Privacy at CVHarbor

Your CV stays private unless you choose to share it. We use your information only to provide CVHarbor and the features you start.

Your data

What we store

Your account details, CV content, saved jobs, export history, and the records needed to run the features you use.

What you tell us about your work

When you improve or tailor a CV we may ask about things the document does not mention — the size of a team, the outcome of a project. Answering is always optional. Answers are saved to your account so the same question is not asked again, and are used only to write your own CVs and cover letters. You can read every answer we hold, and delete any of them, in Account & privacy.

How we use it

We use your information to run your account, create and export documents, provide support, process payments, keep the service secure, and improve it when you allow optional analytics.

AI features

AI features use OpenAI. Requests include the professional content needed for the feature, such as your work history, skills, education, and target job. Direct contact details and the name in your CV header are removed before AI processing; CV import is parsed locally first and sends a redacted version for structure cleanup. OpenAI does not train its models on API data.

Who we share it with

Service providers

We use trusted providers where needed: Stripe for payments, Resend for account email, OpenAI for AI features, and Sentry for scrubbed error monitoring. Sign-in can use Google, GitHub, or Microsoft when you choose those buttons (they receive the email and profile data needed to complete OAuth). Location autocomplete may query GeoDB Cities, GeoNames, and OpenStreetMap Nominatim with the text you type. Cloudflare provides CDN/security, cookieless Web Analytics, and — when a job board blocks a normal fetch — Browser Rendering to import a public job page you asked us to fetch. We do not sell your information or use it for advertising.

Analytics and error monitoring

Cloudflare Web Analytics measures aggregate traffic and performance without cookies or individual fingerprinting. Optional product analytics records coarse event names and categories for landing-page and template conversion analysis; it excludes CV text, job descriptions, emails, and user identifiers. Optional browser error monitoring via Sentry is scrubbed (CV text, form values, media, request bodies, URLs with query strings, and user identity are excluded) and runs in your browser only after you allow optional analytics. Server-side error monitoring uses the same scrubbing and does not depend on the cookie banner.

Your rights and controls

Keeping and deleting your data

Your account, CVs, and the answers you have given about your work stay available until you delete them — we do not auto-delete your content. Short-lived security and operations records (sign-in codes, expired sessions, processed webhooks, old audit logs, anonymous usage counters) are purged on a schedule; see Purposes, legal bases, and retention below. You can download your data, delete individual answers, or permanently delete your account from Account & privacy. Account deletion removes active account data immediately; encrypted recovery backups may retain it for up to 30 days. After you delete your account we anonymise leftover audit-log and product-feedback rows that the database keeps without a user link (IP and message content cleared).

Feedback

Feedback you send may include your message, the page you were using, your plan, and general browser information. We use it only to improve CVHarbor.

Who else processes your data

Account email — the welcome message, and anything similar we add later — is sent through Resend. Payments are handled by Stripe, which receives your email address and billing details; we never see or store your card number. AI features go to OpenAI in the United States, as described above. We do not sell your data, and nothing is shared for advertising.

Subprocessors

We use these processors to run CVHarbor. Each only receives what that job needs: Resend (account email, EU/US depending on Resend routing); Stripe (payments — billing email and payment details; we never store card numbers); OpenAI (AI features — professional CV content after contact details and header name are removed; United States); Sentry (scrubbed error events — no CV text or user identity); Cloudflare (CDN, security, cookieless Web Analytics, and optional Browser Rendering for job-URL import); Google, GitHub, and Microsoft (OAuth sign-in only when you use that provider — account email/profile needed to create or link your CVHarbor account); GeoDB Cities, GeoNames, and OpenStreetMap Nominatim (location autocomplete — the search text you type). Ask info@cvharbor.com for the current list. Transfer safeguards for non-EU processors are reviewed with counsel and are not claimed here beyond naming the recipient and purpose.

Automated feedback

ATS Review and Recruiter Check are guidance about your document. Employers do not receive them and they do not make decisions about you.

Purposes, legal bases, and retention

Purpose — legal basis (GDPR Art. 6) — how long we keep it: • Account and sign-in — Art. 6(1)(b) contract — until you delete the account. • CVs, work answers, tracked jobs — Art. 6(1)(b) contract — until you delete them or the account. • Billing and invoices — Art. 6(1)(b) contract and Art. 6(1)(c) where tax law requires — for the life of the account, then invoices we must keep for up to 7 years. • Optional product analytics — Art. 6(1)(a) consent — until you withdraw consent (Essential only / Manage cookie preferences); no CV text. • Security (sessions, email sign-in codes) — Art. 6(1)(f) legitimate interests — codes until they expire (then purged); sessions until they expire or you revoke them (expired/revoked rows purged). • Audit logs — Art. 6(1)(f) — 24 months, then purged. • AI features (OpenAI) — Art. 6(1)(b); United States transfer disclosed elsewhere — request-scoped processing; anonymous usage counters kept for up to 3 months for quotas. • Support / product feedback — Art. 6(1)(f) when you submit it — up to 24 months unless tied to an open dispute. These bases reflect how CVHarbor runs today. A lawyer should confirm them for your situation.

Your controls

Under the GDPR you can access, correct, download (portability), or erase your personal data, and object to or restrict certain processing. In the product: update your information, download your data, delete individual work answers, revoke public links, or permanently delete your account from Account & privacy. Email info@cvharbor.com for any request we cannot complete in-app. You can also complain to your local data protection authority.

Who is responsible

CVHarbor is operated by Khaled Alhasan (trading as Infroware), Mühlenbach 53, 50676 Köln, Germany. Contact: info@cvharbor.com. Data protection questions go to info@cvharbor.com. If you are in the EU or UK, you can complain to the data protection authority where you live or work.

Where your data is stored

Your account and CV data are stored on our own server in the European Union, not on third-party cloud storage. AI features send content to OpenAI in the United States, as described above; nothing else leaves the EU except where a section on this page says so.

International transfers

Some processors are outside the EEA/UK — notably OpenAI in the United States for AI features, and depending on routing also Resend, Sentry, Cloudflare, and the OAuth provider you choose (Google, GitHub, or Microsoft). When personal data leaves the EEA/UK we rely on a Chapter V GDPR transfer tool appropriate to that processor (for example an adequacy decision or Standard Contractual Clauses). We do not claim a specific certification on this page; ask info@cvharbor.com for the current transfer mechanism for a named processor.