Privacy at CVHarbor

Your resume is yours. CVHarbor uses it to build, tailor, export, and share the documents you ask it to share.

What we store

Your account identity, resume content, saved job information, export history, and AI usage records needed to operate the workspace.

Why we are allowed to

Your account, your CVs and the features you ask for are processed to provide the service you signed up for (Art. 6(1)(b) GDPR — performance of a contract). Optional analytics runs only on your consent, and you can withdraw it at any time from Cookie choices (Art. 6(1)(a)). Keeping the service secure and preventing abuse — rate limits, audit logs, fraud checks on payments — rests on our legitimate interest in a service that works and is not abused (Art. 6(1)(f)). Billing records are kept because tax and commercial law require it (Art. 6(1)(c)).

Your rights

You can download everything we hold on you, or delete your account outright, from Account & privacy — both take effect immediately, without asking us. You also have the right to correct your data, to object to processing based on legitimate interest, to ask for processing to be restricted, and to complain to a supervisory authority in the EU country where you live or work.

What the AI is sent

AI features are processed by OpenAI (OpenAI, L.L.C., United States) as our processor. Your name and contact details are deliberately withheld: what leaves our servers for tailoring, matching, rewriting, screening and cover letters is your job title, summary, work history, education, skills, languages, certifications, projects and custom sections — not your full name, email address, phone number, postal address, profile links or photo. Importing a CV is the one exception, because reading those fields off the page is the whole point of an import: the text extracted from the file you upload is sent as it stands, and will contain whatever identifying details your CV contains. If you would rather nothing identifying were sent, build your CV in the editor instead of importing one. OpenAI does not train its models on data sent through its API.

Analytics

Product analytics is optional, consent-gated, and records product events rather than resume text. Events may include page path, action name, account plan, or anonymous client error type; CV content, error messages, URLs, and job-description text are not sent to analytics. Analytics events are retained for up to 12 months; the PostHog project retention setting must match before production launch.

How long we keep things

Your account, CVs and tracked jobs are kept until you delete them — they are yours, and we do not expire them out from under you. Data tied to a signed-out browser is kept only as long as it is doing something: the AI quota counter for a signed-out visitor is deleted once its monthly period is three months past, because after that it can no longer be counted against anything. Deleting your account removes the rest immediately, subject to the backup window below.

Feedback you send

When you send feedback from the builder we store your message, whether you rated it positive or negative, the page you were on, your plan, and your browser and operating system family. If you are signed out we set a first-party cookie holding a random identifier so repeat feedback from the same browser can be read as one voice; it is used only for feedback and is never shared or used for advertising. Clearing your cookies removes it.

Who else processes your data

Your account and CVs are stored with Supabase on servers in Ireland, inside the EU. Account email — the welcome message, and anything similar we add later — is sent through Resend, also on servers in Ireland. Payments are handled by Stripe, which receives your email address and billing details; we never see or store your card number, and Stripe sends its own receipts and renewal reminders. AI features go to OpenAI in the United States, as described above, and are the only part of this that leaves the EU. Company-name and job-title suggestions are looked up through our own servers, so the services behind them never see who you are or where you are connecting from. We do not sell your data, and nothing is shared for advertising.

Automated scoring, and what it does not do

CVHarbor produces three automated outputs about your document: an ATS readability score, a match percentage against a job description you supply, and a hiring-manager verdict on whether the application would advance. Each is generated by software from the text of your CV and the job — the checks look for whether a parser can read your fields, whether the requirements in the job appear as evidence in your history, and how a reader would weigh what is there. No employer receives them, no decision about you or your application is made by us, and they produce no legal or similarly significant effect. They are advice you asked for. If a result looks wrong, write to [email protected] and a person will look at it.

Sensitive details in a CV

CVs often carry things the law treats as special categories: health or disability, religious affiliation, trade union membership, and in some markets a photograph and a date of birth. We do not ask for any of it and do not need it. Where you choose to include it, we process it only to build and export the documents you asked for, on the basis of your explicit request. Leaving it out is always an option, and for several markets it is what we recommend.

Your controls

Download your account data or permanently delete your account from Account & privacy. Public links are read-only and can be revoked from the builder.

Deletion and backups

Account deletion removes your active account and resumes immediately. Encrypted recovery backups may retain deleted records for up to 30 days, are not used by the live service, and expire through the backup-retention process.

Who is responsible

CVHarbor is operated from Germany. The operating entity is being registered; its name, address and registration details will be published in the Impressum before any paid plan is offered. Contact: [email protected]. Data protection questions go to [email protected]. You can also complain to the data protection authority for the German state we operate from, or to the authority where you live or work. Full details are in the Impressum.