MatchRadar

Privacy Policy

Last updated: 8 September 2026

This policy explains how Tibidabo Consulting SRL ("we", "us") processes personal data when you use MatchRadar at matchradar.ai. We are the controller for the MatchRadar account and product data described below. Contact us at info@tibidaboconsulting.ro for privacy questions or requests.

1. Data we process

  • Account and identity: your email address, your first and last name (asked when you create an account with an email and password, and editable at any time on your Account page), your MatchRadar account identifier, account dates and plan status. If you choose Google Sign-In, Google supplies an identity identifier, verified email and basic profile information such as your name and profile image. If you choose LinkedIn Sign-In, LinkedIn supplies an identity identifier, primary email and basic profile information. If Apple Sign-In is offered and you choose it, Apple supplies an identity identifier and verified email, which may be an Apple private-relay address. MatchRadar itself uses the resulting account identifier and email.
  • Profile and CV: the CV text you upload, a structured profile derived from it, country, location and remote-work preferences, target roles, skills, industries, candidate-confirmed vendor or product experience, keywords, score threshold and shortlist size.
  • Matches and activity: job matches, scores, explanations, coverage and gaps; saved or dismissed status; product events; model usage totals; and data-export or account-setting actions.
  • Feedback: the category, short summary and details you submit, a product-area label, an internal reference and, only if you choose to provide it, an email address for a reply. Please do not include passwords, payment details, sign-in links or unnecessary sensitive information.
  • Security and connection data: service providers may process IP address, device/browser information, request timing and security signals needed for TLS delivery, rate limiting, fraud prevention and Turnstile bot checks. We do not use this data for advertising.
  • Page-view analytics: when a page of this site loads in your browser, MatchRadar uses the request IP transiently for rate limiting and immediately converts it to a keyed pseudonymous identifier before storage. We retain the page route without its query or fragment, reported country, a coarse device category and — only when you arrived from another website — that website's origin without its path or query. We do not retain the raw IP or full browser user-agent in this analytics dataset. It sets no analytics cookie, stores nothing on your device, is never combined with your account or CV, and is not shared with an advertising or analytics company. Distinct identifiers are not treated as unique people. Records are deleted after at most 30 days.
  • Authenticated product analytics: when this deployment has PostHog enabled and you are signed in, we send a random MatchRadar account identifier and a small set of predefined product events to PostHog's EU service. Those events cover a normalized app screen, finite account-access and radar-readiness states, a recognized MatchRadar digest entry, onboarding step and refusal category, inbox availability and controls, successful save/dismiss/rating actions, an outbound apply handoff, fit-check verdict band, settings and CV-maintenance actions, plan and checkout transitions, confirmed subscription payments, renewals, payment failures and subscription endings, a coarse source category for the current signed-in entry, and feedback category. Payment events contain no amounts or payment details. The events record only the bounded state or action, never the underlying profile, match, file or message values. They do not include your email, name, CV, target roles, skills, job identifier, job title, job or fit-check text, scoring explanation, feedback message, URL query or fragment. Automatic click capture, session replay and person profiles are disabled. This channel writes no cookie, local-storage or session-storage identifier; its in-memory state ends when the page closes.

Fit check: when you paste a job posting into the fit check, MatchRadar sends that text together with your stored CV — redacted as described below — to the configured AI provider, and returns the score, verdict and gaps to you. The posting text and the verdict are not saved: unlike your daily matches, a fit check is returned and not stored. MatchRadar retains only content-free usage and budget records for it.

Before CV text is sent to the AI provider, MatchRadar automatically redacts common contact details such as email addresses, phone numbers, street addresses and personal profile links. This local, automated safeguard does not replace data minimisation: please remove unnecessary sensitive or special-category information before upload. MatchRadar's scoring instructions also prohibit inferring or scoring protected personal attributes.

2. How and why we use data

We process data to:

  • create and secure your account;
  • build the profile you review and generate job-fit matches;
  • show, save, dismiss, export and delete your MatchRadar data;
  • review feedback, diagnose problems and improve the product;
  • enforce limits, prevent abuse and keep the service reliable; and
  • meet legal obligations and establish or defend legal claims.

Where the GDPR applies, our principal legal basis is performance of the service you request (Article 6(1)(b)). Security, abuse prevention, service reliability and both page-view and authenticated product analytics rely on our legitimate interests (Article 6(1)(f)). We use consent where the law requires it, and legal obligation where applicable.

