to our server and AI providers. Saved content and AI interaction records remain on the server until deleted as described below. Signing out or uninstalling the extension does not delete your cloud workspace.

For a copy of your data, deletion, or a privacy question, email airaamane.pro@gmail.com. You can use this route even if an in-app account control is unavailable.

1. Who is responsible

Tawori is operated by Abdellah Iraamane, based in Ireland ("Tawori", "we", "us"). We are the data controller for the processing described in this policy. Contact us at airaamane.pro@gmail.com; you do not need a Tawori account to make a privacy request.

This policy covers the website, web app and Tawori Job Saver. It complements the AI processing notice, which explains AI operations in more detail. The privacy policy describes our handling of information; reading it does not itself give consent to optional processing.

2. Information we process

Some career documents reveal health, disability, religion or other sensitive information, or contain other people's details. Please omit information that is unnecessary for your application and avoid uploading confidential employer material. Do not supply another person's private information unless you are entitled to do so. If a captured posting includes your information and you are not a Tawori user, you can contact us to exercise your rights.

3. What the extension does

When you open its popup on a page, the extension reads recognised job content or job-description text you select and shows a preview. It uses temporary access to the active tab; it does not request access to your general browsing history or continuously collect every page you visit. Extraction is designed to exclude form values, editable regions, hidden content and unrelated page metadata. Credential-bearing URLs are rejected; URL fragments and unrecognised tracking/search parameters are removed while supported listing identifiers are retained.

The preview stays in extension session storage until you choose Save to Tawori. Saving sends the capture and URLs over HTTPS to the Tawori backend, associates them with your account and starts AI extraction through OpenRouter and its model providers. A save can continue after the popup closes. Re-reading a page refreshes the preview; signing in uses WorkOS independently of whether you save a job.

Local authentication data enables sign-in and token refresh. Temporary previews and save-progress records allow retries and reopening the popup. Local/session storage in the web app also supports sign-in, preferences, recovery drafts and cached workspace content. Removing local data may sign you out or discard unsaved work.

Chrome Web Store Limited Use: our use of information received through Chrome APIs follows the Chrome Web Store User Data Policy, including its Limited Use requirements. We use captured information to provide and improve the job-saving features you use. We do not sell it, use it for personalised advertising or creditworthiness/lending decisions, or transfer it for unrelated purposes. Human access to extension user data is limited to the exceptions allowed by that policy, such as your specific agreement to help with support, security/abuse investigation or a legal requirement.

4. Purposes and legal bases

PurposeLegal basis under the GDPR
Create and maintain your account; save jobs and workspace content; perform the AI operations you request; provide exports and ordinary support.Performance of our agreement with you, or steps you request before entering it (Article 6(1)(b)).
Review your beta request and contact you about the requested access.Steps at your request before entering an agreement. Managing invitation capacity and preventing duplicate or abusive requests also serves our legitimate interests (Article 6(1)(f)).
Organise limited recruiter/professional information contained in job postings selected by users.Our and our users' legitimate interests in keeping relevant application information together, balanced against the rights of the people named in a posting. Their data is not processed on the basis of a contract with them.
Secure and maintain the service, investigate failures or abuse, and evaluate whether features operate correctly.Our legitimate interests in a reliable and secure service, balanced against your rights. Full-content diagnostic records are restricted to these purposes and are not used to train models.
Collect optional account-linked product-usage events.Your consent (Article 6(1)(a)). You can decline or withdraw through Data & privacy without losing the core service.
Understand website traffic through Vercel Web Analytics.Our legitimate interests in understanding and maintaining the website, using the limited analytics described below. This is separate from optional account-linked product events.
Respond to privacy requests, comply with applicable law, and establish, exercise or defend legal claims.Legal obligations (Article 6(1)(c)) and, for appropriate claims handling, legitimate interests.

We use only information relevant to the purpose and consider the effect on you when relying on legitimate interests. You can object to that processing. A general agreement to use AI does not authorise unrelated uses or replace any additional legal condition required for special-category information.

