Privacy Policy
Operated by Jaspin LLC · Effective
At a glance
We do not sell your data, and we do not train AI models on it.
Your resume goes to Anthropic to power the AI features, as you wrote it, including your name. Anthropic does not train on it and deletes it within 30 days. We would rather say that plainly than claim an anonymisation we do not perform.
Uploaded PDF and DOCX files are never stored. We read them in memory and keep only the extracted text.
You can export everything and delete everything from Settings, in a couple of clicks, without emailing anyone.
This summary is for orientation only. The full text below is what actually applies.
This policy explains what SupaCV collects, who receives it, how long it is kept, and what you can do about all of it. It is written to be checkable: where a retention period or a vendor is named, that is what the product actually does today, not an aspiration.
1. Who we are
SupaCV is operated by Jaspin LLC, a Wyoming limited liability company, at 30 N Gould St Ste N, Sheridan, WY 82801, United States. Jaspin is the controller of personal information processed through SupaCV.
For anything in this policy, including a request to see or delete your data, write to privacy@supacv.com.
2. Your controls
These work today, from inside the product, without asking us:
- Export everything. Settings gives you a complete JSON download of your account: Resumes, Analyses, Target Roles, Cover Letters, Interview Session answers, saved stories, Applications, and your billing records.
- Delete your account. Settings, under Danger Zone. This cancels any active subscription and removes your data, including any free scan you ran before signing up, and it takes you off our mailing list rather than leaving you to unsubscribe afterwards. Four records survive it, and we would rather name them than let you find out later. Three are detached from your account rather than deleted: the billing records described in section 3, which tax and accounting rules require us to keep for up to 7 years, our record of what AI calls cost, which keeps the figures, and the product events section 11 already lists. None of those three holds your Resume, your email address, or your IP address. The fourth is not detached and we will not pretend otherwise: our staff audit log records that the deletion happened, and that entry keeps your account id, your email address and your Stripe customer id, so that we can answer a later question about the deletion or a refund. A fifth exists only if it was ever made: if our support team copied your account into a temporary internal workspace (section 14), our record of that support session stays behind. It holds your account id, when the session started and ended, how it ended, and how many rows were copied, and it never held your name or your email address. Section 11 gives a period for each of them.
- Delete one Resume. Deleted Resumes sit in trash for 30 days so an accident is recoverable, then a daily job removes them permanently.
- Benchmark participation. Settings has a peer-benchmarking control and Discover has one for compensation data. Section 6 explains why neither currently changes what we hold.
- Turn off session recording. Decline on the cookie banner, or change your mind later on the Cookie Policy page.
- Stop the optional emails. Settings controls the weekly digest and follow-up reminders, and every marketing email has a one-click unsubscribe. We still send transactional email such as password resets and receipts.
3. What we collect
What you give us
- Account details. Email address, name, and authentication credentials, handled by Supabase Auth. We never see your password, only a hash held by Supabase.
- Resume and career information. Employment history, job titles, employers, education, skills, certifications, achievements, projects, and anything else you put in a resume.
- Uploaded files. PDF and DOCX uploads are parsed in memory during the request and are never written to storage. We keep the extracted text, capped at 30,000 characters, and the structured data derived from it.
- Job-search information. Target Roles, job descriptions you paste or save, Applications and their status, offers, salary expectations, preferred locations and industries.
- Interview Sessions. The questions, the answers you write, the AI feedback on them, and the stories you save to your story bank.
- Correspondence. Support requests, feedback submitted in the product, and anything you email us.
What the product generates
- ATS scores, section feedback, fit checks, rewrites, Tailored Versions, and Cover Letters.
- Subscription and billing state. Card details go to Stripe on its own checkout page and never reach SupaCV. We keep a billing record of each subscription event: plan, billing interval, amount, currency, any discount, the date, the subscription status, and Stripe reference ids. It never includes your name, address, or card. When a subscription ends, the record also keeps why, for example that you asked to cancel or that a payment failed, and, where Stripe asks you to pick a reason for leaving and you pick one, that reason, for example that it was too expensive or that you switched to something else. The free-text box Stripe offers beside it is never stored.
