Privacy policy
OyilaPrompt AI Privacy Policy
OyilaPrompt AI processes only the text or CV file you choose to send, plus the minimum account and usage data needed to run the service. We do not sell your data, and we do not use it to train AI models.
Who this applies to
This policy covers the OyilaPrompt AI website at oyilaprompt.com and the OyilaPrompt AI Chrome extension. OyilaPrompt AI is a service of Cloudpilar Limited, a company registered in England and Wales under company number 15273802, whose registered office is at 23 Derwent Road, Bristol, BS5 7SJ, United Kingdom. For UK data protection purposes Cloudpilar Limited is the data controller for the information described below. You can reach us at support@oyilaprompt.com.
What we collect
Account information
If you create an account we store your name, email address and the date the account was created. Passwords are never stored in readable form — they are kept only as a salted scrypt hash, and we cannot recover or read your password. If you sign in with Google we receive your name and email address from Google, never your Google password.
Text you submit for improvement
When you use the extension, the text you have selected or written, any CV file text you upload, and the options you choose (writing mode, optional job context, tone and English variant) are sent to our backend so the requested improvement can be generated. That input is processed to answer the request and is not stored: we keep no copy of the drafts, CV files, job adverts or background notes you send us. Uploaded CV files are read in memory to extract their text and are never written to disk or kept.
Generation history
If you are signed in, a successful generation is saved to your own history so you can reopen it later. Each saved entry holds the result we generated for you, plus a short title of up to 80 characters, the writing mode, which model ran, the credits it cost, the language and the date. The title is a brief label (for example “Targeted CV: Support Worker”) — never your full input.
Generation history is kept for up to 30 days unless you delete it sooner. After 30 days an entry stops being visible and is deleted from the database automatically — generated CVs, personal statements and application answers can be sensitive, so we do not keep them indefinitely by default.
Your history is private to your account. Every read and delete is scoped to your own user ID, so no other user can list, open or delete your entries. Failed generations are never saved, and requests made while signed out are never saved at all.
You stay in control: turn saving off at any time with the Save historysetting in the extension popup, delete any single entry, or clear your whole history — both from the History view in the extension. Deleting is immediate and permanent.
Usage and fair-use records
To operate weekly credit allowances we store counters against three identifiers: an anonymous install ID generated by the extension, your user ID if you are signed in, and a one-way SHA-256 digest of the network address the request came from. The network address itself is never stored, logged or shared — only the digest, which exists so that creating endless new install IDs cannot be used to bypass the free allowance. We also store which plan an account is on.
Payment information
Subscription payments are processed by Stripe. Card details are entered on Stripe’s own checkout pages and are never sent to, seen by, or stored by OyilaPrompt AI. We store only the Stripe customer and subscription identifiers needed to know whether your subscription is active. Stripe processes this data as an independent controller under its own privacy policy.
What the Chrome extension reads
The extension reads selected or current text only after you click Improve, and reads an uploaded CV file only after you choose one in Complete CV Enhancer. It does not read passwords or hidden fields, does not submit forms, does not auto-apply to jobs, and does not send emails on your behalf. It runs only on the sites listed in its Chrome Web Store listing.
If you link the extension to your account, the website passes it a scoped link token. That token identifies your account so your plan applies in the extension. It is not a website login, carries no plan claim of its own, expires, and is revoked immediately when you sign out on the website.
Who processes your data
- Neon — hosts the PostgreSQL database holding accounts, plans, usage counters and saved history entries.
- Google Cloud (Cloud Run) — hosts the application that serves the website and backend.
- OpenRouter — routes improvement requests to the AI model provider that generates the result. Where the deployment enables it, requests are restricted to providers offering Zero Data Retention, meaning the provider does not retain the request after answering it.
- Stripe — processes subscription payments and holds the card data we never receive.
These providers may process data outside the UK. Where that happens we rely on the providers’ own approved safeguards for international transfers.
What we do not do
- We do not keep the input you send us — only the results saved to your own history, which you can switch off or delete.
- We do not use your content to train AI models.
- We do not read your history, and no other user can see it.
- We do not sell or rent your personal data.
- We do not use advertising or third-party analytics trackers.
Cookies
The website sets a single essential cookie to keep you signed in. There are no advertising or analytics cookies, so there is no consent banner to click through.
How long we keep it
Account data is kept while your account exists. Usage counters are tied to a weekly period and are not kept as a long-term profile of your activity. The text you send for improvement is not retained at all. Saved history entries are kept for up to 30 days and are then deleted automatically; you can delete them sooner yourself, and deleting your account removes them immediately. If subscriptions are active, billing records are kept for as long as UK tax and accounting law requires.
Your rights
Under UK data protection law you have the right to access a copy of your personal data, to have inaccurate data corrected, to have your data deleted, to restrict or object to processing, and to receive your data in a portable form. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).
Deleting your data
Email support@oyilaprompt.com from the address on your account and ask us to delete it. We will confirm and action the request within 30 days. Deleting your account removes your profile, plan, usage records and every saved history entry. You can also clear your history yourself at any time from the History view in the extension, without deleting your account. If you have an active subscription, cancel it first (or ask us to cancel it as part of the same request).
To stop the extension using your account without deleting anything, sign out on the website — that immediately revokes the extension link.
Free allowance
The free plan includes 7 credits per week. See Pricing for what each plan includes and Terms for the fair-use rules.
Changes to this policy
If this policy changes materially we will update this page and, where the change affects how your data is used, tell account holders by email.
Contact
Questions or requests: support@oyilaprompt.com.
Cloudpilar Limited, 23 Derwent Road, Bristol, BS5 7SJ, United Kingdom. Registered in England and Wales, company number 15273802.