Privacy Policy
This Privacy Policy explains how BidSharpe (“BidSharpe”, “we”, “us”) collects, uses, shares and protects personal data when you use the BidSharpe job-search web application (the “Service”). It should be read together with our Terms of Service.
1. Who we are
The Service is operated by Andranik Grigoryan, Yerevan, Republic of Armenia. For the personal data described in this policy, we act as the data controller. You can reach us about privacy matters at [email protected].
We process personal data in line with the Law of the Republic of Armenia “On Protection of Personal Data”, and, where they apply to you, the EU and UK General Data Protection Regulation and other privacy laws described below. We have not appointed a representative in the European Union or the United Kingdom.
2. Data we collect
Data you give us
- Account data: email address, display name and password. We never store your password itself; we store only a salted scrypt hash of it.
- Search profile: target roles, locations and markets you choose to search in.
- Evidence: self-attested information about your experience, skills and achievements that you enter to support applications.
- Application tracking: the status, dates, tags and notes you record for job applications.
- Files: documents you upload, such as CVs or cover letters (PDF, DOCX, TXT or MD, up to 20 MB each).
- Communications: messages you send us, for example support requests.
- Sign-in with another account: if you sign in with Google or X, we receive your identifier at that provider, your email address and whether it is verified, and your display name. We do not receive your password at that provider and we do not read or post anything on that account.
- Your own AI key: if you connect your own Anthropic API key, we store it encrypted so that only the component that calls the AI provider can use it. We keep the last few characters so you can recognise it. The key cannot be shown again after you save it, and you can remove it at any time.
Edits to your search profile and evidence are kept as immutable versions, so earlier versions remain in your account until you delete your account.
Please upload only information you have the right to share. Avoid including sensitive data (such as health information, religious beliefs or government identifiers) or other people’s personal data unless it is necessary and you are entitled to provide it.
Data created when you use the Service
- Saved jobs and search history: job postings saved to your workspace and a record of search runs you requested.
- AI usage records: how much you use AI features, so usage can be metered and limited according to your plan.
- Security and technical data: session identifiers, a CSRF token, and hashed IP address and account identifiers used for rate limiting and abuse prevention. Our edge provider also processes request data such as IP address and browser information to deliver and protect the Service.
Payment data
Payments for AI credits and for the own-key plan are processed by Paddle.com, our online reseller and Merchant of Record. Paddle collects your payment details, billing address and tax information directly and handles them as an independent controller under its own privacy policy. We receive limited billing information from Paddle: your Paddle customer and transaction references, what you bought, the amount and currency, the payment, subscription and refund status, and the renewal date. We do not receive or store your full card number.
We also keep a record of your credit balance and every change to it (purchases, AI charges, refunds and adjustments).
3. How we use data and lawful bases
If the EU or UK General Data Protection Regulation (GDPR) applies to you, we rely on the following lawful bases.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and running your account, signing you in | Account data, sign-in provider data, session data | Performance of a contract |
| Searching job sources and saving results at your request | Search profile, saved jobs | Performance of a contract |
| Storing your evidence, applications and files | Evidence, application tracking, files | Performance of a contract |
| AI ranking and drafting when you request it | Profile, evidence, relevant postings | Performance of a contract |
| Metering AI usage and enforcing plan limits | AI usage records | Performance of a contract |
| Verification, welcome and password-reset emails | Email address, display name | Performance of a contract |
| Security, rate limiting and abuse prevention | Security and technical data | Legitimate interests in keeping the Service and its users safe |
| Selling AI credits and the own-key plan, automatic top-ups, refunds | Payment and billing data | Performance of a contract; legal obligation for tax and accounting records |
| Responding to support requests and legal claims | Communications, relevant account data | Legitimate interests; legal obligation where applicable |
We do not use your data for advertising, we do not build advertising profiles, and we do not make decisions that produce legal or similarly significant effects about you solely by automated means.
4. AI features
AI features run only when you request them. When you do, the relevant parts of your search profile, evidence and job posting content are sent to an AI model to rank jobs and to draft application material. We send only what is needed for the task you requested. Requests normally go through OpenRouter, which passes them to the model provider we have chosen for that feature (for example Anthropic, OpenAI or Google); we only allow providers that do not keep or train on the data. If that model is unavailable, the request may be answered by another model available through OpenRouter.
- AI outputs are drafts. You must review them for accuracy before using them.
- Under our agreement with the provider, data we send through the API is not used to train its models.
- If you use your own API key, the same data is sent to Anthropic under your account with it, and Anthropic’s terms with you apply to that processing.
- Ranking several jobs at once may use the provider’s batch service. The provider then holds the request and its result for a limited time, up to about a month, so that we can collect it.
- AI usage is metered per request (the feature used, the model, and the amount of text processed) so it can be charged and limited.
5. Third-party job sources
When you run a search, the Service queries third-party job boards and public job APIs (for example LinkedIn public listings, hh.ru, Staff.am, CareerCenter.am, Jobindex, Jobnet, Jobbank, Jobdanmark, FreeHire and global remote job boards) and saves the resulting postings to your workspace. These searches use your search criteria, such as target roles and locations. We do not send your account details, evidence or files to these sources, and we never apply to jobs on your behalf.
6. Cookies
We use only cookies that are strictly necessary to run the Service:
- a session cookie that keeps you signed in, set as HttpOnly and SameSite=Lax; and
- a CSRF token that protects your account against cross-site request forgery.