- A record of AI use and cost per user, for capacity and quota management, for support, and to understand which AI features are used. It holds no prompt or response content: which feature ran, which model, how many tokens it used, what it cost, how long it took, and whether the call worked. It is tied to your account while the account exists, and when you delete your account the link to you is removed and the cost figures are kept. A free scan writes the same record with no account, no email address, and no IP address on it at all.
- A record of each email our own system sends you: which message it was (for example the welcome email or a receipt), when, which email provider handled it, and whether it went out. It holds no email address and nothing from the message.
What we collect automatically
- Product events. Sign-ins, which features you use, and errors you hit, recorded in our own database. Event properties are limited to 12 keys, any string over 120 characters is dropped, and sensitive keys are stripped, so content cannot ride along inside an event. While you are signed in, these records are tied to your account, whatever you chose about cookies (section 9). One of them is written once, when you complete sign-up: it notes how you first arrived (a source category such as a search engine, and the first page you landed on), a two-letter country, and whether the device was a phone, tablet, or desktop. We also keep the first time you use each feature and the calendar dates on which you open the signed-in app. A date is only a date: it does not record which page you opened.
- Page views. The page visited, with any id in its address replaced by a placeholder, whether it was the first page of your visit, a two-letter country, and whether the device is a phone, tablet, or desktop. The country comes from a header set at the edge, not from an IP address we store. No IP address is written to these records, and page-view records are never linked to an account. (Two records put a country and a device type next to something that identifies you: the sign-up record above, and a free scan, in section 7.) Once a day we add these records up into daily totals per page, source category, country and device type. The totals keep no time of day, are never linked to an account, and are kept after the individual records are deleted (section 11).
- Your IP address, briefly. It is used as a rate-limiting key to stop abuse of public endpoints. Those counters live in Upstash Redis and expire on their own within one hour for most limits, or 24 hours for the free landing-page scan. They are never joined to your account or to any content. The one exception is the free scan itself, covered in section 7.
- Server logs. Every log line passes through a scrubber that redacts resume text, structured data, job descriptions, cover letters, prompts, emails, phone numbers, passwords, and tokens, and truncates anything long, before it is written.
We do not deliberately collect special categories of data such as health information, government identifiers, racial or ethnic origin, or precise location. Please do not put them in your resume unless a role genuinely requires it.
4. How we use it, and why we may
Where the law requires a legal basis, the one we rely on is shown in brackets.
- Running the product: analysing, tailoring, generating, scoring, storing, and exporting your material (performance of a contract).
- Sending the relevant parts of your content to our AI provider so a feature you asked for can run (performance of a contract).
- Taking payments, managing subscriptions and refunds, and providing support (performance of a contract, and legal obligation).
- Surfacing Recommended Roles based on your Resume and preferences (performance of a contract).
- Sending transactional email such as receipts, password resets, and scan results (performance of a contract).
- Sending optional email such as the weekly digest, follow-up reminders, and product news, which you can switch off at any time (consent, or legitimate interests where consent is not required).
- Preventing fraud, abuse, and unauthorised access (legitimate interests, and legal obligation).
- Understanding how the product is used and where it fails, so we can fix it (legitimate interests, and consent for session recording).
- Computing aggregate benchmarks from the anonymised pool, described in section 6 (consent).
- Meeting legal obligations and enforcing our agreements (legal obligation, and legitimate interests).
We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. We run no advertising cookies or ad pixels.
5. What the AI provider receives
SupaCV uses Anthropic’s Claude models for every AI feature. There is no other AI provider in the live path, and AI requests go directly to Anthropic rather than through an intermediary.
What gets sent depends on the feature you run:
- Analysis: the extracted Resume text.
- Tailored Versions and rewrites: the Resume, plus the job description you are targeting.
- Cover Letters: the Resume, the job description, and any instructions you add.
- Interview Sessions: the question, the answer you wrote, and the Resume bullets being scored against it.
