Privacy Policy
1. Who we are
CVTailor ("we", "our", "us") is a service based in the Netherlands. Contact: help@cvtailor.nl (see Section 12).
2. What data we process
An account is required to generate CVs. When you use CVTailor, we process the following data:
- Account email address — collected when you create an account, used to authenticate you and allow you to sign in
- Profile details — the master profile you build or upload can include your name, email, phone number, location, target location, and LinkedIn/GitHub/website links, and optionally a profile photo. You choose what to fill in.
- Documents and CV content — the CVs and supporting documents you upload (PDF, Word, text, Markdown), and the CV text you paste or edit
- Job description text and application questions — the job postings, notes, and application questions you provide
- Generated outputs — the tailored CVs, cover letters, application answers, and fit assessments the service produces for you
- Payment data — if you buy credits, payment is handled by Stripe; we receive confirmation of your purchase (account ID, credit pack) but never your card details
- Usage data — IP address and request timestamps for rate limiting and abuse prevention; and, only if you opt in, pseudonymous analytics events (see Section 8)
3. How we use your data
- Email address — used to authenticate your account (sign in, password reset) and to identify and reply to you when you contact support or send feedback. We send no marketing emails unless you opt in to product-update emails in Settings.
- Your profile, documents, CV and job description text are sent to the Anthropic Claude API to generate tailored CVs, cover letters, and application answers.
- Your generation history is stored in your account — job descriptions, generated CVs, cover letters, application answers, and fit assessments are kept so you can revisit, re-download, and iterate on them. They stay until you delete the individual generation or your account (see Sections 6 and 7).
- Your master profile, uploaded documents, and photos are encrypted (AES-256-GCM) before being stored; working copies exist on the application server while you use the service. Generated CVs saved to your history contain whatever appears on the CV itself — including your photo, if you enabled one — and are stored as documents in our database rather than with this additional encryption layer.
- IP addresses are used for rate limiting, and a salted, irreversible hash of your IP address may be recorded at sign-up to prevent free-credit abuse — it is deleted within 31 days of sign-up, or when you delete your account, whichever comes first (a daily job removes hashes older than 30 days). Raw IP addresses are not written to our application logs or linked to your content.
4. Third-party processors
We use the following third-party services that may process your data:
- Anthropic (Claude API) — your profile, documents, CV and job description text are sent to Anthropic's API for AI processing. Anthropic's privacy policy applies: anthropic.com/privacy. Anthropic does not use API inputs to train their models by default.
- Supabase — our authentication provider and database/storage platform, hosted in London, United Kingdom. Your account, generation history, credit balance and preferences are stored in Supabase's managed database; your encrypted profile, documents and photos in its storage. Supabase's privacy policy applies: supabase.com/privacy.
- Railway — our cloud hosting provider. Server infrastructure and logs are processed on Railway's platform.
- Stripe — payment processing when purchasing credits. Stripe collects your card details directly; we never see them. Stripe's privacy policy applies: stripe.com/privacy.
- Cloudflare Turnstile — bot protection on sign-up and sign-in. Cloudflare processes technical signals from your browser (such as IP address and device characteristics) to distinguish humans from bots. Cloudflare's privacy policy applies: cloudflare.com/privacypolicy.
- Resend — email delivery for transactional and support messages. If you contact support or send feedback, the content of your message is delivered through Resend.
5. Legal basis for processing (GDPR)
We are based in the Netherlands and process personal data under the following legal bases:
- Contract performance / service delivery (Art. 6(1)(b) GDPR) — for your account, profile, documents, generation history, and payment processing: everything needed to provide the service you requested
- Legitimate interest (Art. 6(1)(f) GDPR) — for rate limiting, bot protection, and abuse prevention
- Consent (Art. 6(1)(a) GDPR) — for the optional analytics cookie and events (Section 8). You can withdraw consent at any time via Cookie Preferences.
6. Data retention
- Account email, profile, documents, and generation history — retained while your account is active, until you delete the individual item or your account. Deleting your account removes all of it immediately (see Section 7). If your account has been inactive for 2 years, we may delete it.
- Working files on the application server — the copies used during generation live on ephemeral infrastructure, do not survive server redeployments, and are deleted automatically once your account has made no request for 24 hours (your stored profile, documents and history are unaffected and are loaded again the next time you sign in).
- IP-based rate limit counters — stored in memory and reset on server restart. Sign-up IP hashes used for free-credit abuse prevention are salted and not reversible to your address, and are deleted automatically within 31 days of sign-up (or with your account, if that comes first).
