Privacy Policy
Last Updated: September 15, 2026
1. Who Is Responsible for Your Data
The controller responsible for processing your personal data is:
- Owner: Toni Sort
- Address: Barcelona, Spain
- Privacy contact: privacy@workrepublic.io
This policy applies to the application at workrepublic.io, to public profiles and job pages at wrep.io, and to rezum.io, our former domain, which only redirects to the other two.
2. The Short Version
- Nothing you write is public until you publish it. Once published, it is public on the internet and search engines can index it.
- Salary expectations, availability, your date of birth, your AI conversations and your scores are never shown on your public pages.
- We use third-party AI providers to power the product. We do not use your content to train AI models, we do not sell your data and we do not show advertising.
- Visitors can ask an AI assistant questions about your published profile. Those conversations are stored and you can read them.
- Analytics that store anything on your device only run if you accept them.
- You can delete your account at any time. The few records that survive deletion, and why, are listed in section 13.
3. Who This Policy Covers
- Members: people with a Work Republic account who build résumés, portfolios, cover letters and applications.
- Organization members: people who use Work Republic on behalf of a business to publish job roles.
- Visitors: anyone who views a public profile, portfolio or job page, or chats with a profile’s AI assistant, with or without an account.
- People who contact us through the support form or by email.
Members sometimes mention other people in their content, such as a former manager or a project collaborator. The member who adds that information is responsible for having the right to share it. If you are mentioned and want something removed, contact us.
4. Data We Collect
Your account
- Email address and password. Passwords are stored in hashed form by our authentication provider; we never see them. If you sign in with Google, we receive your name, email address and profile photo from Google.
- Full name and username (your handle).
- Date of birth, used only to confirm that you meet the minimum age. It is not shown on your profile or shared with anyone.
- Interface language, account creation date and last sign-in time.
Your career content
- Résumés and everything in them: experience, education, skills, languages, projects, articles and cover letters.
- Applications, including the job descriptions you paste to tailor a résumé or cover letter.
- Contact details you save, such as email addresses, phone numbers and links.
- Preferences: target salary and currency, work model, contract type, remote days, city of residence, willingness to relocate, availability, notice period and anything else you write about what you are looking for.
- Target roles and skills.
- Notes and context you give the AI, and the knowledge it organizes from them.
- Uploaded media: your photo, images, logos and videos.
We do not need special categories of data, such as health, religious beliefs, political opinions or ethnic origin, or identity document numbers. Please leave them out. If you include them, they are processed like the rest of your content and become public if you publish them.
AI conversations and results
- Conversations with the AI assistant in the editor, including generated titles and summaries, and any thumbs-up or thumbs-down feedback you give.
- AI-generated evaluations of you and your content: résumé quality and evidence scores, checks of résumé claims against your portfolio, skill levels, and suggested matches between your skills or roles and our skills catalogue.
- Skill exams. If you take an exam, we store the challenge, your answers, the assessment and an integrity verdict. While you answer, we record how the answer was composed: the number of keystrokes and deletions, the number and size of pastes, how long the tab was hidden, and composing and idle time. We do not record which keys you press beyond the text you submit, and we never use your camera, microphone or screen.
Billing and usage
- Plan, subscription status and renewal date, the identifiers Polar (our payment provider) assigns to you and your subscription, and AI Pack purchases (amount, currency and tokens granted). Card and payment details are handled by Polar; we never receive them.
- Usage counters: AI tokens used in each period, content counts and storage used.
Organizations
- Organization details: name, legal name, domain, website, logo, description, industry, size and location.
- Membership: your role in the organization and who invited you.
- Job roles: the public description and requirements; private hiring fields such as budget, internal notes and stages; job descriptions you paste to import; and an audit log recording who changed which requirement, when, and what it looked like before and after.
- Conversations with the AI in the hiring space stay in your browser and are not stored on our servers.
Visitors to public pages
Page analytics, AI assistant conversations and rate-limiting data, described in section 8.
Support requests
Your message and the email address you give us. If you are signed in, also your account ID and account email. To help us reproduce problems, the form also sends the page address, the previous page, your browser, language, screen and window size, and time zone.
Technical data
Like any website, our servers receive your IP address, browser and device information, and the pages you request. We also record product events, described in section 9.
5. Why We Use Your Data and Our Legal Bases
- Providing the service — your account, the editor, AI features, exams, publishing, your public profile and its AI assistant, PDF export, organizations and job roles. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR).
- Checking the minimum age with your date of birth. Legal basis: our legal obligations and our legitimate interest in not providing the service to children (Article 6(1)(c) and (f)).
- Security and abuse prevention — bot protection, rate limits, fair-use quotas and preventing repeated sign-ups to reset them. Legal basis: legitimate interest in keeping the service secure and fairly available (Article 6(1)(f)).
