Privacy Policy
Last updated: 10 July 2026
1. Introduction
Compyle ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and disclose your personal information when you use our platform at compyleapp.com (the "Service").
This policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you are located outside Australia, you consent to the transfer and processing of your information in Australia.
2. Information We Collect
2.1 Information You Provide
- Account data: Email address, name, password (hashed with bcrypt)
- Professional profile: Education history, work experience, projects, skills, certifications
- Personal details: Phone number, location, LinkedIn URL, GitHub URL
- Work rights: Visa status and work authorisation details
- Job descriptions: Text you paste for application generation
- API keys: Third-party API keys you provide (OpenAI, Anthropic, etc.)
- Documents: Files you upload (resumes, cover letters, transcripts)
2.2 Automatically Collected
- Usage data: Pages visited, features used, application history
- Token usage: API call counts, token consumption (no prompt/response content)
- Technical data: IP address, browser type, device information
- Logs: Server logs with request IDs (no personal content)
3. How We Use Your Information
- To provide and maintain the Service
- To generate tailored resumes and cover letters on your behalf
- To process payments (when applicable)
- To send service-related communications
- To improve the Service and develop new features
- To detect and prevent fraud or abuse
- To comply with legal obligations
4. Data Storage and Security
4.1 Encryption
- In transit: All data is transmitted over TLS 1.3 (HTTPS)
- At rest: Database files are stored on encrypted volumes (AES-256 in production)
- Passwords: Hashed with bcrypt (12+ rounds), never stored in plaintext
- API keys: Encrypted at rest using Fernet symmetric encryption (AES-128-CBC). Your keys are never logged or transmitted in plaintext. You may revoke and replace your keys at any time through the Settings page.
4.2 Data Residency
All data is stored on servers located in Australia (Sydney region). If you use a self-hosted deployment, data residency depends on your hosting provider.
4.3 What We Cannot Access
We never have access to:
- Your raw prompts sent to LLM providers (processed server-side during generation, never stored)
- LLM response content (used ephemerally to build your documents, then discarded)
- Your third-party API keys (used ephemerally during generation, encrypted at rest, never logged)
5. Third-Party Services & AI Providers
5.1 AI Processing Partners
When you generate a resume or cover letter, your professional profile and job description are sent to one or more of the following AI providers for processing:
- Groq, Inc. — Resume and cover letter generation, job description analysis (default platform provider)
- OpenAI, Inc. — Resume and cover letter generation (when using your own API key)
- Anthropic, PBC — Resume and cover letter generation (when using your own API key)
- Google LLC (Gemini) — Resume and cover letter generation (when using your own API key)
- Mistral AI — Resume and cover letter generation (when using your own API key)
- DeepSeek — Resume and cover letter generation (when using your own API key)
- OpenRouter — Resume and cover letter generation (when using your own API key)
- Ollama — Local model inference (when self-hosted)
We act as an intermediary: your data is sent to these providers solely to generate your documents. We do not store the content of these AI interactions beyond token usage counts (number of tokens consumed, not the text itself). Each provider's use of data is subject to their own privacy policies.
5.2 Data Retention by AI Providers
AI providers may temporarily process your data to generate responses. Their retention policies vary:
- Groq: Does not retain prompt/response data for training. See Groq Privacy Policy
- OpenAI: API data is not used for training by default. See OpenAI Privacy Policy
- Anthropic: API data is not used for training. See Anthropic Privacy Policy
- Google: Gemini API data handling varies by tier. See Google Privacy Policy
When using the BYOK (Bring Your Own Key) feature, your prompts are sent to your chosen provider using your own API key. Your use of these services is subject to their respective terms.
5.3 Platform Free-Tier Key
Compyle provides a free-tier API key (powered by Groq) so you can try the product without your own API key. This key is shared across free-tier users. Usage is rate-limited and monitored. Your data is still processed ephemerally and not stored beyond token counts.
5.4 Cross-Border Data Transfers
Your data is stored in Australia. However, when you use AI features, your prompts are transmitted to third-party AI providers whose servers may be located outside Australia (e.g., OpenAI and Anthropic in the US, Groq in the US). By using AI features, you consent to this cross-border transfer. We select providers with strong privacy practices, but you acknowledge that data processed overseas may be subject to different privacy laws.
6. Data Sharing
We do not sell, trade, or rent your personal information. We may share data only:
- With your explicit consent
- To comply with legal obligations or court orders
- To protect our rights, privacy, safety, or property
- With service providers who assist in operating the Service (hosting, payment processing), bound by confidentiality agreements
7. Your Rights
Under the Privacy Act 1988 and APPs, you have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information and all associated data
- Complaint: Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
To exercise these rights, contact us at privacy@compyleapp.com.
8. Data Retention
We retain your data for as long as your account is active. When you delete your account:
- All personal data is permanently deleted within 30 days
- All generated content (resumes, cover letters, PDFs) is deleted
- All application records are deleted
- Server logs containing your data are purged within 90 days
- Anonymised, aggregated analytics may be retained indefinitely
9. How to Delete Your Data
You have full control over your data. Two simple options:
Option 1: Self-Service
- Go to Settings in your dashboard
- Scroll to the Danger Zone section
- Click Delete Account
- Confirm deletion
All data is permanently removed within 30 days.
Option 2: Email Request
Send an email to privacy@compyleapp.com with the subject line "Delete My Account" and we will process your request.
10. Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be notified via email or prominent notice on the Service. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact
For privacy-related inquiries:
- Email: privacy@compyleapp.com
- Post: Compyle, Melbourne, VIC 3000, Australia
- OAIC: www.oaic.gov.au