We do not use advertising or analytics cookies. Our edge provider may set cookies that are strictly necessary for security and abuse protection.
7. How we share data
We do not sell personal data. We share it only:
- with the service providers listed in Subprocessors, who process it on our instructions;
- with job sources, limited to the search criteria described above;
- when required by law, or to protect the rights, safety or property of our users, the public or us; and
- with a successor entity in a merger, acquisition or sale of assets, subject to this policy.
8. Subprocessors
| Category | Purpose | Location |
|---|---|---|
| Hosting, database, object storage and backups (OVHcloud) | Running the application, storing account data, uploaded files and backups | European Union |
| AI routing (OpenRouter) | Passing AI requests to the chosen model provider, on request | United States |
| AI model providers (Anthropic, OpenAI, Google, through OpenRouter or directly) | Job ranking and drafting application material, on request | United States |
| Edge network, CDN and abuse protection (Cloudflare) | Delivering the Service, blocking abusive traffic | United States; global edge network |
| Email delivery (Brevo) | Verification, welcome and password-reset emails | France (European Union) |
| Merchant of Record (Paddle), an independent controller for payment data | Selling AI credits and the own-key plan, invoices, sales tax, refunds | United Kingdom |
| Sign-in providers (Google, X), only if you choose to use them | Confirming your identity when you sign in | United States |
9. International transfers
We operate from the Republic of Armenia, and our service providers may process data in countries other than your own, including countries that do not offer the same level of protection as the EEA or the UK. Where we transfer personal data out of the EEA or the UK, we rely on an adequacy decision where one exists or on the European Commission’s Standard Contractual Clauses (together with the UK Addendum where relevant), and we assess the transfer and apply supplementary measures where needed. You can ask us for a copy of the relevant safeguards. Transfers from Armenia follow the conditions of the Law “On Protection of Personal Data”.
10. Retention and deletion
- Account content (account, profile and evidence versions, saved jobs, applications and files) is kept while your account is active.
- Search run history is automatically pruned after 30 days.
- Security logs and rate-limit records are kept only as long as needed for security purposes.
- Billing records are kept for as long as tax and accounting laws require.
You can export your data and delete your account from your account settings. Deleting your account removes your account, search profile, evidence, saved jobs, applications and uploaded files. Copies in backups expire within 35 days. Billing records we must keep by law are retained for the legally required period.
11. Security
We use technical and organisational measures appropriate to the risk, including:
- per-user (tenant) data isolation enforced with database row-level security;
- passwords stored only as salted scrypt hashes;
- HttpOnly, SameSite session cookies and CSRF protection;
- encryption of data in transit;
- uploaded files kept in private object storage that is not publicly accessible;
- rate limiting and abuse protection using hashed identifiers; and
- access to production data limited to what is necessary to operate the Service.
No system is completely secure. If we become aware of a breach affecting your personal data, we will notify you and the authorities as required by law.
12. Your rights (EEA and UK)
If the GDPR or UK GDPR applies to you, you have the right to:
- access your personal data and receive a copy;
- rectification of inaccurate or incomplete data;
- erasure of your data;
- restriction of processing in certain circumstances;
- data portability, meaning a copy of data you provided in a structured, machine-readable format;
- object to processing based on our legitimate interests; and
- lodge a complaint with a supervisory authority, in particular in the country where you live or work, or where an alleged infringement occurred.
Many of these rights can be used directly in the app: you can edit your profile and evidence, export your data and delete your account from settings. For anything else, contact us at [email protected]. We will respond within one month, which may be extended where the law allows. We may need to verify your identity before acting on a request.
13. Your rights (California)
If the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), applies to you, this section adds to the rest of this policy.
Categories collected in the last 12 months: identifiers (email address, display name, hashed IP and account identifiers); customer records (account and billing records); professional or employment-related information (search profile, evidence, applications and files); internet or network activity (session and security data); and inferences limited to AI job ranking you request. Sources, purposes and recipients are described in sections 2 to 8. If you enter sensitive personal information, we use it only to provide the Service you requested.
No sale or sharing: we do not sell personal information and do not share it for cross-context behavioural advertising. We have no actual knowledge of selling or sharing personal information of consumers under 16.
Your rights: you may request to know what personal information we collect, use and disclose; to access it; to delete it; to correct it; and to limit the use of sensitive personal information (which we already use only as permitted). You may use an authorised agent, and we will verify requests before acting on them.
Non-discrimination: we will not deny you service, charge you a different price or provide a different level of quality because you exercised your privacy rights.
14. Other jurisdictions
BidSharpe is available worldwide. Wherever you live, you may request access to, correction of or deletion of your personal data by contacting us, and we will honour the rights granted by the privacy laws that apply to you, such as those in Canada, Brazil, Switzerland, Australia and other countries. If local law requires consent for a particular processing activity, we will ask for it. If you are unhappy with our response, you may contact your local data protection authority.
Armenia: under the Law “On Protection of Personal Data”, you may access, correct, block or delete your personal data, withdraw consent, and complain to the Personal Data Protection Agency of the Ministry of Justice of the Republic of Armenia.
15. Children
You must be at least 16 years old to use BidSharpe. The Service is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
16. Changes to this policy
We may update this policy from time to time. The “Last updated” date and version at the top of the page show when it last changed. If we make material changes, we will notify you by email or in the app before they take effect.
17. Contact us
Andranik Grigoryan
Yerevan, Republic of Armenia
Email: [email protected]