- Operating and improving the service — service telemetry, cookieless analytics, error diagnosis and cost control. Legal basis: legitimate interest (Article 6(1)(f)).
- Analytics that store data on your device. Legal basis: your consent (Article 6(1)(a)), which you can refuse or withdraw.
- Showing profile owners how their public pages are used — visit analytics and visitor conversations. Legal basis: our and the profile owner’s legitimate interest (Article 6(1)(f)).
- Payments, invoicing and tax. Legal basis: performance of the contract and our legal obligations (Article 6(1)(b) and (c)).
- Answering support requests. Legal basis: contract performance or legitimate interest (Article 6(1)(b) and (f)).
- Handling disputes and legal claims, including handle revocations and reports of illegal content. Legal basis: legitimate interest and legal obligations (Article 6(1)(c) and (f)).
Where we rely on legitimate interest, you have the right to object (section 14). We do not use your data for advertising, and we do not sell it or share it with data brokers.
6. How We Use AI
What the AI does
AI models help you write and edit résumés and cover letters, tailor applications, import a résumé from a PDF, score your résumé, run skill exams, organize your notes, answer visitors on your public profile, draft and import job roles for organizations, and title and summarize conversations. We also turn your content into embeddings (numeric representations of meaning) so the AI can find the parts relevant to a question. Embeddings are stored with the content they come from and deleted with it.
Who processes it
- All AI requests go through the Vercel AI Gateway to models from Alibaba Cloud (Qwen), DeepSeek, Anthropic (Claude), Google (Gemini), which reads the résumé PDFs you import, and OpenAI (embeddings).
- Each request contains the content needed for the task, for example the résumé section being edited, relevant notes and the conversation, together with a pseudonymous account ID used for abuse monitoring and cost attribution. We do not send your password or payment details.
- We may change models as better ones become available and will keep this list current.
No training on your content
We do not use your content to train or fine-tune AI models. We use these providers through paid API access under terms that do not allow them to train their models on the data we send. Providers may keep requests for a limited period for abuse monitoring, under their own terms.
Evaluations are yours
Your résumé scores, skill levels, exam results and integrity verdicts are visible only to you. They are not shown to visitors or organizations, and we do not use them to make decisions about you. They are automated estimates that can be wrong; you can edit your content, retake assessments, or ask us to delete them.
Automated decisions
Work Republic does not make decisions about you based solely on automated processing that produce legal or similarly significant effects (Article 22 GDPR). Organizations use AI only to write and edit job roles: the AI proposes changes and a person with authority in that organization accepts or rejects them. Work Republic does not currently screen, rank or match candidates for organizations. Before any such feature launches, we will update this policy, tell you, and make sure people make the final decisions.
Voice dictation
Dictation uses your browser’s built-in speech recognition. Your audio is processed by your browser’s vendor (for example Google in Chrome or Apple in Safari) under its own privacy terms. We only receive the resulting text.
7. What Becomes Public
Publishing
Everything starts private. When you publish a résumé, we save a snapshot of it and show that snapshot at your public address (wrep.io/your-handle). Later edits stay private until you publish again. A published résumé can include your name, photo, headline, location, the contact details you selected for it, your summary, experience (including locations), education, languages, skills, projects, articles and cover letter.
Never public
Your preferences (including salary expectations and availability), date of birth, account email (unless you add it as a contact detail), AI conversations, scores, exam results, unpublished drafts and the private hiring fields of job roles.
Your public AI assistant
Visitors to your public profile can ask an AI assistant about you. It answers from a copy made when you publish, containing your published résumé and portfolio and the notes and knowledge in your workspace, including knowledge organized from your exam answers. Do not keep anything in your notes that you would not want the assistant to share. The assistant is instructed not to reveal contact details you have not published, and its answers are checked for email addresses, phone numbers and street addresses before they are shown. Visitors’ questions count towards your AI quota.
Other public pages
- Applications and company-specific cover letters are public only when you share them. Anyone with the link can open them, but they are marked so search engines do not index them.
- Portfolio projects and articles are public as soon as you publish them, even if you have not published a résumé. Unlike résumés, edits to a published post appear immediately.
- Your contact page lists the contact details saved in your profile.
- Uploaded media is stored on our content delivery network at hard-to-guess addresses. Anyone who has the address of a file can open it, even if the post it belongs to is not published. We remove location data from photos in JPG, PNG, WebP and AVIF format when you upload them; GIFs, SVGs and videos are stored as uploaded, so check them for embedded metadata first.
Search engines, search and the feed
- Your main public profile, portfolio, published posts and main cover letter can be indexed by search engines and appear in our sitemap. Your name and photo appear in link previews when someone shares your address. The only way to stop indexing today is to unpublish.
