Privacy Policy
Last updated: January 3, 2026
This Privacy Policy for P/E Danylo Klymenko (doing business as OfferFlow) (“OfferFlow,” “we,” “us,” “our”) explains how and why we access, collect, store, use, and share (“process”) personal information when you use our websites and services (collectively, the “Services”), including when you:
- Visit https://offerflow.pro/ or https://app.offerflow.pro/ (or any page linking to this Privacy Policy)
- Create an account and use our features (including AI-powered CV improvements and job search tracking)
- Contact us, subscribe to updates, or interact with us for support, sales, or marketing
Questions or concerns? This Privacy Policy helps you understand your privacy rights and choices. If you do not agree with this Policy, please do not use the Services. If you have questions, contact us at privacy@offerflow.pro.
Summary of key points
- What personal information do we process? We process information you provide (such as account details and documents/content you upload) and information collected automatically (such as device and usage data).
- Do we process sensitive personal information? We do not request or require sensitive data. However, resumes and career documents may include sensitive information depending on what you choose to include; if you upload such content, we will process it to provide the Services.
- Do we collect information from third parties? We may receive limited information from third-party login providers (if you use them) and limited subscription/transaction records from our payment/merchant-of-record provider.
- How do we process your information? To provide the Services, operate accounts, enable AI features, improve performance, keep the Services secure, communicate with you, and comply with law.
- Do we share personal information? Yes—only as necessary—with service providers (including hosting, AI processing, and payments), and when required by law.
- What are your rights? Depending on where you live, you may have rights to access, delete, correct, or restrict processing of your personal information.
1. Information we collect
1.1 Personal information you provide to us
We collect personal information you voluntarily provide, including:
Account and profile information
- Email address
- Name (if you provide it)
- Username (if applicable)
- Authentication data (e.g., password hash, session tokens)
- Account preferences and settings
User content and job search data
- CV/resume files and the text within them
- Cover letters and other career documents you upload or generate
- Job descriptions, roles, companies, notes, and pipeline/status data you add to track your job search
- Content you submit into AI features (“inputs”) and the resulting outputs
Communications
- Support requests and messages you send to us
- Feedback and survey responses (if any)
Payment and subscription information We do not store full payment card details. Payments are processed by our merchant of record (Paddle). We may receive and store limited billing-related records such as:
- Subscription status (active/canceled), plan identifiers
- Invoice IDs, transaction timestamps
- Country/region and tax-related fields (where required)
- Refund/chargeback status (where applicable)
1.2 Information collected automatically
When you visit or use the Services, we may automatically collect:
Device and usage data
- IP address and approximate location derived from IP (where available)
- Browser type, device type, operating system
- Referring URL, pages viewed, timestamps, and feature usage
- Diagnostic/performance data (e.g., error logs)
Log data Our servers and infrastructure providers may generate logs for security, debugging, and service reliability.
2. How we use your information
We process personal information for the following purposes:
- Provide and operate the Services (account creation, authentication, core features, customer support)
- Enable AI-powered features (CV review, rewriting, suggestions, structured improvements)
- Process subscriptions and billing (through our merchant-of-record/payment provider)
- Maintain, improve, and debug the Services (performance monitoring, feature development)
- Communicate with you (service updates, security notices, administrative messages; marketing messages consistent with your preferences and applicable law)
- Security and fraud prevention (prevent abuse, protect accounts and infrastructure)
- Legal compliance (tax/accounting, responding to lawful requests, enforcing our terms)
3. Legal bases for processing (EEA/UK and similar jurisdictions)
If you are in the EEA/UK (or another jurisdiction requiring legal bases), we rely on:
- Performance of a contract: to provide the Services you request and manage your account/subscription.
- Legitimate interests: to secure and improve the Services, prevent fraud, and understand usage (balanced against your rights).
- Consent: for optional cookies/analytics/marketing where required; you can withdraw consent at any time.
- Legal obligations: to comply with laws (including tax and accounting obligations).
4. When and with whom we share your information
We share personal information only as necessary to provide and operate the Services, including with:
4.1 Hosting and infrastructure (Hetzner)
We use Hetzner Online GmbH as a hosting/infrastructure provider to run and store data for our Services. Hetzner processes personal data on our behalf under a data processing agreement framework consistent with Article 28 GDPR.
4.2 AI processing (OpenAI)
We use OpenAI’s API (ChatGPT API) to provide AI-powered functionality. When you use AI features, relevant inputs (e.g., resume text, job description text, and your instructions) are transmitted to OpenAI to generate outputs and return them to you.
OpenAI’s API documentation indicates:
- For key API endpoints used for text generation (e.g.,
/v1/chat/completions,/v1/responses), data is not used for training. - By default, OpenAI may retain abuse monitoring logs (which can include prompts and responses) for up to 30 days, unless legally required to retain longer; eligible organizations may apply for “Zero Data Retention” controls.
