Privacy and your data
Updated October 5, 2026
Controller and contact
Oleksii Ktitarov, Linzer Straße 17, 4100 Ottensheim, Austria, is the controller. Email: support@changemycv.com. Postal contact and registration details are in the imprint.
Data and purposes
We process your account name, email, password hash, sign-in identifiers, subscription and usage information to provide your account and purchased service (contract, GDPR Article 6(1)(b)). Saved documents contain the text, editable sections, revision history and original uploaded files you choose to save. We do not sell resume content or use it for advertising targeting.
Security checks process request information and keyed hashes of IP addresses to limit abuse; generation locks and spending counters protect availability (legitimate interests, Article 6(1)(f)). Required billing and tax records may be retained to meet legal obligations (Article 6(1)(c)). Account data is necessary to provide an account; AI generation requires the experience you choose to submit.
Providers and AI
Vercel hosts the application. Google Cloud Firestore stores accounts and saved documents in the United States. Google and Firebase Authentication handle optional Google sign-in; we receive a verified email, display name and account identifier, without access to Gmail or Drive. Groq receives your submitted resume/notes and job details for AI generation. Whop runs checkout, payment details and subscriptions as an independent controller under its own privacy policy; we retain identifiers, status and credit receipts, not full card details. Whop Ads runs our advertising on Meta; its pixel loads only with your separate consent, described below. Resend sends password recovery emails from its EU region. GitHub stores our encrypted daily database backups for 30 days; it cannot read them.
Several providers are based in the United States, so your data may be processed there. Vercel, Google, PostHog, Resend, GitHub and Meta are certified under the EU-U.S. Data Privacy Framework, which the European Commission recognises as providing adequate protection (Article 45 GDPR). Groq is bound by its data processing addendum, which incorporates the EU standard contractual clauses (Article 46 GDPR). PostHog keeps our analytics in its EU region. Whop and Meta decide themselves how they transfer the data they process as controllers. You can request a copy of the safeguards that apply to your data through the contact in the imprint.
Retention
Saved resumes and letters remain until you delete them or request account deletion. Deleting a saved document removes its active stored content and file chunks. Temporary generation uploads are removed after the request finishes. Password reset links expire after 30 minutes and are single-use. Expired reset hashes are cleared by daily maintenance; expired request-limit records are removed by the same job. Generation safety records are kept for up to 90 days. Deletion jobs are bounded and may require extra runs to clear a backlog.
Optional analytics aggregates and one-way conversion markers are kept for up to 400 days; daily visitor markers for up to 2 days. A local privacy choice remains until you change it or clear browser storage. Encrypted database backups are taken daily and kept for 30 days, so deleted data disappears from backups within 30 days. Legally required billing records and records needed for disputes may be retained beyond account deletion, limited to what is necessary.
Optional analytics
Analytics starts only when you turn on “Product analytics” under “Choose” and save your choices, or select “Allow”. Refusing does not affect the service. You can change your choice using “Privacy choices” in the footer. We count visits, registrations, selected document flows, first successful documents, browser-reported exports, checkout starts and provider-confirmed paid transactions. We keep aggregate counts by day, advertising channel and campaign target market (US, Canada, UK, Australia or other); the market is a campaign label, not a precise location.
PostHog Cloud EU receives explicit analytics events from our server. A random identifier in session storage and a keyed pseudonymous account identifier connect events into conversion funnels. These identifiers are personal data even though your name and email are not sent. Session recording, automatic click capture and geolocation enrichment are disabled. Existing users are asked again before this provider is enabled. First-party one-way markers prevent repeated counts. We do not store your document text, email, raw IP, complete page URL or arbitrary campaign text in analytics. The legal basis is consent (Article 6(1)(a)); withdrawing consent stops new collection from that browser. Our first-party historical aggregates cannot be linked back to you; linked PostHog events can be addressed through a verified data-rights request. PostHog project retention follows the configured provider plan; currently the free plan provides one year of retention. Provider-confirmed attribution reflects consent given when that checkout was started; withdrawing browser consent does not automatically remove already-recorded checkout attribution.
Optional ad measurement
We advertise ChangeMyCV through Whop Ads, which runs campaigns on Meta (Facebook and Instagram). If you turn on “Ad measurement” under “Choose” or select “Allow”, our pages load the Whop pixel from t.whop.tw. It records page views and, after you create an account, a “registration completed” event, so Whop and Meta can see which ads lead to sign-ups and optimise ad delivery. We do not pass your name, email, phone number or document content to the pixel. Like any script loaded from another server, it receives technical data such as your IP address, browser details and the page address, including advertising click identifiers, and Whop may set its own identifiers in your browser. Whop and Meta process this data under their own privacy policies and may transfer it outside the EEA. The legal basis is consent (Article 6(1)(a)). Ad measurement is separate from product analytics: refusing it does not affect the service, and withdrawing it under “Privacy choices” stops the pixel from loading. Purchases made through Whop checkout are recorded by Whop as our payment provider in any case.
Your rights
You may request access, correction, erasure, restriction, portability and object to processing based on legitimate interests. You may withdraw optional consent at any time. We normally respond within one month, subject to legally permitted extensions. Use the operator contact in the imprint; identity verification may be needed to protect your account. You may complain to the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna) or your local supervisory authority. We do not make automated employment eligibility decisions.
Browser storage
Your sign-in token and account display details are stored in local storage to maintain your session. Signing out clears them. Optional analytics and ad measurement use the separate choices and session storage described above. The Whop advertising pixel, and any identifiers it sets, load only if you allow ad measurement; they are never required to use ChangeMyCV.