Privacy & Cookies
The short version
- Your Fact Bank, resumes, job descriptions, pipeline and API keys are saved in your browser, not on our servers.
- We store your account (from Google or GitHub), your plan and monthly usage counts.
- Text you send to an AI feature passes through our server to the AI provider and is not stored or used to train models by us.
- We use only the cookies needed to keep you signed in. No advertising, analytics or cross-site tracking.
- We do not sell or share your personal information for advertising.
Stored in your browser, not by us
The app saves your work in your browser's local storage on the device you use. We cannot see it unless you send it in a request, it does not sync between devices, and clearing your browser data deletes it. Export your Fact Bank from the app if you want a backup.
What we store about you
- Account: your name, email address and profile picture from Google or GitHub, the provider account id, and the sign-in tokens the provider issues.
- Sessions: a session record with the IP address and browser type it was created from, used to keep you signed in and to detect misuse.
- Subscription: plan, status, billing interval, renewal dates and Lemon Squeezy customer and subscription ids (never card details).
- Usage: monthly counts of resume generations and AI credits used, and how much of the one-time built-in AI trial you have used.
- Without an account: a random id from the guest cookie and how many tailored resumes were made with it, so the no-account allowance works.
- Billing events: the id, type and time of each payment notification, for accounting and to avoid processing one twice.
Content you process
When you use an AI feature, the text needed for that request (for example your Fact Bank and a job description) passes through our server to the AI provider: the one you chose with your own key, or OpenRouter for built-in AI on Pro. If you use your own key, it travels with the request so we can call the provider, and it is not stored on our servers. We do not store this content or use it to train models. The AI provider processes it under its own terms, and some free AI tiers allow the provider to use prompts to improve its models, so check your provider's terms.
When you import a job posting from a link, our server fetches that page. Document parsing (PDF, DOCX) and PDF, DOCX and LaTeX exports happen in your browser.
Service providers
- Cloudflare: hosting, database, security and short-lived request logs used for reliability and abuse prevention.
- Lemon Squeezy: payments, tax and receipts as merchant of record.
- Google and GitHub: sign-in.
- OpenRouter and the AI provider you select: processing AI requests.
- jsDelivr: when a resume contains Chinese, Japanese or Korean text, your browser downloads the matching open-source font from this CDN to build the PDF.
- GitHub API: if you use the GitHub project import, your browser requests your public repositories from GitHub directly.
These providers may process data outside your country. Where the law requires it, transfers rely on safeguards such as the EU Standard Contractual Clauses that these providers offer.
Cookies and local storage
StructuredCV uses only strictly necessary cookies, so there is no cookie banner. Signing out removes the session cookies.
| Cookie | Purpose | Lasts |
|---|---|---|
| Session token | Keeps you signed in. HttpOnly, set by our sign-in system. | Up to 30 days |
| Session cache | A signed copy of your session so pages load without a database lookup. | 5 minutes |
| Sign-in state | Protects the Google or GitHub sign-in handshake against forgery. | Minutes, during sign-in |
| Guest allowance | A random id that counts tailored resumes made without an account. We store only the id and the count. | 1 year |
The app also uses your browser's local storage, which is never sent to us automatically:
- Fact Bank and resumes: Your experience, generated resumes, the current job description and application history.
- Pipeline and tools: Your application board, outreach queue, visa tracker and other tool data.
- Settings: Your AI provider choice and API key, theme and preferences.
The Lemon Squeezy checkout and customer portal open on Lemon Squeezy's own site and use its cookies under its privacy policy.
The browser extension
The StructuredCV extension reads job postings on pages you visit (or that you ask it to read), keeps its settings in your browser, and hands job descriptions to the app through the page address, which is never sent to a server. It fills contact fields from your Fact Bank only when you ask, and never submits forms.
Why we process your data
We process account, subscription and usage data to provide the service you signed up for (performing our contract with you), and session and log data for security and abuse prevention (our legitimate interest in keeping the service safe). We keep billing records because tax law requires it.
Retention and deletion
We keep account data while your account exists. Sessions expire after 30 days without use. Delete your account anytime from the Account page: it removes your account, sessions, subscription record and usage history, and cancels an active subscription. Payment records held by Lemon Squeezy are retained as tax law requires.
Your rights
Depending on where you live (for example under the GDPR, UK GDPR or CCPA) you can ask to access, correct, export or delete your data, or object to its processing. Most of your data is already in your browser, where you can view, export and delete it yourself. For anything else, email support@structuredcv.com. We respond within 30 days, and you can also complain to your local data protection authority.
Security
Connections are encrypted with HTTPS, payment webhooks are signature-checked, and we follow the practices described on our Legal & Trust page. Report security issues to the address there.
Children
StructuredCV is not intended for children under 16, and we do not knowingly collect their data.
Changes and contact
We will post changes here and update the date above, and tell signed-in users about material changes. The data controller is Ayoub Zulfiqar. Contact: support@structuredcv.com.