Privacy policy
Controller (Art. 4(7) GDPR)
Simon Grammel
Am Schwaigfeld 13a
82061 Neuried
Germany
Email: info@midvalla.ai
1. What this is about
This privacy policy explains which personal data Midvalla processes, for what purposes, and what rights you have. Application data is particularly sensitive — data minimisation is therefore a core principle of this platform: we only collect what the features require, we do not sell data, and we do not show ads.
2. Hosting (Vercel)
This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you visit the site, Vercel processes technically necessary connection data (in particular IP address, time of access, page accessed, browser identifier) in server logs to deliver the website and keep it secure. The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). Vercel is certified under the EU-US Data Privacy Framework; EU standard contractual clauses apply in addition.
3. Account, profile and application data (Supabase)
When you create an account, we store your email address and your password (stored in encrypted form). The data you enter into your profile — e.g. work experience, education, skills, contact details — as well as the CVs, cover letters and application-tracker entries you create are stored so you can use the platform's features. The legal basis is performance of the user agreement (Art. 6(1)(b) GDPR).
The database and sign-in are operated by our processor Supabase; the data is stored in the Frankfurt am Main region (EU). Access is technically protected by row level security: each user can only read and change their own data.
Optionally, you can sign in with your Google account. In that case we receive your email address from Google; Google's privacy policy applies in addition.
4. AI features (Anthropic)
For the AI features (CV and cover-letter generation, profile chat, application coach, CV import, job-ad import, matching score, prioritisation of search results, the “Your arguments” value analysis) we transmit the necessary content — e.g. your profile data or a job ad you provide — to the Claude API operated by Anthropic (Anthropic PBC, USA). Data is only transmitted when you actively use an AI feature. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
According to Anthropic, data submitted via the API is not used to train its models and is only retained for a limited period for abuse monitoring. EU standard contractual clauses are in place for the transfer to the USA; Anthropic is also certified under the EU-US Data Privacy Framework.
The public reference check (usable without an account) works the same way: the reference text you paste is transmitted to the Claude API solely for the analysis and is not stored by us; we only record anonymous technical values (e.g. text length, duration, cost). To enforce the limit of three analyses per day we set a technically necessary cookie containing a daily counter — without any personal reference (Art. 6(1)(f) GDPR).
The public resume check works the same way: the uploaded file is processed in memory only, transmitted to the Claude API for the analysis, and is not stored by us. Without an account we keep only the check result (score and findings) for 24 hours before deleting it automatically; with an account the report remains stored until you delete it. Here too, a technically necessary counter cookie limits anonymous use (Art. 6(1)(f) GDPR). Please upload your own documents only.
The public LinkedIn profile check follows the same rules: the uploaded PDF export of your LinkedIn profile is processed in memory only, transmitted to the Claude API for the analysis, and is not stored by us; only the result is kept (without an account: 24 hours, then automatic deletion). A technically necessary counter cookie limits anonymous use (Art. 6(1)(f) GDPR). Please upload the export of your own profile only. Midvalla is not affiliated with LinkedIn.
5. Job search (Federal Employment Agency)
The job search uses the public job-search API of the German Federal Employment Agency (Bundesagentur für Arbeit). Your search parameters (e.g. keyword, location, radius) are transmitted to the agency — without your name or account data.
6. Payment processing (Stripe)
When you purchase a Premium subscription, payment is handled by the payment provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; parent company: Stripe, Inc., USA). You enter your payment details (e.g. card number or bank account, name, email address, amount) directly on Stripe's pages — they never reach our servers. We only store a Stripe customer and subscription identifier, the subscription status and the period end in order to activate your Premium plan.
The legal basis is performance of the contract (Art. 6(1)(b) GDPR); invoice and accounting data is additionally subject to statutory retention obligations (Art. 6(1)(c) GDPR in conjunction with § 147 AO, § 257 HGB) — this data therefore survives an account deletion. Stripe processes payment data partly under its own responsibility, for example for fraud prevention and to comply with payment regulations; Stripe's privacy policy applies in addition. EU standard contractual clauses are in place for possible transfers to the USA; Stripe is also certified under the EU-US Data Privacy Framework.
