Privacy policy
This document describes the CV Unfold service in its current product version.
What we process
We process the CV file and optional job description solely to produce the requested analysis. The selected target role and seniority are used for the analysis and, only after optional measurement consent, as closed statistical categories. Contact details are masked before the main model review where possible. We do not use CV content for advertising or analytics.
Purposes and legal bases
Document processing and role recognition are necessary to provide the requested service. We rely on our legitimate interest in measuring product and acquisition fit only for the brief processing needed to create the anonymous audience counters described below. The inferred category is not sent to Google.
Storage and retention
The source document is processed in server memory and is not saved in product storage. When you choose a file, and before you start the analysis, we read it once in memory to detect the target role and preselect the review criteria; that step stores nothing and produces only a role category. The generated report, raw voluntary feedback and minimal operational metadata are stored in a private database for up to 30 days, unless you delete them earlier. If you add a written comment, we keep a separate product-feedback copy for up to 90 days so it can be reviewed after the report expires. That copy has no report or issue identifier and we do not add CV or report content to it. Controlled failures do not intentionally retain the source file.
Anonymous product statistics
After an analysis, the role perceived by the model is mapped once to one of a closed set of categories: supported IT, other IT, unclear, or one of about a dozen specific non-IT categories (for example construction, healthcare, legal or education) — never free text. We retain only cumulative counters by that category and a broad acquisition source (Google Ads or other). The counters contain no analysis identifier, exact role, date, CV or report content, IP address, click identifier or UTM value and cannot be used to restore a deleted report. The raw perceived role remains part of the report and is deleted with it. Voluntary report ratings are retained as separate cumulative quality counters without comments or analysis links.
Processors
OpenAI processes text for the AI review, Supabase stores the private report and operational records, Stripe handles payment, and Vercel hosts the application. Google measurement tools run only after optional consent and never receive CV, job-description or report content.
Your controls
You can delete a report immediately from the report screen or use the deletion instructions. You may contact the service provider to exercise applicable data rights or object to future audience-fit aggregation. Once a counter has been irreversibly aggregated, it can no longer be linked back to or removed for a particular report.