Legal
Privacy Policy
Last updated: 20 September 2026
Lykka helps you apply for jobs: it stores the career history you give it, compares it against job descriptions, and generates tailored resumes and cover letters. That means we handle personal data that matters to you. This policy says — in plain language — what we store, what we do with it, who else touches it, and what your rights are. The plain language is the policy; there is no second, hidden version.
1. Who is responsible, and who this applies to
The data controller is William Nord, operating as Nord Digital Labs (sole proprietorship, Ennetbaden, Switzerland — postal address in the Impressum) ("Lykka", "we"). Contact: support@lykka.io.
We are based in Switzerland. Lykka is designed for worldwide availability; during the current invited private beta, access is by invitation only. This policy is written to the strictest standard we serve — the EU General Data Protection Regulation (GDPR) and the revised Swiss Federal Act on Data Protection (nFADP) — and we apply the same rights and protections to every user, wherever you are. For users in the United States: we do not sell or share personal data for advertising in the sense of the CCPA/CPRA, and the rights in §7 are available to you the same as to everyone else.
2. What we collect
- Your account. Name and email address. Your password is handled transiently to sign you in and is stored only as a hash by our authentication provider — Lykka never stores it in plaintext. Optionally a profile photo. Your plan and product preferences (tone, focus area, target country and city, export format).
- Private beta and waitlist. During the invited beta we keep the invited email address, whether access is active or revoked, and the beta-feature allowances used. If you are not invited and ask to join the waitlist, we keep the email address and collection time only. Joining the waitlist is not consent to marketing.
- Personal details for your documents (optional). If you choose to add them, we store the details some job markets expect on a resume header: phone number, LinkedIn URL, nationality, work permit status, date of birth, and up to two application photos. You control these; leaving them empty is always allowed and the product works without them.
- Your career data. Work history, education, certifications, skills, tools, languages, professional summary, career goals — entered by you or extracted from a resume you upload. This includes your target role titles and, derived from them, numerical similarity representations (embeddings) we compute to rank job matches.
- Uploaded files. Resume files you upload (PDF/DOCX/TXT), stored in a private bucket, plus the text we extract from them.
- What Lykka is not designed for. Please don't include medical information, disability details, racial or ethnic origin, political or religious beliefs, trade-union membership, sexual-orientation information, criminal records, government ID numbers, or other highly sensitive information in your career data or uploads — remove it before uploading unless it is genuinely needed for your application. If we ever decide to support intentional processing of such information, we will first add the required consent flow and explain it here.
- Your applications. Job descriptions you paste or select, match scores and per-dimension match analyses, the applications you track, and every version of the resumes and cover letters Lykka generates for you.
- Other sources and other people. If you choose Google sign-in, Google gives us basic account details — your Google account identifier, name, email address, and profile image — so we can create or sign in to your account. Google also learns that you chose Google sign-in; Google handles its side under its own privacy policy. Separately, resumes and job listings can contain professional details about other people, such as a reference's or recruiter's name and contact details. We receive these from files or text users provide and from public employer job pages and ATS feeds, and we process them only as part of that resume or listing — we do not build contact lists or use them for marketing. Our legal basis is our legitimate interest in providing Lykka's drafting and job-matching service while limiting this incidental use. If this describes your data, the rights in §7 apply to you too.
- Usage records. Records of your use of metered features — AI actions, document exports, resume uploads/extractions, and embedding updates — with endpoint, timestamp, and token counts where applicable (including attempts that failed after reaching our AI provider; that's how fair-use limits work).
- Billing coordination and security records. If you open Checkout or buy Lykka+, Lykka keeps only the server-side coordinates needed to attribute the subscription safely, stop its exact renewal during account deletion, process signed Stripe events, and audit owner support. These can include one-way billing-subject fingerprints, environment and lifecycle state, the exact Stripe subscription and approved price, minimum webhook/deletion-operation state, and an owner-support audit with purpose, time, target account, safe outcome, and a one-way subscription fingerprint. We do not store the billing email, payment method, card details, invoice body, Checkout URL, or raw webhook body in these records. After deletion, the account link is erased and a stable one-way retired-subject digest can remain temporarily to recognize replay of an already- issued Checkout identity.
- Notifications. The in-app notifications we send you.
- If you delete your account. We keep a deletion record with no email address, account ID, or other identifier — the time and any feedback you chose to leave — so we can learn why people leave. Free text can still identify you if you include personal details in it, so please don't. We keep the feedback text for up to 12 months, then delete it; the bare deletion timestamp may be kept as an anonymous statistic.
- Technical and security basics. The session cookies needed to keep you signed in, and browser security reports (Content-Security-Policy violation reports, which contain the page and blocked-resource URLs, not your content). The public waitlist uses Cloudflare Turnstile for bot detection; it processes security signals including IP address, TLS/browser information, the site key, and page origin. Lykka sends the short-lived verification token — not your waitlist email — to Cloudflare for validation and does not retain that token or response. We do not run advertising trackers, and we do not sell personal data or share it for targeted advertising.
