ϟmymanager← Product overviewUK
TermsPrivacyLegal

Privacy

This policy explains what personal data the mymanager service (mymgr.app) processes, why, who else receives it, how long it is kept and how to exercise your rights. The terms for using the service are on the “Terms of Use” page (mymgr.app/en/terms).

Who processes your data

Personal data is processed by the service operator listed on the “Legal information” page. Questions and requests about personal data: support@mymgr.app.

What data we process

  • Sign-in and account data — email and authentication data.
  • CV and search settings — CV text, target salary, chosen currency, keywords and other search parameters.
  • Saved and hidden jobs — jobs you saved, hid or viewed.
  • Application status — the status of your applications and your notes on the search.
  • Payment data — subscription status, payment amounts and dates. Card details are processed by the payment provider; we do not receive them.
  • Usage analytics — which pages and app screens you open (as page types such as “jobs” or “settings”, never search terms, job details or anything you type), the site you came from (domain only), campaign tags (source, medium, campaign name), browser, device type and approximate country. If you allow analytics, these events are linked across your visits and, after sign-in, to your account identifier (never your email). Until you allow it, or if you decline, we only count visits in aggregate, without linking them to you.
  • Technical and security logs — for diagnosing errors and preventing abuse.

Why we process it

  • To match jobs to your CV and show a personal feed.
  • To make your account, sign-in and subscription work correctly and securely.
  • To answer your requests and process payments.
  • To keep the service reliable and secure.
  • To understand how people find and use the service, so we can improve it and judge which channels work.

Legal bases

  • Performance of a contract — to provide the service you signed up for: account, feed, AI matching, subscription.
  • Legitimate interests — security, abuse prevention, error diagnostics, and anonymous aggregate visit counts while you have not allowed analytics.
  • Consent — optional AI (Vision) recognition of your CV, which you switch on yourself, and usage analytics linked to your visits and account, which you allow or decline in the analytics banner and can change at any time.
  • Legal obligation — keeping payment records for accounting.

Who else processes data

  • Infrastructure: Supabase (database and authentication; each user’s data is restricted to their own account) and Vercel (serverless functions).
  • AI matching: requests to Anthropic, OpenAI and Groq models are sent only from the server; your browser never contacts AI providers directly. OpenRouter may be enabled only as a fallback.
  • Error monitoring: Sentry.
  • Usage analytics: PostHog (PostHog Inc., EU Cloud, Frankfurt); requests go through our own domain. Session recording, heatmaps and automatic click capture are off.
  • Bot protection: Cloudflare Turnstile (Cloudflare, Inc.) checks sign-up (/register) and sign-in link requests (/auth/callback resend); it processes the challenge token, technical browser and device signals needed for the challenge, and your IP address.
  • Payments: Plata by mono, LiqPay and Paddle receive the data needed to process a payment.
  • An email service for service emails (for example, account action confirmations).

International transfers

Some providers (including Anthropic, OpenAI, Vercel and Sentry) process data outside Ukraine, including in the United States and the EU. We share only the data each provider needs for its function.

Usage analytics are stored in PostHog's EU region.

Retention

We keep data only as long as it is needed for the purposes above. Usage analytics are kept for up to 1 year. Deleting your account deletes the related records in our database. Payment records may be kept separately as required for accounting and dispute handling.

Age

The service is not intended for anyone under 18, and we do not knowingly collect their data. If you believe such data has reached us, write to support@mymgr.app and we will delete it.

Cookies

Until you choose in the analytics banner, and if you decline, analytics only counts visits in aggregate (see below) and stores nothing in your browser. Your choice itself is remembered in browser local storage (`mm:analytics-consent`) so that we do not ask again. If you allow analytics, PostHog stores a first-party cookie `ph_<project>_posthog` on mymgr.app for up to 365 days, plus related data in browser local storage, to recognise repeat visits and link visits made before and after sign-in, including the campaign tags of your first visit. Without permission, PostHog stores nothing in your browser; it counts visits only in aggregate from a technical hash of the request, which is not linked to your account. You can change your choice at any time via “Analytics settings” at the bottom of every page and in the app settings. Withdrawing removes the PostHog cookie and local data and stops analytics linked to you; aggregate counting continues as after a decline. After sign-in, the app also uses browser local storage for your session and settings.

Your rights

You can request a copy of your data, a correction, or deletion of your account and its data by writing to support@mymgr.app from your account email.

You can withdraw analytics consent at any time via “Analytics settings”. Withdrawal does not delete analytics already collected; to have it deleted, write to support@mymgr.app. Deleting your account also deletes it.

UK