Privacy Policy
FerretDen — Last updated 31 July 2026
1. Who we are
This Privacy Policy explains how Eyad Mostafa, an individual sole proprietor based in 6th of October City, Giza Governorate, Egypt, trading as"FerretDen" ("FerretDen," "we," "us," or "our"), handles personal data when you use ferretden.com, app.ferretden.com, and the FerretDen service (together, the "Service"). We are the controller of the personal data we collect directly about users of the Service, as described below.
Privacy questions or requests: support.ferretden@gmail.com.
2. Personal data we collect
| Category | Examples | Purpose |
|---|---|---|
| Account & identity | Name, email address, authentication credentials (via our identity provider, Supabase) | Creating and securing your account, signing you in |
| Profile / "Vault" data | Work history, education, skills, certifications, publications, languages, accomplishments, projects, and application-question answers you enter | Matching you to opportunities and drafting tailored application materials |
| Uploaded documents | CVs, cover letters, and other supporting documents you upload | Providing the Service — extracting your background and, where you request it, compiling generated documents to download |
| AI-generated content | Draft cover letters and CV language generated on your request | Assisting your applications — you review and approve before use |
| Source configuration | Job boards, RSS feeds, and Telegram channels you choose to track | Finding opportunities relevant to you |
| Billing data | A customer reference ID linking your account to our payment processor; we do not store your card details | Managing your subscription |
| Usage & security data | IP address, request logs, rate-limit counters, device/browser information | Keeping the Service secure, preventing abuse, diagnosing problems |
Payment card details are collected and processed directly by Paddle, our Merchant of Record — we never see or store them.
3. Why we process your data (legal basis)
- Performance of a contract — providing the Service you signed up for (matching, document generation, account management).
- Legitimate interests — securing the Service, preventing fraud and abuse, and improving the product, balanced against your rights.
- Consent — where required, for example for optional marketing communications or non-essential cookies.
- Legal obligation — record-keeping required for tax and accounting purposes (largely handled by Paddle as Merchant of Record).
4. Who we share data with
We share personal data with the following categories of recipients, all bound by contract to protect it:
| Recipient | Role |
|---|---|
| Supabase | Authentication / identity provider — manages your login session and stored credentials |
| Cloudflare | Object storage (R2) for uploaded/generated documents; content delivery and edge network for the website and API |
| Oracle Cloud (Germany) | Hosting for our application servers and database — our primary infrastructure runs in a German (EU) data center |
| Paddle.com | Merchant of Record — payment processing, subscription management, tax collection and remittance, invoicing. Paddle sends billing-related emails (receipts, invoices, payment-recovery notices) to you directly |
| Google (Gemini API) | AI processing for opportunity matching, extraction, and document drafting, using our platform API key by default |
| Brevo | Sends account-security emails on our behalf — email verification, password reset, and email-change confirmation links |
If you use a "Bring Your Own Key" (BYOK) plan, requests you make are sent directly to your chosen third-party AI provider using your own API key, under that provider's own privacy terms — not ours.
We may also disclose personal data to professional advisers (legal, accounting, audit) and to authorities where required by law or necessary to protect the rights, property, or safety of FerretDen, our users, or the public. We do not sell your personal data.
5. International data transfers
We operate as a sole proprietor based in Egypt, but our primary infrastructure — application servers and database — is hosted in Germany (EU) via Oracle Cloud. Other sub-processors (Cloudflare, Google, Paddle, Supabase, Brevo) operate infrastructure in additional countries, including the United States. Personal data may therefore be processed in Egypt, the EU/EEA, the UK, and the United States depending on the sub-processor involved.
6. How long we keep your data
We keep your account and Vault data for as long as your account is active. If you delete your account, we soft-delete your data immediately (it stops being used to provide the Service) and permanently remove it — including any documents stored in object storage — within 30 days. Some records, such as those Paddle retains for tax and financial compliance, are kept for the period required by applicable law, independent of our own retention window.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Delete your data ("right to erasure");
- Export your data in a portable format;
- Restrict or object to certain processing;
- Withdraw consent at any time, where processing is based on consent.
You can access, export, or delete most of your data directly from your account settings. For anything else, contact us at support.ferretden@gmail.com. We'll respond within one month, or as required by applicable law.
If you believe we haven't handled your data properly, you have the right to complain to your own country's data protection authority — for example, Egypt's Personal Data Protection Center (our home regulator), the UK's Information Commissioner's Office, or your local EU data protection authority, depending on where you live.
8. Security
We apply technical and organizational measures appropriate to the sensitivity of the data, including application-layer AES-256 encryption of core identity fields at rest, cryptographic (SHA-256) blind indexing rather than storing lookup values in plain text, strict per-account data isolation, and encrypted connections in transit. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard practices.
9. Cookies and local storage
We use essential browser local storage to keep you signed in between visits. We do not currently use third-party advertising or cross-site tracking cookies.
10. AI-generated content
Some content on the Service — including drafted cover letters and CV language — is generated using AI on your request, based on the profile data you provide. This content is a draft for you to review and edit; we don't guarantee its accuracy, and you remain responsible for anything you ultimately submit to a third party.
11. Children's privacy
The Service is not directed at children and we do not knowingly collect personal data from anyone under 16 (or the applicable minimum age in your jurisdiction). If you believe a child has provided us data, contact us and we'll delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We'll notify you of material changes by email or an in-product notice before they take effect.
13. Contact us
Eyad Mostafa, trading as FerretDen
6th of October City, Giza Governorate, Egypt
Email: support.ferretden@gmail.com