Every AI task, what starts it, and where it runs.
Erioun uses AI as decision support — it never sends anything and never decides anything about you. This page names every provider and country, says which tasks wait for your click and which run on events, and explains the pseudonymisation that strips your identity out of everything that leaves our servers.
The short version
The whole page in seven points:
- Most AI tasks run when you click. A small, named set runs on events: sorting inbound replies, safety-checking outgoing mail, analysing a CV you upload, the scheduled ranking of your job feed, the extension's field fallback, and the steps inside an import you started.
- Providers: Mistral AI (Paris, France — EU) for almost everything; Anthropic (US) for premium drafts, long-form writing, the tracker import and the web-searched interview coach; our own model on our own hardware in Thessaloniki, Greece, for two background text tasks. No Chinese-origin model is reachable in production.
- Everything that leaves our hardware is pseudonymised first: your name, e-mail, phone, addresses and other identifiers become placeholders, and the real values are put back only after the answer returns. Only our own local model reads text as written — because nothing leaves our machine.
- The named vendors state that they do not train on API customer data. We repeat their terms below, including retention, exactly as published.
- Chat features that talk with you — the interview coach, the help assistant, a hiring team's chat interview — tell you that you are talking to an AI.
- Teams AI screening is off by default, per workspace. Where an employer switches it on, applicants are told before they submit, can refuse AI outright, and a person makes every decision.
- Your AI consent in Settings governs the tasks that read your content, including tracker imports. AI request logs hold metadata only — never your prompts — and are kept 13 months.
1. When AI runs: your click, an event, or a schedule
Three triggers exist, and each task has exactly one. Nothing else runs.
- You click: job-fit deep looks you request, application and answer drafts, the tailored CV, cover letters and long-form answers in the extension, reply and follow-up drafts, interview prep and the interview coach, JD summaries, translations, the help assistant.
- An event: every inbound mail to your alias is classified and matched so replies file themselves (gated by your e-mail-processing consent); every outgoing mail passes a safety check before it leaves (this one cannot be switched off — it protects recipients and our sending domain); a CV you upload is analysed on arrival (gated by your AI consent); when you start a tracker import, its column-mapping, row-rescue and logo-recognition steps run inside it; the extension drafts unmatched form fields as a fallback when you use it.
- A schedule: Opportunity Radar refreshes your ranking on the schedule shown on the pricing page, and gives the top three matches of each run a deeper look that reads your full CV text. Gated by your AI consent.
- In Erioun for Teams: where a workspace switched AI screening on, each new application is screened as it arrives and on a member's click — never in a workspace that left it off — and chat-interview answers are evaluated only where the employer marked questions for it. See section 7.
2. The providers, by country
Every provider that can receive data from a production code path. Anything not listed here cannot be reached.
- Mistral AI SAS — Paris, France (EU). The default for almost every task, Teams screening included, and the OCR service for documents our own parser cannot read. Mistral stores customer data in the EU by default; on its global API endpoint it does not commit to a specific inference location.
- Anthropic PBC — United States. Runs premium application drafts, the extension's long-form answers and cover letters, the tracker import and the interview coach's web-searched answers (which also send the model's own search queries — company, role, market — to a search provider). Reached through the Cloudflare AI Gateway or directly.
- Cloudflare, Inc. — United States. Not a model we choose: its AI Gateway is the pipe that carries our Anthropic traffic. Its Workers AI models are configured as an operator option only — since the AI rework, no task falls back to them, because every task runs in privacy mode.
- Our own hardware — Thessaloniki, Greece. An IBM Granite model (US-origin open weights, Apache 2.0) on a server we own runs job-posting extraction and inbound-mail classification when enrolled. Nothing leaves the machine.
- Dormant, for completeness: OpenAI (US) — a key exists, zero requests ever, and no task routes there. CompactifAI (Multiverse Computing, Spain — EU) — off in production; the only place Chinese-origin open-weight models (Qwen, GLM) exist in our code is behind this switched-off integration, run on EU/US servers, never reachable today. No DeepSeek, no Kimi, anywhere.
3. Pseudonymisation — what leaves our servers, and what never does
Before any text goes to a hosted provider, one masking pass replaces identifiers with placeholders like [[PERSON_1]] and [[EMAIL_1]]. The mapping lives in memory for that one call — never stored, never logged — and the answer is restored before anyone reads it, so a draft is still signed with your real name. If your identifiers cannot be read, nothing is sent at all.
- Masked: the name, e-mail and phone we hold for the person the text is about; addresses; IBANs, national id numbers, passport numbers, labelled birth dates; and any e-mail address, URL, phone number or labelled name found in the text itself.
- Deliberately not masked: organisation names (employers, schools — they are what the task is about), job titles, skills, dates, and a bystander's name that nothing labels — guessing names from capitalised words made results worse, not safer.
- So pseudonymised is not anonymised: the text still describes a career. What stays home is who you are.
- The exceptions, each with its reason: job-posting-only tasks (extraction, salary estimate, translation) carry no candidate data; OCR sends the uploaded file itself, because an unread PDF has no text to mask; logo recognition sends only images. Every other task is masked — a task nobody classified is masked by default.
- For Teams screening, the applicant's CV is masked twice — once by the screening engine with the applicant's own details, once more by the router.
4. Training and retention, per vendor
What the vendors' published terms say, stated carefully. We repeat them; we do not improve on them.
- Mistral: its Commercial Terms state it does not train on customer data or outputs. Inputs and outputs are kept for 30 rolling days for abuse monitoring unless zero-data-retention is approved; our OCR uploads are deleted right after the read. We are confirming the zero-retention and improvement-data settings on our account.
