Privacy Policy
Nexlo is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how we protect it.
1. Who We Are
Nexlo is an autonomous AI job search service operated by Usama Fateh Ali ("we", "us", "our"). We are based in the United Kingdom.
For questions about this policy, contact us at: alifateh0919@gmail.com
2. Data We Collect
We collect the following information when you use Nexlo:
- Account information: Your name, username, email address, and password (stored as a secure hash — we never store plain text passwords).
- CV / Resume: The document you upload for job matching. Stored securely on our servers and used only to personalise your job scores.
- Job preferences: Target roles, location, salary expectations, and notification preferences.
- Usage data: Which jobs you viewed, applied to, or marked as rejected. Used to improve your experience.
- Communication identifiers: Telegram Chat ID or email address for sending job alerts.
3. How We Use Your Data
We use your data solely to provide the Nexlo service:
- Matching your profile against job listings using AI scoring
- Generating tailored CVs and interview preparation materials
- Sending job alerts via email or Telegram
- Improving the accuracy of our scoring system
We do not sell your data to third parties. We do not use your data for advertising. We do not share your CV with employers without your explicit action.
4. Data Storage and Security
Your data is stored on servers located in the European Union (Hetzner, Germany). We use industry-standard encryption for data in transit (HTTPS/TLS). Passwords are hashed using bcrypt and are never stored in plain text.
We retain your data for as long as your account is active. You may request deletion at any time by contacting us.
5. Your Rights (GDPR)
If you are located in the UK or EU, you have the following rights:
- Access: Request a copy of all data we hold about you
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your account and all associated data
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing of your personal data
To exercise any of these rights, email us at alifateh0919@gmail.com. We will respond within 30 days.
6. Cookies
Nexlo uses a single authentication cookie (jp_token) to keep you signed in. This cookie is httpOnly, meaning it cannot be accessed by JavaScript, and expires after 30 days. We do not use tracking or advertising cookies.
7. Third-Party Services
Nexlo uses the following third-party services to operate:
- Groq / Google Gemini / Anthropic: AI scoring of job listings. Job titles and descriptions are sent to these services. Your CV is not sent to third-party AI providers.
- Gmail SMTP: Sending job alert emails.
- Telegram Bot API: Optional push notifications.
- Hetzner: Server hosting (EU-based).
8. Children
Nexlo is not intended for use by anyone under the age of 16. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this policy from time to time. We will notify registered users of significant changes via email. Continued use of Nexlo after changes constitutes acceptance of the updated policy.
10. Contact
For any privacy-related questions or requests, contact us at: alifateh0919@gmail.com