3. Why we process it (purposes and legal bases)
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Store and let you edit your career data; score job matches; generate resumes and cover letters; export documents | This is the product you signed up for | Contract performance (Art. 6(1)(b)) |
| Keep you signed in; protect accounts; enforce fair-use limits; collect security telemetry | Security and fair use | Legitimate interests (Art. 6(1)(f)) |
| Store optional personal details and photos for document headers | You choose to include them | Contract performance; provided voluntarily |
| Send account emails (confirmation, password reset) | Operating your account | Contract performance |
| Operate Lykka+ checkout, entitlement, subscription support, payment administration, and exact non-renewal during account deletion | Provide and secure the paid service; administer the contract; meet billing and legal duties | Contract performance (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)); legitimate interests in fraud prevention, support, and recovery safety (Art. 6(1)(f)) |
| Administer private-beta invitations, prevent repeated free-quota resets, and respond to waitlist requests | Controlled access, fair use, and responding to your request | Legitimate interests (Art. 6(1)(f)); steps at your request where applicable |
| Keep a minimal record when an account is deleted | Product learning; evidence of deletion | Legitimate interests |
| Use the basic account data received through Google sign-in | Authenticate you using the method you chose | Contract performance |
| Answer support and privacy requests and investigate security reports | Help you, protect the service, meet legal duties, and handle legal claims | Contract or steps at your request; legal obligation; legitimate interests where applicable |
| Disclose the minimum necessary in exceptional cases (§5) | Valid legal requests, security incidents, legal claims, or a business succession | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| Retain records where the law requires | Compliance | Legal obligation (Art. 6(1)(c)) |
You are not legally required to give Lykka personal data. An email address and a sign-in method are needed to create an account, and an email address is needed to join the waitlist. Career information and a job description are needed for the matching and drafting features you ask us to perform — without them, we cannot provide the corresponding feature. Header details, photos, feedback, and the other fields marked optional are never required.
We do not use your data for advertising, we do not profile you for third parties, and we make no automated decisions with legal or similarly significant effects. The AI drafts documents; you decide what to do with them.
4. The AI processing — said plainly
This is the part most policies bury. We won't.
What goes to Anthropic (our AI provider, processing in the United States), depending on the feature you use:
- Match scoring and document generation: your career narrative (work history, education, certifications, skills, languages, summary) and the job description (including its title, company, location, and — for generation — the posting's URL). Fields like your user ID, legacy data, and internal bookkeeping are excluded from these calls; the payload is the professional story the product exists to work with.
- Your identity is pseudonymized before these calls leave our systems: your name, contact details, and the optional header details are replaced with neutral placeholder tokens before match scoring and generation; the real values are re-inserted only after the AI's answer comes back to us. The one designed exception is resume-upload parsing, described below. Honest caveat: names or contact details you type into free-text career content (for example inside a bullet point) are not reliably detectable and may ride along.
- Onboarding and "strengthen this role": the role details in question (titles, employers, bullets), your target roles, and the answers you give in the worksheet — so the AI can suggest responsibilities and draft bullets for you.
- Regenerating a section: the current version of that generated document and the stored job analysis, so the revision fits what's already there.
- Resume upload: the file's extracted text is sent to Anthropic to parse. A resume inherently contains your identifiers; this specific flow cannot be fully anonymized without breaking it, so we disclose it here explicitly.
- Anthropic does not use our API content to train its models, and conversation content is not retained by default on the API endpoints we use (content flagged by its trust-and-safety systems can be held up to 2 years). Lykka itself never uses your content to train any model.
What goes to Voyage AI (United States): public job titles and your chosen target-role titles — sent as bare text with no account identifiers and none of your broader career history — to compute similarity rankings. Voyage may retain and use that title text under its standard terms; it receives no Lykka account identifier and none of your broader career history, which materially reduces its ability to link a title to you.
Job descriptions sometimes contain third-party contact details (e.g. a recruiter's email). Lykka passes the text through for analysis; we don't harvest or store those contacts for any separate purpose.
