Zusaga
BlogNewsPricing
DESign inOpen Zusaga

Privacy Policy

Controller within the meaning of Art. 4 (7) GDPR

Atieh VaziriEinzelunternehmen

Postal address
Thomas-Jefferson-Straße 14
68309 Mannheim
Deutschland
Email
legal@zusaga.com
Responsible for content pursuant to § 18 (2) MStV
Atieh Vaziri

This is a translation for convenience. The German version is authoritative; in case of any discrepancy, the German text prevails.

1. Overview

Zusaga is an online service that helps you search for jobs and prepare application documents: collecting and scoring job postings, tracking applications, and writing and improving resumes and cover letters. To do that we process personal data that you enter yourself.

The controller is the entity named above. Please send data-protection requests to the email address given there. We have not appointed a data protection officer; the statutory conditions requiring one are not met.

2. What data we process

Account data. Your email address, a cryptographic hash of your password (we do not store the password itself) or — if you sign in with Google, LinkedIn or GitHub — the identifier and email address supplied by that provider, plus your language setting and account preferences.

Application data. Everything you enter into your profile and documents: your resume with work experience, education, skills and contact details, cover letters, saved job postings, application status and your notes.

Chat and coach histories. Your inputs to the resume coach and the job chat, and the system’s responses.

Support data. If you open a ticket: your message, its language and its status, plus a small amount of context so we can reproduce what you describe — the page of the app you were on (without the web address’s query part), the size of your browser window, and a coarse description of your browser and operating system (for example “Chrome, Android, mobile”). We do not store your IP address with a ticket, and we do not take screenshots of your screen.

Usage and security data. Sign-in and security events (time, event type, IP address, browser identification), a throttling table for failed sign-in attempts (which stores a hash of the email address, not the address itself), and technical server logs.

Credits. The balance and consumption of your credits for AI features. We currently do not process payment data: no payment processing is active during the beta, no payment service provider is integrated, and we do not collect card or bank details.

Special categories. A resume may contain data specially protected under Art. 9 GDPR (e.g. health, disability status, religion, trade-union membership, origin, or a photograph). Such details are not required in order to use Zusaga. If you enter them voluntarily, we process them on the basis of your explicit consent (Art. 9 (2) (a) GDPR). You can withdraw that consent at any time by deleting the entry.

3. Purposes and legal bases

PurposeLegal basis
Providing the account and the features you useArt. 6 (1) (b) GDPR (contract)
Creating and improving resumes, cover letters and scores using AIArt. 6 (1) (b) GDPR (contract)
Searching for and scoring job postingsArt. 6 (1) (b) GDPR (contract)
Support and answering your enquiriesArt. 6 (1) (b) or (f) GDPR
Security, abuse and attack prevention, logging of sign-in eventsArt. 6 (1) (f) GDPR (legitimate interest in secure operation)
Compliance with legal obligationsArt. 6 (1) (c) GDPR
Special-category data in your documentsArt. 9 (2) (a) GDPR (explicit consent)

Your email address is required in order to have an account. Everything else is voluntary — without it, individual features cannot work.

4. Processing by AI providers

To produce scores, suggestions, chat replies and documents, we transmit the content required for that particular task — in particular excerpts of your resume, your cover letter and the job posting concerned — to an AI provider that generates the response on our behalf.

These requests go through the routing interface (API) of OpenRouter, Inc. (USA). OpenRouter does not generate the responses itself; it forwards them to the model configured for the task, and receives the transmitted content in doing so. The models currently used through OpenRouter are:

  • Google (Gemini) — for classification, chat replies, text suggestions, document generation and the image check for application photos;
  • Z.ai / Zhipu AI (China) — for the German resume-check criteria only.

Separately, for job search and Help search we call an embedding model directly at OpenAI, Inc. (USA), which turns text into numeric vectors; those requests do not go through OpenRouter.

