Privacy Policy
Last updated: 24 August 2026
What we collect
- Account data: your email address and a user identifier, provided when you sign in with Google through our authentication provider.
- Your CV: the PDF file you upload, plus the profile fields we extract from it (name, contact details, work history, education, skills).
- Application preferences and history: the answers you save for reuse and a record of the applications you filled.
- Product-update email: if you ask to hear about Founding Pro or another product update before signing in, we store the email address you submit and the signup source. It is used only for that requested update and is not linked to an account unless you later sign in with the same address.
- Usage analytics: aggregate page views and events. No CV content is sent to analytics.
- Browser extension: if you connect the browser extension, the extension stores the connection token locally in Chrome storage so it can authenticate requests to cvautofill. Our server stores only a hash of that token. The token expires after 180 days, and you can revoke it at any time from your dashboard or disconnect it from the extension.
- Contact messages: if you use our contact form, we store the email address and message you send us so we can reply.
- Billing data: Stripe processes your payment details and subscription. We receive identifiers, status, price and limited payment metadata needed to provision your plan; cvautofill does not receive or store your full card number.
Where it is stored
Profile fields, preferences, application records and waitlist emails are stored in a Neon PostgreSQL database located in the United States. Your CV file is stored in Cloudflare R2 object storage; we have not pinned it to a specific region, so we don't assert one here.
Who processes your data
- Clerk — authentication and session management (email, user identifier).
- Railway — hosts our application server, which receives your uploaded CV, extracts its text, and reads and writes your profile, preferences and application records.
- Neon — database hosting (profile, preferences, application and waitlist records).
- Cloudflare R2 — CV file storage.
- Google Gemini — extracts structured fields from your CV and drafts answers to open-ended application questions.
- Vercel — website hosting and aggregate analytics.
- Stripe — checkout, recurring payments, invoices, subscription management and payment-related fraud prevention.
What we never do
We do not sell your data, and we do not submit job applications on your behalf without your review. Nothing is sent to an employer until you press submit yourself.
Chrome Web Store Limited Use
Our use and transfer of information received from Google APIs and through the cvautofill browser extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information only to provide and improve the job-application autofill features you request. We do not use or transfer it for personalized advertising, creditworthiness, lending, or unrelated purposes, and we do not permit humans to read it except with your explicit consent for support, when required for security or by law, or when the data has been aggregated and anonymized for internal operations.
Retention and deletion
We keep your data for as long as your account exists. Product-update emails are kept until the requested notifications are sent or you ask us to remove them, whichever comes first. Contact form messages are kept only as long as we need them to handle your request, and are deleted sooner if you ask us to. Contact us via our contact form to request access to or deletion of your data — this includes removing your address from the waitlist. Signed-in users can also delete their account and stored CV directly from the dashboard; contact-form deletion requests are completed within 30 days.
Contact
Questions about this policy: use our contact form.