Cookie Notice
Last updated 15 August 2026
We set two kinds of cookie: the ones without which you could not stay signed in, and product analytics. There are no advertising cookies and no third-party trackers selling your behaviour on.
Strictly necessary
These cannot be turned off, because the product does not function without them.
| Cookie | Purpose | Life |
|---|---|---|
authjs.session-token | Keeps you signed in after Google authentication. Marked httpOnly, secure and sameSite=lax, so it is not readable by scripts and is not sent on cross-site requests. | Session |
rc.guest | Set only if you start a tailoring before signing in. It holds a signed identifier — no name, no email — so the work you generate anonymously is still yours when you come back, and can be moved onto your account if you sign in. It is deleted when you sign in and claim that work. | Expires automatically |
authjs.csrf-token, authjs.callback-url | Sign-in security and returning you to the page you came from. | Session |
Analytics
We use PostHog to understand which steps of the flow people reach and where they get stuck — for example, how many people who upload a résumé go on to download a tailored one. This is how we find broken parts of the product.
| Cookie | Purpose | Life |
|---|---|---|
ph_* (PostHog) | Distinguishes one visitor from another so a funnel can be counted. Events carry internal ids, counts and durations only — never résumé content, never a job posting, never your email address. Where session recording is enabled, every input and all text is masked before it leaves your browser. | Up to 1 year |
You can turn analytics off with your browser's "do not track" setting or any standard blocker; the product works normally without it.
What we do not do
- No advertising or retargeting cookies
- No selling or sharing of behavioural data
- No cross-site tracking pixels
More detail on what we collect and why is in the Privacy Policy. Questions: soulaimane.boukrab@gmail.com.