Training. Under the terms applicable to the OpenAI and Google API accounts, the transmitted content is not used to train the models. For Z.ai / Zhipu AI we hold no such commitment (as at 6 September 2026), and we send no setting with those requests that would rule out use for training.

Your user id, your email address and your account data are not part of that transmission; what is transmitted is the text content itself.

No automated decision with legal effect. Zusaga’s scores, checks and text suggestions are guidance for you. No decision is taken about you, neither by us nor automatically within the meaning of Art. 22 GDPR; whether you apply, and with which documents, is entirely your decision. Scores can be wrong — check every generated document before you use it.

5. Recipients and processors

We disclose personal data only to the following parties. We are entering into a data processing agreement pursuant to Art. 28 GDPR with each of them; as of the publication of this notice, this has not yet been completed with every recipient. We do not sell data and do not pass it on for advertising.

RecipientPurposeLocation
Hetzner Online GmbHServer hosting for the applicationGermany (Falkenstein)
Supabase Inc.Operating the PostgreSQL database holding all account and application dataEU (Ireland)
OpenRouter, Inc.Routing of all AI requests (see section 4)USA
GoogleGemini AI model, via OpenRouter (see section 4)USA / EU
Z.ai / Zhipu AIAI model for the German resume-check criteria, via OpenRouter (see section 4)China
OpenAI, Inc.Embedding model for job and Help search (see section 4)USA
PostHogCookieless product analytics (see section 6)EU (Frankfurt)
Brevo GmbH, BerlinSending our emails to you (see below)Germany (Berlin)

Third-country transfers. Where data is transferred to the USA in this context, it is done on the basis of the European Commission’s standard contractual clauses (Art. 46 (2) (c) GDPR) or of an adequacy decision, where the provider is certified under the EU-US Data Privacy Framework.

There is no adequacy decision by the European Commission for China. The transfer to Z.ai / Zhipu AI therefore rests solely on the European Commission’s standard contractual clauses (Art. 46 (2) (c) GDPR), together with an assessment of the legal situation in the recipient country. It affects only the content transmitted for the German resume-check criteria.

Job search. To search for job postings we query external job sources (including Adzuna). We transmit search terms such as job title and location — not your id, your email address or your documents.

Domain and reachability. Our domains are managed via Cloudflare; name resolution runs without a proxy, so page requests go directly to our own server. Cloudflare therefore receives no content of your usage.

Email delivery and measurement. We use Brevo to send you our emails — notifications and the nightly summary. Brevo receives your email address and the content of the message.

Brevo does not only record the technical delivery status; it also measures whether you opened an email and whether you clicked a link inside it. To do so, a tracking pixel is loaded from the provider’s server when you open the message, and links are redirected via the provider. Your IP address and the time of retrieval are processed in that step.

For transactional email, our provider offers no way to switch this measurement off. We therefore state it here explicitly rather than leaving it unmentioned. The legal basis is our legitimate interest in deliverability and troubleshooting (Art. 6 (1) (f) GDPR). You can prevent open tracking effectively by disabling the automatic loading of external images in your email client; delivery of the email itself is unaffected.

Sign-in via third parties. If you sign in with Google, LinkedIn or GitHub, that provider learns that you are signing in to Zusaga. Its own privacy policy applies to that; we are not the controller in that respect.

6. Cookies, storage on your device, and analytics

Zusaga sets no cookies for advertising or cross-site tracking, and we build no cross-site profiles.

The only things stored on your device are strictly necessary for operating the service (§ 25 (2) no. 2 TTDSG): your sign-in token, so that you stay signed in, and your language and view preferences — plus, if you switch analytics off (see below), the record of that objection. No consent is required for any of this, which is also why we show no cookie banner.

Product analytics (PostHog), without cookies. We measure how the website and the application are used so that we can improve them. We use PostHog for this, running on European infrastructure (Frankfurt); no analytics data is transferred to the USA.

