Back to CVready

Privacy Policy

Last updated: September 29, 2026

CVready is committed to protecting your privacy. This policy explains what data we collect, why, how we use it and your rights under the GDPR.

1. Data controller

CVready is the data controller for all personal data processed through this service. You can reach us at support@cvready.app for any privacy-related question.

2. What data we collect

We collect only what we need: the email address you sign in with, the CV content you create (names, work history, education, etc.), metadata about your CV exports (timestamps, template used), anonymous usage telemetry (page views), technical error reports, and whatever you send us through the feedback form (details in section 6). We never ask for government IDs or bank details.

3. Why we process your data

We process data to provide the CVready service: verifying sign-in, storing CVs, counting credits and delivering exports. We also use aggregated anonymous data to improve the product. We do not train our own AI models on your CV content. An AI rewrite sends our subprocessor (OpenAI or Anthropic) only the text of your summary, with a flag asking that the response not be retained; their own processing is governed by their API terms.

4. Processors we rely on

We use Supabase (hosted in the EU) for database + authentication, Stripe for billing, and — for the AI rewriting feature — OpenAI or Anthropic as a subprocessor. With BYOK (bring-your-own-key) we spend your key instead of ours. The key and the text pass through our server, which uses the key for that one call to the provider and drops it immediately — we never store it in the database, never write it to a log and never return it in a response.

5. Data retention

CV content is retained for as long as your account exists. We do not delete accounts automatically after a period of inactivity and we send no warning email before any such deletion — your account stays until you delete it or ask us to. You can delete it yourself at any time under Settings → Account → Danger zone, or email support@cvready.app. Doing so removes your profile, every CV and your CV Checker results. Payment records must be kept for the period required by accounting law, but deleting your account anonymises them: the amount, type and date remain, with nothing linking them to you.

6. Error reports and feedback

When something breaks on the site, we store a technical error report: the error text and stack trace (with email addresses and keys removed), the page address without its query parameters, your browser's user agent, the app version and the time. A report is not linked to your account or to your IP address and is used only to fix bugs. We keep it for 90 days after that error last occurred. If you send us feedback through the form, we store what you write, a reply email address if you give one, and — if you are signed in — a link to your account. Technical details (the page you are writing from, language, browser, screen size, app version and error number) are attached only if you leave that option switched on. It is pre-selected, and you can untick it; if you do, we store none of these details, not even your browser's user agent. Feedback is deleted 365 days after it was sent, and immediately together with your account if you delete it. It is not part of the self-service data export — email support@cvready.app and we will send you a copy.

7. Your rights (GDPR)

You can request access, rectification, deletion, restriction of processing or data portability at any time by emailing support@cvready.app. You also have the right to lodge a complaint with your national data protection authority. Two of those rights you can exercise yourself, immediately: download a copy of all your data under Settings → Account → Export your data, and delete your account under Settings → Account → Danger zone.

8. International transfers

Primary storage is EU-hosted. When the AI rewriting feature uses OpenAI or Anthropic, some data may be processed in the United States under Standard Contractual Clauses. BYOK does not remove that transfer — your CV content still reaches the provider through our server, using your own key; it only changes whose provider account is billed.

9. Cookies

We use essential cookies (sign-in session, language preference, checkout continuity). Besides those, a functional cookie holds your time zone, but only when your device is not on Central European time; it is a session cookie, deleted when you close your browser. We do not use advertising or profiling cookies. See our Cookies Policy for details.

10. Changes to this policy

When we change this policy we update the "Last updated" date at the top and notify signed-in users by email before the change takes effect.