Last updated: August 12, 2026
Privacy Policy
This policy explains what Cerno does with your personal data, why, and what you can do about it. It is written to be read, not to be survived. If anything in it is unclear or looks wrong to you, write to us and we will fix it or explain it.
Who is responsible for your data
Cerno is a product of Aubora. Cerno is not a company and is not a legal entity of its own.
The controller of the personal data described in this policy, and the publisher of this site, is Arthur Franco, acting on behalf of Aubora, a company in formation (société en formation), Paris, France. Aubora is not yet incorporated: it has no registration number and is not yet entered in any companies register. Until it is, Arthur Franco carries the controller's obligations personally, on Aubora's behalf. Once Aubora is incorporated, it will take over the processing described here in its own name, and we will update this policy with the company's registered name and SIREN.
For anything to do with your personal data — access, correction, deletion, objection, or a question about this policy — write to privacy@aubora.co.
For anything to do with the product itself — how it works, an account problem, a bug, feedback — write to contact@cerno.me.
Scope: this is a private alpha
Cerno is in private alpha. Access is granted in stages, and the product changes often. This policy describes the service as it works today; where something is not yet in use, we say so rather than reserving a right we are not exercising.
An account means: you give us an email address, a name, and a password; you upload a CV; you answer a set of questions about what you are looking for; and we use all of that to shortlist roles and draft application materials for you to review. Cerno never sends anything on your behalf. Every outgoing action stays with you.
What we collect
Account data. Your email address, your name, and your password. Your password is never stored: we keep only a salted scrypt hash of it, from which the password cannot be recovered.
Your CV. When you upload a CV we store the original file (PDF or DOCX, up to 5 MB), the full text extracted from it, and the structured profile our AI derives from that text — your work history, education, skills, languages, and the contact details printed on the CV, such as your phone number and your professional profile links. Text extraction happens on our own servers; the file itself is not sent anywhere for that step.
What you tell us. Your answers to the onboarding questions, your stated preferences (locations, types of role, sectors, ways of working, tone), any free-text notes you add, including notes about compensation, and your decisions on the roles we propose.
What we generate for you. The shortlists, the fit rationales, and the draft CVs, cover letters, and outreach emails, along with the version history of each draft.
Interviews you record. Dates, locations, and any notes you add.
Support and feedback. If you use the feedback form, we receive your message together with your email address and the page you were on.
Technical data. Aggregate audience measurement, described under "Analytics" below, and the server logs our hosting provider keeps to run and secure the service.
We do not buy personal data, we do not enrich your profile from outside sources, and we do not sell anything about you.
Two things you should know about uploading a CV
A CV can reveal special categories of data. Article 9 of the GDPR gives particular protection to data revealing health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation, and to genetic and biometric data. A CV often contains some of it without the writer thinking of it that way: a period of medical leave, a role at a religious or political organisation, a union mandate, a disability-related adjustment, a volunteering commitment. When you upload a CV, you deliberately provide us with its contents, and we process any such data on the basis of your explicit consent under article 9(2)(a) of the GDPR, given by the act of uploading. We use it for one purpose only: to provide you with the service — to read your CV, build your profile, shortlist roles, and draft materials. We do not use special-category data to improve our algorithms, we do not use it to profile you for any other purpose, and we do not disclose it to anyone beyond the processors named below. You can withdraw that consent at any time by deleting the CV or your account, or by writing to privacy@aubora.co. Withdrawing consent does not affect what was lawfully done before you withdrew it. If you would rather not share something, remove it from the file before you upload it — the service works perfectly well without it.
A CV usually contains other people's data. Referees, managers, colleagues, co-authors and clients appear on CVs by name, and sometimes with their phone number or email address. Those people are data subjects too, and we receive their data from you rather than from them, which engages article 14 of the GDPR. We do not contact them, we do not build profiles of them, and we do not use their data for anything other than reading your CV and drafting your materials; their data is deleted with yours. Even so, please only include other people's details where you are entitled to share them — ask a referee first, and leave out contact details you were not given permission to pass on.
How we use your data, and on what legal basis
- **To provide the service** — creating and running your account, reading your CV, building your profile, generating shortlists and drafts, and keeping your interview notes. Legal basis: performance of the contract between us, article 6(1)(b) GDPR. For any special-category data in your CV, the additional basis is your explicit consent, article 9(2)(a).
- **To communicate with you about your account** — for example, sending you a password reset link when you ask for one. Legal basis: performance of the contract, article 6(1)(b).
- **To answer your messages** — handling feedback and support requests. Legal basis: our legitimate interest in running a usable product and replying to the people who use it, article 6(1)(f).
- **To keep the service secure and working** — server logs, abuse prevention, and limits on how often certain operations can be run. Legal basis: our legitimate interest in the integrity and availability of the service, article 6(1)(f).
