Privacy Policy

Last updated: 2/3/2026

1. Introduction

CV Guide ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered resume analysis service.

2. Information We Collect

We collect the following types of information:

2.1 Account Information

  • Email address (required for account creation)
  • Password (encrypted using industry-standard hashing)
  • Subscription tier and status
  • Account creation and last login timestamps

2.2 Resume Content

  • Free Users: Resume text/content is processed for analysis but files are automatically deleted after processing. Analysis results may be stored temporarily.
  • Paid Users: Resume files and content are stored securely on our servers according to your subscription tier (up to 3 resumes for Pro, up to 5 for Power).
  • Resume metadata (file name, type, size, upload date)

2.3 Job Descriptions

When you use job-specific matching features (Pro/Power tiers), we collect and store the job descriptions you provide for analysis purposes.

2.4 Analysis Results

We store analysis results, compatibility scores, improvement suggestions, and interview preparation content associated with your account.

2.5 API Keys (Power Tier Only)

If you choose to use your own API key (Developer tier), we store your encrypted API keys securely. Keys are encrypted at rest and only used for processing your requests.

2.6 Usage Data

  • Number of analyses performed
  • AI provider and model used for each analysis
  • Token usage and cost estimates
  • Rate limit tracking
  • Feature usage patterns

2.7 Technical Information

  • IP address (for security and rate limiting)
  • Browser type and version
  • Device information
  • Session cookies (essential for authentication)

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Provision: To provide resume analysis, job matching, and interview preparation features
  • AI Processing: To send your resume content and job descriptions to third-party AI providers (OpenAI, Google Gemini, DeepSeek) for analysis
  • Account Management: To create and manage your account, process subscriptions, and provide customer support
  • Rate Limiting: To enforce daily analysis limits based on your subscription tier
  • Cost Tracking: To monitor AI usage and costs (for users with their own API keys and internal cost management)
  • Security: To detect and prevent fraud, abuse, and unauthorized access
  • Improvements: To analyze usage patterns and improve our service (using aggregated, anonymized data)
  • Communication: To send you service-related notifications, updates, and support responses

4. Data Storage and Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Passwords are encrypted using industry-standard hashing algorithms (bcrypt)
  • User-provided API keys are encrypted at rest
  • Resume files are stored in secure, access-controlled directories
  • Database connections use encrypted connections (TLS/SSL)
  • Regular security audits and updates
  • Access to personal data is restricted to authorized personnel only

Free Users: Your resume files are automatically deleted after processing. Only analysis results may be retained temporarily.

Data Breach: In the event of a data breach, we will notify affected users and relevant authorities as required by law.

5. Third-Party Services

We use the following third-party services that may process your data:

5.1 AI Providers

Your resume content and job descriptions are sent to third-party AI providers (OpenAI, Google Gemini, DeepSeek) for processing. These providers have their own privacy policies and data processing practices. We recommend reviewing their privacy policies:

Important: When you use your own API keys, your data is sent directly to your chosen AI provider. We do not control how these providers process your data when using your own API keys.

5.2 Other Services

  • Database Hosting: MySQL database hosted on secure servers
  • File Storage: Resume files stored on secure file systems
  • Payment Processing: If using Gumroad or other payment processors, they handle payment data according to their privacy policies

6. Data Retention

We retain your data for the following periods:

  • Account Data: Retained while your account is active. Deleted within 30 days of account deletion.
  • Free User Resumes: Files are deleted immediately after processing. Analysis results may be retained for up to 30 days.
  • Paid User Resumes: Retained while your account is active and within your subscription limits. Deleted within 30 days of account deletion or when you manually delete them.
  • Analysis Results: Retained while your account is active. Deleted within 30 days of account deletion.
  • Usage Data: Retained for up to 2 years for cost tracking and analytics (aggregated and anonymized where possible).
  • API Keys: Deleted immediately upon removal from your account.

You can request deletion of your account and all associated data at any time by contacting us at support@example.com.

7. Cookies

We use essential cookies to maintain your session and authentication state. We do not use third-party tracking cookies for advertising purposes. You can disable cookies in your browser settings, but this may affect your ability to use the Service.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your account and associated data
  • Portability: Request your data in a machine-readable format
  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing of your data for certain purposes

To exercise these rights, please contact us at support@example.com. We will respond to your request within 30 days.

9. Children's Privacy

Our Service is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

10. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our Service, you consent to the transfer of your data to these countries. We ensure appropriate safeguards are in place to protect your data.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

12. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at: support@example.com