Privacy Policy

Last updated: September 4, 2025

AI-Powered Resume Builder
LinkedIn Integration
Secure & Compliant
Introduction

Welcome to CVilo ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered resume builder platform.

By using CVilo, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.

Information We Collect

Personal Information

  • Account Information: Name, email address, phone number, and password when you create an account
  • Profile Information: Professional summary, education, work experience, skills, languages, and location
  • LinkedIn Data: When you connect your LinkedIn account, we may access your public profile information including name, email, and professional details
  • Resume Content: All resume data you create, edit, or generate using our AI features

AI Interaction Data

  • AI Prompts: All text prompts you provide to our AI resume generation service
  • AI Responses: Generated resume content and modifications made by our AI
  • Chat History: Complete conversation history with our AI for context-aware resume updates
  • Usage Patterns: How you interact with AI features, templates, and themes

Technical Information

  • Device Information: Browser type, operating system, and device identifiers
  • Usage Analytics: Pages visited, features used, and time spent on the platform
  • Log Data: IP addresses, access times, and error logs for security and performance
  • Cookies: Authentication tokens and session data stored in your browser
How We Use Your Information

Core Services

  • Account Management: Creating and maintaining your user account
  • Resume Creation: Generating, editing, and storing your resumes
  • AI Processing: Using your prompts and data to generate professional resume content
  • PDF Generation: Converting your resumes to downloadable PDF format

AI and Machine Learning

  • Resume Generation: Processing your prompts through OpenAI GPT-4 or GitHub Models to create professional resumes
  • Context Awareness: Using chat history to maintain consistency across resume updates
  • Template Optimization: Improving resume templates and themes based on usage patterns
  • Quality Enhancement: Training and improving our AI models to provide better resume suggestions

Service Improvement

  • Performance Monitoring: Analyzing usage patterns to improve platform performance
  • Feature Development: Understanding user needs to develop new features
  • Bug Fixes: Identifying and resolving technical issues
  • Security: Detecting and preventing fraudulent or malicious activities
AI Services and Third-Party Providers

OpenAI Integration

We use OpenAI's GPT-4 model to generate and enhance your resumes. When you use our AI features:

  • Your prompts and resume data are sent to OpenAI for processing
  • OpenAI's privacy policy applies to data processed by their services
  • We do not share your personal information with OpenAI beyond what's necessary for resume generation
  • OpenAI may retain data for model improvement, subject to their privacy policy

GitHub Models (Alternative AI Provider)

We may also use GitHub Models as an alternative AI provider for resume generation:

  • GitHub Models processes your prompts using their GPT-4o model
  • Data processing is subject to GitHub's privacy policy
  • We may switch between AI providers for optimal performance

LinkedIn Integration

When you connect your LinkedIn account, we access:

  • Your public profile information (name, email, location)
  • Professional summary and basic profile data
  • LinkedIn profile URL for resume inclusion
  • This data is used to pre-populate your resume information

PDF Generation Service

Our PDF generation service uses Chrome DevTools Protocol to create high-quality PDFs:

  • Your resume data is processed locally on our servers
  • No third-party services are involved in PDF generation
  • PDFs are generated with A4 formatting and professional styling
Data Storage and Security

Data Storage

  • PostgreSQL Database: All user data, resumes, and chat history are stored in a secure PostgreSQL database
  • Local Storage: Authentication tokens are stored in your browser's localStorage
  • Encryption: All data is encrypted in transit using HTTPS and at rest
  • Backup: Regular automated backups ensure data safety and recovery

Security Measures

  • JWT Authentication: Secure token-based authentication with automatic refresh
  • Password Hashing: All passwords are hashed using bcrypt before storage
  • Rate Limiting: API endpoints are protected against abuse and attacks
  • Security Headers: Comprehensive security headers prevent common web vulnerabilities
  • Input Validation: All user inputs are validated and sanitized

Data Retention

  • Account Data: Retained until you delete your account or request deletion
  • Resume Data: Stored indefinitely unless you delete specific resumes
  • Chat History: Retained for context-aware AI interactions, can be deleted by user
  • Log Data: Retained for 30 days for security and debugging purposes
Your Rights and Choices

Access and Control

  • View Your Data: Access all your personal information and resumes through your account
  • Edit Information: Update your profile, resume content, and account settings at any time
  • Delete Data: Remove specific resumes, chat history, or your entire account
  • Export Data: Download your resumes in PDF format or request data export

AI and Privacy Controls

  • Chat History Management: View, search, and delete your AI conversation history
  • Prompt Privacy: Choose what information to include in AI prompts
  • Context Control: Clear chat history to remove context from future AI interactions
  • Provider Selection: We may offer choice between AI providers in the future

Communication Preferences

  • Email Notifications: Control account-related email communications
  • Marketing Communications: Opt in or out of promotional emails
  • Service Updates: Receive important service announcements and updates
Data Sharing and Disclosure

We Do Not Sell Your Data

CVilo does not sell, rent, or trade your personal information to third parties for marketing purposes.

Limited Sharing

We may share your information only in these limited circumstances:

  • AI Service Providers: OpenAI and GitHub Models for resume generation (as described above)
  • LinkedIn: When you choose to connect your LinkedIn account
  • Legal Requirements: When required by law or to protect our rights and safety
  • Service Providers: Trusted third-party services for hosting, analytics, and support

Aggregated Data

We may share anonymized, aggregated data for analytics and service improvement. This data cannot be used to identify individual users.

International Data Transfers

Your data may be processed in countries other than your own, including the United States where our AI service providers are located. We ensure appropriate safeguards are in place to protect your data during international transfers.

By using CVilo, you consent to the transfer of your information to countries outside your residence, including the United States.

Children's Privacy

CVilo is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@cvilo.com

Support: support@cvilo.com

Website: https://cvilo.com

We will respond to your inquiry within 30 days of receipt.

This Privacy Policy is effective as of the date listed above and applies to all users of the CVilo platform.