We do not remove your name, email, or phone number before sending. Some services claim to de-identify content before it reaches an AI provider. We do not do that, for two reasons: the features would work worse, and stripping direct identifiers from a career history that lists your employers, dates, and job titles does not make it anonymous anyway. Saying so is more useful to you than a reassurance that would not survive scrutiny.
What is true instead:
- Anthropic processes this material on our instructions, as our processor, and may not use it for its own purposes.
- Anthropic does not train its models on data submitted through its API by default, and SupaCV has not opted in to any arrangement that would change that.
- Anthropic retains API inputs and outputs for up to 30 days for abuse monitoring, then deletes them.
- All of it travels over TLS.
Because of this, do not paste anything into SupaCV that your job search does not need. A resume is enough.
6. The benchmark pool
Some SupaCV features compare your resume against a pool of other resumes, for example to say how a section length or a score compares with resumes for similar roles.
That pool is seeded from a public research dataset of resumes published on Hugging Face, not from SupaCV users. There is a contribution path that can add an anonymised copy of your own resume to it, governed by the peer-benchmarking control in Settings, but no screen in the product currently invokes it, so in practice the pool is the seeded dataset.
Being exact about that control, because it matters: it is an opt-out, not an opt-in. Contribution is permitted unless you switch it off. Switching it off prevents future contribution; it does not delete anything already contributed, and you should email us if you want that. Discover carries a separate control for contributing salary information, which works the same way.
If anything is contributed, we remove your name, email address, phone number, LinkedIn and portfolio URLs, your street address, and employer and school names, including inside the free text of your bullets. Job titles, employment dates and the wording of your bullets remain, because they are what is being measured, so treat this as strong pseudonymisation rather than true anonymity.
Aggregates shown in the product are suppressed unless the group behind them is large enough that no single resume can be picked out of it.
Nothing in this pool is sent to an AI provider for training, by us or by anyone else.
7. The free scan without an account
The free resume check on our homepage does not need an account. When you use it, we store your email address, the extracted text of the resume you scanned and the structured version of it that our parser produces, the file’s name, your ATS score and its breakdown, and your IP address, which is kept here to detect abuse of a free unauthenticated endpoint.
The scan also records how you arrived, the same four short values a sign-up records: a source category such as a search engine, the first page of your visit with any id in its address replaced by a placeholder, a two-letter country, and whether the device is a phone, tablet, desktop, or automated traffic. The country comes from a header set at the edge, not from a lookup on your IP address, and your browser’s user agent string is not stored.
We use it to:
- Email you the score and the top issues straight away.
- Send you a small number of follow-up emails about SupaCV, with one-click unsubscribe on every one.
- Recognise you if you create an account with the same address within 30 days. Once you have confirmed that address, the resume you scanned becomes the first resume in your account, so you are not asked to upload it again. It counts as one analysis on your plan.
- Recognise, in our own records, that an account began with a free scan, if you later create one with the same address. This tells us how people find SupaCV. Unlike the handoff above, it is not limited to 30 days: it applies for as long as we hold the scan.
This is the only place SupaCV holds a resume without an account behind it, and it is the most sensitive row in our database: an email address, a full resume, and an IP address together. A daily job deletes these records once they are 24 months old. If you go on to create an account, deleting that account deletes the scan too. Either way you can have yours removed sooner by emailing privacy@supacv.com from the address you used. We never sell your email address.
We also keep a record that the score email was sent and whether it went out. It holds no email address, is linked to the scan, and is deleted with the scan or after 90 days, whichever comes first. If a free scan is refused or cannot be read, we count it with a category for why, the same source, country and device type, and nothing that identifies you.
8. Who else receives your data
The full list, with what each vendor receives and where it processes it, is on the sub-processors page. In summary:
| Provider | What it does |
|---|---|
| Supabase | Database and authentication |
| Vercel | Application hosting, content delivery, and visitor counting |
| Anthropic | AI features (Claude) |
| Stripe | Payment processing and subscription billing |
| Upstash | Rate limiting |
| Resend | Transactional email |
| Mailrelay | Transactional and follow-up email |
| Microsoft Clarity | Session replay and heatmaps (only after you accept cookies) |
| Ahrefs Analytics | Aggregate traffic measurement |
| Cloudflare | Bot protection (Turnstile) |
| Zoho Cliq | Internal error alerting |
| logo.dev | Company logos next to job listings |
| Voyage AI | Text embeddings for keyword analysis (not currently receiving data) |
Beyond those, we may share personal information:
- With professional advisers, accountants, insurers, or auditors, where reasonably necessary.
