Introduction & Scope
This policy applies when you:
- Visit, register for, or use claricv.com;
- Upload CV or personal information into any feature;
- Use any AI-powered feature (JD matching, CV rewriting, ATS scoring, bullet enhancement);
- Communicate with us.
Legal bases for processing: contract performance β to provide the Service you registered for; legitimate interests β to maintain platform security, prevent abuse, fix bugs, and improve reliability; legal obligation β where required by law; consent β sought explicitly and separately where we rely on it. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
Data Controller
ClariCV is an independently operated platform. For all legal and privacy enquiries: admin@claricv.com.
For data transmitted to any Third-Party AI Provider or infrastructure provider (Supabase, Vercel), those parties act as independent data controllers or processors under their own terms.
EU/EEA Representation
ClariCV's processing of EU/EEA user data is currently limited in scale and does not involve systematic monitoring of individuals. On this basis, ClariCV relies on the GDPR Article 27 exemption for organisations whose processing is occasional and unlikely to involve high risk to data subjects. ClariCV will appoint an EU-based representative and notify EU/EEA users if the volume or nature of EU processing changes such that this exemption no longer applies.
Information We Collect
3.1 Account Information
- Email address β authentication and account management;
- Name β if provided during sign-up or via Google OAuth;
- Profile picture URL β if you sign in via Google OAuth;
- Authentication tokens β session tokens managed by Supabase.
3.2 CV & Professional Content
- CV content you enter into the CV Builder;
- CV documents you upload for ATS checking or parsing;
- Job descriptions you paste into the JD Matcher;
- AI-generated outputs produced during your session;
- Job applications and tracking data you enter into the Job Tracker.
3.3 Usage & Technical Data
- IP address and approximate geographic location;
- Browser type and version, operating system;
- Pages visited, features used, and time spent on the platform;
- Error logs and diagnostic information;
- Session and authentication cookies β see claricv.com/cookies for full details.
How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Provide and operate the Service | Contract performance |
| Authentication and account security | Contract / Legitimate interest |
| AI feature processing (CV rewrite, JD match, ATS scoring) | Contract performance |
| Improve platform reliability | Legitimate interest |
| Respond to support requests | Legitimate interest |
| Enforce our Terms of Service | Legal obligation / Legitimate interest |
| Send critical service notifications | Contract / Legal obligation |
Third-Party AI Providers & Data Transmission
Data handling commitments:
- ClariCV will only transmit your data to a provider where a lawful EU/EEA data transfer mechanism is confirmed in place;
- ClariCV maintains a provider processing log with a 90-day lookback window. For requests within that window, email admin@claricv.com with the approximate date and feature used β we will identify the provider where the request can be matched to our metadata logs, and aim to respond within 14 days;
- For erasure requests, ClariCV will (a) delete the data from our own systems within 30 days, and (b) provide you with the contact details and privacy policy link for each provider that received your data so you can direct an erasure request to them directly;
- ClariCV does not share your data with any provider for any purpose other than generating the AI output you requested;
- ClariCV does not use your CV data for our own AI model training.
To request provider identification or object to processing by a specific provider, contact admin@claricv.com.
Infrastructure & Service Providers
ClariCV currently stores primary application data in [PLACEHOLDER: insert actual Supabase region, e.g. ap-southeast-1]. If this region is outside the EEA, ClariCV relies on the transfer mechanisms described in Β§11. Supabase is SOC 2 Type II certified.
Hosts the ClariCV web application and processes server-side requests using a global edge network, with function execution in the region nearest to the requesting user. Vercel may collect server access logs including IP addresses.
Payment Processing
If you purchase a Pro Tier subscription, payment details are processed by our third-party payment provider (currently PayPal). ClariCV does not directly store, process, or have access to your full card number or payment credentials. We may receive limited billing information from the payment provider, including:
- Payment status (successful, failed, cancelled);
- Plan type and billing period;
- Transaction ID and invoice history;
- Billing email address;
- Renewal and cancellation status.
This information is used solely to manage your subscription and respond to billing enquiries. For full details on how your payment data is handled, see the PayPal Privacy Statement.
Data Retention
Anonymous users (no account)
- CV uploads, pasted CV text, job descriptions, and AI-generated results from anonymous free checks are deleted within 24 hours of processing;
- No account-level data is created for anonymous checks.