- Anthropic: by default it does not train on API inputs or outputs; API data is deleted within 30 days (longer only for content flagged under its usage policy). Read 30 days as the upper bound.
- Cloudflare: states it does not use customer content to train AI models. Its AI Gateway can keep request logs; since the AI rework those logs would contain only pseudonymised text, and we are confirming the logging setting on our gateway.
- Our own model: no training, no vendor retention — it is our machine, in our office.
- We never train any model on your data ourselves, and no provider is permitted to.
5. Your controls
- AI consent (Settings → AI) governs the tasks that read your content — the radar's scheduled ranking and deep looks, CV analysis, drafts, the tailored CV, interview prep and coach, and tracker imports. Withdraw it and those stop.
- Two event tasks sit under other switches, and we say so plainly: inbound-mail classification follows your e-mail-processing consent (it is the same feature), and the outgoing-mail safety check cannot be switched off while you use Email Hub, because it protects the people you write to and our sending domain.
- The extension's AI drafting has its own gate inside the extension.
- Applicants to a Teams posting can refuse AI on their application with one unticked box — see section 7.
- AI outputs stored in your account (scores, drafts, analyses) are yours: export them, delete them, or delete the account.
6. Talking to an AI — and what AI never does here
Where you converse with a machine, we say so on the screen: the interview coach and the help assistant identify themselves as AI, and a hiring team's chat interview tells the candidate, before the first question, whether the answers will be AI-evaluated — and that statement binds: it is recorded for each invitation, and the evaluation runs only where the page said it would. AI in Erioun never sends mail, never submits an application, never rejects anyone, never sets a price for you, and never makes a decision with legal or similarly significant effect. Suggestions are labelled, and a person always sits between an AI output and anything that happens.
7. AI screening in Erioun for Teams
Our one recruitment-related AI feature, built deliberately narrow:
- Off by default, per workspace. Every workspace starts with AI screening off; an owner or admin must switch it on in Seats & settings, where the card explains what the AI does and links the Terms for Teams and the DPA. When it is off, nothing is screened — not on intake, not by a member's click.
- A suggestion, never a move. A screen stores a fit suggestion with reasons. It never moves an applicant's card and never rejects anyone; a person moves cards and makes every decision.
- The applicant is told, and can say no. In a workspace with screening on, the public form says before submission that the employer uses AI assistance and that a person makes every decision, and offers an unticked “Please don't use AI on my application” box. Tick it and no AI touches your application, a CV file you attach or your chat-interview answers — with no effect on your chances. People who applied before screening was switched on are never screened either.
- A CV file never reaches a model. Where an applicant pasted no CV text, screening reads the text of their Word (.docx) file, read on our own servers and pseudonymised like pasted text; a PDF's text is not read at all.
- The model never learns who the applicant is: the CV is pseudonymised before it leaves, the call stays with Mistral (EU) in privacy mode, and there is no fallback to any other provider.
- What we measure about it is the employer's own usage — screening switched on or off, runs counted per workspace — never the applicant.
- EU AI Act: AI used to filter or evaluate job applications is listed as high-risk (Annex III). The high-risk obligations apply from 2 December 2027, and we are preparing for them as the provider of this feature — risk management, technical documentation, logging, human-oversight design — with employers as its deployers. The transparency you can already see (the notice on the form, the refuse-AI box, the human decision) is how the feature runs today, not a future promise.
8. Changes to this document
This page follows an internal provider inventory that is pinned to the code by tests: a new provider, model or AI task fails our build until it is documented, so this page cannot silently fall behind. We revise the date at the top on every change. Change log: 26 September 2026 — first version of this page: all providers and countries named, triggers stated per task class, pseudonymisation explained, vendor terms quoted, Teams screening described as the opt-in it is. It now also covers applicants' CV files in Teams screening and the chat interview's binding AI notice.
9. Contact
Questions about AI processing, or an objection: privacy@erioun.com. Everything else: support@erioun.com. Who we are: Loukas Tzekos – Sole Proprietorship, D. Papathanasiou Vas. 79, 54629 Thessaloniki, Greece. You can complain to the Hellenic Data Protection Authority (dpa.gr) at any time.
Frequently asked
Does AI run on my data without me clicking anything?
Yes, in a small, named set of cases: replies arriving at your alias are classified so they file themselves, outgoing mail is safety-checked before it leaves, an uploaded CV is analysed on arrival, and Opportunity Radar re-ranks your feed on a schedule — including a deeper look at the top three matches that reads your full CV text. Everything else waits for your click, and everything that leaves our servers is pseudonymised first.
Which AI companies see my CV?
Mistral (France) for analysis, summaries and the tailored CV; Anthropic (US) for long-form extension writing and cover letters. In both cases the text is pseudonymised first — your name and contact details are placeholders — and both vendors state they do not train on API data.
Is my data used to train AI models?
We never train any model on your data. Mistral, Anthropic and Cloudflare all state in their published terms that API customer data is not used for training, and our own local model does not learn from what it reads.
Can an employer's AI reject my application?
No. Screening exists only in workspaces that switched it on, it produces a suggestion with reasons, it never moves your card, and a person makes every decision. You can also refuse AI entirely with one box on the application form, with no effect on your chances.
Do any Chinese AI models process my data?
No. No Chinese-origin model is reachable in production. The only place such models exist in our code is behind an EU provider integration (CompactifAI, Spain) that is switched off; if it were ever switched on, those models run on EU/US servers as open weights, and our rules refuse them raw personal data. No DeepSeek and no Kimi model is reachable anywhere.
Keep exploring
Every AI task, what starts it, and where it runs.
Start your free trial and keep your job search under control.
- EU-built
- GDPR-native
- export & delete anytime