Privacy Policy
Last updated: August 2026
Who controls your data
The data controller is Bosphorus Elevate LLC, registered in Delaware, United States. For any privacy question or request, email privacy@passats.pro.
What we collect
When you use PassATS, we process:
- Your uploaded resume file (PDF or DOCX) and any job description you provide
- Payment and transaction information handled by Stripe
- Limited operational telemetry, such as request IDs, file type, analysis score, detected role, and error details
- Which steps of the process you reached, recorded against a random identifier that lives only in your browser tab and is discarded when you close it
Why we are allowed to process it
We process your resume and job description to perform the contract you entered into when you paid for an analysis. We process payment data to meet our legal obligations around tax and accounting. We process operational telemetry under our legitimate interest in keeping the service working and diagnosing failures, and that telemetry never contains your resume text.
What happens to your resume
Your resume is processed in real time and deleted from our temporary storage when the request finishes, including when analysis fails. We do not store resume text in analytics, and we do not use your resume to train AI models.
How long we keep things
| Data | Kept for |
|---|---|
| Resume file and extracted text | Deleted when the request finishes. Never written to a database. |
| Your analysis report | Held only in your own browser tab. We do not keep a copy. |
| Payment records (Stripe) | As long as tax and accounting law requires, typically seven years. |
| Operational logs and telemetry | Up to 90 days, then deleted. |
Payment data
All payments are processed through Stripe. We never see or store your credit card details. Stripe's privacy policy governs their handling of your payment data.
Cookies and tracking
PassATS uses Vercel Web Analytics for basic page traffic and may use PostHog for server-side operational events and error diagnostics. Neither sets advertising cookies, and neither receives your resume text or job description.
We load no third-party analytics script on the page. To understand where people get stuck, the site tells our own server which step you reached, from a fixed list of step names, alongside the tab-scoped random identifier described above. The server accepts nothing else, so no part of your resume or job description can reach an analytics tool through it.
Server-side events about a purchase are grouped under a one-way cryptographic hash of your checkout reference, not the reference itself. This lets us see that one purchase produced one report without our analytics tool holding anything that can be traced back to your payment or your identity. The hash cannot be reversed without a secret that stays in our deployment.
Data sharing and international transfers
We do not sell or rent your data. We use service providers only to operate PassATS: Stripe for payments, Anthropic for resume analysis, Vercel for hosting and web analytics, and PostHog for optional operational telemetry. Resume text and job descriptions are sent to Anthropic for analysis and are subject to their data processing terms.
Some of these providers process data in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an equivalent approved transfer mechanism, in each provider's data processing agreement.
Your rights
If you are in the EU or the UK, you have the right to access, correct, delete, restrict, or object to our processing of your personal data, the right to data portability, and the right to withdraw consent where processing relies on it. Because we do not retain your resume, most of these requests concern payment records and logs.
Email privacy@passats.pro and we will respond within one month. You also have the right to complain to your local data protection authority.
Contact
Questions? Email privacy@passats.pro. For refunds and support, email support@passats.pro.