Logged-in users (account holders)
- Saved CVs and documents β retained until you delete them or close your account;
- Saved AI outputs β retained until you delete them or close your account;
- Job tracker data β retained until you delete it or close your account;
- Account profile and authentication data β retained until you delete your account;
- Usage and diagnostic logs β 30β90 days for operational purposes;
- AI provider metadata logs (provider name, model, feature used, timestamp) β 90 days. No CV text is stored in these logs.
Free Tier inactive account purge
- Free Tier accounts inactive for 12 months will be purged. You will receive 30 days' advance email notice. You will have 14 days from that notice to export your data via account settings before purge proceeds.
Backup retention
- When data is deleted from ClariCV's active systems, it may persist in encrypted system backups for up to 90 days before permanent removal. During this period the data is not accessible for normal operations.
Your Rights & Choices
Where available in account settings, you can:
- Delete individual saved CVs and AI outputs;
- Export your saved CV data;
- Delete your account and all associated data.
Additional rights
Depending on your jurisdiction, you may also have rights to: access a copy of your data, correct inaccuracies, restrict certain processing, and object to processing based on legitimate interests. To exercise these rights, email admin@claricv.com. We will respond to valid requests within 30 days, unless a longer period is permitted by applicable law.
AI provider identification
ClariCV maintains provider metadata logs for 90 days (provider name, model, feature used, timestamp β no CV text). Where your account history shows provider information, you can view it directly. For requests within the 90-day window, email admin@claricv.com with the approximate date and feature used β we will identify the provider where the request can be matched to our metadata logs, and aim to respond within 14 days.
Data Security
We implement the following technical and organisational security measures:
- HTTPS/TLS encryption for all data in transit between your browser and ClariCV's servers.Note: this is transport-layer encryption β ClariCV's servers decrypt data to enable AI processing. It is not end-to-end encryption.
- Row-level security (RLS) policies in Supabase to isolate your data from other users' data at rest;
- Secure session token management via Supabase Auth;
- API keys stored as environment variables, never exposed client-side;
- Access controls restricting data to authenticated account holders.
Children's Privacy
ClariCV is not directed at individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe a minor has provided us with personal information, please contact admin@claricv.com and we will delete such information promptly.
International Data Transfers
Your personal data may be processed and stored in countries outside your own, including the United States, where Supabase, Vercel, and various AI providers operate infrastructure.
For EU/EEA users, ClariCV commits to the following:
- ClariCV will only transmit your personal data to a third country where a lawful transfer mechanism is in place: an EU adequacy decision, Standard Contractual Clauses (SCCs), binding corporate rules, or another GDPR Chapter V-compliant mechanism;
- ClariCV's internal provider register documents the transfer mechanism applicable to each provider, updated within 14 days of any change, and available on written request;
- Any new provider will have a confirmed transfer mechanism in place before any EU/EEA user data is transmitted to them;
- You may request confirmation of the applicable transfer mechanism for any specific provider by emailing admin@claricv.com.
- Supabase DPA β
- Vercel DPA β
- OpenAI DPA β
- Anthropic Privacy β
- Google GDPR β
- OpenRouter Privacy β
- Additional providers: contact admin@claricv.com within 90 days of any AI request for specific provider transfer documentation.
Cookies & Tracking Technologies
ClariCV uses a limited set of cookies for authentication and secure session management. We do not use advertising or cross-site tracking cookies.
For full details, see our Cookie Policy at claricv.com/cookies β
Changes to This Policy
For material changes to this Policy:
- We will provide 30 days' advance notice via email or prominent in-app notice;
- Where a material change requires consent as the legal basis, we will request that consent explicitly β continued use during the notice period will not be treated as consent;
- Non-material changes (clarifications, contact updates, formatting) will be noted by updating the βLast Updatedβ date without advance notice;
- The current version is always available at claricv.com/privacy.
Contact Us
- Legal and privacy enquiries: admin@claricv.com
- Platform: claricv.com
- Provider identification requests: email admin@claricv.com with the approximate date and feature used within 90 days of any AI request.
We aim to respond within 10 business days.
This document was last updated on May 11, 2026.
By continuing to use ClariCV, you acknowledge that you have read and understood this document.