Last updated: August 12, 2026
GetCVAI ("we", "our", "us") operates the getcvai.com website. This Privacy Policy explains how we collect, use, and protect your personal information.
Account Information: When you register, we collect your email address and password (stored securely as a hash).
Profile Data: Information you provide to build your CV, including your name, phone number, work experience, education, skills, and links to professional profiles (LinkedIn, GitHub, portfolio).
Application Data: Job applications you create, including company names, job titles, cover letters, and generated CV PDFs.
We do not sell, trade, or transfer your personal information to third parties. We share data only with:
We rely on the following processors to operate the Service. Some of them process data in the United States:
Where data is transferred to the United States, those transfers rely on the providers' data-transfer safeguards, such as the EU/Swiss Data Privacy Framework and/or the EU Standard Contractual Clauses. Your data is retained for as long as your account exists and is deleted on account deletion.
Your data is stored on secure servers in the EU. Passwords are hashed using bcrypt. API communication is encrypted via HTTPS. Authentication tokens expire after a set period.
You can request to access, update, or delete your personal data at any time by contacting us. You can also delete your account yourself at any time from Profile → Delete account, which permanently removes your account and all associated data.
We always use essential cookies for authentication and to keep you signed in — these are required for the Service to work.
We also use Google Analytics, which sets analytics cookies. It is loaded only after you accept the cookie banner — until then it is blocked by Google Consent Mode, which we default to denied. You can decline, in which case only the essential cookies are used and the site works exactly the same.
Separately, we run our own usage measurement on our own servers, described in section 8. That one uses no cookies at all and sends nothing to any third party. The only cookie it involves is gca_no_track, set on your device if you switch measurement off, because that choice has to be remembered somewhere.
You can change your mind at any time. The button below clears your cookie-banner choice; you will be asked again the next time you open the app.
In addition to Google Analytics (section 7), we run our own usage measurement to understand which parts of the Service are actually useful. This one is done entirely by our own software on our own servers in the EU — no third party receives any of it, it uses no cookies, and it is never used for advertising, profiling for marketing, or automated decisions about you.
For each visit we record: the pages you open (the page address only, never the contents of any form, CV or document), how many seconds each page was visible, how far down each page you scrolled, clicks on a fixed list of labelled buttons and links, your device category (mobile, tablet or desktop), your browser's user-agent string, and the page that referred you to us. If you are signed in, this activity is linked to your account so we can see how the product is used by real users rather than only in aggregate.
We do not store your IP address. It is combined with your browser's user agent, a secret key and the current date into a one-way hash, and then discarded. That hash lets us tell one visitor from another within a single day; it cannot be turned back into an IP address, and it changes every night, so it cannot be used to follow anyone from one day to the next. Separately we keep the first three parts of the IP address (for example 203.0.113.0), which identifies a network rather than a person, and is used only to recognise and exclude search-engine crawlers and automated scanners — which make up the large majority of requests to this site.
This data is kept for at most 180 days and then deleted automatically. It is also deleted with the rest of your data if you delete your account.
You can switch it off. Signed-in users can turn usage measurement off under Profile → Privacy, which stops collection for that account on our servers, not merely in your browser. The setting is honoured server-side, and you can turn it on again at any time.
When someone opens a CV you shared, we count the view so you can see how often your link was opened. We do not store the visitor's IP address: it is combined with the browser's user agent, the link and the current month into a one-way hash, and then discarded. That hash lets us recognise repeat visits to the same CV within a calendar month, so the visitor count is not inflated by one person opening the link twice. It cannot be turned back into an IP address, is specific to that one CV link, and changes at the start of each month, so it cannot be used to follow anyone across months or between CVs.
For privacy-related questions, contact us at: info@getcvai.com or via getcvai.com/contact.