5. Who else receives data (subprocessors)
We use a small number of service providers to run Lykka. The full list, what each receives, and where they process it is published at /subprocessors. In short: Supabase (database, authentication, file storage — hosted in Switzerland), Anthropic (AI, US), Voyage AI (embeddings, US), Cloudflare (Turnstile waitlist bot detection; browser security signals, not the waitlist email), Netlify (web hosting — as the host it transiently processes the web requests that make the app work, including sign-in requests and file uploads; it does not hold the database), Zoho Mail (the support inbox — it holds what you choose to send to support@lykka.io; EU data center), Resend (transactional account emails — confirmation and password reset), and Sentry (server error monitoring, EU — receives scrubbed error reports from our servers, never anything from your browser; deleted after 90 days). When you buy Lykka+, two more providers are involved: Superwall (Nest22, Inc., US) hosts the purchase screen and keeps the record of which subscription unlocks Lykka+ for your account. It receives a pseudonymous billing identifier (not your Lykka account ID), the email you type at checkout, and purchase and paywall events, never your career data. Stripe (payment processing, global) receives the email, payment method, billing country and tax details you enter at checkout and issues receipts and invoices. Stripe acts as our processor for running the payment and as an independent controller for fraud prevention and its own legal compliance; for those activities its own privacy policy applies. Where a provider processes data outside Switzerland/the EEA, we rely on recognized transfer safeguards — in particular Standard Contractual Clauses — stated per provider on the subprocessor page.
The subprocessor page identifies the destination and safeguard for each transfer. Where a destination has not been recognized as providing adequate protection, we use the safeguard named there — usually Standard Contractual Clauses adapted for Switzerland. Email support@lykka.io if you would like a copy of the clauses that apply to your data; we may redact commercial details that do not affect their protections.
Exceptional disclosures. We may disclose the minimum data necessary when a valid law, court order, or competent authority requires it; to investigate abuse or a security incident; to establish, exercise, or defend a legal claim; or to a successor if Lykka is reorganized or transferred. A successor must respect this policy and applicable law, and we will give notice where the law requires it. We do not disclose data merely because someone asks.
We update the subprocessor list before adding any new provider that touches user data.
6. How long we keep it
Your data is kept while your account exists — it's your working material, not a log we mine.
- Delete your account (Settings → Delete account) and your profile, career data, applications, generated documents, match analyses, notifications, usage records, and your files in storage (uploaded resumes and photos) are deleted in the same step; if a transient storage error interrupts the file removal, an automated cleanup backstop removes any remainder within days. What remains: the anonymous feedback record described in §2. During private beta only, the minimum invited-email and allowance record also remains so deleting and recreating an account cannot reset the five-generation beta limit. It is deleted 30 days after private beta closes. A separate userless provider event (paid feature, conservative risk weight, and timestamps only) may remain for up to 48 hours so the rolling 24-hour safety limit cannot be reset by deletion; it contains no account id, email, prompt, or output.
- Billing records survive account deletion. Deleting your account stops any Lykka+ renewal and erases your Lykka data, but it does not erase the payment history held by Stripe: invoices, receipts, the name, billing email, country and card details you entered, and any refund or dispute records. Stripe keeps these for as long as tax, accounting and anti-fraud law requires (in Switzerland ten years for accounting records) and processes them under its own legal obligations. Superwall keeps the pseudonymous billing identifier, checkout email and purchase events for your former account until we ask it to delete them; on a verified request to support@lykka.io we forward an end-user erasure request through Superwall's documented privacy contact. Completion timing is controlled by Superwall and its backup process. None of this data lets Lykka restore your account or identify you inside Lykka.
- Lykka billing-security records are minimized and time-bounded. Exact subscription associations, deletion operations, and signed- webhook work remain service-only until provider cleanup is safely complete; terminal operation and event evidence is normally removed after 30 days. Owner support audits remain for 12 months unless a documented legal or security hold applies. The userless retired- subject digest remains only while an already-issued static Checkout identity can technically be replayed; we review it at least annually and when Checkout changes, and purge it after provider-enforced non- replayability or complete retirement of the subject format plus the final provider-delivery window.
- A waitlist address is deleted when it becomes an invite, when you ask us to remove it, or 12 months after collection, whichever comes first.
- Uploaded resume files are deleted 30 days after successful extraction — the extracted text and the career data built from it remain yours in the app. Notifications you have read or dismissed are removed after 90 days. Failed sign-in throttle records live 24 hours. Usage records are kept while your account exists (that is how fair-use limits work); if we later aggregate older records, this policy will say so first.
- Applications you archive stay visible in your archived lane — they are your history, not hidden storage — and are erased when your account is deleted. Saved jobs you remove are deleted right away.
- Support email (what you send to support@lykka.io and our replies) is normally deleted within 12 months after a conversation is resolved — or sooner on request where we can — unless we need it for a legal obligation, a security investigation, or to establish, exercise, or defend a claim.
- Public job listings stay visible while active; expired copies are retained only as long as needed to prevent duplicates, keep the catalogue accurate, and preserve applications that already refer to them.
- Database backups at our hosting provider expire automatically after a bounded period (currently 7 days; never more than 30).
7. Your rights — for everyone, everywhere
We use the same privacy-request process for everyone whose personal data we process — users and non-users alike, wherever you live, and not only where the law requires it. These rights remain subject to identity checks and the exceptions, limits, and protections required by applicable law:
- See and correct your data — most of it is directly visible and editable in the app (profile, career data, applications).