You manage invoices, payment method and cancellation yourself via the Stripe customer portal, which you can reach in the signed-in area (the “Your plan” card).
7. Cookies and ad measurement on campaign pages
In normal operation Midvalla only uses technically necessary cookies: for your sign-in session, for your language preference and for the daily counters of the free checks. There are no third-party advertising or tracking cookies. The legal basis is § 25(2) no. 2 of the German TDDDG and Art. 6(1)(b) GDPR.
An exception are our campaign landing pages (addresses under /lp/…) that ads link to: there a banner asks whether we may recognise your visit with a first-party cookie and store the click origin (such as the Google click ID and campaign parameters) in order to measure which ads lead to registrations. The legal basis is your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR); it is voluntary, the page works just the same without it, and without consent we only count visits anonymously and without accessing your device. The cookies expire after at most 6 months (consent choice) or 90 days (click origin); the measurement data contains no real names and no IP addresses and is deleted after 14 months.
8. Anonymous visitor statistics (Plausible) and guide click counting
For anonymous visitor statistics we use Plausible Analytics (Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia). Plausible works without cookies and without cross-device tracking and stores no personal data: the IP address is only processed transiently (e.g. to determine the approximate country of origin) and is not stored; no link to you as a person or to your account is established. The data is stored on servers in the EU. The legal basis is our legitimate interest in understanding how our service is used (Art. 6(1)(f) GDPR).
In addition, we also count page views ourselves in our own database — likewise without cookies, without a visitor identifier and without IP addresses. We only store the page path, the referring page or campaign parameters, the time, and whether the view came from a logged-in session (as a plain yes/no without any link to your account). No link to you as a person is established; the raw data is deleted after 14 months. The legal basis is again our legitimate interest (Art. 6(1)(f) GDPR).
In the guide section we additionally count how often recommended article links are clicked — as a pure daily aggregate without IP addresses, without cookies and without any link to your account. This count contains no personal data.
9. Error diagnostics (Sentry)
To detect and fix technical errors quickly, we use Sentry (Functional Software, Inc., 45 Fremont Street, San Francisco, CA 94105, USA). When an error occurs in the app, a technical error report is transmitted automatically — in particular the error message, the affected page, browser and system information, and the time. We have deliberately configured Sentry to be data-minimising: IP addresses are not stored, and profile or application content is not part of the error reports; the data is stored in Sentry's EU data region.
The legal basis is our legitimate interest in stable and secure operation of the platform (Art. 6(1)(f) GDPR). EU standard contractual clauses are in place for transfers to the USA; Sentry is also certified under the EU-US Data Privacy Framework.
10. Email notifications
Where enabled, we send you account emails (e.g. registration confirmation, password reset) and reminders about the follow-ups and deadlines you have entered in the application tracker. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). We do not send marketing newsletters.
11. Company scout and Monday digest (only with consent)
If you turn on the company scout, we analyse what you search for and apply to — your search profiles, your application-tracker entries and your profile details (e.g. desired position, location, skills) — in order to suggest matching companies. The recommendations appear on your dashboard and are sent to you by email. The recommendations are AI-assisted.
If you turn on the Monday digest “Fresh jobs for the week”, we analyse your profile and search goals to rate new job ads from our job sources for fit (AI-assisted) and send you the best matches by email once a week.
The legal basis is in each case your consent (Art. 6(1)(a) GDPR), which you give separately when turning on the respective feature. You can withdraw it at any time with effect for the future — via the switch on your dashboard or the unsubscribe link in every email. Without consent, the respective analysis does not take place.
12. Retention and deletion
We store your data for as long as your account exists. You can delete your account yourself at any time (profile page, section “Account & data”) or request deletion by email — your personal data will then be deleted unless statutory retention obligations require otherwise. Usage statistics are only retained in anonymised form (with no link to you as a person); in addition, technical usage events (e.g. the time and feature of a request) are deleted automatically no later than 24 months after they occur. Server logs are deleted automatically after a short period.
13. Your rights
You have the right of access to your stored data (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). You can export your data and delete your account yourself on your profile page under “Account & data”; for anything else, simply contact the email address given above.
You also have the right to lodge a complaint with a data protection supervisory authority.
Last updated: 30 July 2026. We will update this policy when the platform's features change.