Overview
cv2spec is responsible for the personal data covered by this policy. The service is designed as a private workspace. Your profile, CVs, job applications, and generated documents are not public.
We process personal data to provide the service you request, secure your account, complete payments, respond to support enquiries, and maintain the product. We do not sell personal data or use it for targeted advertising.
For privacy questions or requests, contact support@cv2spec.com.
Information we collect
Account and security information
This includes your email address, preferred name, profile photo, connected Google or GitHub account, provider identifier, sign-in sessions, passkeys, and two-factor authentication settings. We store passkey public keys, never the secret held by your authenticator.
Application content
This includes uploaded CV files and extracted text, saved career highlights, job descriptions or public job URLs, company names, clarifications, revision requests, generated CVs and cover letters, review notes, document versions, and approval status.
Payment and credit information
We keep your cv2spec usage-credit balance, purchase references, transaction history, pack details, and a Stripe customer identifier. Stripe collects and handles full payment card details through its hosted checkout. cv2spec does not store full card numbers or financial credit information.
Technical and support information
Our servers and optional monitoring tools may receive your IP address, browser and device details, request times, pages and actions, error diagnostics, limited session replay data, and AI usage measurements such as token counts, cache use, model configuration, and request type. We also process what you send when you contact support.
CVs can contain sensitive information. Only include health, accessibility, diversity, immigration, or other special-category data when it is necessary for your application.
How we use personal data
We use personal data to:
- Create, save, revise, approve, and export your applications.
- Authenticate you, maintain sessions, and protect accounts from abuse.
- Process credit purchases, maintain balances, and prevent duplicate or fraudulent transactions.
- Answer support enquiries and investigate product or payment issues.
- Monitor reliability, diagnose errors, and improve the safety and performance of the service.
- Meet legal, accounting, security, and regulatory obligations.
Our legal bases depend on the activity. They include performing our contract with you, our legitimate interests in operating and securing the service, complying with legal obligations, and consent where the law requires it. You may withdraw consent at any time, without affecting processing that already took place lawfully.
AI processing
When you ask cv2spec to create or revise documents, the relevant CV text, career highlights, job specification, instructions, and prior revision context are sent to OpenAI through its API. The resulting output is returned to cv2spec and saved in your private application workspace.
If you provide a public job URL, the service may retrieve that page so the job description can be used. Information sent to OpenAI is handled under OpenAI's API data terms and data controls.
AI output can be incomplete or wrong. It does not make employment decisions about you, submit applications, or approve documents. You choose what to edit, approve, download, and send.
Retention and deletion
Account and application content is kept while your account remains active so you can return to previous work. Archiving an application hides it from the active list but does not delete it.
You can permanently delete an archived application, replace or remove your saved CV and profile photo, download a JSON copy of your account data, or delete all account data from Profile settings.
Deletion removes the data from active systems. Limited copies may remain for a short period in protected backups, security records, or a service provider's retention cycle. Payment and transaction records may be retained where tax, accounting, fraud-prevention, or other law requires it.
International transfers
Some providers may process data outside the United Kingdom. Where required, we rely on approved contractual safeguards, adequacy regulations, or another lawful transfer mechanism. Provider-specific terms may also apply when you choose Google, GitHub, Stripe, or another external service.
Your data protection rights
Depending on where you live and any legal exceptions, you may have the right to access, correct, erase, restrict, or receive a portable copy of your personal data. You may also object to certain processing and withdraw consent where consent is the legal basis.
You can download account data or delete the account from Profile settings. For any other request, email support@cv2spec.com. We may need to verify your identity before acting.
If you are in the United Kingdom, you may also complain to the Information Commissioner's Office. If you are elsewhere, you may contact your local data protection authority.
Security
We use access controls, private account routes, encrypted HTTPS connections, signed secure cookies in production, restricted storage access, and established providers to protect personal data. No online service can guarantee absolute security.
Keep your connected account and authentication methods secure. Contact support@cv2spec.com promptly if you think someone has accessed your account without permission.
Children
cv2spec is not directed to children under 16. If you are under 18, use the service only with permission from a parent or guardian, and do not purchase credits unless they authorise the payment.
Changes and contact
We may update this policy when the product, providers, or law changes. We will change the date at the top and give additional notice when a change materially affects how we use personal data.
Contact support@cv2spec.com with privacy questions, rights requests, or complaints.