- Work Republic has a talent search, open to anyone, that finds people with a published résumé. It searches and displays only information you have published: name, handle, photo, résumé title, skills and published projects.
- Signed-in members see a feed of recently published posts, and a skills directory showing how many people list each skill. The directory shows counts only, never who.
Unpublishing
When you unpublish, your content disappears from our public pages within a few minutes and the assistant’s copy is deleted immediately. We cannot remove copies that search engines, other websites or people have already made.
Handles
Your handle is public. If you change it, your old handle keeps redirecting to the new one and is never given to anyone else. The rules on handles are in our Terms of Service.
Job roles
Organizations choose whether a role is reachable by private link only (the default, not indexed) or public (indexed, with structured data that job search engines can read). Work Republic does not currently accept applications itself: a role page may link to the organization’s own application page, where that organization’s privacy policy applies.
8. If You Visit a Public Profile
Page analytics
To show profile owners how their pages are used, we record each visit to a published résumé or application: which sections and projects were viewed and for how long, which links were clicked (site and path only), the number of messages sent to the assistant, your browser name and version, operating system, device type and window size. We do not store cookies or anything else on your device for this, and we do not record your IP address with it. Owners see only totals and breakdowns, not individual visits. This data is kept for as long as the résumé exists.
Chatting with a profile’s assistant
- You are told you are talking to an AI before you start. Your questions are sent to our AI providers (section 6) to generate an answer.
- Your messages and the answers are stored with a random session ID and your language, and the profile owner can read them. Do not share information you would not want the owner to see.
- Conversations are kept for as long as the owner’s résumé exists. If you want a conversation deleted, contact us and tell us which profile and roughly when; we usually cannot identify you otherwise.
- To prevent abuse, we count messages using a hash of your IP address and a hash of your session ID. These records are deleted after 30 days.
Embedded videos
Portfolio posts can contain YouTube videos. When one loads, YouTube (Google) may set cookies and receive your IP address under its own privacy policy.
9. Cookies, Device Storage and Analytics
Strictly necessary
These are needed for the service to work and do not require consent.
- Session cookies from Supabase, our authentication provider, keep you signed in on workrepublic.io. Public profiles on wrep.io set no session cookies.
- Language cookie remembering your interface language, for one year.
- Browser storage (localStorage and sessionStorage) for your cookie choice, unsaved drafts so you do not lose work, layout and theme preferences, and the state of open conversations and sign-up steps. This data stays on your device; clearing your browser data removes it.
- Cloudflare Turnstile on sign-in and sign-up pages, to tell people from bots, and Google Identity Services for the “Continue with Google” button.
Product analytics (PostHog)
- If you accept analytics, PostHog stores an identifier in your browser so it can recognize repeat visits, and records page views, page exits, product events (for example, “résumé published”) and error reports.
- Before you choose, or if you decline, PostHog runs in cookieless mode: nothing is stored on your device and visits cannot be linked to each other, but anonymous page views and product events are still counted.
- PostHog processes this data on servers in the European Union. We do not use session recording, heatmaps, advertising pixels or cross-site tracking.
- To change your choice, clear this site’s data in your browser; the banner will ask you again.
Service telemetry
Our servers record operational events linked to your account ID, such as which AI model handled a request, tokens used, cost and response time, quota limits reached, errors, and subscription events (plan, amount and currency). These events do not contain the text of your content or conversations. They are sent to PostHog so we can run the service, control costs and fix problems. They do not depend on the cookie banner, because they do not store or read anything on your device; you can object to them under section 14.
Other third-party content
Some marketing pages load images directly from Unsplash, which receives your IP address when they load. YouTube embeds are described in section 8.
10. Who We Share Data With
Service providers
These providers process data on our behalf, under contracts that limit what they can do with it:
- Supabase — database, authentication and search. Hosted in Zurich, Switzerland.
- Vercel — hosting, server functions and the AI Gateway. United States and global edge network.
- AI model providers — Alibaba Cloud, DeepSeek, Anthropic, OpenAI and Google (section 6).
- Cloudflare — file storage and delivery (R2), bot protection (Turnstile), DNS and email routing. Global network.
- PostHog — product analytics and error tracking. European Union.
- Polar — payments. Polar acts as merchant of record and is responsible for the payment data it collects under its own privacy policy.
- Resend — delivery of support emails. United States.
- Google — sign-in with Google.
Other people, as you choose
Anything you publish is visible to anyone (section 7). Members of the same organization see each other’s name and photo, but not each other’s email or contact details.
Organizations
We do not give organizations any of your personal data beyond what you publish for everyone to see. If we introduce ways to apply to roles or be discovered by organizations, this policy will be updated before those features launch, and your data will only be shared when you choose to share it.
