Trevo.work
JobsMatches
עב
Sign inSign up free
Loading…
Terms of ServicePrivacy PolicyRefund Policy

© Trevo.work

// legal

Privacy Policy

Last updated: July 4, 2026

Trevo.work ("Trevo") is committed to protecting the privacy of its users. This policy explains what information we collect, how we use it, and with whom we share it. It is aligned with the Israeli Privacy Protection Law, 5741-1981 and with GDPR where applicable to EU residents.

1. Data we collect

  • Account data: email address, display name, hashed password (handled by Supabase Auth).
  • CV files: the optional CV you upload, plus the technologies and seniority signal extracted from it for matching.
  • Voice profile interview: if you use the voice interview to build your profile, your recording is sent to our AI provider (OpenAI) for transcription and discarded immediately afterwards — we store only the transcript text, never the audio itself.
  • Career-fit assessment: if you use the voice assessment, your LinkedIn screenshot (if attached) and your recording are processed by our AI providers and discarded immediately — we keep only the processed text and the fit report generated for you.
  • Activity history:jobs you saved, archived, marked "CV sent", and any private notes you wrote.
  • Saved searches: keywords, preferred roles, regions.
  • Payment data (Pro only): processed directly by PayPal. We never see or store your card number.
  • Technical data: IP, browser type, current page URL (only attached when you voluntarily submit a bug report).
  • Security and abuse-prevention logs: IP address, User-Agent, request rate and patterns, accessed paths, and automation/scraping signatures. This data is collected to protect the Service and its catalog against data exfiltration, reverse engineering, and circumvention of plan limits, in line with section 6 of the Terms of Service. Legal basis: Trevo's legitimate interest (Section 11 of the Israeli Privacy Protection Law; Art. 6(1)(f) GDPR).

2. How we use the data

We use the data to:
  • provide the Service (filter jobs, personalize ranking, generate the daily brief);
  • retain your CV and match you with employers: we may keep the CV you uploaded to proactively search and match suitable roles for you with employers in the industry. We will never share your details with an employer without your explicit approval.
  • authenticate users and run accounts;
  • send transactional email (signup confirmation, alerts, brief, billing notices);
  • improve the algorithm and the catalog (in aggregate; not personally identifying);
  • comply with legal requirements (invoices, payment audit trail).

3. Third-party processors

We share minimal data with the following providers, only as needed to deliver the Service:
  • Supabase — DB hosting + auth. Stored in EU (eu-central-1).
  • Vercel — application hosting.
  • PayPal — payment processing — the payment processor for Pro users.
  • Resend — transactional email delivery.
  • OpenAI (the primary AI provider for CV analysis and brief generation), with Anthropic and Google AI as fallbacks. These providers' servers are in the USA — so your CV text and employment history are transferred to and processed outside Israel. Data is sent only for the inference call, never to train models. Legal basis for the transfer: your explicit consent at upload. Note that transferring personal data abroad cannot be undone after the fact.
  • PostHog and Microsoft Clarity — anonymous usage analytics (you can block these with a DNT/Privacy browser extension).
  • Admin access — Trevo administrators may view first-party activity data (last login, in-app actions, and saved searches) associated with your account for operations, support, and service improvement. Detailed behavioural data (session recordings, heatmaps) is collected masked and identified by an anonymous identifier only.

Transfer of data outside Israel: some data is processed and stored outside Israel. Supabase (the database and auth) servers are located in the European Union (eu-central-1); Vercel (application hosting) and Resend (transactional email) run infrastructure in the USA and the EU; and the AI providers (OpenAI, Anthropic, Google AI) process requests in the USA. Legal basis for the transfer: performance of our contract with you and delivery of the service you requested, your explicit consent (for CV text and content you upload), and our legitimate interest in protecting the service — all in line with the Israeli Privacy Protection Law, 5741-1981 (including Amendment 13) and the GDPR where applicable. Data is transferred solely to deliver the Service, is covered by data-processing agreements (DPAs) with the providers, and is never used to train models. Note that transferring personal data outside Israel cannot be undone after the fact.

We do not sell personal data to any third party and do not use it for targeted advertising.

4. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or longer where required by law. Retention periods by data type:

  • Account and registration data — retained as long as your account is active.
  • CV file — retained until you delete it from /account/cv.
  • Activity history and saved searches — retained while the account is active and deleted when the account is deleted.
  • Voice profile transcripts — retained for 90 days then auto-deleted (the audio itself is never stored).
  • Daily briefs — auto-pruned after 90 days.
  • Analytics data (PostHog, Clarity) — retained under an anonymous identifier only per those providers' retention policies, with no name or email.
  • Security and abuse-prevention logs — retained for up to 12 months, or longer if needed to investigate an active incident or for legal proceedings.
  • Deleted account — personal data deleted within 30 days. Billing records and invoices retained as required by law (7 years under tax rules).

5. Rights of the data subject

Under the Israeli Privacy Protection Law, 5741-1981 (including Amendment 13) and the GDPR where applicable to you, you have the following rights regarding your personal data:
  • Right of access: to know whether we hold data about you and to inspect it (Section 13 of the Law).
  • Right to correction: to request correction or update of data that is inaccurate, incomplete, unclear, or out of date (Section 14 of the Law).
  • Right to erasure:to request deletion of personal data ("right to be forgotten"), subject to statutory retention obligations.
  • Restriction of processing: to request that we limit the use of your data in certain situations (e.g. while a correction or objection request is being reviewed).
  • Objection to processing: to object to processing based on legitimate interest, and to opt out of marketing or mailings.
  • Data portability: to receive the data you provided in a structured, commonly used, machine-readable format and transfer it elsewhere.
  • Withdrawal of consent: to withdraw consent you gave at any time, without affecting the lawfulness of processing carried out beforehand.
  • Lodging a complaint: to lodge a complaint with the Israeli Privacy Protection Authority (the Database Registrar) or your local supervisory authority.

To exercise any of these rights, contact us via the contact form or at roya@trevo.work. We respond within 30 days. We may need to verify your identity before acting on a request, to protect your data.

6. Cookies

We use essential cookies for app function (Supabase session cookies) and analytics tools (PostHog and Microsoft Clarity). The data is stored in the EU, masked (all text and inputs are hidden in recordings), and never includes your name or email — you're identified by an anonymous id only. You can opt out of analytics collection anytime via the "Don't collect usage data" button in the cookie notice at the bottom of the screen, or block cookies in your browser.

7. Security

We apply industry-standard security: HTTPS everywhere, hashed passwords (bcrypt via Supabase Auth), Row-Level Security on the database, service-role access only from the server. No system is 100% secure though. In the event of a material security incident we will notify affected users and the Israeli Privacy Protection Authority as required.

8. Children under 16

The Service is not directed to minors under 16. We do not knowingly collect data from minors. If we discover an account belongs to a minor it will be removed.

9. Policy changes

Material changes are announced 14 days in advance on this page and by email to Pro users.

10. Contact and data-controller details

Data controller & service operator: Roy Avrahami (sole proprietor), Trevo.work, Tel Aviv, Israel. For privacy requests (access, correction, deletion) and any other inquiry: roya@trevo.work or via the contact form. Response within 30 days.