- Where the law, legal process, or a valid authority request requires it, or to protect rights, safety, and security.
- With a successor in a merger, acquisition, financing, reorganisation, or sale of assets, subject to this policy.
9. Analytics and tracking
SupaCV runs four measurement tools, and only one of them needs your consent. The Cookie and Tracking Policy lists every cookie and storage key individually and lets you change your choice.
- Our own product analytics. First-party, stored in our own database, nothing leaves it. These run whether or not you accept cookies, and the cookie choice does not change them. While you are signed in, what you do in SupaCV is recorded against your account, so that we can support you and see where the product fails; we rely on legitimate interests for this (section 4), not on consent. Page views are never tied to an account (a day-active record holds a date, not a page), and nothing can be tied to one before you sign in, with one exception: the sign-up record. How you first arrived (source category and landing page) is remembered in your browser for the visit and, if you sign up, written once against the new account, whatever you chose about cookies.
- Vercel Web Analytics. Counts visitors. Sets no cookies, stores nothing on your device, and uses an identifier discarded within 24 hours. Query strings are stripped to a marketing-parameter allowlist before the measurement leaves your browser, so links that carry an email address never reach it.
- Ahrefs Web Analytics. Aggregate traffic measurement. Cookieless, and it sets no identifier on your device. It loads on every page, including signed-in ones, and receives the page URL.
- Microsoft Clarity. Records sessions, including mouse movement, clicks, and typed input, and produces heatmaps. This one is consent-gated: the script does not load at all until you accept, so declining means Microsoft receives nothing.
Resume content and job descriptions are never sent to any analytics system. Two caveats we would rather state than have you discover: our own product analytics and the two cookieless tools run on signed-in pages as well as marketing pages, so a page path such as a Target Role URL is measured, and where a link carries an email address in its query string, the cookieless tools may receive that URL.
We honour Global Privacy Control. If your browser sends the GPC signal we treat it as a standing instruction to decline: Microsoft Clarity does not load, no sessions are recorded, and you are not shown the consent banner at all. This applies wherever you are, not only where the law compels it. The signal is about sharing data with third parties, so it does not change our own product records described above, which we do not sell or share.
10. International transfers
Jaspin is based in the United States, and most of our providers process data there. If you are in the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred outside your country.
Where those transfers need a safeguard, we rely on the European Commission’s Standard Contractual Clauses together with the UK Addendum or IDTA, or on a recipient’s certification under an applicable adequacy framework. Ask us at privacy@supacv.com and we will tell you which applies to a given provider.
