Privacy Policy
CVRev analyzes the CV you upload and gives you honest, AI-generated feedback. Doing that means processing personal data — this page explains exactly what we collect, why, where it goes, and the controls you have. No legalese padding.
Who is responsible
CVRev is operated by Ali Al Lawati, Muscat, Oman (the “data controller”). Contact for anything privacy-related: ali4ever4@gmail.com.
What we collect
- Account: your name, email address, and Google account ID — provided by Google when you sign in. We never see your password.
- Your CV: the file you upload (PDF/DOCX) and the text and structure we extract from it. CVs often contain sensitive details (photo, nationality, and similar) — we only process what your document contains and never ask for more.
- Job description (optional): if you paste one, we store it with that upload to compute the job-match analysis.
- Results: the scores, advice, annotations, and reports we generate for you, and a share card only if you choose to create one.
- Consent records: when you accept this policy at upload, we record the timestamp and policy version.
- Payments: if you buy a review pack, our payment provider Polar collects the card and billing details needed to process it. We receive only the purchase confirmation, the product bought, and the email used — which we use to activate your review credits. We never see or store your full card number.
- Technical: one strictly-necessary session cookie (see Cookies) and short-lived server logs for security and debugging.
- Usage & advertising measurement (only with your consent): if you accept, Google Analytics records standard usage data (pages viewed, referrer, approximate location and device/browser type, on-site interactions), and Google Ads measures conversions from our advertising and may support remarketing. Decline, and none of it loads.
We don’t sell your data, and we don’t show ads on this site. With your consent we use Google Analytics (site usage) and Google Ads (measuring our ad campaigns), each with their own cookies — see Cookies below. Decline and neither loads.
Why we process it (lawful bases)
- Your consent — analyzing the CV you upload, including any sensitive details it happens to contain. You give this explicitly at upload and can withdraw it any time by deleting the upload or your account.
- Your consent (analytics & advertising) — optional Google Analytics and Google Ads cookies load only if you choose “Accept” in the cookie banner. Withdraw anytime via “Cookie settings” in the footer.
- Providing the service you signed up for — operating your account, showing your history, generating your reports.
- Performing our contract with you — processing a review-pack purchase and granting the credits you paid for.
- Legitimate interests — keeping the service secure and preventing abuse.
- Your separate opt-in — occasional product tips and offers by email. Optional, never pre-ticked, withdraw anytime.
AI processing
Your CV is analyzed automatically by AI models from OpenAI. The output is advice — scores and suggestions for you alone. It produces no legal or similarly significant effects, no third party makes decisions about you with it, and we never invent facts about you. Before any text is sent to the AI provider, we strip direct contact details (email addresses, phone numbers, and link URLs). Our AI provider does not use data sent via its API to train models.
Who processes data for us
- OpenAI — AI analysis of your CV content (servers in the US/EU), under a data processing agreement.
- Google (Sign-In) — authentication when you log in.
- Polar (Polar Software Inc.) — payment processing and Merchant of Record for paid packs (servers in the US), under their data processing terms.
- Google Analytics — website-usage analytics, loaded only if you consent; you can decline or withdraw anytime.
- Google Ads — measures conversions from our advertising and may support remarketing; loaded only if you consent.
- Railway — application hosting, database, and file storage.
- Email delivery provider — only if you request a report by email.
Where these providers process data outside your country, the transfer is covered by appropriate safeguards (such as Standard Contractual Clauses in their data processing agreements).
How long we keep it
- CVs, analyses, reports, share cards: deleted automatically 365 days after upload — or immediately, whenever you delete them.
- Account: kept until you delete it from Your data.
- Consent records: kept while your account exists, as evidence of consent.
- Purchase & entitlement records: kept while your account exists and as needed for tax and accounting.
Your rights
From Your data you can — instantly, no email required — download everything we hold about you (access & portability) and delete your account with all data (erasure). To correct something, upload the corrected CV. You can withdraw consent at any time; it stops future processing. You also have the right to complain to your data protection authority — your local EU/EEA authority, the UK ICO, or Oman’s Ministry of Transport, Communications and IT (MTCIT), depending on where you live.
Marketing emails
We send tips and offers only if you tick the separate marketing checkbox — it is optional and never pre-selected. Every marketing email includes an unsubscribe link, and you can opt out anytime from Your data. Opting out never affects emails you ask for, like a report you request.
Cookies
Essential: one cookie, connect.sid, keeps you signed in
for up to 7 days. It is strictly necessary, so it is always set and needs no consent.
Analytics & advertising (optional, consent-based): only if you click
“Accept” in the cookie banner, Google Analytics sets cookies (such as _ga and
_ga_*) to measure how the site is used, and Google Ads sets cookies (such as
_gcl_*) to measure conversions from our advertising. Nothing optional loads
until you accept, and “Decline” keeps it all off. You can change your choice anytime via
“Cookie settings” in the footer, or by clearing cookies in your browser. See
Google’s privacy policy
and the Google Analytics opt-out.
Sharing & publishing
Nothing about you is public unless you create a share card and share its link yourself. We never publish your CV or your score, and we never contact your employer.
Children
CVRev is for ages 16 and over.
Changes
If this policy changes materially, the version above changes and you’ll be asked to consent again at your next upload.