Privacy Policy
Last updated 2026-05-06 — DRAFT pending lawyer review.
Kudos is a bilingual AI career coach for the Saudi Arabian job market. This policy describes the personal data we collect, how we use it, where it is stored, and the rights you have under the Saudi Personal Data Protection Law (PDPL).
Data controller
Kudos is operated by an entity registered in the Kingdom of Saudi Arabia. Contact: privacy@kudos.sa.
What we collect
- Account identifiers — email, user ID.
- CV content — job titles, education, skills, free-text summaries you paste or type.
- Preferred language (Arabic / English), city, target roles.
- Anonymous page views and completed-funnel events.
- Moyasar payment ID, amount, VAT split, status. We never see or store card numbers — Moyasar handles all card data.
Where your data lives
Account data, CV drafts, and roadmap content live in Saudi Arabia in our database hosted on SCCC (Riyadh region me-central-1). Generated PDFs are stored in Saudi-resident object storage. Authentication runs on a Saudi-resident virtual machine.
Some processing requires sending data outside Saudi Arabia: the AI model that powers your CV (Anthropic's Claude), transactional email (Resend), anonymous analytics with hashed identifiers (PostHog), and error reporting (Sentry). These transfers are necessary for the performance of your contract with us (PDPL Article 29(2)(a)).
How we use your data
- To generate your CV drafts, suggestions, and summaries via Claude.
- To produce the four output files (ATS CV × 2 languages, designed CV × 2 languages).
- To send you sign-in magic links, payment receipts, and account notifications.
- For anonymous product improvement using hashed identifiers.
- To debug service errors (stack traces only — your CV content is never sent to error reporting).
Your rights (PDPL Articles 20–25)
You have the right to access your data, correct inaccuracies, request deletion, withdraw consent, request data portability, and object to processing. You can exercise these rights instantly from your account page or by emailing privacy@kudos.sa. We respond within 30 days.
Retention
- Account data: kept while your account is active. Deleted on request.
- Unfinished CV drafts: 30 days. Paid drafts: kept while your account is active.
- Payment records: 7 years (Saudi tax law).
- Audit logs: 12 months rolling. Records of deletion requests are kept indefinitely as proof.
Breach notification
If we discover a breach affecting your personal data, we will notify SDAIA (the Saudi Data and AI Authority) within 72 hours and notify you without undue delay if the breach poses high risk to your rights.
Children
Kudos is for adult job-seekers. We require that you are 18 or older to use the service.
Changes
We will update this page and refresh the 'Last updated' date when this policy changes. Material changes will be announced via email at least 14 days before they take effect.
Contact
Questions or complaints? Email privacy@kudos.sa or write to our entity address (provided on request).