Privacy Policy
This policy describes how CVBranch ("we", "us") handles information when you use cvbranch.com and related services. It is written for clarity, not as a substitute for professional legal advice.
What we collect
- Account data — a Firebase Auth user id. Guests use an anonymous session; signed-in users may provide a Google account name and email.
- Resume files and parsed content — PDF/DOCX you upload, plus structured text we extract (jobs, bullets, skills, contact fields).
- Job descriptions and tailor session data — JDs you paste, match results, gap answers, story-bank facts, and compositions you create.
- Usage and security signals — AI feature quotas, approximate request rate limits, and App Check / reCAPTCHA tokens used to protect the service.
How we use it
- To match your CV to a job description and help you draft resume content.
- To store your work so you can return later (while your account or guest session lasts).
- To enforce free-trial limits and reduce abuse.
- To operate, secure, and improve the product.
We do not sell your resume content. We do not use your uploads to train our own machine-learning models.
AI processing
Some features send relevant text (for example resume snippets, a job description, or your gap answers) to a third-party large language model provider (currently OpenAI in production) to generate drafts, examples, or parse recovery. Those providers process data under their own terms and privacy policies. Outputs can be wrong or incomplete — treat them as suggestions you must edit.
Where data is stored
Application data is stored using Google Firebase (Authentication, Firestore, Cloud Storage, and Cloud Functions), typically in Google Cloud regions configured for this project. Browser clients talk to our backend over HTTPS.
Guest sessions
If you use CVBranch without Google sign-in, we still create an anonymous account so we can save your uploads and limits. Clearing cookies or switching devices may create a new guest session. Sign in with Google if you want a more durable account.
Retention and deletion
We keep account-linked data while your account is active and as needed to provide the service, enforce quotas, and meet legal obligations. You can delete individual saved resumes in the product where that control is offered. To request deletion of your account data, email privacy@cvbranch.com from the address associated with your account (or describe your guest session as best you can).
Sharing
We share data only as needed to run the service, including:
- Infrastructure and auth providers (Google / Firebase).
- AI providers when you use AI features (as described above).
- When required by law or to protect the service and users.
Security
We use industry-standard controls such as encrypted transport, authenticated API access, and owner-scoped data rules. No method of storage or transmission is 100% secure.
Children
CVBranch is not directed at children under 16. Do not use the service if you are under 16.
Changes
We may update this policy. The "Last updated" date will change when we do. Continued use after an update means you accept the revised policy.
Contact
Privacy questions: privacy@cvbranch.com