The current forms do not submit when fields marked required are left blank. If you cannot or do not want to provide a requested detail, contact us to discuss another way to handle your request. Providing optional workspace content and analytics consent is your choice. A beta request does not automatically subscribe you to promotional email.

AI scores and suggestions help you review your own application. Tawori does not make an employer's hiring decision about you or use these scores to make a solely automated decision with legal or similarly significant effects. Review generated information before using it.

5. Providers and sharing

We use service providers to operate Tawori. Their access depends on the feature you use:

Provider or serviceRole and information involved
VercelWebsite hosting and Web Analytics; web requests, URLs and technical visitor information.
Railway, including Railway BucketsApplication servers, database, file storage and scanning infrastructure; account/workspace data, uploads, AI interaction records and operational requests.
WorkOSAccount authentication, sessions and verification; identity/contact details and sign-in/security information. Any identity provider you choose also processes information under its own notice.
OpenRouter and its routed Google Gemini model providersRequested AI extraction, drafting, comparison and feedback; submitted content and relevant workspace context. The actual hosting provider can vary with routing and availability. See OpenRouter's model-provider directory and subprocessor information.
Exa, through OpenRouterWeb research for company-aware interview preparation; relevant company/role search queries and search results when that feature is used.
GoogleGoogle Fonts requests on the website and email sent to our Gmail support address; font-request metadata or the support correspondence you send.

Requested AI calls are made under Tawori's service account. We request OpenRouter endpoints that support zero data retention and deny provider data collection. This is not a promise that every provider keeps no operational, security or billing metadata. Tawori itself retains the interaction records described here. We do not use your content to train AI models.

Vercel describes its Web Analytics as cookie-free and based on short-lived request-derived identifiers. It can collect page paths, referrers, approximate country and browser/device information. The in-app product-analytics switch controls our account-linked events; it does not control this separate website analytics service. See Vercel's analytics explanation. This privacy-policy page does not load an analytics script or external fonts.

We may disclose relevant information when legally required or necessary to investigate abuse, protect rights or obtain professional advice, with access limited to what is needed. For extension-derived information, these disclosures remain subject to the narrower Limited Use rules in section 3. We do not sell your personal information or disclose your private workspace to employers or job boards as part of saving a job. If you export and share an application yourself, its recipient's handling is outside Tawori's control.

6. International processing

Tawori is operated from Ireland, but its providers and their subprocessors may process information outside Ireland and the European Economic Area, including in the United States. Choosing an EU server region does not ensure that authentication, AI, support and other provider processing remain in the EU.

We use standard self-service provider accounts. Railway's data-processing terms, WorkOS's data-processing terms and the Vercel data-processing terms for our Pro hosting plan are incorporated into their service agreements and include European Commission Standard Contractual Clauses for applicable transfers. These clauses impose contractual safeguards on recipients outside the EEA. A separate individually signed document is not the only way these terms take effect.

AI provider arrangements are still being verified. OpenRouter's current published commercial-use terms incorporate its DPA, which includes Standard Contractual Clauses. We have not yet confirmed the version applicable to our existing account or that its permitted data categories cover identifiable CV and employment information. We therefore cannot currently confirm the contractual safeguards for all AI processing described in this policy. We will update this section when that review is resolved; this notice does not establish that the outstanding arrangements are compliant.

Contact airaamane.pro@gmail.com for details of the providers and safeguards applicable to your processing, or to request a copy of relevant safeguards with confidential information removed where necessary. We do not describe Tawori as an EU-only storage or processing service.

7. Retention

Retention depends on the type of record. Deleting a visible item and deleting all historical copies of its content are different operations.