- **To measure audience** — the aggregate statistics described under "Analytics". Legal basis: our legitimate interest in knowing which pages are used, article 6(1)(f).
- **To improve our recommendation and drafting algorithms** — described in its own section below. Legal basis: our legitimate interest in improving the product, article 6(1)(f).
We do not use your data for advertising, and we do not make decisions producing legal effects about you by automated means. The shortlists and drafts Cerno produces are proposals for you to accept, edit, or throw away.
AI processing
Cerno is built on large language models, and this is the part of the service that moves your data furthest, so it deserves a plain description.
We use OpenAI as a processor. OpenAI receives, over an encrypted connection and only when a step of the service requires it:
- the text extracted from your CV, when we parse it — including the contact details printed on it;
- your structured profile, your preferences, your free-text notes and your previous answers, when we generate onboarding questions, shortlist roles, or build a search query;
- your profile together with the details of a specific role, when we draft a CV, a cover letter, or an outreach email;
- the titles, employers, locations, and short descriptions of the job listings we are ranking.
OpenAI processes this only to return a result to us. Under OpenAI's API terms, content sent through the API is not used to train or improve OpenAI's models. OpenAI retains request and response content for a limited period — up to thirty days for most endpoints — so that it can monitor for abuse of its platform, after which it is deleted.
The original CV file is never sent to OpenAI; only text and structured data are.
Improving our recommendation and drafting algorithms
Separately from generating your results, we use the content you provide and the outputs we generate for you to review and improve the quality of our recommendation and drafting algorithms — to see where a shortlist missed the point, where a draft reads badly, and where a question was useless, and to change our prompts, our scoring, and our models accordingly. This is a real, distinct purpose, and we would rather name it than bury it.
The legal basis is our legitimate interest in improving the product, article 6(1)(f) GDPR. We have weighed that interest against your rights and limited the processing accordingly: it is carried out by us, on our own systems; it does not involve making your CV available to any third party to train their models; it does not include special-category data, which we use only to provide the service; and it does not produce any decision about you.
You can object to this specific use at any time, on grounds relating to your particular situation or otherwise, by writing to privacy@aubora.co. We will stop using your data for it and confirm that we have. Objecting costs you nothing: the service works exactly the same way for you afterwards.
Job sources
To find roles, we query public job APIs: Adzuna, France Travail, The Muse, Arbeitnow, and Remotive. What we send them is a search query — keywords and a location, derived by our models from your profile. We do not send your name, your email address, your CV, or any identifier that points back to you. These providers return listings to us; they do not receive an account.
Analytics
We use Vercel Web Analytics to understand which pages are used.
It is cookieless. It stores nothing on your device and reads nothing stored there. For each page view it records the page URL and the referring URL. To tell a returning visitor from a new one, it derives a hash from the incoming request; that hash is discarded after twenty-four hours and cannot afterwards be linked to you. What we see is aggregate statistics — page views, referrers, broad location — never an individual's browsing history and never a profile.
This processing is strictly limited to measuring the audience of our own site, on our own behalf. It produces anonymous statistics only, it is not cross-referenced with any other processing, and the data is not passed to anyone else or used to track you across other sites. It therefore falls within the exception to the consent requirement laid down by article 82 of the loi Informatique et Libertés, on the conditions set out by the CNIL in deliberation n° 2020-091 of 17 September 2020, article 5. That is why the site does not put a consent banner in front of you: not because we have decided consent is unnecessary, but because this narrow, non-tracking form of audience measurement is exempted by the framework itself. We do not run any other analytics, advertising, or tracking technology.
Cookies and your session
Cerno sets one cookie in ordinary use, and only once you sign in.
- **rocket_session** — this is what keeps you signed in. It holds a signed token identifying your account and lasts seven days. It is flagged HttpOnly, so scripts in the browser cannot read it, SameSite=Lax, and Secure in production so it is only ever sent over HTTPS. The token is signed, not encrypted, and includes your name and email address alongside your account identifier.
If we later enable the optional mail and calendar connections, a second cookie, cerno_oauth_nonce, exists for ten minutes during the connection flow to protect it against cross-site request forgery. That feature is not active today.
Both cookies are strictly necessary to deliver a service you have expressly requested — staying signed in, and doing so safely. They are therefore exempt from the consent requirement under article 82 of the loi Informatique et Libertés. You can delete them in your browser at any time; if you delete the session cookie you will simply be signed out. We set no advertising, no tracking, and no third-party cookies of any kind.
Hosting, processors, and international transfers
Your data is held in a PostgreSQL database — including your CV file and its extracted text — and the application runs on Vercel Inc., in Vercel's Paris (fra1) region. Database hosting is provided by our database hosting provider under a data processing agreement; we will name that provider here, and confirm the region in which your data is stored, in the next revision of this policy.
