CVPulse scores résumés. To do that we have to read yours. This page explains exactly what we collect, why, who processes it, and how long we keep it.
What we collect
- Your email address, to sign you in and send your reports.
- Your Google account name, email and profile picture, if you choose to sign in with Google. We don’t receive your Google password or access to anything else in your Google account.
- Your résumé file and the text extracted from it.
- Your results: the score, roast line, strengths and gaps.
- Your answers to Deep Fix follow-up questions, and the rewritten résumé we generate.
- Payment records (amount, currency, status, provider reference). We never see or store card or UPI details.
- Consent time: when you agreed to processing on upload.
- Email addresses you share your score with, used once to send that email and never stored. The email shows your address so the recipient knows who sent it, and their replies go to you.
- Product analytics: page views and clicks, without résumé text or other personal content.
How we use it
Only to provide the service: scoring your résumé, generating Deep Fix reports, crediting referrals, processing payments, and fixing bugs. We don’t sell your data or use your résumé to train models.
Who processes it
- Google (Gemini API): analyses résumé text to produce scores and rewrites.
- Google (Sign-In): confirms your identity if you choose to sign in with Google.
- Railway: hosting, database and file storage.
- Razorpay and Lemon Squeezy: payments.
- Resend: sign-in emails, notifications, and score-share emails you send to friends.
- PostHog and Sentry: analytics and error monitoring, configured to exclude résumé content.
How long we keep it
Résumé files, extracted text, scores and Deep Fix reports are deleted automatically 30 days after upload. You can delete them immediately at any time from your account page. Payment records are kept as long as tax law requires.
Your rights
You can access, correct, export or delete your data. Most of this is self-serve from your account; for anything else, contact us at the address below.
Contact
privacy@[your-domain] — replace before launch.