Privacy policy

Last updated: 08.07.2026 · v3

This policy explains what personal data Firstday (firstday.work) processes, why, on what legal basis, and how you stay in control. It follows Article 13 GDPR. Plain language — if anything here is unclear, ask us.

Who is responsible

The controller for your data is Elena Karlsen, acting as an individual (sole trader), Calcada da Bica Grande 25, Portugal. Contact: support@firstday.work. (Also in the Impressum.)

What we collect

  • Account data — your email address, and the identifiers needed to sign you in. You can sign in with a one-time email code or with a password. If you set a password, we store only a salted hash of it (via Supabase Auth), never the password itself.
  • Sign-in security data — to prevent abuse of the password sign-in, signup, and reset forms, we briefly log the IP address and email address used for each attempt. These logs are deleted after 24 hours.
  • Profile data — the career information you enter: work stations, education, languages, skills, and the metadata of documents you add to your vault.
  • Documents — files you upload to your document vault (e.g. degree certificates, reference letters).
  • Free-tool inputs — the text you paste into the reference-letter decoder and the answers you give the visa-points calculator. Decoder inputs are automatically deleted after 24 hours unless you save the result to an account.
  • Messages you send us — if you use the contact form, we process your name, email address, and the content of your message. A contact message is emailed to Firstday support so we can reply to you. It is not saved to our database. To limit abuse, we cap how many messages we accept from one IP address in an hour.
  • Payment data — handled by our payments provider, Stripe Managed Payments (the merchant of record is Sold through Link, LLC). We receive confirmation of your purchase and plan, not your card number.
  • Usage analytics — aggregate, cookieless statistics (via Plausible). No cross-site tracking, no personal profiles, no advertising IDs.

Why we process it, and on what legal basis

PurposeLegal basis (Art. 6 GDPR)
Provide the tools, profile, and document features you ask forPerformance of a contract — Art. 6(1)(b)
Sign you in and keep your account securePerformance of a contract — Art. 6(1)(b)
AI-assisted analysis and drafting from your own inputPerformance of a contract — Art. 6(1)(b)
Prevent abuse, fraud, and secure the serviceLegitimate interests — Art. 6(1)(f)
Aggregate, cookieless usage statisticsLegitimate interests — Art. 6(1)(f)
Process paymentsPerformance of a contract — Art. 6(1)(b)
Reply to a message you send usLegitimate interests — Art. 6(1)(f)

We do not train AI on your data

Your inputs are processed to produce your result and nothing else. We do not use your data to train AI models, and our AI provider processes API inputs under terms that do not use them for model training.

Who processes data for us (subprocessors)

SubprocessorWhat they doWhere
SupabaseDatabase, authentication, document storageFrankfurt, EU (eu-central-1)
Anthropic (Claude API)AI analysis and drafting on your inputUnited States
VercelHosting — functions in Frankfurt (fra1); static assets via global CDNEU functions / global CDN
Stripe — Sold through Link, LLC (Managed Payments)Payments, tax, and refunds (merchant of record)United States
ResendTransactional email (sign-in codes, contact-form messages)United States
CloudflareBot protection on the sign-in and sign-up forms (Turnstile)United States
PlausibleCookieless, aggregate analyticsEuropean Union

Where a subprocessor is outside the EEA, the transfer relies on a named mechanism:

  • Anthropic (US) — EU Standard Contractual Clauses (Modules 2/3), per the Anthropic DPA. Anthropic does not train its models on API inputs.
  • Vercel (US) — 2021 EU Standard Contractual Clauses, per the Vercel DPA.
  • Resend (US) — EU Standard Contractual Clauses and the EU-US Data Privacy Framework, per the Resend DPA.
  • Cloudflare (US) — EU Standard Contractual Clauses and the EU-US Data Privacy Framework, per the Cloudflare DPA. Turnstile runs a privacy-preserving bot check; it does not use tracking cookies.
  • Stripe / Sold through Link, LLC (US) — EU Standard Contractual Clauses, per the Stripe Data Processing Agreement; Sold through Link, LLC is the merchant of record for payments (see the Link Consumer Terms).
  • Supabase — your stored data stays in the EU (Frankfurt); Supabase Inc (US) provides a DPA incorporating SCCs for any support access, per the Supabase DPA.

Where your data lives

Your account, profile, and documents are stored in the European Union (Frankfurt). Server-side processing runs on serverless functions pinned to Frankfurt (fra1); only static assets (the pages themselves, which carry no personal data) are served from a global CDN. This is architectural, not a preference we might quietly change.

How long we keep it

  • Decoder inputs — deleted after 24 hours, unless you save the result to your account.
  • Sign-in attempt logs — deleted after 24 hours.
  • Contact messages — a contact message stays in our support inbox, not in our database. We keep it only as long as needed to handle your request, then delete it.
  • Account, profile, and documents — kept until you delete them. Deletion is real (a hard delete, not a hidden flag).
  • Analytics — aggregate only; not tied to you.

Your rights

Under the GDPR you can, at any time:

  • Access and export your data — do it now in Settings.
  • Delete your account and everything in it — do it now in Settings.
  • Rectify anything inaccurate — edit it directly in your profile.
  • Restrict or object to certain processing, and withdraw consent where we rely on it.
  • Lodge a complaint with a supervisory authority.

The competent supervisory authority is the CNPD — Comissão Nacional de Proteção de Dados (Portugal): cnpd.pt. For any privacy request, contact support@firstday.work.

Changes

If we change this policy we will update the date above and, for material changes, tell you in the product.