Legal reasons and business changes
We may disclose data when the law requires it, or when necessary to protect the rights, safety or property of our users, the public or Work Republic. If Work Republic is sold, merged or transferred, your data may move to the new owner, who will be bound by this policy, and we will tell you in advance.
11. International Transfers
Our main database is in Switzerland, which the European Commission recognizes as providing adequate protection. Several providers process data outside the European Economic Area. Depending on the model, the companies providing and hosting AI models may be located in the United States, China or other countries.
When data leaves the EEA, we rely on an adequacy decision where one exists (for example, the EU–US Data Privacy Framework for certified US companies) or on the European Commission’s Standard Contractual Clauses included in our providers’ data processing terms, together with the additional measures described in this policy, such as sending only the content a task needs and using pseudonymous identifiers. You can ask us for more information about the safeguards for a specific provider.
12. How Long We Keep Data
- Account and content: until you delete them or your account.
- Editor AI conversations: the three most recent conversations per document; older ones are deleted automatically when you start a new one.
- Visitor conversations and page analytics: as long as the résumé they belong to exists.
- Hashed IP addresses and visitor message counters: 30 days.
- Job roles, imported job descriptions and their audit log: as long as the role exists.
- Product analytics and service telemetry: 30 days.
- Support emails: up to 24 months after your request is resolved.
- Server logs kept by our hosting and database providers: short periods set by those providers, no longer than 30 days.
- Backups: deleted data can remain in our providers’ encrypted backups until they are overwritten, within 30 days. We never restore a deleted account from a backup.
- Records that survive account deletion: see section 13.
13. Deleting Your Account
You can delete your account from Settings at any time. Deletion is immediate and cannot be undone. It permanently removes your account, résumés, applications, cover letters, portfolio, notes, AI conversations and results, exams, preferences, skills, organization memberships and uploaded media. Media that cannot be removed straight away is removed in a follow-up cleanup. Deleting your account also cancels any active subscription, so you are not charged again.
A small number of records remain, each for a specific reason:
- Your handle stays reserved and is never given to anyone else, so links on résumés and applications already sent can never lead to a stranger. It stops showing any content.
- A quota record: a salted cryptographic hash of your email address (with “+” suffixes removed), your AI usage in the current periods and any unused AI Pack balance. It exists so that deleting and re-registering cannot reset usage limits, and so that a purchased AI Pack balance is restored if you return. The hash is pseudonymous: it does not reveal your email, but it can be matched if the same email registers again. It is deleted when you re-register or after 24 months.
- Organizations you created are not deleted, because other people may depend on them. Changes you made to job roles stay in the audit log with the link to your account removed. If you are the only owner of an organization, contact us before deleting your account and we will remove the organization and its roles.
- Handle revocation records (if a handle of yours was ever revoked) are kept for up to 5 years for legal claims.
- Analytics and telemetry linked to your former account ID remain until they expire (section 12). Ask us to delete them sooner.
- Transaction records held by Polar, as merchant of record, for as long as tax law requires.
- Support emails you sent us, until they expire.
- Drafts saved in your browser stay on your device until you clear your browser data.
14. Your Rights
Under the GDPR and Spanish data protection law, you have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- have your data deleted;
- restrict how we process it;
- receive your data in a structured, machine-readable format and have it sent to another service (portability);
- object to processing based on legitimate interest, including profiling;
- withdraw consent at any time, without affecting processing that happened before;
- not be subject to decisions based solely on automated processing that significantly affect you.
You can view, edit, unpublish and delete most of your data yourself in the product, and export résumés and cover letters as PDF. For anything else, including a full copy of your data in JSON format, email privacy@workrepublic.io. We may ask you to confirm your identity. We answer within one month, free of charge; for complex requests we may extend this by two more months and will tell you why.
If you are unhappy with how we handle your data, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es) or to the data protection authority where you live or work. We would appreciate the chance to resolve it with you first.
15. Security
We protect your data with encryption in transit, encryption at rest provided by our infrastructure providers, database access rules that limit each account to its own data, server-only access keys, hashed identifiers where the original is not needed, bot protection and rate limits. Access to production data is limited to what is needed to run and support the service; we look at personal data only when you ask for help, or when necessary to investigate security issues or abuse.
No system is perfectly secure. If a personal data breach puts your rights at risk, we will notify the supervisory authority within 72 hours and tell you without undue delay where required by law.
16. Minimum Age
Work Republic is not intended for anyone under 16. We ask for your date of birth when you set up your account and do not create profiles for people below that age. If we learn that we hold data about someone under 16, we delete it.
17. Changes to This Policy
We update this policy when the product or the law changes. The date at the top shows the latest version. If a change materially affects how we use your data, we will tell you by email or in the product before it takes effect, and ask for your consent where the law requires it.
18. Contact
For any question about this policy or your data, email privacy@workrepublic.io.