Sarto Privacy Policy

Last updated: August 7, 2026

This policy explains what information BEAST LABS, SLU ("Beast Labs", "we", "us") handles when you use the Sarto iOS app, the sarto.app website, and the Sarto web app at app.sarto.app, why we handle it, and the choices you have. It is written to describe exactly what happens, nothing more.

1. Who we are

The data controller is BEAST LABS, SLU, registered in the Registry of Companies of the Principality of Andorra (registration no. 23757, book S-455, page 7180), NRT L-718834-Y, D-U-N-S 679993152. Registered office: Avinguda Verge de Canòlich 124, 1r pis, 2a porta, despatx 12, Edifici La Freixera, Sant Julià de Lòria, AD600, Principality of Andorra. Company site: beast-labs.com. Privacy contact: [email protected].

As an Andorran company, our processing of personal data is governed by Andorra's Qualified Law 29/2021 on personal data protection, supervised by the Andorran Data Protection Agency (APDA). Andorra is recognized by the European Commission as providing an adequate level of data protection.

2. The short version

3. Your resume and job postings

Your resume may include information you chose to put there that data protection laws treat as special or sensitive, such as a photo, your nationality, a disability note, or volunteer work that hints at religious or political affiliation. Where the GDPR or similar laws apply, we process such content only because you explicitly choose to submit it for tailoring (Article 9(2)(a), explicit consent), we process it transiently like everything else, and we never store it. If you prefer, remove the photo or any sensitive detail before importing; the results are just as good without them.

Resume files, photos, and job postings you import are sent to our server only to be read into structured text, scored against the job, and used to generate your tailored resume and cover letter. They are processed transiently and are not stored or logged on the server. In the iOS app, your resume, applications, and exported documents are stored on your device and, if iCloud is enabled, synced to your own private iCloud so a new device can restore them. We cannot read your private iCloud data. Deleting the app removes them from the device; "Delete account" in Settings removes them everywhere, including the iCloud copies.

In the web app the same content is kept in your browser's own local storage, on the computer you are using, and nowhere else. We hold no copy of it and cannot restore it, so it does not follow you to another browser, another computer, or your phone, and clearing your browser data erases it. "Start over" in the web app clears it immediately. Download what you want to keep.

To generate results, content is processed by third-party large-language-model providers (currently OpenAI and/or Anthropic, depending on the task) under API agreements that do not permit them to train models on your data. Our own server runs in the European Union (Germany).

4. Account and sign-in

When you first use Sarto, the app creates a pseudonymous internal user identifier so we can apply fair-use limits and remember your subscription. It is not tied to your name and is never shared with advertising platforms.

To unlock tailoring and keep your subscription across devices, you sign in with your email address, Apple, or Google. We store your email address (or the sign-in provider's identifier), basic session and device records that keep you signed in, and one-time sign-in codes that expire shortly after they are sent. A transactional email provider delivers those codes on our behalf; the emails contain no marketing. Your email address is never used for marketing and never shared for advertising.

5. Purchases

Where you buy decides who bills you. Both routes are described here, and in neither one do we receive your payment card details.

In the iOS app. Subscriptions are bought through Apple and billed to your Apple ID. We use RevenueCat to validate those purchases and manage subscription status.

On the web. Subscriptions bought at app.sarto.app are sold by Paddle.com Market Ltd, which acts as our reseller and merchant of record. Paddle is the seller of record for the transaction: it takes the payment, issues the invoice, handles sales tax and VAT, and runs its own fraud checks. You enter your billing details with Paddle and not with us, and Paddle is an independent controller of that billing information. Paddle passes us only what is needed to unlock your subscription: an identifier for it, the product, the period, and its state. What Paddle does with your billing data is governed by Paddle's privacy notice.

In both cases we store subscription status (product, expiry, state, and which of the two systems sold it) to unlock features and prevent fraud. That last field is also what tells us where to send you to cancel, and what lets us cancel a web subscription for you when you delete your account.

6. Usage analytics

We record coarse, first-party usage events (for example "score shown", with a score band rather than the exact score) to understand where the product works and where it fails. These events never contain resume or job-posting content; the event pipeline rejects content fields by design. They are stored on our own server, keyed to your pseudonymous user identifier, deleted after 365 days, and never shared with advertising platforms. If you delete your account, these events lose their link to any identity (the identifier can no longer be connected to you) and are kept only until that same 365-day limit. We use no third-party analytics SDKs; a copy of these coarse event markers (names and bands only, never content) is attached to your subscription profile in RevenueCat, our purchase infrastructure (section 12), kept with your purchase records (section 13) and removed on request.

7. Advertising measurement

To know whether our ads work, the app shares limited signals with AppsFlyer, the ad measurement service we use, which passes them to the advertising platforms we run ads on: a device advertising identifier (only if you allow tracking when iOS asks), app install and launch events, and purchase events (product, price, and currency). Currently those platforms are Meta and TikTok; if we advertise elsewhere in the future, the same limits apply. Your resume, job postings, email address, and internal user identifier are never shared with AppsFlyer or the advertising platforms. If you deny tracking, no advertising identifier is shared. You can change your choice at any time in iOS Settings > Privacy & Security > Tracking.

