Privacy Policy
Last updated: July 2026
This is a draft. Please review with a lawyer before going live.
1. What we collect
- Account info: email, name, password hash (handled by Supabase Auth).
- Resumes: file content + parsed structured data, stored in your account.
- Job-related data: target roles, applications, interview sessions, cover letters you generate.
- Interview practice: interview questions, the answers you write during Interview Prep, and the AI feedback on them.
- Story Bank: the STAR-format stories you save from interview practice or write directly, including any tags you add.
- Preferences: location, salary expectations, target industries, email opt-ins.
- Usage data: when you sign in, what features you use, and errors you encounter. We collect this ourselves and store it in our own database. The one exception is Microsoft Clarity, which records how you use the site (mouse movement, clicks, typed input) and only loads if you accept cookies.
- Payment data: handled by Stripe. We never see card numbers. We store only Stripe customer + subscription IDs.
2. How we use it
- To run the product (analyse resumes, send transactional emails, etc.)
- To improve the product (anonymised performance + feature analytics)
- To recommend roles based on your resume + preferences
- To process payments (via Stripe)
- To send transactional emails (welcome, password reset, payment receipts) and opt-in emails (weekly digest, follow-up reminders)
3. Anonymised benchmarks
With your explicit opt-in (via Settings → Recommended Roles preferences and Settings → Peer Benchmarking), we may use anonymised versions of your resume + compensation data to compute aggregated medians (e.g. “median Senior Engineer salary in London”). We strip name, email, phone, and company names before contributing. You can opt out at any time.
4. Anonymous landing-page scans
When you use the free ATS scan on our homepage without an account, we collect your email address and a copy of your resume text. We use it to: (1) send you your ATS score and top issues via email immediately after the scan, and (2) contribute anonymised score data to our benchmark corpus. We may also send you one follow-up email about SupaCV. You can unsubscribe with one click from any email. We never sell your email address.
5. Sub-processors
- Supabase: auth + database hosting
- Vercel: application hosting
- Stripe: payment processing
- Anthropic: AI features (resume tailoring, cover letters, interview questions and feedback). Scoring an interview answer sends that answer's text, together with relevant bullets from your resume, to Anthropic.
- Resend: transactional email
- Microsoft Clarity: session recording and heatmaps. Loads only after you accept cookies; declining means it never runs.
- Zoho Cliq: receives our internal error alerts (error type and message only, never resume content or personal data)
- Cloudflare: CDN + bot protection
6. Cookies
We use cookies for sign-in (keeping your session active) and a small consent preference stored in your browser. Our own product analytics run either way, but declining keeps them anonymous: the event is recorded with no account attached. Microsoft Clarity sets its own cookies and only loads if you accept. We set no advertising cookies.
7. Data retention + deletion
You can export all your data at any time from Settings → Export your data, and delete your account from Settings → Danger Zone. Deletion removes all your data within 30 days (deleted resumes are kept for 30 days in case of accidental deletion, then permanently removed).
8. Your rights
Depending on your jurisdiction (GDPR, CCPA, etc.) you may have rights to access, correct, port, or delete your data. Email privacy@supacv.com for any data request.
9. Contact
Questions about this policy: privacy@supacv.com.