Privacy
Last updated: August 27, 2026
This page describes how CVCraft currently handles information during the private beta. It is a factual product notice, not a claim of certification under any particular privacy framework.
Account information
We store the email address, password hash, first and last name, preferred language, country, account role, Free or Pro plan state, and account timestamps needed to provide and secure the service. Passwords are stored as one-way hashes, not readable passwords.
CV and profile information
CVCraft stores the Master CV facts you review or enter, uploaded CV documents and extracted text, optional profile photos, guided answers, and free-text career information. Generated CV versions are fixed snapshots and can be rendered or downloaded as PDFs. This information is used to build and deliver the CV features you request.
Jobs, matches, and generated recommendations
We store job descriptions, source details, structured job requirements, match results, scores, explanations, and the generated CV versions associated with them. Match Score is informational. Your outcome or feedback data does not currently auto-train or automatically modify the scoring system.
Applications, outcomes, and feedback
If you use application tracking, we store the role, company, source, submitted CV version, application date, notes, status history, callbacks, interviews, offers, and other outcomes you record. Optional CV feedback is kept separately from your Master CV and scores. Private-beta feedback stores the area, category, optional message, account, and timestamp you submit; it does not automatically attach CV or job-description text. Outcome and feedback information may later help improve product quality in aggregate, but it does not currently change an individual score.
First-party analytics
We record a small set of product events such as registration, Master CV confirmation, job analysis, matching, CV generation, PDF responses, applications, callbacks, interviews, and offers. These records use internal resource identifiers and limited operational metadata rather than CV or job-description text.
Private files and deletion
Uploaded documents and profile images are private and are not published as public files. Access is restricted to the authenticated owner. Account deletion removes user-linked customer records and private stored files. Security and infrastructure logs outside the customer database may remain for their normal operational retention period.
Plans and payment providers
CVCraft stores the Free or Pro plan and usage state needed for quotas. PayPal checkout is disabled during the current private beta. If third-party payments are enabled later, the provider will handle the payment interaction and CVCraft will store provider identifiers, subscription state, and payment-event records needed to activate and administer the plan; CVCraft is not designed to store payment card numbers.
Security and operations
We use authentication, owner-scoped data access, private file storage, input validation, rate limits, and operational logs to run and protect the service. No internet service can promise absolute security or uninterrupted availability.
Your choices
You can edit supported account details, manage your CV and application records, and permanently delete your account from Settings. Email changes are unavailable in the private beta because a secure re-verification flow is not enabled.