Our website, sarto.app, uses Google Ads conversion cookies for the same purpose: to measure whether visits and App Store clicks come from our ads. These cookies (names starting with "_gcl", kept about 90 days) are set only if you accept them in the cookie banner; the only cookie set without consent is the one that stores your choice (kept 6 months). You can change your choice at any time via "Cookie preferences" in the site footer, and the full cookie tables are in the Cookie Policy. The website also uses Cloudflare Web Analytics, a cookieless audience and performance measurement served by our infrastructure provider: it sets no cookies, stores no identifiers, and does not track you across sites. The website never receives resume content.

8. Support

If you email us, we use your address and the content of your message only to respond and to fix the problem you report. Please do not include sensitive personal information in support messages.

9. Technical data

Like almost every internet service, our server briefly processes technical request data, such as your IP address and basic request metadata (endpoint, status code, timing), to deliver responses, enforce the rate limits that protect the service, and detect abuse. IP addresses are never stored in our database, and request logs never contain resume or job-posting content.

10. How we use information

We do not use your information for any other purpose. We do not build advertising profiles of you, and we send no marketing emails.

11. Legal bases

Where laws such as the EU/EEA GDPR apply, we rely on: performance of a contract (providing the app, your account, and your subscription), consent (tracking permission on iOS, advertising cookies on the website), legitimate interests (security, fraud prevention, first-party product analytics), and compliance with legal obligations.

12. When we share information

We do not sell your personal information for money, and we never share your content or email address for advertising. We share information only with:

13. How long we keep information

Resume and job content: not stored on our servers at all. Account data (email, sessions, subscription status): kept while your account exists and deleted when you delete it. Analytics events: deleted after 365 days. One-time sign-in codes: expire shortly after being sent. Purchase records: kept as long as needed to maintain your access and meet legal obligations. Anything else is kept only as long as needed for the purposes described above.

14. International transfers

Our server runs in the European Union (Germany), and data can flow lawfully between the EU/EEA and Andorra under the European Commission's adequacy decision for Andorra. Some providers (for example our AI providers, our merchant of record Paddle, and advertising platforms) process data in the United Kingdom or the United States; where required, those transfers rely on appropriate safeguards such as contractual protections.

15. Security

All traffic between the app, the website, and our server is encrypted in transit. Access to production systems is restricted, and the design principle of this product is minimization: the most sensitive data, your resume, is never stored on our side in the first place. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we handle as little as possible so there is as little as possible to lose.

16. Your rights and choices

Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected or deleted, to receive a copy in a portable format, to object to or restrict certain processing, and to withdraw consent at any time (for example by changing the iOS tracking setting or the website cookie choice). To exercise any of these rights, email [email protected]. We may ask you to verify your identity, and we respond within the time required by applicable law (at most 30 to 45 days in most jurisdictions).

If you are in the EU/EEA, you also have the right to lodge a complaint with your local supervisory authority or with the Andorran Data Protection Agency (APDA).

If you are a California resident, you have rights under the CCPA/CPRA, including to know, access, correct, and delete personal information, and to opt out of "sale" or "sharing". We do not sell personal information for money, but sharing device identifiers and purchase events with advertising platforms (section 7) may count as "sharing" for cross-context behavioral advertising under California law. You can opt out by denying tracking in iOS, rejecting advertising cookies on the website, or emailing us. We never discriminate against you for exercising any right.

17. Children and minors

Sarto is a job-application tool for adults. The Terms of Service require you to be at least 18, and the Service is neither designed for nor directed to children or teenagers. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, email us and we will delete it.

18. Deleting your data

In the app, Settings > "Delete account" removes your account, your server data, and everything stored on your device (resume, applications, exports), immediately and irreversibly. Deletion requires an internet connection: the app first asks our server to erase your account, and only after the server confirms does it remove everything from your device and sign you out. If the server cannot be reached, nothing is deleted, you stay signed in, and you can try again once you are back online. The web app has the same option in its own Settings, and it clears what your browser is holding.

If you have a subscription bought on the web, deleting your account cancels that subscription first, so it cannot keep billing a card once the records tying it to you are gone. If the cancellation cannot be completed, we tell you so and leave your account intact rather than delete it, because the deleted account would be the only way back to the subscription. A subscription bought in the app is billed by Apple and only you can cancel it, in your Apple ID subscription settings.

What survives a deletion: the anonymous usage-event stream described in section 6 (never your documents' content, no longer linked to any identity, erased after at most 365 days) and the purchase records described in section 13, kept as long as tax and accounting law requires. You can also email us to request deletion.

19. Changes to this policy

We may update this policy as the product evolves. We will post the updated version on this page and revise the "Last updated" date; if a change meaningfully reduces your rights, we will point it out in the app or on the site before it takes effect.

20. Contact

[email protected] · BEAST LABS, SLU, Avinguda Verge de Canòlich 124, Sant Julià de Lòria, AD600, Andorra

Terms of Service · Refund Policy