CV Studio AI
Privacy Policy
Last updated: August 1, 2026. This Privacy Policy explains how CV Studio AI processes personal data when users create an account, upload a CV or job offer, generate a tailored CV, buy credits, contact support, subscribe to product emails, consent to optional analytics or use related features.
1. Controller
- Service operator: Dawid Przerwa
- Registered address: Dawid Przerwa ul. Modrzewskiego 4/26, 86-300 Grudziadz, Polska
- Registration/tax number: nie dotyczy
- Country: Polska
- Contact email: support@cvstudioai.com
The controller decides why and how personal data is processed in the service. Privacy, account deletion, data access and complaint requests can be sent to the contact email listed above.
2. Data Protection Officer
A Data Protection Officer has not been appointed unless the operator separately states otherwise. All privacy requests should be sent to the contact email.
3. Data categories
- Account data: email address, display/profile name, password hash, email verification status, login/session data, account role, credit balance, consent records and account settings.
- CV and profile data: name, contact details, photo, work experience, education, skills, languages, certificates, interests, GDPR clause, candidate profile fields and other content voluntarily added to a CV.
- Job-offer data: offer URL, employer/job description text, requirements, responsibilities, screenshots, files or pasted content used for matching.
- Generated content: generated CV text, selected template/style, ATS score, missing and matched keywords, analysis metadata and download/edit history within the service.
- Payment, credit and purchase-evidence data: selected credit package, Stripe Checkout/session identifiers, payment status, amount/currency, the version and wording of purchase confirmations, credit additions and credit usage history. The evidence table stores email, IP and user-agent values only as HMAC hashes; payment-card data is processed by Stripe and is not stored by the service.
- Support and communication data: contact form content, email address, topic, message, automatic replies and support history.
- Newsletter data: marketing-consent status and history, campaign delivery status, estimated opens, CTA clicks, unsubscribe status and timestamps. Open statistics may be inaccurate because email applications can block or automatically download images.
- Technical and security data: IP address, browser and device data, timestamps, request logs, rate-limit events, security events, cookies and local storage identifiers needed to operate the service.
- Optional analytics data: if the user consents, Google Analytics may receive page and event data such as page URL/path, approximate device/browser information, referrer/UTM parameters and interaction events. CV content, uploaded files, passwords and payment card data are not intentionally sent to Google Analytics.
4. Special categories of data
The service is not designed to request special-category data, such as health, biometric, political, religious or union-related information. A user should avoid adding such data unless it is necessary for the CV and the user has a lawful basis to provide it. If the user voluntarily includes such data in a CV or uploaded file, it may be processed only to generate, analyze or store the requested CV.
5. Purposes and legal bases
- Providing the service and account: creating and maintaining the account, verifying email, logging in, saving CV history, managing credits and generating CVs; legal basis: performance of a contract or steps requested before entering into a contract.
- AI-assisted CV generation: analyzing CVs and job offers, producing a tailored CV, ATS score and recommendations; legal basis: performance of the requested service and, where required, the user's explicit consent to AI/external-provider processing.
- Payments and accounting: processing credit purchases, payment confirmation, invoices/records and tax/accounting obligations; legal basis: contract performance and legal obligation.
- Support, complaints and disputes: answering requests, handling payment or credit problems and defending claims; legal basis: legitimate interest and legal obligations.
- Security and abuse prevention: rate limiting, session protection, fraud prevention, error diagnosis and admin access control; legal basis: legitimate interest and legal obligation where applicable.
- Marketing emails: product updates, guides or promotional messages only if the user gives optional consent; legal basis: consent, which can be withdrawn at any time in account settings or through the unsubscribe link in each message. Limited delivery, open and click events are used to assess campaign performance.
- Essential cookies and browser storage: login, session protection, optional "keep me signed in" session persistence, language preferences, payments and remembering cookie preferences; legal basis: contract performance and legitimate interest in secure service operation.
- Optional analytics: measuring page views and product interactions in Google Analytics to understand usage and improve the service; legal basis: consent, which can be given in the cookie banner and withdrawn at any time through "Cookie settings" in the footer. The service does not use advertising cookies or remarketing pixels.
6. AI processing and human control
CV Studio AI uses AI to support the user in drafting, rewriting and analyzing CV content. AI output may contain mistakes, omissions or wording that should be reviewed by the user before sending a CV to an employer. The service does not make recruitment decisions, does not represent an employer and does not guarantee an interview or employment.