11. How long we keep things
| Data | Kept for |
|---|---|
| Account, Resumes, Analyses, Target Roles, Cover Letters, Interview Session answers, saved stories, ApplicationsDeleting your account removes all of it. Deleting a single Resume moves it to trash for 30 days first, so an accidental delete is recoverable, then a daily job removes it permanently. | Until you delete them, or your account |
| Uploaded PDF and DOCX filesThe file is parsed in memory during the upload request. Only the extracted text and structured data are saved. | Never stored |
| Free landing-page scans (email, Resume text, IP address, how you arrived, country, device type)Delete sooner by emailing us. This is the one place a Resume is stored without an account. | 24 months |
| Anonymous page-view recordsNever linked to an account, then deleted automatically by a daily job. | 90 days |
| Daily traffic totalsOnce a day the page-view records are added up: how many views each page had that day, split by source category, two-letter country and device type. The totals hold no time of day, no IP address and no account, and outlive the 90-day records they are built from. On a quiet day a total can be 1. Deleting your account does not change them, because nothing in them refers to you. | Kept indefinitely |
| Other product events (for example sign-up completed)Account deletion detaches these from you rather than deleting the row, so the aggregate funnel survives without naming anyone. Nothing deletes the detached rows afterwards, which is why the column says indefinitely rather than giving a date. | While the account exists, then indefinitely |
| First-time feature milestones and days activeThe first time you used each feature (for example your first export) and the calendar dates on which you opened the signed-in app. A date only, never which page or what time of day, and no IP address or device details. Tied to your account and deleted with it. | Retained while the account exists |
| Internal-account flagA yes or no our staff can set to mark a test or staff account so it is left out of our own statistics. Deleted with the account. | Retained while the account exists |
| Email sending records (which message we sent, when, and whether it went out; never the address or the content)Deleted automatically by a daily job. Records tied to your account are deleted with it, and the record of a free scan result email is deleted with the scan. | 90 days |
| Rate-limiting counters keyed to your IP addressExpires on its own. Never joined to your account or to any content. | 1 hour, or 24 hours for the free scan |
| Your resume in the benchmark poolThe benchmark pool is seeded from a public research dataset. No SupaCV user’s resume is added to it. | Never stored there |
| Prompts and responses held by AnthropicAnthropic’s own abuse-monitoring window, after which it is deleted. Anthropic does not train on API data by default. | Up to 30 days |
| AI usage and cost records (feature, model, token counts, cost, time taken, whether the call worked)Deleting your account removes the link to you and keeps the figures, so our record of what we spent stays true without naming anyone. Nothing deletes what is left afterwards, which is why the column says indefinitely rather than giving a date. What is left holds no content, no email address and no IP address. A free scan writes the same kind of record with no account or email on it at all. | While the account exists, then indefinitely |
| Billing records (plan, billing interval, amounts, currency, discounts, dates, subscription status, the cancellation reason you pick, and Stripe reference ids)Kept for tax, accounting, and audit purposes, and, for the cancellation reason, to understand why people leave. Deleting your account detaches these records from it rather than deleting them. They never held your name, email, address, or card, and never the free-text comment Stripe offers beside the cancellation reason. Stripe keeps its own copy under its own policy. | Up to 7 years |
| Staff audit log (which action was taken on an account, by whom, and when)Written when our staff act on an account, and once when you delete your own. That deletion entry holds your account id, your email address and your Stripe customer id, so that we can answer a later question about the deletion or a refund. Nothing removes these entries on a schedule, and this is the one record of yours that outlives your account while still naming you. | Kept indefinitely |
| Support session records (which account a copy was taken from, which staff member asked for it, when it started and ended, how it ended, and how many rows were copied)Written when our staff copy an account into a temporary internal workspace to look into a problem, and updated when that copy is deleted. Account ids, times and counts only: no name, no email address, no Resume content and no sign-in link. It is kept once the copy is gone, and kept when you delete your account, so our own record that the session happened stays true. Nothing removes these entries on a schedule, which is why the column says indefinitely rather than giving a date. | Kept indefinitely |
| Support and feedback correspondence | Up to 24 months after the issue is resolved |
| Server and security logsScrubbed of Resume content, emails, and tokens before they are written. | Up to 30 days |
| Records of our scheduled maintenance tasks (which task ran, when, how long it took, and counts of what it did)About our systems, not about you: no account, email address, IP address or content is recorded. Deleted automatically each day. | 180 days |
| Encrypted database backupsDeleted data can persist in a backup until the backup rotates out. | Up to 90 days |
We may keep information longer where the law requires it, to resolve a dispute, or to enforce our agreements.
12. Your rights
Depending on where you live, you may have the right to access your personal information, correct it, delete it, get a portable copy, restrict or object to certain processing, withdraw consent, and not be treated worse for exercising any of it.
How to exercise them
The fastest route is Settings: export and deletion are both self-service and immediate. Otherwise write to privacy@supacv.com. We may need to verify your identity first, and we will respond within the time the applicable law allows. An authorised agent may act for you where the law permits, subject to verification.