- Delete it — the in-app account deletion, no email required.
- Take it with you (portability) — the in-app "Download my data" export (Settings) gives you your account, career data, applications, and generated documents as a machine-readable archive, after a short email confirmation step that protects it from a hijacked session.
- Ask about restricted billing-security records — they are not included in the normal self-service export because exposing internal provider locators, administrator identity, or anti-replay material would weaken security. After identity verification, a formal access request can receive a rights-reviewed sanitized summary where applicable law requires it.
- Object or ask us to restrict processing — when we rely on legitimate interests, you may object based on your particular situation, and we will stop that processing unless we have compelling legitimate grounds to continue or need it for a legal claim. You may also ask us to restrict processing in the circumstances provided by law. If we ever ask for your consent for a future feature, you can withdraw it at any time without affecting what already happened lawfully.
- Complain — in Switzerland to the FDPIC; in the EU/EEA to your local supervisory authority; elsewhere to your local privacy regulator where one exists. We'd appreciate the chance to fix it first: support@lykka.io.
We answer rights requests without undue delay and ordinarily within one month. Where the law allows more time because a request is complex or numerous, we may extend by up to two further months — and we'll tell you within the first month if so.
8. Security
We protect your data with layered technical and organizational measures:
- Access control enforced at the database level (row-level security), designed so that each account can reach only its own records; a small set of authorized server processes may operate across accounts for administration and cleanup.
- Encryption in transit (HTTPS across the production deployment) and at rest through our hosting provider.
- Restricted administrative access, protected by multi-factor authentication, with security-relevant events logged.
- A security-first development process, built against recognized industry practices (including the OWASP standards), with sensitive changes reviewed before they ship.
No system is perfectly secure. If a breach ever affects your data, we will notify you and the competent authority as the law requires. And if you think someone has accessed your Lykka account or data without permission, email support@lykka.io so we can investigate.
9. Cookies and your device
Lykka sets only the cookies required to keep you signed in (authentication/session). No advertising cookies, no third-party tracking cookies. Two narrow exceptions to "nothing else on your device", both functional: during account deletion, a temporary one-time token is placed in your browser's session storage so you can leave feedback afterwards — it is short-lived and tracks nothing. And on the page with the public waitlist form, the Cloudflare Turnstile bot-check widget keeps one small working value (cf.turnstile.u) in your browser — inside Cloudflare's own partitioned storage area, not our site's. It exists so the widget can tell humans from bots on the form you are submitting; in our audit it set no cookies, and the browser's partitioning is designed to prevent cross-site recognition. We treat both as technically necessary for the features you're using, which is why we show no consent banner — and if applicable law or a future implementation requires consent, we will ask for it before using that technology. We list them because we said we'd tell you about everything on your device.
Today, product usage is measured entirely inside our own systems, and no behavioral data is shared with any analytics third party. We plan to introduce privacy-respecting analytics over time to understand how the product is used — anonymized or aggregated wherever possible. Whenever such a tool is added, we will assess its data and device-storage impact first, update this policy and the subprocessor list before it goes live, and obtain consent where the law requires it.
Company logos displayed in the app are served from Lykka's own infrastructure. To obtain a logo, our servers request the icon for the company's domain from a public icon service (DuckDuckGo); your browser never contacts that service, and it receives only the company domain — never your IP address, your identity, or any of your data.
Buying Lykka+ takes you to two hosted pages that are not ours. The purchase screen is served by Superwall on its own domain and sets cookies there: a pseudonymous billing identifier (`_sw_app_user_id`), Superwall's alias for it (`_sw_alias_id`), a device identifier (`_sw_device_id`, kept for a year) and one short-lived cookie per checkout you open (`_sw_checkout_…`). We observed no advertising or analytics cookies; these exist so your purchase is credited to your account and can be resumed, and we treat them as necessary for the purchase you requested. Payment itself happens on Stripe's hosted checkout page, under Stripe's own privacy and cookie terms: Stripe and its partners store working data in your browser for the payment form, fraud prevention (`m.stripe.network`), bot protection (hCaptcha) and any wallet you choose (Google Pay, Link, Amazon Pay). Stripe is the controller for its fraud-prevention processing. Lykka receives none of that browser data; after payment you return to Lykka with no purchase details in the address bar.
When you follow a job posting or any other external link, the destination site handles what you do there under its own privacy notice — Lykka does not control that site's data handling.
10. Who Lykka is for
Lykka is built for people managing their own job search and is not directed at children. You must be at least 16 years old to create an account. If we learn that an account belongs to someone younger, we will delete it.
11. Changes
We'll update this policy when the product's data handling changes — material changes are announced in-app before they take effect, and the "last updated" date always reflects the current version.