This measurement is cookieless: PostHog stores nothing at all on your device — no cookie, no localStorage entry, no sessionStorage entry. The identifier that groups the page views of a single visit exists only in your browser’s working memory and is gone when you close the tab. We therefore cannot recognise you on a later visit and cannot link your visits to one another. Because nothing is written to or read from your terminal equipment, § 25 (1) TTDSG does not apply and no consent is required — this is precisely why there is no cookie banner in front of it.

What is recorded: the page called up, the referring page, approximate region, and coarse device and browser information. Your IP address is used only to derive that approximate region and is not stored. On the public website no user profile is created at all. In the application, signed-in usage is linked to your account id so that we can see which features are actually used; this still stores nothing on your device.

Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in a product that works and in recognising errors, weighed against an intentionally minimal, cookieless measurement.

Objecting. In the application you can switch this off at any time under Account → Analytics; the setting is stored on your account and applies on every device. Both the website and the application also honour the “Do Not Track” / Global Privacy Control signal of your browser — if that is set, we measure nothing, without your having to do anything.

7. Access by us

As a rule we do not access the data stored in your account.

Support access (impersonation). In order to handle a support case, a person with administrative authorisation can open your account in the application exactly as you see it — and in doing so can also view your application documents. This access is technically constrained: it is valid only for a short period, it is visible in the interface throughout, irreversible actions (such as deleting the account) are blocked while it is active, and every access is permanently logged with the acting person, the account concerned, and its start and end. The legal basis is Art. 6 (1) (b) GDPR where the access is necessary to fulfil your support request, and otherwise Art. 6 (1) (f) GDPR (operating and debugging the service). You may request information about whether and when your account was accessed in this way.

Beyond that, maintenance and fault diagnosis may technically require access to the database. Such access happens for a specific reason and is limited to what is necessary to fix the fault.

8. Retention and erasure

We store your account and application data for as long as your account exists. You can delete your account yourself at any time in your account settings; you must type your email address to confirm.

What happens on deletion. The deletion runs in a single database transaction — it either completes in full or not at all. It deletes your account and everything attached to it (resumes and cover letters, saved jobs and applications, notes, chat and coach histories, support tickets, credit and consumption entries) plus those tables that are technically not attached to your account and would therefore not be removed automatically: security and sign-in events, referral entries, idempotency records, one-time sign-in codes, the daily AI-spend record, and the throttling counter for your email address. That this set is complete is guarded by an automated test which fails as soon as a new table holding personal data is added without being included in the deletion.

Two things are not deleted but severed from your identity: any invitation your account was created from (the email address stored on it is removed), and the link to accounts you referred. In addition, one entry is written recording that an erasure took place — with no reference to you, so that it cannot be traced back.

After deletion, restoration is not possible.

Other periods. Security and sign-in events are processed for abuse prevention and are removed at the latest when the account is deleted. Technical server logs arise as a matter of operation and are overwritten as part of normal rotation. Data subject to a statutory retention obligation is retained until that period expires, and its further processing is restricted in the meantime.

9. Security

All transmission is encrypted (TLS). Passwords are stored only as a hash. Sign-in sessions expire after a short time and are renewed; repeated failed sign-in attempts are throttled. Access to the systems is limited to the people required to operate the service.

10. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and the right to object, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 21 GDPR). You may withdraw any consent you have given at any time with effect for the future; the lawfulness of processing carried out until then is unaffected.

For access, rectification, portability and erasure, a message to the email address given above is enough. You can also delete your account yourself at any time in your account settings.

Independently of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular with the authority of your habitual residence or the one competent for our registered address.

11. Changes to this policy

We update this privacy policy whenever the processing changes — in particular before a new feature or a new processor goes live. The version published on this page is the applicable one.

Last updated: 3 August 2026.

© 2026 Zusaga — The job search copilot for Germany.
ImprintPrivacy PolicyTermsCancel subscription
v0.8214-beta+123bc5b2d