Privacy Policy
Welcome to CV Builder. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, store, and protect your information when you use our CV building platform.
This policy applies to all users of our service and complies with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address (required for both Email OTP and Google OAuth authentication)
- Authentication data including login timestamps and session tokens
- Google profile information (if you choose Google sign-in): name, profile picture, and Google user ID
1.2 Profile Information
You provide the following professional information:
- Basic details: First name, last name, phone number, location, timezone
- Professional links: LinkedIn, GitHub, personal website, portfolio URLs
- Profile photos: Images you upload (stored in a public storage bucket)
- Professional summary: Your tagline and biography
- Language preference: English or German
1.3 Career Data
We store career information you provide about:
- Your work experience and employment history
- Your education and qualifications
- Your professional skills and competences
- Certifications and professional references (including uploaded documents)
- Other career-related information you choose to add
1.4 Documents & Files
- CV Documents: Generated CVs with custom formatting, templates, and display settings
- Cover Letters: AI-generated or manually written cover letters
- Job Applications: Company names, job titles, URLs, descriptions, application status
- Uploaded Files: PDF, DOCX, TXT files (max 5-10MB) for CV data extraction
1.5 Share Link Analytics
When you create a public share link for your CV, we collect limited analytics:
- Visitor IP address
- User agent (browser and device type)
- HTTP referrer (source of the visit)
- Visit timestamp and view count
Note: This is the only analytics we collect. We do not use Google Analytics, tracking pixels, or third-party advertising cookies.
2. How We Use Your Information
2.1 Core Services
- Account management: Create, secure, and maintain your account
- CV generation: Build professional CVs and cover letters
- Content storage: Save your profile, career data, and documents securely
- Job application tracking: Organize and track your job search progress
2.2 AI-Powered Features
We use Google Gemini AI to enhance your experience:
Data sent to AI services:
- Your profile and career information
- Your CV content and cover letters
- Job postings you paste for analysis
- Uploaded files (PDFs, images) for data extraction
AI features available throughout the application:
- CV and cover letter content generation
- Document analysis and data extraction
- Job matching and fit analysis
- Content optimization suggestions
Your control: All AI features are optional. You can create all content manually without using AI generation.
Important: Data sent to Google may be processed according to Google's Privacy Policy and AI Terms of Service.
3. Data Storage and Security
3.1 Storage Infrastructure
We use secure cloud storage for your data.
Location: European Union
3.2 Security Measures
- Users can only access their own data
- All data transmitted via encrypted connections (HTTPS/TLS)
- Secure authentication methods
- Automatic data deletion when you delete your account
3.3 Data Retention
- Active accounts: Data retained while your account is active
- Account deletion: All data permanently deleted within 30 days
4. Third-Party Services
Supabase (Database, Auth, Storage)
- Provider: Supabase Inc.
- Purpose: Database, authentication, and file storage
- Data shared: All application data
- Privacy Policy: supabase.com/privacy
Google Gemini AI
- Provider: Google LLC
- Purpose: AI content generation and document analysis
- Data shared: Your content (when using AI features)
- Privacy Policy: policies.google.com/privacy
Google OAuth (Optional)
- Provider: Google LLC
- Purpose: Authentication only (no tracking or advertising)
- Data shared: Only if you choose Google sign-in
- Privacy Policy: policies.google.com/privacy
5. Your Privacy Rights
GDPR Rights (EU Users)
You have the right to:
- Access: Download a copy of all your data (JSON export)
- Rectification: Update or correct your information
- Erasure: Request deletion of your account and all data
- Portability: Export your data in machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to certain types of processing
- Withdraw consent: Opt out of optional features at any time
How to Exercise Your Rights
- In-app: Go to Settings → Account → Privacy Controls
- Email: Contact us at privacy@cv-builder.com
- Response time: We will respond within 30 days
6. Cookies and Tracking
Essential Cookies
- Authentication tokens (keep you logged in)
- Preferences (language, theme settings)
- Security tokens (CSRF protection)
We do NOT use:
- Google Analytics
- Third-party advertising cookies
- Social media tracking pixels
7. Children's Privacy
Our service is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at privacy@cv-builder.com.
8. International Data Transfers
- Data location: European Union
- EU users: Your data may be transferred outside the European Economic Area (EEA)
- Safeguards: We use Standard Contractual Clauses (SCCs) with our service providers
- Third countries: Google (United States), Supabase (EU (Europe))
9. Sharing Your Data
We do not sell your personal information to third parties.
We share data only with:
- Supabase: For database, authentication, and storage (all data)
- Google: For AI processing (when you use AI features) and OAuth (if you choose Google sign-in)
- Legal authorities: When required by law or to protect our rights
When you create a public share link, the CV content you choose to share becomes publicly accessible.
10. Changes to This Policy
- Notifications: We will notify you by email of material changes
- Effective date: Changes take effect 30 days after posting
- Continued use: Using the service after changes constitutes acceptance
11. Contact Us
Data Controller
CV Builder
To be determined
Zurich
Switzerland
Privacy Inquiries
Email: privacy@cv-builder.com
Subject: "Privacy Inquiry - CV Builder"
Response Time: Within 7 business days
Summary of Key Points
For questions or concerns, please contact us at privacy@cv-builder.com.