Privacy Policy
Last updated: 20 July 2026
StaffGenerator (“we”, “us”) is operated by Website Holding. This policy explains what we collect when you use staffgenerator.com, why, and the choices you have. We keep it deliberately short because we collect very little.
What we collect
- Account details. If you create an account, we store your email address and a salted, scrypt-hashed password. We never store your password in plain text.
- Saved generations. The job title, industry, seniority, and generated documents you explicitly save to your dashboard are stored so you can return to and edit them.
- Plan status. Your plan (free, Pro, or trial) and related fields, so we can apply the right entitlements. Any paid plan is billed by Website Holding as merchant of record (see our Terms).
- API keys. If you create an API key, we store a one-way hash of the key (never the key itself), a short display prefix, and your label for it. The full key is shown to you only once, at creation.
- Usage metering. When you call the generation API or export a pack (Word/PDF), we log a usage event — the endpoint, a count, and a timestamp — to enforce plan limits and show your usage chart.
- IP address (abuse prevention only). Sign-up, sign-in, the contact form, and the public generation API briefly check the request’s IP address against a short-lived rate limit to stop automated abuse. The IP address is held only long enough to enforce that limit (a rolling window of a few minutes) and is not stored in our database or linked to your account.
- Slack webhook URL (optional, only if you connect it). If you choose to connect a Slack Incoming Webhook in account settings, we store that webhook URL so you can send a pack to your own Slack channel with one click. When you use “Send to Slack,” the pack’s content is sent directly to Slack, which is then subject to Slack’s own privacy policy for that message. We never send anything to Slack unless you explicitly click “Send to Slack.”
Documents you generate in the browser without saving them are not written to our database. For API and export calls we record only the usage event above, never the generated content itself.
Cookies
We use first-party, HTTP-only cookies for authentication only — there are no advertising, analytics, or cross-site tracking cookies:
sg_session— keeps you signed in to your account.sg_admin— set only for the site operator when signing in to the internal operations panel; it is never set for normal visitors.
What we do not do
- We do not sell or rent your personal data.
- We do not run third-party advertising, analytics, or tracking pixels.
- We do not use your content to train models.
How the documents are generated
Documents are assembled by a deterministic, rules-based generator that runs on our own servers. There is no third-party AI service or large language model in the loop, so your inputs are never sent to an outside model provider. Your inputs are processed to produce the output and are only persisted if you choose to save the result.
Where your data is processed & sub-processors
The service runs on Amazon Web Services (AWS): an AWS Lambda function served through Amazon CloudFront, with your data stored in an isolated Amazon RDS (PostgreSQL) database in the EU. This infrastructure, and payment processing, are operated on our behalf by Website Holding, our sole sub-processor and the merchant of record. We do not share your personal data with any other third parties, with one exception you control directly: if you connect Slack and click “Send to Slack,” the pack you chose to send is delivered to the Slack workspace you configured — never automatically, and never without that explicit action.
Data retention & deletion
Saved generations remain until you delete them from your dashboard. You can delete your account and all associated data at any time from your account settings, which permanently removes your user record, sessions, and saved generations.
Your rights
Depending on where you live — including the EU/EEA under the GDPR and California under the CCPA — you may have the right to access, correct, export, or delete your personal data, and to opt out of any sale of personal information (we never sell it). To exercise any of these, use account settings to export or permanently delete your data, or reach us via the contact page.
Contact
Questions about this policy? See our contact & support page. StaffGenerator is operated by Website Holding, the merchant of record for this service.