Legal

Privacy policy

This policy explains what cv2spec processes when you create and tailor job applications, and the choices you have.

Last updated 19 July 2026

Overview

cv2spec is responsible for the personal data covered by this policy. The service is designed as a private workspace. Your profile, CVs, job applications, and generated documents are not public.

We process personal data to provide the service you request, secure your account, complete payments, respond to support enquiries, and maintain the product. We do not sell personal data or use it for targeted advertising.

For privacy questions or requests, contact support@cv2spec.com.

Information we collect

Account and security information

This includes your email address, preferred name, profile photo, connected Google or GitHub account, provider identifier, sign-in sessions, passkeys, and two-factor authentication settings. We store passkey public keys, never the secret held by your authenticator.

Application content

This includes uploaded CV files and extracted text, saved career highlights, job descriptions or public job URLs, company names, clarifications, revision requests, generated CVs and cover letters, review notes, document versions, and approval status.

Payment and credit information

We keep your cv2spec usage-credit balance, purchase references, transaction history, pack details, and a Stripe customer identifier. Stripe collects and handles full payment card details through its hosted checkout. cv2spec does not store full card numbers or financial credit information.

Technical and support information

Our servers and optional monitoring tools may receive your IP address, browser and device details, request times, pages and actions, error diagnostics, limited session replay data, and AI usage measurements such as token counts, cache use, model configuration, and request type. We also process what you send when you contact support.

CVs can contain sensitive information. Only include health, accessibility, diversity, immigration, or other special-category data when it is necessary for your application.

How we use personal data

We use personal data to:

  • Create, save, revise, approve, and export your applications.
  • Authenticate you, maintain sessions, and protect accounts from abuse.
  • Process credit purchases, maintain balances, and prevent duplicate or fraudulent transactions.
  • Answer support enquiries and investigate product or payment issues.
  • Monitor reliability, diagnose errors, and improve the safety and performance of the service.
  • Meet legal, accounting, security, and regulatory obligations.

Our legal bases depend on the activity. They include performing our contract with you, our legitimate interests in operating and securing the service, complying with legal obligations, and consent where the law requires it. You may withdraw consent at any time, without affecting processing that already took place lawfully.

AI processing

When you ask cv2spec to create or revise documents, the relevant CV text, career highlights, job specification, instructions, and prior revision context are sent to OpenAI through its API. The resulting output is returned to cv2spec and saved in your private application workspace.

If you provide a public job URL, the service may retrieve that page so the job description can be used. Information sent to OpenAI is handled under OpenAI's API data terms and data controls.

AI output can be incomplete or wrong. It does not make employment decisions about you, submit applications, or approve documents. You choose what to edit, approve, download, and send.

Cookies and diagnostics

cv2spec uses essential cookies for authentication, security, temporary redirects, form messages, and your light or dark theme preference. Disabling essential cookies will prevent account features from working.

When error monitoring is configured, diagnostic tools may collect performance traces, errors, browser events, and sampled session replays. These records help us reproduce failures and improve reliability. They are not used for advertising.

Who receives personal data

We disclose only what is needed to providers that help operate cv2spec:

  • OpenAI for AI document generation and revision processing.
  • Stripe for checkout, payment processing, tax, and fraud checks.
  • Google or GitHub when you choose that provider to create or access an account.
  • Hosting, database, and object-storage providers that run the service and store profile images.
  • Error-monitoring and email providers when those services are configured.

We may also disclose information when required by law, to protect people or the service, or as part of a business reorganisation. We do not allow service providers to use personal data for their own advertising.

Retention and deletion

Account and application content is kept while your account remains active so you can return to previous work. Archiving an application hides it from the active list but does not delete it.

You can permanently delete an archived application, replace or remove your saved CV and profile photo, download a JSON copy of your account data, or delete all account data from Profile settings.

Deletion removes the data from active systems. Limited copies may remain for a short period in protected backups, security records, or a service provider's retention cycle. Payment and transaction records may be retained where tax, accounting, fraud-prevention, or other law requires it.

International transfers

Some providers may process data outside the United Kingdom. Where required, we rely on approved contractual safeguards, adequacy regulations, or another lawful transfer mechanism. Provider-specific terms may also apply when you choose Google, GitHub, Stripe, or another external service.

Your data protection rights

Depending on where you live and any legal exceptions, you may have the right to access, correct, erase, restrict, or receive a portable copy of your personal data. You may also object to certain processing and withdraw consent where consent is the legal basis.

You can download account data or delete the account from Profile settings. For any other request, email support@cv2spec.com. We may need to verify your identity before acting.

If you are in the United Kingdom, you may also complain to the Information Commissioner's Office. If you are elsewhere, you may contact your local data protection authority.

Security

We use access controls, private account routes, encrypted HTTPS connections, signed secure cookies in production, restricted storage access, and established providers to protect personal data. No online service can guarantee absolute security.

Keep your connected account and authentication methods secure. Contact support@cv2spec.com promptly if you think someone has accessed your account without permission.

Children

cv2spec is not directed to children under 16. If you are under 18, use the service only with permission from a parent or guardian, and do not purchase credits unless they authorise the payment.

Changes and contact

We may update this policy when the product, providers, or law changes. We will change the date at the top and give additional notice when a change materially affects how we use personal data.

Contact support@cv2spec.com with privacy questions, rights requests, or complaints.