VitaMine

Privacy

Privacy policy

Effective 6 August 2026

Controller and contact

Andreas Horn
Am Steinfeld 6, D-50354 Hürth, Germany
info@vitamine.cloud

What VitaMine processes

We process your account information (email, display name, password hash, login and security records); the CV databases, documents, portraits, templates, and other content you choose to store; optional public-profile content; encrypted ORCID and Zotero connection credentials; essential session cookies; and privacy-minimal operational records such as job status, support IDs, and OpenAI token counts. We do not use CV content, prompts, or model output for analytics, aggregate research, product improvement, or model development without separate, explicit consent.

Why we process it

We process account and CV data to provide the service and perform the agreement with you (Art. 6(1)(b) GDPR), to protect the service and prevent abuse (Art. 6(1)(f) GDPR), and where required for the managed AI features, on your explicit permission (Art. 6(1)(a) GDPR). You can withdraw the AI permission in Settings at any time; withdrawal does not affect processing already carried out before it.

Managed OpenAI processing

Before an AI-assisted operation begins, VitaMine asks for and records your versioned permission. With permission, selected CV text and, where relevant, Word-template text are sent to OpenAI through VitaMine’s managed OpenAI account for AI-assisted import, enrichment, cleanup, and custom-template analysis or translation. Do not enable this if you are not authorised to share the content. Withdrawing permission blocks new managed-AI requests.

Service providers and external recipients

We use the following services only for the stated purposes. Optional scholarly integrations are contacted only when you choose to use them.

ServicePurpose and data involvedWhen used
Strato AG
Germany
Hosting, database storage, encrypted job files, backups, and transactional email infrastructure. This may involve account data, encrypted CV storage, service metadata, and email delivery data.To operate VitaMine and send account emails.
OpenAIManaged AI processing of selected CV or template content. Token and cost metadata, but not prompts or outputs, are retained in VitaMine’s private ledger.Only after your explicit Settings permission and when you start an AI-assisted feature.
ORCIDOptional sign-in/identity and works data. Encrypted OAuth credentials are stored by VitaMine when you connect ORCID.Only when you connect or sync ORCID.
ZoteroOptional publication-library and collection data. An encrypted OAuth API credential is stored by VitaMine when you connect Zotero.Only when you connect or sync Zotero.
OpenAlexPublic scholarly metadata and affiliation data used for enrichment and collaboration mapping.Only when you request relevant enrichment or mapping.
Email and monitoring providersVitaMine currently uses Strato for transactional email. No separate external monitoring provider is configured. Any future provider will be named here before it receives personal data.For account messages or, if introduced, security and reliability monitoring.

Storage, security, and retention

Hosted CV snapshots and queued uploads are encrypted at the application layer. Active workspaces and decrypted job inputs are runtime-only. Portraits are stored inside your CV database; public-profile portraits exist only while the profile is published. Completed and failed job records are normally retained for 30 days; runtime job files are removed when processing finishes. Essential device sessions last up to 180 days unless you sign out, reset your password, or delete your account. The service keeps same-server backup copies for up to 14 days for disaster recovery.

Deletion

Deleting an account requires password confirmation and immediately removes its live CV snapshots, embedded portraits, sessions, public-profile snapshot, integration credentials, consent records, and queued job artifacts. It also removes linked operational records through database deletion rules. Backup copies age out on their normal 14-day retention cycle and are not restored for ordinary access.

Cookies and logs

VitaMine uses only essential HTTP-only cookies for account, workspace, and administrator sessions. It does not use advertising or analytics cookies. Operational failure logs use a random support ID and structural metadata; they deliberately exclude CV content, filenames, credentials, request bodies, and cookies.

Your rights

Subject to the GDPR, you may request access, correction, erasure, restriction, portability, or object to processing. You may withdraw consent at any time. Contact info@vitamine.cloud. You may also lodge a complaint with a data-protection supervisory authority.

© 2026 VitaMinePrivacy policyTerms of serviceImprint