← Back to Paa.Legal

Privacy Policy

Last updated: 12 September 2026. This policy describes how Paa. handles information when you use the website and Chrome extension.

What Paa. handles

Paa. may process account information, the CV and application information you choose to save, job-page information needed for the active application, saved jobs and application progress, user-written answers and letters, and professional contact-search information requested for a specific job or company.

How job-page information is used

Paa. is designed to inspect the employer or job page you are actively working with so it can show relevant requirements and support the application workflow. It is not designed to build an unrelated browsing-history profile.

Professional contact research

When a user requests contact discovery, Paa. may process a company or domain, public professional names and roles, source URLs, candidate work-email addresses and technical validation evidence. Results can be incomplete, stale or inferred. Paa. is not designed as a bulk people database or mass-outreach tool.

Service providers

Paa. uses Supabase for account and backend infrastructure in the current production design. Where a user requests an automatic contact search, an approved server-side search provider may receive the minimum query information needed to perform that search. A Merchant of Record/payment provider may process payment and billing information when a user purchases PAA Pro. Paa. is designed so raw card details and private provider secrets are not stored in the browser extension.

Advertising and sale of data

Paa. does not use CV data or employer-page content for targeted advertising and is not built to sell that data to advertisers.

Local storage and account separation

The extension can keep working data in browser storage. In account-enabled builds, private cached data is scoped to the authenticated account so switching accounts does not intentionally expose another user's saved CV, jobs, contacts or settings.

Security

Network traffic to production services is intended to use HTTPS. Sensitive service-role credentials, payment secrets and third-party provider secrets are kept server-side rather than shipped in the extension. No internet service can guarantee absolute security.

Retention and deletion

Paa. retains workspace data while an account is active and for as long as reasonably needed to provide the service, protect the platform, resolve disputes, meet accounting obligations or comply with law. Users may request account or privacy assistance at paasupport@gmail.com. Deletion from backups may take additional time where technically necessary.

Third-party sites

Paa. operates alongside third-party job sites and applicant-tracking systems. Those sites have their own privacy practices and terms. Paa. is not affiliated with those platforms unless explicitly stated.

Contact

Privacy and account requests can be sent to paasupport@gmail.com. The product is operated from Morocco.