United States
If you live in California, Colorado, Connecticut, Virginia, Texas, or another state with a comprehensive privacy law, you may have rights to know, access, correct, delete, and port your personal information, and to opt out of sale, sharing, targeted advertising, and certain profiling. As set out above, we do not sell or share personal information for targeted advertising, and we do not profile you in a way that produces legal or similarly significant effects. If we turn down a request you may appeal by replying to our decision, and if we turn down the appeal you may complain to your state Attorney General.
European Economic Area, United Kingdom, and Switzerland
You have the rights of access, rectification, erasure, restriction, portability, and objection under the GDPR or UK GDPR, and you can withdraw consent at any time without affecting processing that already happened. You can also complain to your local supervisory authority, including the Information Commissioner’s Office in the UK.
Automated decisions
SupaCV scores and analyses your own materials to help you improve them. It makes no automated decision about you that produces legal or similarly significant effects. Decisions about your job applications are made by employers, not by SupaCV, and an ATS score from us has no bearing on any employer’s system.
13. Children
SupaCV is not for children. You must be at least 16 to use it, and we do not knowingly collect personal information from anyone younger. If you believe a child has given us personal information, write to privacy@supacv.com and we will delete it.
14. How we protect it
- In transit: TLS on every connection, with HTTP Strict Transport Security. There are no plain HTTP routes.
- At rest: AES-256 encryption on the database holding your data, and on backups.
- Access control: row-level security on the tables holding your resumes, analyses, Target Roles, Cover Letters, Interview Sessions and Applications, enforced by the database itself, so another account cannot read them even with a valid session.
- Staff access: authorised staff can view account records and activity to provide support and understand how the product is used. What they do to an account is written to a staff audit log, which is listed in section 11 because it outlives the account.
- Support copies of an account: to look into a problem with your account, staff with admin access can copy it into a temporary internal workspace: a separate account holding a copy of your Resumes, Target Roles and the rest, so we can reproduce the problem there rather than on your own account. Only one such copy can exist at a time. Your account name and email address, your payment details and your share links are not copied into it, and no email can be sent from it. Your Resumes are copied as you wrote them, so whatever you put in one is in the copy. It is kept out of the benchmark pool and out of our own usage statistics, and it is deleted when the session ends. It also expires two hours after it is made: after that the copy deletes itself the next time it is opened, and a daily cleanup job removes anything still left. Deleting your account deletes any copy taken from it, and opening and closing one is written to the staff audit log (section 11).
- Uploads: raw files are never persisted. There is no file storage bucket to breach.
- Exports: the PDF and DOCX render path is authorised by a signed token that expires in 60 seconds and is scoped to one document.
- Share links: a share link is an unguessable identifier with an expiry date, not a signed token. Anyone holding a live link can open the document it points to, which is the point of the feature. Treat it as public.
- Logs and alerts: scrubbed of content and identifiers before they are written or sent.
- Browser hardening: a Content Security Policy that restricts where a successful injection could send data, plus clickjacking and MIME-sniffing protections.
No system is completely secure. If a breach affecting your personal information requires notification, we will notify you and the relevant regulators as the law requires. To report a vulnerability, write to security@supacv.com; please give us a reasonable chance to fix it before disclosing it publicly.
15. Changes to this policy
We will post any updated version here with a new effective date, and give notice of material changes by email or in the product where the law requires it. We review this policy at least once a year.
16. Contact
Privacy questions and data requests: privacy@supacv.com
Security reports: security@supacv.com
Everything else: support@supacv.com
Jaspin LLC
30 N Gould St Ste N
Sheridan, WY 82801
United States
Other policies
- Terms of ServiceThe contract between you and Jaspin LLC covering accounts, subscriptions, your content, AI output, and dispute resolution.
- Cookie and Tracking PolicyThe cookies and storage keys SupaCV sets for sign-in, consent and measurement, what each one does, and how to change your choice at any time.
- Refund, Cancellation and Subscription PolicyHow billing, renewal, cancellation, trials, price changes, and refunds work on the Pro and Career plans.
- Acceptable Use PolicyWhat you may not do with SupaCV, including the line between tailoring a resume and falsifying one.
- Sub-processorsEvery third party that receives SupaCV data, what each one receives, and where it is processed.