- Analytics events (only if you opted in) — pseudonymous usage events are deleted together with your account, and the analytics cookie is cleared. Events recorded before you signed up carry only the random cookie identifier, never your account, so we can erase them only when the browser you delete from is still carrying that cookie — it lasts at most 12 months, and the deletion request is the one moment the link exists. Otherwise, and for pre-signup events from any other browser, those events remain linkable to nobody and are removed by the 14-month sweep below. Independently of any of that, analytics events are deleted automatically once they are more than 14 months old, by a job that runs daily.
- Audit log — a record of actions taken on your account (for example: a data export requested, a document deleted, a purchase fulfilled, the account deleted) is kept for 24 months so we can answer your questions, resolve disputes and demonstrate compliance (Art. 5(2) and Art. 17(3)(e) GDPR). It holds only your account identifier, the event name, the time and technical details such as sizes and ids — never your name, email, documents or CV text. Because it proves what was done to your account, including its deletion, this record is not erased with the account; it expires on its own schedule. Your data export includes it.
7. Your rights (GDPR)
As a person in the EU/EEA, you have the right to:
- Erasure (right to be forgotten) — you can delete your account and all associated data directly from the app: sign in, then click Delete account in the top navigation bar. This permanently deletes your account from our systems immediately. The only thing that remains is the pseudonymous audit record described in Section 6 (the fact that an account with that identifier was deleted, and when), which expires after 24 months.
- Access — download a copy of the personal data we hold about you directly from the app: sign in, open your profile page and, under Privacy & data, click Download my data. The archive also states the purposes, recipients, retention periods and sources of the data.
- Portability — the same download gives you your data in machine-readable formats (JSON, YAML, HTML, Markdown and your original uploaded files) in a ZIP archive.
- Correction — request correction of inaccurate data
- Object to or restrict processing
- Lodge a complaint with your national data protection authority (in the Netherlands: Autoriteit Persoonsgegevens)
Erasure, access and portability are self-serve. For correction, restriction or objection, contact us at help@cvtailor.nl, via the support page or the feedback button in the app.
8. Cookies and local storage
Strictly necessary: a session cookie (to track your generation job), an authentication cookie when you sign in, and a small cookie storing your cookie-consent choice itself. These require no consent.
Analytics is opt-in. Only if you accept analytics in the cookie banner do we set a cv_anon cookie — a random identifier, valid at most 12 months, linked to pseudonymous usage events (pages viewed, features used; never your CV content). Decline, and no analytics cookie is set and no events linked to you are recorded. We do keep anonymous operational counters regardless of your choice — for example, how many CVs were generated with each template, how many credit packs were sold, or how many visits arrived from an AI assistant such as ChatGPT or Perplexity (and which AI crawlers fetched our public pages) — which contain no identifier of any kind and cannot be connected to you. If you accept, we also set a second cookie (cv_src, at most 180 days) recording where you first came from — a channel such as "search", "AI assistant" or "social", plus any campaign tags (utm_source, utm_medium, utm_campaign) on the link you arrived through. It contains no identifier of you, and we never store the address or search terms of the page that referred you — only which kind of site it was. It lets us see whether a search result or a campaign led to a signup or a purchase; the channel is stored alongside your purchase and appears in your data export. Withdraw consent later via "Cookie Preferences" in the footer: both cookies are removed and the recorded source is erased from your purchase records too (the purchases themselves, and your credits, are unaffected). We honour the Global Privacy Control browser signal, which overrides any earlier acceptance. We use no advertising cookies.
Your CV template choice may be kept in your browser's local storage (functional, optional in the same banner).
9. Data transfers outside the EU
Your account data, documents and generation history are stored with Supabase in London, United Kingdom, covered by the European Commission's adequacy decision for the UK. Your CV content is sent to Anthropic's Claude API, which may process data on servers located outside the EU; Anthropic participates in frameworks designed to ensure adequate protection for such transfers (see Anthropic's privacy policy). Our hosting provider Railway may process server infrastructure data outside the EU; Railway's privacy policy applies.
10. Children
CVTailor is not directed at children under 16. We do not knowingly process data from children.
11. Changes to this policy
We may update this policy as the service evolves (e.g., when we add user accounts or paid features). The "last updated" date at the top will reflect any changes. Continued use after changes constitutes acceptance.
12. Contact
Questions about this policy and data-protection requests: help@cvtailor.nl, or the feedback button in the app.