Your right to object. Where we rely on legitimate interests — which includes both analytics channels described above — you have the right to object to that processing at any time. Write to privacy@matchradar.ai and we will stop it for you and delete the analytics records we can associate with your request. You do not have to give a reason, and objecting does not affect your account or your matches.

Match scores are automated recommendations for you. They do not make hiring decisions, are not shown to employers and do not produce legal or similarly significant effects. You decide whether and where to apply.

If you choose the optional email-link sign-in, MatchRadar generates that authentication message and our transactional email provider delivers it from the MatchRadar domain. Google, LinkedIn and Apple sign-in do not send an email-link message. LinkedIn uses its OpenID Connect authorization page and returns through the MatchRadar authentication callback.

3. Google, LinkedIn and Apple account data

Google Sign-In requests only OpenID identity, email and basic profile scopes. We use Google account data only to authenticate you, link you to your MatchRadar account and operate account features. We do not request Google Drive, Gmail, contacts or offline access, and we do not retain a Google API access or refresh token. The one-time Google identity token and nonce are handled in memory during sign-in; MatchRadar then issues the session itself.

We do not sell Google user data, use it for advertising, provide it to data brokers, use it to determine creditworthiness, or use it to train AI models. Google identity data is not sent to our AI scoring provider.

LinkedIn Sign-In requests only OpenID identity, primary email and basic profile scopes. We use that data only to authenticate you and operate your MatchRadar account. We do not request access to your LinkedIn connections, messages, job applications or job-search activity; we do not call LinkedIn APIs with the provider token or store that token in the MatchRadar application database. LinkedIn identity data is not used for job scoring, advertising or AI training and is not sent to our AI scoring provider.

If Apple Sign-In is enabled, MatchRadar requests only the email identity scope. Apple lets you share your address or use its private email relay. We use the Apple identifier and verified email only to authenticate you and operate your MatchRadar account. The one-time Apple identity token, nonce and anti-forgery state are handled in memory; we do not retain an Apple access or refresh token, and Apple identity data is not sent to our AI scoring provider.

4. Service providers and disclosures

We use processors only as needed to provide or secure MatchRadar:

  • Google: identity verification, only when you choose Google Sign-In;
  • LinkedIn: identity verification, only when you choose LinkedIn Sign-In;
  • Apple: identity verification, only if Apple Sign-In is enabled and you choose it;
  • netcup: EU (Germany) hosting for the application, the background worker and the database that stores your account, CV, profile and match records;
  • Cloudflare: DNS, TLS, content delivery, Turnstile security and inbound support-email forwarding;
  • Brevo: transactional delivery of authentication messages, job digests and service notifications;
  • Stripe: checkout, subscription management, payment processing and tax calculation on our behalf. Stripe receives the billing details you enter at checkout; we never see or store your card details.
  • OpenWebNinja JSearch, Careerjet and TheirStack: discovery of public job postings, including postings published through LinkedIn. We send only active radars' target role, keywords and base market—not CV text, email addresses, account identifiers or match history.
  • Voyage AI: relevance re-ranking of candidate job postings against your profile. It receives your declared search and a truncated, redacted extract of your CV together with the postings being ranked. It does not produce your fit scores or explanations.
  • OpenAI: the current AI provider for CV profile generation and job-fit scoring. We send only the content needed for that task, not your Google, LinkedIn or Apple identity data.
  • Sentry: error and performance monitoring for the application and the nightly worker. It receives exception details, stack traces and request metadata, which may incidentally contain personal data appearing in an error message. It is not used for analytics, profiling or advertising.
  • PostHog: EU-hosted product analytics, only when enabled for the web deployment and only for signed-in product use. It receives the random account identifier, bounded events described in section 1 and ordinary connection/device metadata needed to receive those events. It receives no CV, contact details, free text or raw job identifier, and is not used for advertising or cross-site tracking.

Anthropic is not currently used as an AI provider. Stripe processes billing data only when you choose a paid subscription or manage an existing one. For an active radar, the daily job digest contains either the strongest new matches that clear your chosen threshold or a concise no-strong-matches status. Operational notifications use independent delivery switches. We may also disclose data when required by law or to protect users, the service or legal rights. We do not sell personal data.

Public job postings come from employer and applicant-tracking sites such as Greenhouse, Lever and Ashby, from JSearch's Google for Jobs index, and from Careerjet and TheirStack. We do not send your CV, contact details or account identity to those sources. If you follow an external application link, that third party processes your visit under its own terms and privacy policy.

