Privacy-preserving analytics
The single first-party ping in the monitor above is nearly the whole story. From it the server keeps: the page path, the referring site, your window width and language, and, computed on the server, a one-way hashed visitor id (sha256 of your IP address and browser, truncated, so the raw IP is never stored), the browser’s user-agent string, and a device type (phone, tablet or desktop). There is no third-party analytics service, no cross-site tracking, and no advertising network anywhere on the site.
On-device AI and content delivery
The CV Builder and the Learn tutor run their AI in your browser. The model is downloaded once from public code CDNs (such as Cloudflare, jsDelivr and Hugging Face), then runs entirely on your device via WebGPU. You only ever download from those CDNs; your resume, your code and your answers are never sent to them or to any AI company. So if you watch DevTools while the AI loads, you will see those content downloads, and nothing of yours going out.
Cookies
The CV Builder uses one first-party cookie to link your saved draft across visits, plus a standard session cookie for security. No advertising or cross-site cookies, ever. The desktop app uses none; it is not a website.
Children’s privacy
The desktop app collects no data from anyone. The website does not knowingly collect personal data from children under 13. If you believe a child has submitted data, email me and I will remove it.
Your data, your responsibility
Floati’s products are free and provided as is, without warranty of any kind. The flip side of everything living on your device is that I hold no copy: I cannot read your data, and I also cannot recover or restore it if your device is lost or wiped. Keep your own backups; the desktop app and the browser both include export and encrypted-backup tools for exactly this.
When I would disclose data
For the products above I hold almost nothing to disclose. For the little the website does hold (saved CV drafts keyed to a random cookie, certificates, reviews, and hashed analytics), I would only disclose it if a law I am subject to compels it, and I have never been required to. I do not sell or share any of it with advertisers or data brokers, full stop.
Changes, and how to reach me
If anything changes, the updated policy is published at this URL with a new “last updated” date. No silent edits, and no weakening of the on-device principle without a clear, dated notice here.
Questions, corrections or deletion requests: nevintom2018@gmail.com. Built and operated by Nevin Tom in South Africa. Last updated July 2026.