How CVAI protects the data of the people who use it. This page describes what is in place today, and we update it when something changes.
Where the data lives
- Database and file storage: Supabase, in Frankfurt, Germany (EU).
- Cache and background job queues: Upstash, in Frankfurt, Germany (EU).
- Application servers: Vercel, currently in the United States. We are moving them to Frankfurt.
Providers that process data on our behalf
We only use the providers we need to run the service. Some of them process data outside the EU, as the table shows. The data processing agreement we sign with organisations lists them together with the safeguards that apply.
| Provider | What for | Where |
|---|
| Vercel | Application servers and privacy-friendly web analytics | United States |
| Supabase | Database and file storage | Germany (EU) |
| Upstash | Cache and background job queues | Germany (EU) |
| OpenRouter | Routes AI requests to a restricted list of model providers | United States |
| AI model providers | Generate and score CVs and cover letters, and run interview practice. Restricted list. | United States |
| PurelyMail | Sends emails: sign-in links and notifications | United States |
| Stripe | Payments | Ireland and United States |
| GitHub | Stores the daily database backup | United States |
| EnrichLayer | Imports a LinkedIn profile, only when the user asks for it | United States |
| Telegram | Internal alerts, including messages sent through the contact form | Outside the EU |
Signing in with Google or LinkedIn means those companies process the sign-in under their own privacy policies.
How we protect it
- Encrypted connections (TLS) everywhere, and encryption at rest for the database and stored files.
- Row-level security on every database table, so one person's data cannot be read by another even if the application had a bug. An automated check runs every night.
- We store no passwords: people sign in with Google, LinkedIn or a one-time email link.
- Links to share a document are stored only as a hash, expire, and can be revoked at any time by the person who created them.
- Rate limits on sensitive endpoints.
- Development and preview environments are separate and hold no real personal data.
- A daily backup of the database, kept outside the database provider for a limited time.
How long we keep it
- Activity logs: personal fields removed after 90 days, deleted after 365.
- History of reminder and follow-up emails: deleted after 365 days.
- Files no longer linked to an account: removed automatically every day.
- Profile and documents: while the account exists. You can ask us to delete your account at contact@cvai.pro.
Artificial intelligence
- CVAI does not make automated decisions about people. It helps each person prepare their own applications.
- AI output can contain mistakes, so every document can be reviewed and edited before it is used.
For schools and organisations
- Reports to organisations are aggregated and anonymous: they never show a person's name or individual results. A student's document reaches the careers team only when that student chooses to share it, and the student can revoke it.
- A data processing agreement (GDPR article 28) and a detailed security summary are available on request.
If something goes wrong
If a security incident affects personal data, we notify the people and organisations affected without undue delay, and the supervisory authority where the law requires it.
Contact
Questions about security or privacy: contact@cvai.pro. See also our privacy policy.