CV Studio AI
Cookie Policy
Last updated: July 29, 2026. This policy explains which cookies and browser-storage mechanisms are used by CV Studio AI, why they are needed and how the user can manage them.
The service uses essential mechanisms for login, security, language preferences and payments. Google Analytics is activated only after the user consents to optional analytics. The service does not use advertising cookies, cross-site profiling or remarketing pixels.
1. Operator and contact
- Service operator: Dawid Przerwa
- Registered address: Dawid Przerwa ul. Modrzewskiego 4/26, 86-300 Grudziadz, Polska
- Registration/tax number: nie dotyczy
- Country: Polska
- Contact email: support@cvstudioai.com
2. What cookies and browser storage are
Cookies are small pieces of information stored by a website in the browser. Local storage is a similar browser mechanism used to remember settings. This policy covers both technologies.
3. Mechanisms currently used
| Mechanism | Purpose | Storage period |
|---|---|---|
| Flask session cookie | Keeps the user logged in, protects the account session and supports security-sensitive operations. It may also remember limited anonymous trial state. | Session cookie by default; if the user selects "Keep me signed in", it may be retained for up to 30 days. |
| cvstudioai_ui_language_v1 localStorage | Remembers the interface language selected by the user. | Until the user changes the preference or clears browser storage. |
| cvstudioai_cookie_preferences_v1 localStorage | Remembers the user's cookie choice, including whether optional analytics is allowed. | Until browser storage is cleared or the preference version changes. |
| cvstudioai_cookie_notice_v1 localStorage | Legacy acknowledgement of the previous essential-cookie notice. It may be removed automatically when the new preference mechanism is used. | Until browser storage is cleared or the app removes it. |
| _ga, _ga_* Google Analytics cookies | Used only after analytics consent to measure page views and product interactions in aggregated reports. | Set and retained according to Google Analytics configuration and Google's service terms. |
4. Internal technical events
The service may record limited application events on the server for security, error diagnosis and product reliability. The browser does not store a persistent analytics identifier for this purpose, and these events are not used for advertising or cross-site profiling.
Consent-based newsletters may contain an individual unsubscribe link, a tracked CTA link and a one-pixel image used to estimate opens. These mechanisms do not set advertising cookies in the browser. Open statistics are approximate because email applications may block or automatically fetch images.
5. External services
If the user starts Stripe Checkout or chooses an external login provider, the user is redirected to that provider's environment. Stripe, Google or Apple may use their own cookies under their respective policies. These mechanisms are not activated by CV Studio AI before the user starts the relevant payment or login flow.
6. Consent choices
Essential mechanisms are required to provide the service securely and cannot be disabled from the service interface. Optional Google Analytics is disabled by default and starts only after the user chooses the analytics option in the cookie banner. The user can withdraw or change analytics consent at any time through "Cookie settings" in the footer, as easily as consent was given.
7. Managing browser storage
The user can delete or block cookies and local storage in browser settings. Blocking the session cookie may prevent login, account security, trial state or payment-related functions from working. Deleting the language or cookie preference resets those settings and may show the banner again.
8. Privacy and changes
Information about personal-data processing, recipients, retention and user rights is available in the Privacy Policy. If advertising, remarketing or additional optional tracking tools are introduced in the future, this policy and the interface must be updated before those tools are enabled, including a valid consent mechanism where required.