Your privacy matters to us

Privacy Policy

We take your privacy seriously. This policy explains what data we collect, how we use it, and the rights you have over your information.

Last updated: March 11, 2026

Data encryption

Encrypted in transit and at rest

No data selling

We never sell your personal data

Right to delete

Delete your data at any time

GDPR-aligned

Committed to EU & UK GDPR principles

1. Information We Collect

Personal Information

When you create an account, we collect your name, email address, and password. If you subscribe to a paid plan, we collect billing information through our payment processor (Stripe). We do not store full credit card numbers on our servers.

Resume Data

We store the resume content you create, including work history, education, skills, and any other information you enter into our resume builder. This data is stored securely on our infrastructure.

Usage Data

We automatically collect information about how you use our service, including pages visited, features used, session duration, and device information (browser type, operating system, screen resolution). This helps us improve our product.

2. How We Use Your Information

Service Delivery

We use your personal and resume data to provide our core service: generating, optimizing, and exporting resumes. Your resume content is processed by our AI systems to provide tailoring and ATS optimization features.

Communication

We use your email address to send account-related notifications (password resets, subscription confirmations), product updates, and, if you opt in, marketing communications. You can unsubscribe from marketing emails at any time.

Analytics & Improvement

We use aggregated, anonymized usage data to analyze trends, improve our service, and develop new features. We use privacy-focused analytics tools and do not share individual user data with third-party advertising platforms.

3. Data Sharing & Third Parties

Third-Party Services

We share data with the following third-party services strictly as needed to operate our platform: Stripe (payment processing), AWS (cloud hosting and storage), OpenAI and Anthropic (AI processing for resume optimization). These providers are bound by their own privacy policies and data protection agreements.

What We Never Do

We never sell your personal data or resume content to third parties. We never share your resume data with recruiters, employers, or job platforms without your explicit consent. We do not use your data to train our own AI models. Our AI providers (OpenAI, Anthropic) process your data under their API terms, which prohibit use of API data for model training.

4. Data Security

Encryption

All data transmitted between your browser and our servers is encrypted using industry-standard TLS encryption. We apply encryption at rest where supported by our infrastructure providers. Passwords are securely hashed and never stored in plain text.

Infrastructure

Our application is hosted on secure cloud infrastructure with regular security updates, backups, and monitoring. We implement access controls to limit access to user data on a need-to-know basis.

5. Your Rights

Access & Portability

You have the right to access all personal data we hold about you. You can export your resume data at any time through your account settings in multiple formats (PDF, DOCX).

Correction & Deletion

You can update your personal information through your account settings at any time. You can request complete deletion of your account and all associated data by contacting us at support@cvpilot.pro. We aim to process deletion requests within 30 days.

GDPR & UK GDPR

We are committed to aligning our practices with GDPR and UK GDPR principles. If you are located in the EU or UK, you have additional rights including the right to object to processing, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority. We are continuously working to strengthen our compliance posture.

6. Cookies & Tracking

Essential Cookies

We use essential cookies for authentication (keeping you logged in) and security (CSRF protection). These cannot be disabled as they are necessary for the service to function.

Analytics

We use privacy-focused analytics (Matomo, self-hosted) to understand how users interact with our service. You can opt out of analytics tracking through your browser settings or our cookie preferences.

7. Data Retention

Active Accounts

We retain your data for as long as your account is active. Resume data and account information are kept throughout your subscription period and for 30 days after account deletion to allow for recovery.

Deleted Accounts

When you delete your account, we permanently delete all personal data and resume content within 30 days. Some anonymized, aggregated data may be retained for analytics purposes. Backup data is purged within 90 days.

Privacy Questions?

For any privacy-related inquiries, data requests, or concerns, please contact us at support@cvpilot.pro