Privacy Policy
Effective 1 June 2026
CVFriend helps you find jobs and write tailored applications. To do that we process your career data. This policy says exactly what we collect, why, who else touches it, and how you get it out or delete it - no vague reassurances. We are the data controller. Questions: privacy@cvfriend.com.
What we collect
- Account: your email, name, and a hashed password (handled by our auth provider - we never see the plain password). If you sign in with Google, we receive your email and name from Google.
- Career data you give us: your CV, work history, skills, achievements, and the answers you give to tailoring questions. This is the heart of the product and it's sensitive - we treat it that way.
- Generated documents: the CVs and cover letters the service produces for you.
- Profile photo (optional): if you add one, it appears only on the CV and letter designs that have a photo slot. We crop and re-save it on upload, which also removes camera metadata such as location, we never analyse it, and it is never sent to the AI model. Remove it any time from your profile; deleting your account deletes it.
- Usage & billing: token counts and the cost of each AI action (for metering) - never the content of prompts or responses. Payment is handled by Stripe; we store your customer and subscription IDs, not your card number.
Trying it before you have an account
You can upload a CV and see how it scores against a real job before you sign up. No AI model sees anything in this step: the score and the match are worked out by our own code. The upload is checked by Cloudflare Turnstile to keep bots out (see sub-processors below). While you try it, we keep:
- What you upload and choose: the text of your CV and its score, the region and role you pick, the job ad you pick from our feed or paste in, and the match result for that job.
- Where you came from: your answer to "where did you hear about us", if you give one; any utm_ tags, gclid or fbclid in the link you arrived by; and the name of the site that sent you (only its host name, never the full address).
- When you reached each step, so we can see where people stop.
- "Delete what I uploaded" is on every step after the upload. It removes the trial record straight away, with no account needed.
- One cookie, cvf_trial, which holds only the id of your trial record. See Cookies below.
Why we're allowed to process it (lawful basis)
- To provide the service (contract): generating, scoring, and storing your applications, and billing you for it.
- Before you have an account: scoring your CV and matching it to a job are steps you ask us to take before entering a contract with us (GDPR Art. 6(1)(b)). Recording where you came from and which steps you reached is our legitimate interest in knowing which channels and steps work (Art. 6(1)(f)).
- Your consent: processing your career data with AI, and the optional job-match email digest. You give this explicitly at signup and can withdraw it by deleting your account or turning the digest off.
- Legitimate interest: keeping the service secure and preventing abuse (rate limiting, fraud and abuse prevention).
How AI processing works
To write and analyse your applications, we send the relevant career data to Anthropic (the maker of Claude). Anthropic processes it to return the generated text and nothing more. Our API access is configured so your data is excluded from training their models. We don't store the model's intermediate reasoning or the raw prompt/response bodies; we keep the final documents, which are yours.
Who else processes your data (sub-processors)
We use a small set of vetted providers to run the service. Each is bound by a data processing agreement, and for transfers outside the EU, by Standard Contractual Clauses.
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Anthropic | AI generation (CV, cover letter, analysis) | United States | DPA + SCCs; API configured to exclude data from model training |
| Supabase | Database, authentication, file storage | EU (Frankfurt) | DPA; EU data residency |
| Vercel | Application hosting & delivery | EU region preferred; US edge | DPA + SCCs |
| Stripe | Payment processing & billing | United States / EU | DPA + SCCs; PCI-DSS Level 1 |
| Resend | Transactional & digest email | United States | DPA + SCCs |
| Cloudflare | Bot protection (Turnstile) on sign-up and on the CV upload before an account. Receives your IP address, browser user agent and similar technical signals. Cloudflare uses them to tell people from bots, and on its own account to improve that bot detection. | Global network; United States | DPA + SCCs; EU-U.S. Data Privacy Framework |
| Google Analytics | Website traffic analytics (consent-gated; loads only if you accept cookies) | United States | DPA + SCCs; loaded only on opt-in |
How long we keep it
- Uploaded source CVs are deleted after we extract their content, unless you choose to keep them.
- Your profile, applications, and documents are kept until you delete them or close your account.
- Your profile photo is kept until you remove it or delete your account.
- Trial records (before an account) expire 7 days after you start. If no account has taken the record over by then, a daily clean-up deletes all of it by the next day. If you create an account, or log in to one you already have, the job ad moves into it; a new account also gets your CV, region and role, while an account that is already set up keeps its profile as it is. The CV text, the job text, the score and the match are then removed from the trial record, at the latest when the 7-day trial expires. What is left (the region, role and feed job you picked, the page language, where you came from and when you reached each step) is kept 90 days after the record joined your account, to measure the sign-up flow, then deleted. If you delete your account sooner, that record is unlinked from you and still deleted on the same schedule.
- Billing records are retained by Stripe for as long as tax and accounting law requires, even after you delete your account.
Your rights
Under the GDPR you can exercise all of the following - most of them directly in the app, today:
- Access & portability: download a complete copy of your data from Account → Your data → Export.
- Erasure: permanently delete your account and all associated data from the same page. This cascades through our database, purges your stored documents, and cancels any subscription.
- Rectification: edit your profile and documents at any time.
- Withdraw consent / object: by deleting your account or turning off the digest.
You also have the right to complain to a supervisory authority. In Sweden that's Integritetsskyddsmyndigheten (IMY).
How we protect it
Your data is isolated at the database level - row-level security means one user's rows are never reachable by another, even if application code had a bug. Data is encrypted in transit, documents are served only through short-lived signed links, and AI keys live exclusively on the server, never in your browser.
Cookies
- Essential cookies keep you signed in and secure the session. These are always on - the service can't work without them - and need no consent.
- cvf_trial (essential): holds only the id of your trial record, so the steps you take before signing up stay together. It is HttpOnly (no script on the page can read it), lasts 7 days, and is set only when you upload a CV, never when you just visit. It is removed when you delete the trial or when an account takes it over. Because it is strictly necessary for the service you asked for, it needs no consent (Swedish Electronic Communications Act, LEK 9 kap. 28 §).
- Analytics cookies (Google Analytics 4): we use these to measure traffic and improve the product. They load only after you accept on the cookie banner - decline and no analytics script ever runs. You can change or withdraw your choice any time via the "Cookies" link in the footer.
We use no third-party advertising or cross-site ad-tracking cookies. Your analytics choice is stored locally in your browser, not in an account.
Children
The service isn't intended for anyone under 16, and we don't knowingly collect their data.
Changes & contact
If we change this policy we'll update the effective date and, for material changes, tell you in the app or by email. Reach us any time at privacy@cvfriend.com, CVFriend, Stockholm, Sweden.