Privacy Policy
Last updated 26 August 2026
1. Who We Are and What This Covers
1.1 CVBuilderKit (âthe Serviceâ, âweâ, âusâ) is a browser-based CV builder that turns a rĂ©sumĂ© you supply into structured data and renders it with a prebuilt template. This policy explains what personal data the Service processes, on what basis, who it is shared with, and how long it is kept.
1.2 It applies to the CVBuilderKit website at cvbuilderkit.com and its API. It does not apply to any third-party site you reach from them.
1.3 For the purposes of Regulation (EU) 2016/679 and the UK GDPR (together, the âGDPRâ), the operator of CVBuilderKit is the controller of the data described below. Contact details are in section 11.
2. Data We Process
2.1 CV content. When you upload a rĂ©sumĂ©, your browser extracts its text and, for a PDF, renders each page to a JPEG image. That extracted text and those page images are sent to our API and held in the processing jobâs payload. The uploaded file itself is never sent to us and never stored.
2.2 CV data. The structured document produced from your résumé - name, contact details, employment history, education, skills, and anything else you enter or the model extracts - is stored as text.
2.3 Avatar. If you add a profile photograph, one image per user, up to 5 MB, is stored in object storage.
2.4 Chat messages. Instructions you send to refine a CV, and the replies returned, are stored as text against that CV.
2.5 Identifiers. Each visitor is issued an anonymous guest identifier and a bearer token. No name, email address or password is required, and the Service operates no login.
2.6 Technical data. Our hosting provider processes request metadata such as IP address, user agent and timestamps, for delivery, security and abuse prevention. We do not use it to build a profile of you. We also record, once per browser, the website that referred you and the page you first landed on, so that we can tell which channels bring people to the Service.
2.7 We do not ask for special category data as defined in Article 9 GDPR, such as health, religious belief or trade union membership. A résumé sometimes contains it. If you include it you do so on the basis of your explicit consent under Article 9(2)(a), which you withdraw by deleting the CV.
3. What Never Leaves Your Device
3.1 The résumé file you select is read in your browser and is not uploaded. Only the text and page images described in clause 2.1 are transmitted.
3.2 Your guest token, your preview preference and your cookie choice are kept in your browserâs local storage. They are not cookies, they are sent to no third party, and they are removed when you clear site data.
3.3 Clearing that storage permanently disconnects your browser from the CVs created with it. Because there is no login, we cannot restore that access to you.
4. Lawful Basis for Processing
4.1 Article 6(1)(b) GDPR, performance of a contract: reading your résumé, generating CV data and storing your CVs so you can return to them are the service you asked for.
4.2 Article 6(1)(f) GDPR, legitimate interests: keeping the Service available and secure, preventing abuse and diagnosing faults. We have assessed that these interests are not overridden by your rights, because the processing is limited to what operating the Service requires.
4.3 Article 9(2)(a) GDPR, explicit consent: any special category data you choose to include, as described in clause 2.7.
4.4 Article 6(1)(f) GDPR, legitimate interests: the analytics described in section 8, which run by default so that we can find and fix what gets in your way. You may object at any time by turning them off as described in clause 8.3, and we will stop.
5. Recipients and Sub-processors
5.1 Your data is processed by the following, and by no one else:
- Cloudflare, Inc. - application hosting, database and object storage for everything described in section 2.
- OpenCode Zen - the AI gateway that receives your CV text and page images for extraction and editing. The default model is deepseek-v4-flash.
- OpenAI, L.L.C., reached through that same gateway - the model gpt-5.6-luna-fast, used as a fallback when the default model fails or cannot read a document that has no text layer.
- Microsoft Corporation - Microsoft Clarity, which records how pages are used so we can find and fix problems. It receives this only with your permission, as described in section 8.
- A processing runner operated by us, which orchestrates the calls above.
5.2 We do not sell personal data, and we do not share it for advertising or marketing.
5.3 Model providers receive your CV content in order to return a result to you. Their own terms govern what they may do with it, and we do not authorise its use for any other purpose.
6. International Transfers
6.1 The recipients in section 5 run on infrastructure that may sit outside your country, including in the United States.
6.2 Where data leaves the European Economic Area or the United Kingdom, the transfer relies on the European Commissionâs Standard Contractual Clauses or on an adequacy decision, as set out in the relevant providerâs data processing terms.
7. Retention and Deletion
7.1 CV data, chat messages and avatars are kept until you delete the CV or ask us to delete your data.
7.2 Processing job payloads, meaning the extracted text and page images, are kept with the job record that produced your CV.
7.3 Because the Service is anonymous, we cannot find your data from your name or your email address. To have it deleted, contact us as described in section 11 and quote the identifier shown for the CV.
7.4 Deleted records are removed from the live database. Residual copies may persist in provider backups for a limited period before being overwritten.
8. Cookies and Local Storage
8.1 Analytics are enabled by default, and we tell you so on your first visit. You can turn them off at any time and we will not turn them back on. The Service never runs advertising or cross-site tracking scripts, and it never sells or shares what it measures.
8.2 Unless you turn them off, we load Microsoft Clarity, which sets two first-party cookies, â_clckâ and â_clskâ, and records how pages are used, including page views, clicks, scrolling and a replay of the session. Clarity masks sensitive content by default.
8.3 You can change or withdraw that permission at any time through the âCookie preferencesâ link in the footer. Withdrawing it stops the script loading on your next page view.
8.4 The local storage entries described in clause 3.2 are strictly functional and are the only other client-side storage the Service uses.
9. Your Rights
9.1 Subject to the conditions in the GDPR you have the right of access, and the rights to rectification, erasure, restriction of processing and data portability, and to object to processing carried out under Article 6(1)(f).
9.2 Most of these you can exercise directly: your CV data is visible and editable in the builder, can be exported from it, and can be deleted there.
9.3 The limitation in clause 7.3 applies to any request you send us. We can only act on data we can locate, and without an account we depend on the identifiers you give us.
9.4 You have the right to lodge a complaint with your local supervisory authority.
10. Security and Children
10.1 Data is transmitted over TLS and stored on the infrastructure named in section 5. API access requires a bearer token issued to your browser.
10.2 No method of transmission or storage is completely secure, and anyone with access to your browser profile has access to the CVs created in it.
10.3 The Service is not directed at children under 16, and we do not knowingly process their data.
11. Changes and Contact
11.1 We may amend this policy. The date at the head of this page records the current version, and a material change will be reflected there.
11.2 For any privacy question or request, write to support@cvbuilderkit.com.
11.3 This document describes how the Service actually operates. It has not been reviewed by a lawyer and is not legal advice.