4.3 Payments / Merchant of Record (Paddle)
If you purchase a subscription, payments and tax handling are processed by our merchant-of-record/payment provider (for example, Paddle). Paddle’s privacy policy describes how it processes data as a merchant of record. We share necessary information to facilitate checkout, fraud prevention, tax handling, invoicing, and customer support, and we receive limited transaction/subscription metadata (see Section 1.1).
4.4 Other service providers
We may also use vendors for:
- email delivery (transactional emails such as verification and receipts),
- customer support tools,
- analytics/performance monitoring (if enabled and consistent with your cookie choices and local law).
4.5 Legal and safety
We may disclose information if required by law or in good faith to comply with legal processes, protect safety and rights, or investigate fraud/security incidents.
4.6 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate safeguards.
5. Cookies and similar technologies
We use cookies and similar technologies for essential functions (security, session management, preferences) and, where enabled, for analytics/performance measurement.
For details, see our Cookie Policy: https://offerflow.pro/cookie-policy
6. AI-based features
OfferFlow provides features that use artificial intelligence (“AI Features”) such as CV review, rewriting, and suggestions.
6.1 What data is used for AI Features
When you use AI Features, we process:
- inputs you provide (documents, text, prompts, job descriptions), and
- outputs generated by the AI.
6.2 Important notes about resumes and sensitive content
Resumes and related documents may include sensitive or highly personal information depending on what you include. You control what you upload. If you do not want certain information processed, do not include it in the content you submit.
6.3 Output quality
AI outputs can be inaccurate or incomplete. You are responsible for reviewing and verifying outputs before relying on them.
6.4 Automated decision-making
We may produce suggestions and scores to help improve documents, but we do not use solely automated processing to make decisions that produce legal or similarly significant effects about you.
7. Google API data (if applicable)
If you choose to connect a Google account (for example, for sign-in or Google Workspace access), we will access and use Google data only as authorized by you and only to provide the features you request. Our use of information received from Google APIs will comply with the Google API Services User Data Policy, including Limited Use requirements.
8. International transfers
We are based in Georgia. Your personal information may be processed in countries where we or our service providers operate (including locations where Hetzner or OpenAI process data). Where required, we rely on appropriate safeguards for international transfers (such as contractual protections) and take steps designed to protect your information.
9. Data retention
We retain personal information only for as long as necessary to provide the Services and for legitimate business and legal purposes:
- Account data and user content: typically while your account is active, plus a reasonable period for backups, dispute resolution, and compliance.
- Billing records: retained as required by tax/accounting laws and merchant-of-record requirements.
- Logs and security records: retained for a limited period appropriate for security and troubleshooting.
When retention is no longer necessary, we delete or anonymize data, or store it securely and isolate it until deletion is feasible (e.g., in backups).
10. Security
We use reasonable technical and organizational measures designed to protect personal information. No method of transmission or storage is 100% secure; therefore, we cannot guarantee absolute security.
11. Children’s privacy
The Services are not intended for children. We do not knowingly collect personal information from individuals under 16 (or a higher age where required by local law). If you believe a child has provided personal information, contact us at privacy@offerflow.pro and we will take appropriate steps to delete it.
12. Your privacy rights and choices
Depending on your location, you may have the right to:
- access your personal information,
- correct inaccurate information,
- request deletion,
- object to or restrict processing,
- request data portability,
- withdraw consent (where processing is based on consent).
You can also:
- update certain information in your account settings (where available),
- opt out of marketing emails using the unsubscribe link.
13. Do-Not-Track signals
Some browsers offer a “Do Not Track” (“DNT”) setting. There is no consistent industry standard for recognizing DNT signals, so we do not respond to DNT signals at this time. If this changes, we will update this Policy.
14. U.S. state privacy disclosures
If you are a resident of certain U.S. states, you may have additional rights (such as the right to opt out of certain processing, including targeted advertising).
Sale / sharing: We do not sell personal information. We do not share personal information for cross-context behavioral advertising unless we explicitly enable such features and provide the required opt-out choices under applicable law.
Authorized agents: Where required by law, you may use an authorized agent to submit requests on your behalf. We may require proof of authorization and verification of your identity.
15. Updates to this Policy
We may update this Privacy Policy from time to time. The updated date will be shown at the top. If changes are material, we may provide additional notice (e.g., via the Services or by email).
16. Contact us
For questions or requests regarding this Privacy Policy or your personal information:
Email: privacy@offerflow.pro
By post:
P/E Danylo Klymenko
Tbel Abuseridze street, N 38, flat N 63 Batumi, Adjara 6010
Georgia
Phone: +995 (511) 11-14-73
17. How to exercise your rights
To exercise your privacy rights, email privacy@offerflow.pro with the subject line “Privacy Request” and include:
- the email associated with your account (if you have one),
- the request you want to make (access, deletion, correction, etc.),
- any details that help us verify and process your request.
We may need to verify your identity before fulfilling requests and will respond within the timeframes required by applicable law.