The processors who may handle your personal data are:
- **Vercel Inc.** (United States) — application hosting, delivery, server logs, and Web Analytics.
- **OpenAI** (United States) — the AI processing described above.
- **Resend** (United States) — sending the two transactional emails we send: your password reset link, and the notification that carries your feedback message to us.
- Our database hosting provider — storage of the data described in this policy.
Some of these are established in the United States, so some of your data is transferred outside the European Economic Area. Those transfers are covered as follows:
- **Vercel Inc.** is certified under the **EU-U.S. Data Privacy Framework**. Its EU-U.S. certification was verified as active on 12 August 2026. Transfers to Vercel therefore rest on the European Commission's adequacy decision of 10 July 2023, under article 45 GDPR.
- **Resend** is likewise certified under the **EU-U.S. Data Privacy Framework**, verified as active on 12 August 2026, so transfers to Resend rest on the same adequacy decision under article 45 GDPR.
- **OpenAI** is not, as at 12 August 2026, on the Data Privacy Framework list. Transfers to OpenAI are made under the European Commission's **Standard Contractual Clauses** (article 46(2)(c) GDPR), together with the supplementary measures in our agreement with them, including encryption in transit and limitation of retention.
Where any processor's Data Privacy Framework certification lapses, transfers to it fall back on the Standard Contractual Clauses. You can ask us for details of the safeguards in place for any transfer by writing to privacy@aubora.co.
How long we keep your data
We keep your account data, your CV, your profile, your answers, and your drafts for as long as your account exists.
You can delete your account yourself, at any time, from your settings. Deleting your account deletes your account record and, with it, your CV file and its extracted text, your parsed profile, your preferences, your questions and answers, your shortlists and decisions, your drafts and every stored version of them, your interview notes, and any connected-account tokens. That deletion is immediate, not queued. Residual copies held in our providers' routine backups are erased in the ordinary backup cycle and in any event within thirty days.
Two things outlive that deletion, and you should know about them. A message you send us through the feedback form is delivered to our support mailbox and is kept there for as long as we need it to deal with your request. And records of the organisations behind the roles we have shortlisted are kept as reference data about employers; after your account is gone, these no longer identify you.
Password reset tokens expire sixty minutes after they are issued and are single-use. Content sent to OpenAI is retained by OpenAI for up to thirty days, as described above.
Security
Traffic to and from the site is encrypted with TLS, and the site is served with HSTS, a content security policy, and clickjacking protection. Passwords are stored only as salted scrypt hashes. Uploaded files are limited to PDF and DOCX, capped at 5 MB, and checked against their actual file signature rather than what they claim to be. Every endpoint that touches personal data requires an authenticated session and scopes every query to your own account. Tokens for the optional mail and calendar connections are encrypted with AES-256-GCM before they are stored.
No system is perfectly secure, and Cerno is a young product built by a small team. If you find a vulnerability, tell us at contact@cerno.me and we will treat it as a priority.
Your rights
Under the GDPR you have the right to:
- **access** the personal data we hold about you, and obtain a copy of it (article 15);
- **rectify** it if it is inaccurate or incomplete (article 16);
- **erase** it (article 17) — you can do this yourself from your settings, at any time;
- **restrict** our processing of it in the cases the Regulation provides for (article 18);
- **portability** — receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible (article 20);
- **object** to processing based on our legitimate interests, on grounds relating to your particular situation — including, specifically and unconditionally, to the use of your data to improve our algorithms (article 21);
- **withdraw your consent** at any time, where we rely on consent, without affecting the lawfulness of what was done before.
To exercise any of these, write to privacy@aubora.co. We will respond within one month of receiving your request, as article 12(3) of the GDPR requires. If your request is complex, or if you have sent several, we may extend that by up to two further months, and we will tell you within the first month if we do, and why. We may need to ask you something to confirm it is really you.
If you think we have handled your data badly, we would like the chance to put it right first. But you have the right to lodge a complaint with the French supervisory authority at any time, without asking us:
Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr
Data protection officer
We have not designated a data protection officer. None is required: we are not a public authority, our core activity is not large-scale regular and systematic monitoring of individuals, and it is not large-scale processing of special categories of data. If that changes, we will appoint one and say so here. In the meantime, privacy@aubora.co reaches the person actually responsible.
Changes to this policy
We will update this page when the service changes, and we will move the date at the top when we do. If a change is material, we will tell you in the product rather than leaving you to find it. We will update the controller details, and add Aubora's registered name and SIREN, once the company is incorporated.
Contact
For your data and your rights: privacy@aubora.co
For the product and support: contact@cerno.me