Data Processing Agreement
Draft — pending counsel review. Last updated: 2026-05-17.
Anstello is a desktop application. Your CV, your pipeline, your scrape history, and your settings live on your own device. Anstello does not operate a hosted backend for user content. Because no personal data is hosted by us, an Art. 28 GDPR controller–processor relationship with Anstello as processor does not arise for that data.
Two third parties may process data on your behalf when you use paid or AI features. Their processor agreements are listed below.
1. Anthropic (Claude API)
When you invoke CV tailoring or listing scoring, Anstello sends the relevant CV text and job text to the Claude API — using your own Anthropic API key, stored in the macOS Keychain. That request is made from your machine under your own Anthropic account; Anstello is not a party to it and never sees the key or the traffic. Anthropic's commercial terms (no training on API inputs) govern that relationship and are available at anthropic.com/legal.
2. Gumroad (billing)
Gumroad acts as merchant of record for Anstello subscriptions and is the data controller for billing data (name, email, payment method, invoice address). Gumroad's privacy and processor terms are available at gumroad.com/privacy. We receive only the minimum fields needed to deliver and validate a licence key (licence key, hashed email, subscription status).
3. Hosting (marketing site)
The marketing site at anstello.com is a set of static files with no application behind it. The hosting provider that serves them keeps the usual access logs (IP, user agent, path, referer) for abuse defence.
4. Your rights
You can export everything Anstello holds on your device at any time via the in-app export. To exercise rights under GDPR Art. 15 to 21 against any of the third parties listed above, contact hello@anstello.com and we will route the request appropriately.