Privacy Policy
Version 1.0 · Effective July 7, 2026
This Privacy Policy explains how Pisama LLC ("Pisama", "we", "us"), the company that operates Callback Agent ("the Service"), collects, uses, shares, and protects personal data, and the rights you have over that data. It is written to align with the EU General Data Protection Regulation (GDPR), the UK GDPR and PECR, and the California Consumer Privacy Act as amended by the CPRA, alongside other US state privacy laws. Where a term has a specific meaning under one of those laws (for example "personal data", "personal information", "processing", "controller", "sensitive personal information"), we use it in that sense.
1. Who we are (controller and contact)
Pisama LLC is the controller of the personal data described in this policy. You can reach us about privacy using the contact form on this page. The Service operates at the callbackagent.ai and pisama.ai domains; the application backend is hosted in the United States.
For users in the EU/EEA or the UK, we have not yet appointed an Article 27 representative or a Data Protection Officer. Until one is named, send all data-protection requests using the contact form on this page.
2. The personal data we collect
We collect only what the Service needs to prepare and, where you direct it, help submit job applications.
- Account and identity data. Your email address, and, if you sign in with Google or LinkedIn, the basic identity their OAuth/OIDC sign-in returns (an identifier, your name, and email). We do not collect or store your third-party portal or LinkedIn account password, and we never sign in to those platforms by impersonating you.
- Profile and application content. Your résumé/CV text, phone number, location, LinkedIn URL, portfolio and GitHub URLs, target roles, the jobs you add, the fit evaluations we generate, the answers and cover letters we draft, and the tailored résumé documents we render (including generated PDFs).
- Special-category and legally sensitive data. If you choose to provide them, your equal-opportunity (EEO) self-identification answers (such as race or ethnicity, sex or gender, veteran status, and disability status) and your work-authorization, visa or sponsorship, and "true and complete" attestations. EEO self-identification can be special-category data under the GDPR (Article 9) and sensitive personal information under the CCPA/CPRA. We collect these only with your explicit, separate consent, and you can use the Service without providing them.
- Acceptance audit data. When you accept our Terms of Service, we record the terms version, the date and time, your IP address, and your browser user-agent, as evidence that you agreed.
- Payment data. If you subscribe, your card details are collected and processed by Stripe, our payment processor. We do not receive or store full card numbers; we store a customer or subscription reference and basic billing status.
- Usage and technical data. Server logs, request metadata, and, subject to the consent controls in Section 9, privacy-focused product analytics (page views and performance timings) and, where enabled, Google Analytics 4 aggregate measurement. We also keep a first-party record of the product actions you take (for example completing signup, evaluating a job, generating a résumé, or turning on full automation) so we can understand which features are used and improve them. If you arrived from one of our ads, this record may also note the campaign that brought you here (standard "utm" campaign labels from the link you clicked, held briefly in your browser's local storage and subject to the same consent controls). This record notes which feature you used, not the contents of your résumé, jobs, or answers, and no equal-opportunity or attestation data; it stays on our own systems (no third-party analytics vendor) and is deleted with your account.
3. Why we use your data, and our lawful basis
For users in the EU/EEA and the UK, we rely on the following Article 6 (and, for special-category data, Article 9) bases.
- To provide the Service (create your account, store your profile, evaluate fit, draft and render application materials, and run the automation you enable). Basis: performance of a contract with you.
- To enter EEO or work-authorization answers, when you ask us to. Basis: your explicit consent (GDPR Article 9(2)(a) for special-category data), given separately and per question. See Section 4. Withdrawing consent is always available and stops future use.
- To keep the Service secure and reliable, and to keep the Terms-acceptance audit record. Basis: our legitimate interests in security, fraud and abuse prevention, and being able to establish, exercise, or defend legal claims, balanced against your rights.
- To take payment, where you subscribe. Basis: performance of a contract, and compliance with our legal (for example tax and accounting) obligations.
- For product analytics and non-essential cookies. Basis: your consent, where consent is required (see Section 9).
- To comply with the law and respond to lawful requests. Basis: compliance with a legal obligation.
Under the CCPA/CPRA and other US state laws, we process the categories above for the business purposes described here. We do not use your sensitive personal information to infer characteristics about you, and we do not sell or "share" (as the CPRA defines "share", meaning cross-context behavioral advertising) your personal information. See Sections 5 and 8.
4. AI, automation, and automated decisions
The Service uses automated and AI systems, and you should understand how.
- AI-generated content. We send your CV and your answers to a large-language-model provider (Anthropic, and in some configurations OpenAI) to score job fit and to draft résumé content, answers, and cover letters. This output is generated by AI, can be wrong, and is presented to you for review. We disclose its AI origin in line with emerging transparency rules (including Article 50 of the EU AI Act).
- Legal attestations and EEO are not auto-answered by default. The Service pauses on legally significant questions (work-authorization, visa or sponsorship, certifications, "true and complete" attestations, and EEO self-identification) and asks you to answer them. It will enter such an answer on your behalf only where you have given an explicit, per-question pre-authorization that is recorded with your consent and the date and time of that consent, and even then it enters only the exact answer you provided, never one generated for you. EEO self-identification questions are never auto-filled and always require your manual response.
