Your data
What happens to a CV you upload here, written from the code that does it.
The file you upload
It goes to private storage. There is no public link to it: reading it needs a signed address this app creates for a few minutes at a time, for the parsing and the file checks, and then discards. Nobody can open your CV by guessing a URL.
Where the text goes
The text of your CV is sent to Base44, the platform this app runs on, which runs it through a large language model to judge job-title fit and suggest improvements. A job description you paste and any LinkedIn text you give us go the same way, for the same reason. The ATS score and the keyword coverage are not model output: they are counted in code from your CV, which is why the same CV always gives the same number. Your CV is never used to train anything by us.
What we keep, and for how long
- The uploaded file
- The register entry that points at it: 7 days, then marked expired. The file itself: see the note below.
- The written suggestions
- Cached under a hash of your CV text so the same CV does not cost a second run: 7 days without an account, 30 days with one.
- The score records
- Numbers only, no CV text. Anonymous ones are deleted after 90 days; yours are kept with your account until you delete it.
- The hash of your address
- 48 hours. It is a one-way hash, not an address, and it exists only to count requests.
- The random id in your browser
- Until you clear this browser’s data or press delete on a result. It never leaves your device except as a hash.
- Your account and profiles
- Until you delete your account, which erases them.
One thing we cannot yet do, said plainly: Base44 gives us no way to delete a stored file. We can stop pointing at your uploaded file and we do, but the file itself stays on their storage, private and unreachable without a signed address. We would rather tell you than imply an erasure that did not happen.
Files uploaded before 3 October 2026
Until 3 October 2026 an uploaded CV went to public storage. The link was long and unguessable, and was never listed or shared, but anyone who had it could open the file without signing in. Uploads since that date go to private storage and have no public link at all. We cannot delete the older files ourselves, for the reason above, and we have asked Base44 to remove them.
Google Analytics
We use Google Analytics 4 to count how the site is used, loaded only once the page is interactive. It records page views and named events such as a CV being uploaded, an analysis being shown, or someone signing in. Those events carry numbers and short labels, for example a score or how much of a job description your CV covered, and never the text of your CV, your name or your email. Google sets its own cookies to do this. Blocking them in your browser or with an ad blocker stops the measurement and changes nothing else about the service.
Stopping abuse
Free analyses are limited per day. To count them we store a one-way hash of your IP address and a random id your browser generates. Neither names you, neither is shared, and both are gone within 48 hours. It is the least we could use and still stop someone running the service dry.
Removing what you gave us
With an account, deleting it erases your profiles, score records, packages and watchlist. Without one, the button on your result page retires our register entry and clears what this browser kept. In both cases the stored file is subject to the limit above.
One limit worth being straight about: without an account we cannot show you what we hold for you. The id that groups your records is stored only as a one-way hash, so we can match the one your browser presents in order to delete those records, but we cannot work backwards from our side to find or list them, and we have no way to check that a request to see them came from you. The delete button works; a request for a copy cannot be answered for an anonymous visitor.
Asking us something
Use the contact page. If you want to know what is held for you, say so and we will tell you.