What Data We Collect
CV Tailor is a hosted, account-based service. When you sign in, your career data is stored securely in your account (on our server) so it is available across your devices and sessions.
Stored in your account:
- Account information — email address, name, profile image, and linked OAuth accounts (Google, GitHub)
- Facts — your experience, achievements, skills, and career context
- Jobs — job descriptions and parsed briefs
- Iterations — CV drafts, fit scores, and interview answers
- Artifacts — compiled PDF files
- Saved evaluation reports — the deep offer-evaluation results and weighted verdict for roles you evaluate
- STAR story bank — the reusable interview stories generated from your profile
- Tracked applications — the jobs you track, their status, and follow-up timing
- Career goal settings — your north-star goal and target compensation
- Usage records — per-step LLM token usage (model, input/output token counts, cost)
- Pipeline execution logs — job ID, total tokens, total cost, status, and timestamps
- Billing data — subscription tier, monthly usage count, bonus credits, and billing period dates
You can export all of this data at any time from the Settings page. Only lightweight UI preferences (cookie consent, language, analytics opt-out) are kept in your browser.
Third-Party Data Processing
OpenRouter (LLM Provider)
When you run the CV tailoring pipeline, the following data is sent to OpenRouter for AI processing:
- Your profile facts (experience sections)
- The job description text you provided
- Pipeline context (fit scores, interview answers)
This data is transmitted over HTTPS and processed by the language model you selected. We do not control how OpenRouter handles data after transmission. Please review OpenRouter's privacy policy for their data retention and processing practices.
If you provide your own API key, requests go through your OpenRouter account. If you use a paid plan, requests may go through our account on your behalf.
Polar.sh (Billing Provider)
If you subscribe to a paid plan, payment processing is handled by Polar.sh as our Merchant of Record. Polar handles all payment data, tax calculation, and invoicing. We receive your subscription status and customer ID but do not store credit card numbers or payment details.
Job Board APIs (Job Discovery)
The Job Discovery feature fetches open positions from public, documented job-board APIs (Greenhouse, Ashby, Lever) for the company career pages you choose to watch. These requests:
- Contain no personal data — only the public company board identifier you added
- Use the official, documented JSON APIs of each job board — no HTML scraping
- Are rate-limited and cached on our side, and identify our service with a descriptive User-Agent
- Never involve AI processing and never consume your usage quota
Your saved sources and each discovered posting (title, company, link, location, and the description captured at scan time) are stored in your account so the feed is available across devices and rescans can skip postings you have already seen. Job posting content is displayed to you for personal use only and is not redistributed.
Umami Analytics
We use Umami, a privacy-focused analytics tool, to understand how people use CV Tailor. Umami:
- Does not use cookies
- Does not collect personal data
- Does not track users across sites
- Collects only anonymous page view and event data
You can opt out of analytics in the Settings page.
Cookies and Local Storage
CV Tailor does not use cookies. We use browser localStorage for:
- Locale preference — your language choice (EN/RU)
- Consent flag — whether you accepted or declined this notice
- Analytics opt-out — your analytics preference
Your Rights
Under GDPR and similar regulations, you have the right to:
- Access your data — use the Export feature in Settings to download everything as JSON
- Delete your data — request deletion of your account data (facts, jobs, CV drafts, compiled PDFs, evaluation reports, STAR story bank, tracked applications, account information, and usage records) by contacting us. The "Clear local cache" control in Settings clears lightweight browser-side leftovers only.
- Opt out of analytics — toggle the analytics opt-out in Settings
- Portability — export your data as JSON from Settings
To exercise your rights over your account data — facts, jobs, CV drafts, saved reports, stories, tracked applications, and usage records — contact us.
Data Security
- All communication with our server and OpenRouter uses HTTPS encryption
- LLM models and provider keys are managed server-side — you never store or send an API key
- The server does not log pipeline request bodies. It persists only your account data (facts, jobs, CV drafts and PDFs, saved reports, story bank, tracked applications, account, and usage data) as described above
Children's Privacy
CV Tailor is not directed at children under 16. We do not knowingly collect data from children.
Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision.
Contact
If you have questions about this privacy policy, please open an issue on our GitHub repository.