- Automated submission. If you turn on full automation, the Service can fill and submit an application in your own browser session. You remain the author and signer of every application. To the extent any of this is automated decision-making with legal or similarly significant effects under GDPR Article 22 or UK rules, you can ask for human review; in practice the consequential decisions (what to submit, and every legal attestation) rest with you.
5. Who we share data with (processors and subprocessors)
We do not sell your data. We share personal data with the service providers ("processors" under the GDPR; "service providers" under the CCPA) that operate the Service, under contracts that restrict them to processing on our instructions. Our current providers are:
- Anthropic (Claude language models) and, where enabled, OpenAI, to evaluate fit and draft application content. These providers process your CV and answers as our processors.
- Stripe, to process subscription payments.
- Vercel, which hosts the web front end and provides Vercel Analytics and Speed Insights.
- Fly.io, which hosts the application backend (United States region).
- Google and LinkedIn, where you choose them for sign-in, to authenticate you.
- Google Analytics 4, where enabled and where you have consented, for aggregate usage measurement.
A current subprocessor list and the data-processing agreements with these providers are maintained for review (see Section 12). We require an Article 28 / CCPA service-provider agreement with each processor. We may also disclose data where required by law, to enforce our terms, or in connection with a corporate transaction, subject to this policy.
6. International data transfers
The Service is operated from the United States, and our AI and hosting providers process data in the United States and other countries. If you are in the EU/EEA or the UK, your personal data is transferred outside your home region. For those transfers we rely on appropriate safeguards under Chapter V of the GDPR and the UK regime, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and any applicable adequacy decision. You can contact us for more information about the safeguards that apply.
7. How long we keep data (retention)
We keep personal data only as long as we need it for the purposes above.
- Account and profile data, and generated content, are kept while your account is active. When you delete your account, we delete this data, subject to the limited exceptions below and to removal from routine backups on our normal backup cycle.
- The Terms-acceptance audit record (terms version, timestamp, IP address, user-agent) is retained as legal evidence that you agreed, decoupled from your account, even after you delete your account. We keep it for the period needed to establish, exercise, or defend legal claims; after that, we delete or de-identify it unless law requires a longer period.
- Payment and tax records are kept for the period required by law.
- Server logs and security data are kept for a limited period for security and reliability.
8. Your rights
Depending on where you live, you have some or all of the following rights, and we will not discriminate against you for exercising them.
- EU/EEA and UK (GDPR / UK GDPR). The rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to processing based on legitimate interests. Where we rely on consent (for EEO or special-category data, and for non-essential analytics), you can withdraw it at any time without affecting prior processing. You also have the right to lodge a complaint with your supervisory authority (your national data protection authority in the EU/EEA, or the UK Information Commissioner's Office).
- California (CCPA/CPRA) and other US state laws. The rights to know and access, to delete, and to correct your personal information; to opt out of the "sale" or "sharing" of personal information (we do not sell or share it); and to limit the use of sensitive personal information. We honor browser opt-out preference signals such as Global Privacy Control (GPC) where applicable.
- How to exercise them. You can export the data we hold or delete your account and its associated data at any time from your account page, or contact us using the form below. We will verify your identity before acting on a request and respond within the timelines the applicable law requires. You may use an authorized agent where the law allows.
9. Cookies, analytics, and consent
The Service uses a small number of strictly necessary cookies (for example to keep you signed in and to remember your theme choice); these are required for the site to work. It also uses non-essential analytics: privacy-focused product analytics and performance timings (Vercel Analytics and Speed Insights) and, where enabled, Google Analytics 4 aggregate measurement. These analytics see how pages are used, not the contents of your résumé, jobs, or answers.
Where consent is required for non-essential cookies and analytics (for example under EU/UK ePrivacy and PECR rules), we do not load them until you have given consent. Visitors we detect as being in a region that requires prior consent are not tracked by non-essential analytics unless and until they accept; everyone can change their choice. The current detection is best-effort.
10. How we protect your data
Résumé text, phone, location, and LinkedIn URL are encrypted at rest (AES-GCM), and rendered résumé PDFs are encrypted on disk. Your authentication token is held server-side and is never exposed to client-side JavaScript. We do not store your third-party portal or LinkedIn credentials. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security. Where the law requires it, we will notify you and the relevant authority of a personal-data breach within the applicable deadlines.
11. Children
The Service is intended for adults (18 and over) applying for jobs and is not directed to children. We do not knowingly collect personal data from children under 13 (or the minimum age set by local law). If you believe a child has provided us data, contact us using the form on this page and we will delete it.
12. Changes and how to contact us
We may update this policy. When we make a material change we will update the version and effective date above and, where appropriate, notify you. For any privacy question, to exercise a right, or to request our current subprocessor list or the safeguards that apply to international transfers, contact us using the form on this page. EU/EEA and UK users also have the right to complain to their supervisory authority (their national data protection authority, or the UK ICO).