Privacy Policy
What we collect, why, and where it goes.
Fyxor is a Chrome extension and account that tailors your CV to a job description. This covers everything the extension and account collect — your CV, the job descriptions you tailor against, your login details — and how each is used. Last updated 7 July 2026.
What we collect
Account details. Your email address and password when you create an account. Passwords are hashed (scrambled) before they’re stored; we don’t have a way to read them back in plain text. Legal basis: performance of a contract (GDPR Art. 6(1)(b)) — we can’t give you an account without it.
Your CV content. The profile you build or upload — name, contact details, work history, education, skills, and certifications — either typed in directly or extracted from a PDF/DOCX file you upload. Legal basis: performance of a contract (GDPR Art. 6(1)(b)) — it’s the input the tailoring service exists to work with.
Job description text. The job posting you paste in, or — only on LinkedIn job pages, and only when you use the extension there — the listing the extension reads from the page so you don’t have to copy it yourself. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
Usage data. Basic records of your tailoring runs (timestamps, status) so you can track past results and so we can enforce fair-use limits (stopping one account from running an unreasonable number of tailoring jobs a day). We don’t run ad trackers or fingerprint your device. Legal basis: our legitimate interest in running and securing the service (GDPR Art. 6(1)(f)).
Why we collect it
Everything above serves one purpose: turning your CV and a job description into a tailored CV. Your uploaded CV is parsed into a structured profile; your job description is analyzed against it; the two are combined to rewrite your summary, experience bullets, and skills section. Your account lets that work sync across devices and lets you come back to past runs.
We process your CV and job description content because it’s necessary to provide the tailoring service you’re asking for, and we process account and usage data based on our legitimate interest in running and securing the service. We don’t use any of this data for advertising or for any purpose beyond providing and improving this feature.
Who else sees your data
We don’t sell or hand your data to advertisers or data brokers. A short list of parties process it on our behalf, only to the extent needed to run the service:
OpenAI — our AI provider, which receives your CV and job description text to perform the tailoring (see “AI processing” below for what that means for cross-border transfer).
Our hosting provider — the infrastructure our server and database run on. They can access data only as needed to keep that infrastructure running, not for their own purposes.
We don’t currently use a payment processor, SMS provider, or analytics/tracking service. If that changes, we’ll update this section and call it out.
AI processing
Tailoring is done by OpenAI, the only AI provider we currently use. OpenAI receives the full text of your CV and the job description for the duration of a tailoring request — not just a summary — because that’s what the rewrite needs. It never receives your account password.
OpenAI is based in the US, so using it means your data crosses borders. As of this writing, OpenAI’s API terms state that data sent through the API isn’t used to train its models; we don’t control OpenAI’s infrastructure directly, so that assurance rests on OpenAI’s terms, not just ours. Transfers rely on the safeguards OpenAI has in place for international customers (such as standard contractual clauses). If we ever add or switch AI providers, we’ll update this page and call out the change.
How it’s stored
Your account and CV data live in our own database, on our own server — never a third-party data broker. Everything travels over encrypted (HTTPS) connections. A copy of your working profile, along with the session token that keeps you signed in, is also kept in your browser’s local storage so the extension works offline between syncs.
We keep your data while your account is active. If you delete your account or ask us to erase your data, we remove it — including from backups — within 7 days. We don’t sell, rent, or share your data with advertisers, and we don’t use it to train our own models. We’ll only hand data to a third party if the law requires it, if it’s necessary to prevent abuse of the service, or as part of a merger, acquisition, or sale of the business — in which case the rights in this policy carry over to whoever takes it on. If a data breach ever affects your personal data, we’ll notify you and any authority required by law without undue delay.
Extension permissions
The extension requests only what its features need: storage to save your profile locally, downloads to save exported CVs, contextMenus and activeTab/scripting to send a highlighted job description from the page you’re on, and tabs to open the extension in its own tab and to read the job listing from the LinkedIn tab you’re currently on. Host access is limited to linkedin.com (to read a job listing you’re viewing there) and our own backend API (to sync your profile and run tailoring requests). None of this is used to track your browsing outside of that purpose.
Your rights
You can ask us at any time to access, correct, export, or delete the data we hold on you — profile, tailored CVs, and job description history included — and we’ll act on deletion requests within 7 days. You can also ask us to restrict or object to a particular use of your data, and if you’re in the EU/UK, you can lodge a complaint with your local data protection authority. If you’re a California resident, the same rights apply under the CCPA — we don’t sell your data, so there’s nothing to opt out of, but you can still ask what categories we hold on you.
Just send a note to cccopsmaster@gmail.com and we’ll take care of it.
Changes to this policy
We may update this policy as Fyxor changes. If we make a material change — like adding a new AI provider or a new category of data — we’ll update the date below and call it out on this page. The date always reflects the current version.
Children’s privacy
Fyxor isn’t directed at children, and we don’t knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we’ll delete it.
Who operates Fyxor
Fyxor is operated by Azizbek Khaitov (NIP: 4308032187), based in Poland. This is the person responsible for the data described in this policy; the contact below reaches the same team.
Contact
Questions about this policy or your data? Reach us at cccopsmaster@gmail.com.