stackcrew.ai

Legal

Privacy policy

Last updated 2026-10-06

stackcrew.ai helps you find and match with AI-native jobs. This policy explains what personal data we process when you use the site, why, who else handles it, and what you can do about it. We try to keep it plain; if something is unclear, email legal@stackcrew.ai.

Who is responsible

stackcrew.ai is operated by Congoods, a Dutch eenmanszaak (sole proprietorship) registered in The Netherlands. Chamber of Commerce (KvK) number: 76877213. Registered address: Salland 1, 1948 RE Beverwijk. Correspondence address: Postbus 79055, 1070 NC Amsterdam.

Congoods is the controller of your personal data when you use stackcrew.ai. Privacy contact: legal@stackcrew.ai.

We have not appointed a Data Protection Officer.

What we collect

  • Account: your email address, and a sign-in record (email, IP address, timestamp) used to send sign-in links and to stop abuse. We sign you in with an emailed link, so we don't store a password.
  • Profile: whatever you choose to add, such as headline, summary, work experience, education, projects, skills and tools, links, and job preferences.
  • Usage limits: we log when your account uploads a resume and how many free AI Assistant messages you have used, to apply fair-use limits.
  • Resume: if you upload a PDF or Word resume, we read it to fill in your profile. We keep the structured details we extract, which you can review and edit, not the original file.
  • AI Assistant and profile intake: the messages you type. We use them to answer you and do not keep a chat history; we only count messages per day to apply usage limits. Signed-out visitors get a cookie with a random ID for that count.
  • Links you add to projects: we fetch the public page behind the link to summarise it.
  • Your activity: jobs you save, hide or track as applications, and the fit scores calculated for you.
  • Usage analytics: pages viewed and feature use (for example, that the chat was opened), through PostHog. It is not linked to your identity and nothing is stored in your browser for it.
  • Subscription: if you subscribe, our payment provider handles your payment details. We receive your subscription status and a customer reference, not your card number.

Why we use it, and on what legal basis

  • To create and run your account, show job matches, calculate fit scores and run the tracker: performance of a contract (GDPR Art. 6(1)(b)).
  • To process your resume and chat messages with AI so the features work: performance of a contract.
  • To measure and improve the product with analytics: our legitimate interest in understanding how the site is used (Art. 6(1)(f)). You can object at any time.
  • To prevent abuse, such as flooding the sign-in form: our legitimate interest in keeping the service secure.
  • To keep tax and accounting records for subscriptions: legal obligation (Art. 6(1)(c)).

Who else handles your data

We use the following service providers (processors) and only share what each one needs:

  • Supabase: database and sign-in. Stores your account and profile.
  • Anthropic: AI provider. Receives your resume, chat messages and link content to generate responses and extractions.
  • Resend: sends the sign-in emails.
  • PostHog (EU region): product analytics.
  • Stripe: payments. Stripe acts as the merchant of record for subscriptions and is itself responsible for the payment data it collects (see Stripe's privacy policy). Customers may see purchases as sold through Link, Stripe's checkout service.
  • Vercel: hosting. Serves the website and processes requests such as IP addresses and server logs.

Transfers outside the EU

Some of these providers, notably Anthropic, process data in the United States. Where that happens we rely on the provider's EU-US Data Privacy Framework certification or on Standard Contractual Clauses approved by the European Commission.

How long we keep it

  • Account, profile and your free-message count: until you delete your account.
  • Sign-in records (email, IP address, timestamp): 30 days, then deleted automatically.
  • Resume upload log (which account uploaded when, used for a usage limit): 30 days, then deleted automatically.
  • Chat usage counters (messages per day): 7 days, then deleted automatically. The signed-out chat cookie lasts up to one year.
  • Resume and chat text sent to Anthropic: we do not store it ourselves; see Anthropic's own terms for how long it keeps API data.
  • Billing records: as long as Dutch tax law requires (currently seven years).
  • Analytics: up to 12 months in PostHog.
  • Server logs at Vercel: up to one day.

Your rights

You can ask us to give you access to your data, correct it, delete it, restrict or object to how we use it, and give you a portable copy. Where we rely on consent you can withdraw it at any time. Email legal@stackcrew.ai; we answer within one month. To delete your account and everything attached to it, use "Delete account" in your dashboard settings, or email us from the address on the account. If you have an active subscription, cancel it first; the account can be deleted once the subscription has ended.

If you think we handle your data unlawfully you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).

AI features

The AI Assistant, resume import and project summaries are produced by AI and can be wrong. You review and can edit anything that goes into your profile. Fit scores are calculated from your profile and a listing's requirements to help you sort jobs. They are a suggestion for you; they are not shared with employers and nobody makes a decision about you based on them.

Please don't upload sensitive information you don't want processed, such as health details, in your resume or chat.

Cookies and similar technologies

We do not use advertising cookies.

  • Sign-in cookies (Supabase): needed to keep you signed in.
  • Chat session cookie (chat_session_id, one year): a random ID that lets signed-out visitors use the AI Assistant within the daily limit.
  • Analytics (PostHog): counts page views and feature use without storing anything in your browser. It keeps no cookie or identifier between visits, so a return visit counts as a new one.

Children

stackcrew.ai is not meant for anyone under 16, and we don't knowingly collect their data.

Changes

If we change this policy in a way that matters, we will update the date at the top and, for significant changes, tell signed-in users by email or in the app.