Summary: We collect what is needed to build your CV, process your text with an LLM provider, store it encrypted on Cloudflare for a limited time, never sell it, and let you export or delete it yourself from the Privacy page.
Privacy Policy
Version 1.0.0 — effective 15 September 2026.
1. Who is responsible
{{COMPANY_NAME}}, {{COMPANY_ADDRESS}}, {{COMPANY_COUNTRY}} is the controller of personal data processed through the CitedCV Service (citedcv.com and successor domains). Data protection contact: {{DPO_EMAIL}}. General support: {{SUPPORT_EMAIL}}.
This policy applies to everyone who visits the site or uses the Service. Users in Türkiye should also read the KVKK Aydınlatma Metni, which is the formal disclosure notice under Law No. 6698 and includes the explicit-consent text for cross-border transfers.
2. What we collect
- Account data: email address, password hash, display name, preferred language, account settings, and legal acceptance records (which version you accepted, when, and from which IP address and browser).
- Profile and CV data: the facts you provide about yourself in the interview or manually, documents you upload (existing CVs, cover letters), job descriptions you paste, and the CVs, edits and exports we generate for you. This can include work history, education, skills, contact details and, if you choose to include them, details such as nationality or a photo. Please do not enter special-category data (health, religion, political opinions and similar) unless you need it in your CV; such data is processed only because you chose to include it.
- Quiz data: your answers to the pre-signup quiz, tied to an anonymous session cookie until you create an account.
- Payment data: purchase history, amounts, currency, pack, payment status and the Stripe identifiers of the transaction. Card numbers go directly to Stripe; we never see or store them.
- Usage telemetry: which actions you run, stage timings, verification scores, lint results, which suggested edits you accept or reject, error events, and technical data such as IP address, browser type, device type and approximate location derived from the IP address.
- Support communications: emails and messages you send us.
We do not collect data about you from third-party sources, except payment status from Stripe and bot-protection results from Cloudflare Turnstile.
3. Why we process it and on what legal basis
Under the GDPR and the UK GDPR we rely on the legal bases below. The KVKK equivalents (Law No. 6698, Articles 5 and 6) are listed in the KVKK Aydınlatma Metni.
- To provide the Service, including creating your account, building and storing your CVs, exporting documents, processing payments and refunds, and providing support: performance of a contract (Article 6(1)(b)).
- To keep the Service secure, including bot protection, rate limiting, fraud prevention, abuse investigation and security logging: our legitimate interest (Article 6(1)(f)) in protecting the Service and its users.
- To improve the engine, including analysing stage timings, scores and accepted edits, fixing errors, and using de-identified, aggregated data to tune prompts, rules and templates: our legitimate interest (Article 6(1)(f)). We do not use your identifiable CV content to train third-party models.
- To send service emails such as verification, receipts, refund confirmations, security alerts and notices of material changes to the Terms: contract and legal obligation (Article 6(1)(b) and (c)).
- To send product news, only if you opt in: consent (Article 6(1)(a)), which you can withdraw at any time.
- To comply with the law, including tax, accounting, consumer-protection and law-enforcement obligations: legal obligation (Article 6(1)(c)).
- To transfer your data outside your region where no adequacy decision applies and, for residents of Türkiye, for any transfer abroad: your explicit consent where the law requires it, otherwise standard contractual clauses or equivalent safeguards.
4. AI processing
To build, check and edit your CV, the text you provide and the job description are sent to a large language model provider. Our current provider is MiniMax, whose servers may be located outside the EU, the UK and Türkiye. We send only what is needed for the current task, we do not authorise the provider to use your data for its own purposes, and we never send your payment data. Results are stored in your account together with a trace of how they were produced, so that you can see which fact supports each sentence.
We do not make decisions about you that have legal or similarly significant effects by solely automated means. The Service produces a document for you to review and use as you see fit.
5. Who receives your data (sub-processors)
- Cloudflare, Inc.: hosting, database (D1), file storage (R2), email delivery, browser rendering for PDF exports and bot protection (Turnstile). Data is stored with encryption at rest.
- Stripe: payment processing, invoicing and tax calculation.
- MiniMax: large language model inference for building, checking and editing CVs.
- Email provider: delivery of transactional email (currently Cloudflare Email Service; we may use an alternative provider such as Resend).
We may also disclose data to professional advisers, to a successor in a merger or acquisition (with notice to you), and to authorities when the law requires it. We never sell personal data and do not share it with advertisers or data brokers.
6. International transfers
Our sub-processors operate globally. Where data leaves the EU, the UK or Türkiye we rely on adequacy decisions, standard contractual clauses or, where the law requires it (including for transfers from Türkiye under Article 9 of the KVKK), your explicit consent, which we ask for separately. You can withdraw that consent at any time; without it we cannot provide the AI features of the Service.
7. How long we keep it
- Uploaded documents: 30 days after upload, then deleted.
- Generated exports (PDF, DOCX): 90 days after creation, then deleted; you can re-export at any time from your stored CV.
- Run traces (the record of how a CV was built, including stage timings and scores): 180 days.
- Account, profile, fact and CV data: until you delete your account or the data, plus up to 30 days for backups to expire.
- Payment and refund records: for as long as tax and accounting law requires (typically 7 to 10 years), limited to what those laws need.
- Legal acceptance records and security logs: for the period needed to demonstrate compliance and defend claims, normally the limitation period applicable to contract claims.
- Quiz sessions not linked to an account: deleted when the 7-day quiz cookie expires.
De-identified, aggregated statistics may be kept indefinitely.
8. Your rights
Depending on where you live, you have the right to access your data, receive a copy in a portable format, correct it, delete it, restrict or object to processing, withdraw consent, and not to be subject to solely automated decisions with legal effects. California residents have equivalent rights under the CCPA/CPRA, including the right to know, delete and correct, and the right to opt out of sale or sharing (we do neither).
- Export and delete: from the Privacy page in the app you can download all your data and delete your account and its data without contacting us.
- Everything else: email {{DPO_EMAIL}}. We answer within one month (GDPR) or 30 days (KVKK), extendable where the law allows. We may ask you to verify your identity.
- Complaints: you may complain to your data protection authority, for example the ICO in the UK, the supervisory authority of your EU member state, or the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) in Türkiye. We would appreciate the chance to resolve the issue first.
9. Security
We use TLS in transit, encryption at rest, scoped access to production systems, HttpOnly session cookies, Turnstile bot protection, rate limiting and append-only ledgers for Credits and legal acceptances. No system is perfectly secure; if a breach affects your data we will notify you and the competent authorities as the law requires.
10. Cookies
We use only strictly necessary cookies (session, theme, quiz session, CSRF) and Cloudflare Turnstile. We do not use advertising cookies or third-party analytics cookies; our analytics are server-side and cookieless. Details are in the Cookie Policy.
11. Children
The Service is not intended for children under 16. We do not knowingly collect data from them; if we learn that we have, we delete it.
12. Changes
We announce material changes to this policy by email or in-app notice at least 14 days before they take effect. The version number and effective date are shown at the top.
13. Contact
{{COMPANY_NAME}}, {{COMPANY_ADDRESS}}, {{COMPANY_COUNTRY}}. Data protection: {{DPO_EMAIL}}. Support: {{SUPPORT_EMAIL}}.