Extension previews and progress
Unsubmitted raw previews expire after one hour and acknowledged save-progress records after 24 hours. Expired records are removed when the extension next runs or accesses storage. Raw previews are also removed after server acknowledgement, sign-out and relevant tab navigation/closure. Closing the browser clears extension session storage. Sign-in tokens are stored separately until sign-out, invalidation or removal of the extension's local data.
Saved workspace content and captured jobs
We retain content so you can return to your workspace, including versions and historical processing records, until you request the relevant deletion. Removing a job or application does not necessarily remove its original capture or AI interaction history; workspace deletion or a specific privacy request covers those additional records.
CV originals and temporary imports
Successfully imported PDF originals are retained for source preview until the source resume is deleted. Temporary failed or expired imports are scheduled for cleanup; their usual processing expiry is 24 hours. Extracted text may remain in your CV and AI records after temporary import material is removed.
AI interaction history
Submitted inputs, requests, responses and retry/error records are retained with the workspace for troubleshooting and evaluation. They currently have no separate automatic time-based expiry. They are removed with workspace deletion or handled through a specific deletion request, subject to any applicable legal exception.
Exports and account-deletion records
Generated account-export archives normally expire after 24 hours; the download screen shows the applicable expiry. Account-deletion receipt links expire seven days after creation; expired receipt records are subsequently cleaned up once processing has finished. A hashed identity marker used to prevent accidental recreation following deletion is retained for 30 days.
Optional product analytics
Account-linked product events expire after 365 days and are removed by scheduled cleanup or workspace deletion. Withdrawing consent stops new events; it does not itself erase previously collected events. You may request their deletion separately.
Beta requests and support
We keep requests while reviewing access, managing an invitation or handling related follow-up, and correspondence while resolving the issue and any necessary follow-up or dispute. These records do not have an automatic workspace-linked expiry. Ask us to remove them when no longer needed; deleting your workspace alone does not delete a beta request or an email conversation.
Security records, provider logs and backups
Records needed for security, abuse investigation, legal duties or claims can remain separately for those purposes. Providers may retain their own operational records under their terms. Backup copies may remain until their applicable rotation or deletion cycle; we do not promise immediate removal from every backup when an item is deleted. Contact us for the applicable retention details.

8. Deletion and your choices

In the web app, open your account menu and Data & privacy for available export, browser-clear, workspace-deletion, account-deletion and optional analytics controls. If a control is unavailable or a request fails, email airaamane.pro@gmail.com. Include the email associated with your account and what you want us to do; do not send your password.

We may need to verify your identity proportionately before disclosing or deleting information. Deletion can be limited where continued retention is required by law or justified for legal claims or another applicable exception. We will explain any refusal or limitation. Do not assume a request has completed until you receive its result or confirmation.

9. Your rights

Depending on the circumstances, you can request access to your personal information, correction, erasure, restriction of processing, and portability of information processed automatically on the basis of consent or contract. You can object to processing based on legitimate interests and to direct marketing. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing.

We normally respond within one month. Where the law permits an extension because of complexity or the number of requests, we will tell you within that first month and explain why. Requests are generally free of charge, subject to the limited exceptions in data-protection law.

You can complain to Ireland's Data Protection Commission, or the supervisory authority where you live or work. You do not have to contact us first, although we welcome the chance to address a concern.

10. Access and security

We use HTTPS, authenticated workspace access, restricted extension storage and upload-validation/scanning controls to protect information. Authorised operators and service providers may access information as needed to operate the service, investigate security issues or handle support, subject to applicable access and purpose restrictions. Extension-derived information remains subject to section 3's Limited Use rules: ordinary human support access requires your specific agreement to read the information concerned. Technical restrictions on a trace viewer do not mean that no infrastructure administrator can access stored information.

No internet service can guarantee absolute security. Keep your account secure, use a trusted device and contact us promptly if you suspect unauthorised access.

11. Children

Tawori is intended for adults managing their own job applications, not for children under 18. If you believe a child has provided information, contact us so we can assess and handle it appropriately.

12. Changes to this policy

We will update the effective date and version when this policy changes. We will provide an appropriate notice of material changes and seek fresh consent where legally required. A new policy does not retrospectively change the choices you made or authorise a new purpose for earlier data.