← cvgraph

Privacy notice

Last updated 21 August 2026. This notice covers the cvgraph website (cvgraph.ai), the waitlist, and the cvgraph application (app.cvgraph.ai). It is written to meet Articles 12–14 of the GDPR: plain language, everything in one place.

1. Who we are

cvgraph is operated by Peritus slf., a company registered in Reykjavík, Iceland ("we") — the data controller for the personal data described here. We have not appointed a Data Protection Officer; our privacy lead is reachable at privacy@cvgraph.ai.

2. What data we collect, and how

Account data — email address and authentication details, collected when you sign up.

Career data — the skills, roles, occupations, courses, and related information you enter to build your graph. You control what goes in. If you use the AI-assisted import, your CV document itself is never uploaded to us: your own AI assistant produces a structured file, and only the entries you confirm are stored.

Waitlist data — the email address you confirmed via double opt-in, with the time of consent.

Billing data — held by Paddle, our merchant of record (see section 4); we receive subscription status only, never full payment details.

Technical data — short-lived IP-based rate-limiting keys, server logs, and error reports that are scrubbed of personal data before storage.

All of this comes directly from you or from your use of the service — we do not buy data about you or collect it from third parties.

3. Why we process it (purposes and legal bases)

PurposeData usedLegal basis
Providing your account and graphAccount data, career dataContract (Art. 6(1)(b))
AI features: exposure, JD-fit, AskCareer data you submit to the featureContract (Art. 6(1)(b))
Sharing graphs you choose to shareThe graph edition you shareContract (Art. 6(1)(b))
Waitlist and early-access emailsEmail address, consent recordConsent (Art. 6(1)(a))
Billing and subscription statusSubscription state (payments handled by Paddle)Contract (Art. 6(1)(b)); legal obligation for tax records
Security, abuse prevention, rate limitingIP address (short-lived), request metadataLegitimate interest (Art. 6(1)(f)): keeping the service safe
Error monitoringScrubbed technical error reportsLegitimate interest (Art. 6(1)(f)): service reliability
Aggregate analyticsPage views without identifiersLegitimate interest (Art. 6(1)(f)): understanding usage

We do not sell personal data, we do not use your career data to train AI models, and we do not build advertising profiles.

4. Who receives your data

Subprocessors — service providers processing data on our instructions:

ProviderRoleLocationTransfer safeguard
Vercel Inc.Hosting, CDN, aggregate analyticsUSA / EU edgeEU-U.S. Data Privacy Framework + SCCs
SupabaseApplication database (accounts, career graphs)EU regionSCCs with US parent where applicable
ResendTransactional and waitlist emailEU region (US company)SCCs
UpstashRate-limiting store (short-lived IP/email keys)EU/USSCCs / DPF
Functional Software, Inc. (Sentry)Error monitoring — reports scrubbed of personal data before storageEU/USDPF + SCCs
Anthropic, PBCAI model provider for Ask, JD-fit, and exposure featuresUSASCCs; API data not used for model training
OpenAI, LLCText-embedding API used by JD-fit to match job-description requirements against skillsUSASCCs / DPF; API data not used for model training
Cloudflare, Inc.DNS and inbound email routing for cvgraph.ai addressesUSA / globalDPF + SCCs

Independent controllers — Paddle.com Market Limited processes your payment and billing data as merchant of record under its own privacy policy. People you share a graph link with receive the content of that shared edition. Beyond these, we disclose personal data only where the law requires.

We update this list when subprocessors change; the date at the top of this notice reflects the current version.

5. International transfers

We prefer EU regions where our providers offer them. Where a provider processes data outside the EEA (see the table above), the transfer relies on an adequacy decision, the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses.

6. How long we keep it

Account and career data: while your account exists, deleted within 30 days of account deletion. Waitlist emails: until you unsubscribe or ask us to delete them. Rate-limiting keys: hours to days by design. Scrubbed error reports: 90 days. Billing records: retained by Paddle for as long as tax law requires.

7. Your rights

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to processing based on legitimate interests, receive a portable copy, and — where processing rests on consent — withdraw that consent at any time without affecting earlier processing. Write to privacy@cvgraph.ai and we will respond within one month. You also have the right to complain to a supervisory authority: Persónuvernd, the Icelandic Data Protection Authority (personuvernd.is), or the authority of your own country.

8. Automated processing and profiling

AI-exposure scores, JD-fit scores, and Ask answers are produced by automated systems from the data you provide. They are informational outputs shown to you — we make no decisions about you with legal or similarly significant effect based on them, and no automated decision-making within the meaning of Article 22 GDPR takes place.

9. What you must provide

An email address is required to create an account (we cannot provide the service without it). Everything else — every skill, role, and document-derived entry — is voluntary; the only consequence of leaving something out is a less complete graph.

10. Cookies and analytics

This site sets no tracking cookies, which is why there is no cookie banner. We use two strictly functional preferences: your theme choice (stored in your browser’s local storage) and, if you switch it, your display currency (a single functional cookie). Neither identifies you or follows you anywhere.

Page views and anonymous interaction events (for example, which call-to-action button was clicked) are counted in aggregate with Vercel Analytics, which sets no cookies and stores no identifiers on your device. If you arrive via a campaign link, its UTM tags are kept for the duration of the tab (sessionStorage) and attached to those aggregate events so we know which campaign brought visitors — they identify the campaign, not you.

If you sign up after arriving via a campaign link, we record that campaign source (the UTM tags of the link you arrived from) on your account as first-party attribution — our own record of which marketing source brought you, used only to measure our campaigns. No third-party marketing pixel or tracker is involved.

11. Children

The service is not directed at children and requires users to be at least 16. We do not knowingly process children’s data; if you believe a child has created an account, contact us and we will delete it.

12. Security

Data is encrypted in transit, access is restricted and role-based, payment data never touches our systems, and error reports are scrubbed before storage. No system is perfectly secure; if a breach affects your rights we will notify you and the supervisory authority as the GDPR requires.

13. Changes and contact

We will update this notice as the service evolves and change the date above; for material changes affecting your rights we will tell you by email or in the product. Questions: privacy@cvgraph.ai.

Privacy — cvgraph