CV content, candidate profile data, job-offer text, uploaded files or extracted text may be sent to an AI model provider, including OpenAI, only for the purpose of generating, analyzing or improving the requested document.
The service does not request persistent storage of API responses. The AI provider may still process content in security and abuse-monitoring logs under its contractual terms; for the standard OpenAI API, those logs may currently be retained for up to 30 days unless an approved shorter-retention control applies.
7. Recipients and providers
- AI model providers used to generate or analyze CVs.
- Stripe or other payment providers used to process credit purchases.
- Email/SMTP providers used for email verification, password reset, support confirmations, service communication and consent-based newsletters.
- Google Analytics, only if the user consents to optional analytics cookies.
- Hosting, database, logging, security and infrastructure providers used to keep the service available and secure.
- Professional advisers, public authorities or courts if required by law or necessary to protect claims.
8. Transfers outside the EEA
Some providers, especially AI, payment, email, hosting or security providers, may process data outside the European Economic Area. Where this happens, the operator should rely on appropriate safeguards required by GDPR, such as adequacy decisions, Standard Contractual Clauses or other lawful transfer mechanisms.
9. Retention
- Generated CVs saved in the app are stored for up to 7 days and then automatically deleted.
- Raw uploaded files and raw input text are used for generation/extraction and are not intended to be permanently stored as CV history.
- Pseudonymized HMAC values used to protect the contact form from abuse are retained for no more than 48 hours. The anti-spam table does not store the plain email address or IP address.
- Account data, profile data, consent logs and saved settings are stored while the account exists or until deletion, unless longer retention is required by law or claim protection.
- Payment, accounting and purchase-evidence records are stored for mandatory retention periods and relevant limitation periods. After account deletion, necessary evidence is retained without an active account link where required.
- Security logs may be stored as long as needed to protect the service, investigate incidents and defend claims.
- Support correspondence is stored for the time needed to handle the request and possible claims.
- Newsletter recipient-level delivery and engagement records are retained for up to 730 days and are then anonymized. Withdrawing consent stops future marketing messages immediately but does not erase the historical fact that a campaign was sent.
- Google Analytics data is stored according to the retention settings configured in Google Analytics and Google's own service terms. Withdrawing analytics consent stops future collection from this browser unless consent is granted again.
10. Account deletion
The user may delete the account from the account panel. Account deletion removes the active account, candidate profile, saved CVs, reset tokens, email verification codes and consent records assigned to the account. Newsletter recipient records are anonymized. Necessary payment, accounting and pseudonymized purchase-evidence records may be retained without an active account link where required by law or claim protection.
11. User rights
Subject to GDPR conditions, the user has the right to access data, obtain a copy, rectify data, erase data, restrict processing, object to processing based on legitimate interest, receive data portability and withdraw consent at any time where processing is based on consent. Withdrawal of consent does not affect processing performed before withdrawal.
12. Complaint to supervisory authority
The user may lodge a complaint with a supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).
13. Voluntary data provision
Providing account and CV data is voluntary, but some data is necessary to create an account, buy credits, generate a CV, deliver a PDF, handle support or meet legal obligations. Without the required data, the service may not work or may work only in limited trial mode.
14. Automated decision-making
The service may automatically calculate ATS scores, keyword matches and recommendations. These results are advisory and do not produce legal effects for the user. The service does not make employment, credit, insurance or similarly significant decisions about the user.
15. Cookies and browser storage
The service uses essential cookies and browser storage to keep users logged in, protect sessions, support optional "keep me signed in", remember the selected language, support payments and remember cookie preferences. Optional Google Analytics is disabled by default and is activated only after analytics consent. The service does not use advertising cookies, cross-site profiling or remarketing pixels.
Detailed information about each mechanism, its purpose and retention is available in the Cookie Policy. Blocking essential mechanisms may prevent login, payments or account features from working correctly.
16. Security
The service uses technical and organizational measures such as password hashing, session protection, request limits, upload limits, role-based admin access, input validation and limited retention. No online service can guarantee absolute security, so the user should keep account credentials confidential and immediately report suspected unauthorized access.
17. Changes
This Privacy Policy may be updated when the service, providers, legal requirements or processing operations change. The current version is always available on this page. Material changes affecting registered users may be communicated through the service or by email where appropriate.