Privacy Policy

Last updated: February 15, 2026

1. Introduction

CVLab ("we", "our", or "us") is committed to protecting your privacy. This policy describes what data we collect, why we collect it, and how you can request deletion of your data.

2. Data We Collect

We collect only the data necessary to provide our services:

  • ‱Account data: Email address, name, phone number (optional), city (optional), LinkedIn URL (optional), profile image
  • ‱CV/Resume content: The information you enter when building or tailoring your CV
  • ‱Job postings: Job descriptions you provide for CV tailoring, cover letter generation, or interview preparation
  • ‱Billing data: Processed by Stripe (payment provider); we do not store full card numbers

3. Why We Collect Data

  • ‱To create and manage your account
  • ‱To provide CV building, tailoring, cover letter generation, and interview preparation features
  • ‱To process payments and manage subscriptions
  • ‱To improve our services and respond to support requests

4. Where Data Is Stored

Data is stored in Supabase (database and file storage) and served via Vercel (hosting). All infrastructure uses industry-standard encryption.

5. Sub-Processors

We use the following sub-processors to operate our service:

  • ‱Supabase — Database, authentication, file storage
  • ‱Vercel — Hosting and serverless functions
  • ‱OpenAI — AI processing for CV tailoring, cover letters, and interview questions
  • ‱Stripe — Payment processing and subscription management
  • ‱Upstash — Rate limiting (server-side only; no user tracking)
  • ‱Zyte — Job URL scraping when you provide a job link to analyze

These processors are bound by their own privacy policies and data processing agreements.

6. Retention

  • ‱Account and CV data: Retained until you delete your account
  • ‱Logs: Server logs are retained for up to 30 days for debugging and security
  • ‱Stripe data: Retained according to Stripe's policy for legal and tax purposes

7. Your Rights (GDPR)

If you are in the European Economic Area, you have the right to:

  • ‱Access your personal data
  • ‱Rectify inaccurate data
  • ‱Request deletion of your data
  • ‱Object to processing
  • ‱Data portability

To delete your account and associated data, go to your Profile page and use the "Delete account" option. You can also contact us for assistance.

8. Cookies

We use session cookies for authentication (via Supabase Auth). We do not use tracking cookies or third-party analytics that require cookie consent.

9. Contact

For privacy-related requests or questions, please contact our support team.