Privacy Policy

Last updated: September 2026

This policy explains what BeSuix collects and how it's used, written plainly for a limited early launch. It is not legal advice.

1. Who is responsible

The data controller is Rubén Martín Cordero, Spain. Contact: besuix.app@gmail.com. We process personal data under the EU GDPR.

2. What we collect

  • Account data: name, email, password (stored hashed by our auth provider), and optional profile photo.
  • Profile content: everything you add, experience, education, skills, projects, documents you upload, and the CVs/letters Iris generates.
  • Usage data: basic logs and feature usage needed to run and improve the Service.
  • Billing data: handled by Stripe; we don't store your full card details.
  • Contact messages: your name, your email and whatever you write to us in the contact form, so we can reply. We keep them for up to 12 months after we answer, then delete them. We store a one-way hash of your IP address to block spam, never the address itself.

3. Why we use it (legal bases)

To provide the Service and your account (contract); to generate your documents via AI (contract); to keep the Service secure and working (legitimate interest); to send optional product emails (consent, you can opt out anytime in Settings); to comply with legal obligations.

4. AI processing

To draft your CVs and documents, the relevant profile content is sent to our AI provider (Anthropic) to generate output. The documents you upload are kept privately in your account, where only you can access them, so an import can be checked if something was read wrong; they are deleted when you delete your account. Your content is not used to train third-party models.

5. Service providers (processors)

We rely on trusted providers to operate BeSuix:
  • Supabase, database, authentication, file storage.
  • Anthropic, AI generation (Iris).
  • Stripe, payments.
  • Vercel, hosting and cookieless traffic measurement.
  • Google, optional sign-in with Google, and advertising measurement on our public pages, only if you accept cookies.
  • PostHog, product analytics and session replay, EU region. Sets a cookie only if you accept.
  • Sentry, error monitoring.
  • Resend, account and product emails.
  • Cloudflare, anti-spam protection on our forms.
  • Meta, advertising measurement on our public pages, only if you accept cookies.
Some providers may process data outside the EU under appropriate safeguards.

We never sell your personal data, and we do not hand it over to anyone for their own purposes.

6. Cookies and analytics

If you accept in the banner, we set one first-party analytics cookie (PostHog, EU region) so we can recognise repeat visits and see which ads work, plus the advertising cookies of Meta and Google. If you decline, analytics keeps running without cookies and anonymously, counting every visit as a new one, and neither Meta nor Google Ads ever loads. Session recordings mask all text and inputs, so your profile, the offers you paste and your CVs are never recorded. Advertising cookies only load on our public pages, never inside your account. Declining costs you nothing: the Service works exactly the same, and we remember your answer so we don't ask again. If you reach us from one of our ads, we store the campaign details alongside your sign-up so we can tell which ads work.

7. Retention

We keep your data while your account is active. When you delete your account, your personal data is removed (some minimal records may persist briefly in backups or where required by law). We keep a minimal record that the account was deleted (your email, the dates, who deleted it and a usage summary with none of your content, such as your plan or how many analyses you ran) for 12 months, so we can prove the deletion and prevent abuse of the free plan, and then we delete it. Contact messages don't depend on an account: they are kept for up to 12 months after we reply and then deleted.

8. Your rights

Under GDPR you can access, correct, export, or delete your data, and object to or restrict certain processing. You can edit or delete most data directly in the app, or email us at besuix.app@gmail.com. You may also complain to the Spanish data protection authority (AEPD).

9. Security

We use reputable providers and reasonable safeguards. No system is perfectly secure; as an early product, please avoid uploading highly sensitive information you wouldn't want processed by AI.

10. Changes

We'll update this page and the date above when things change, and notify you of material changes in the app.