5. International processing and safeguards

Core account, CV and profile records are stored in our EU-hosted database, and both it and the application compute run on our own server in the EU (Germany). Authentication runs in that same application and is not outsourced. Cloudflare, Brevo, Google, LinkedIn, Apple, OpenWebNinja, Careerjet, TheirStack, Sentry, PostHog, Voyage AI and other AI providers may process data globally, including outside the EEA. Where required, we rely on the provider's contractual transfer safeguards or another lawful transfer mechanism. Contact us for more information about the safeguards relevant to your data.

6. Retention and deletion

  • Account, CV, profile, saved matches, usage ledger and account events are kept until you delete the account or they are no longer needed for the service.
  • Dismissed matches are deleted after 30 days.
  • Authentication sessions last until expiry or sign-out; the authentication identity is removed with account deletion.
  • Security and platform logs follow the limited retention configured with the relevant provider.
  • Page-view records — route without query/fragment, keyed IP pseudonym, reported country, coarse device category and any external referrer origin — are deleted after at most 30 days.
  • Authenticated PostHog product events are retained for at most 12 months and can be deleted earlier when you exercise an applicable right. Account deletion ends new collection immediately; contact us if you also want the retained PostHog event history removed before its scheduled expiry.
  • Feedback and an optional reply address are kept for up to 24 months, or less when no longer needed to resolve the issue or improve the service.
  • Support correspondence — the messages you send to info@tibidaboconsulting.ro and our replies, with their subject, date and sender address — is kept for up to 24 months, or less when no longer needed. File attachments are not stored on our servers; we record only the file name, type and size. Correspondence tied to your account is deleted with the account.
  • Content-free global capacity records and pseudonymous operational summaries are kept only as long as needed for abuse prevention, cost control and service operations.
  • Encrypted backup copies may retain deleted records temporarily until the backups are securely rotated; access is restricted and backups are used only for recovery.
  • After account deletion, we keep an irreversible SHA-256 hash of the random authentication subject and a non-identifying deletion audit record. These records contain neither your raw identifier nor email and are retained to prevent an old session from recreating a deleted account and to evidence the deletion operation.

Public job-posting records are not tied to your account and are not removed when you delete it.

Delete your account from Profile → Data & account. This removes the MatchRadar account data and authentication identity. You may also email info@tibidaboconsulting.ro. Deleting MatchRadar does not delete your Google, LinkedIn or Apple account. You can remove MatchRadar from LinkedIn's permitted services separately. If you used Apple Sign-In and want to revoke its authorization, you can also remove MatchRadar from your Apple Account's Sign in with Apple settings.

7. Storage on your device and security

MatchRadar keeps sign-in state in a host-only session cookie marked HttpOnly, Secure and SameSite=Strict. JavaScript cannot read the cookie, and access or refresh tokens are not stored in browser storage. Public account display data is held in memory only. Cloudflare Turnstile, Google Identity Services and, when enabled, Apple Sign-In may use browser storage, cookies or browser-provided identity mechanisms for security and sign-in. LinkedIn receives ordinary browser and connection data only after you choose its sign-in button and navigate to LinkedIn. MatchRadar does not use advertising or cross-site tracking cookies.

Our page-view analytics is deliberately cookieless: it writes no cookie and no identifier to your browser or device, and it does not read one. That is why you are not shown a cookie banner for it. The trade-off is stated plainly in section 1 — with nothing stored on your device, we cannot recognise a returning visitor. The server-side keyed pseudonym lets us count repeat views during the short retention window, but it is not a count of unique people.

Authenticated product analytics is also configured without cookies or browser storage. It uses memory only while the page is open, disables automatic click capture and session replay, and sends only the predefined events in section 1. We do not use PostHog to follow you across other websites or for advertising.

Safeguards include TLS in transit, restrictive browser security policies, least-privilege runtime access, server-side authorization, rate limits and encrypted operational backups. No service can guarantee absolute security; contact us promptly if you suspect misuse of your account.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing relies on consent. Export a portability copy of your MatchRadar data as JSON, or delete the account, from Profile → Data & account, or contact info@tibidaboconsulting.ro. We may need to verify your identity before acting on a request.

You may also lodge a complaint with a data protection supervisory authority — in particular in the country where you live or work, or with the operator's supervisory authority (the ANSPDCP).

9. Children and policy changes

MatchRadar is intended for adults seeking work and is not directed to children. We may update this policy when the service or legal requirements change. The current version and update date will remain available on this page; we will give additional notice before a material change where required.