How PrivaCV handles your data

Privacy, in plain language

Your resume and job search stay on your device

PrivaCV runs as a local-first editor. Resume drafts, saved versions, applications, notes, timeline events, job descriptions, and submitted-resume snapshots are stored in IndexedDB in your browser profile or the desktop app's Electron profile. PrivaCV does not require an account or upload this information to a PrivaCV server. The website and desktop app use separate profiles, so use a JSON backup to move data between them.

Resume edits also use local browser storage for a temporary recovery copy until a save completes. Compatibility copies may remain for older versions of the editor. Delete all data removes these copies along with your workspace.

Files you choose to import

PDF, DOCX, JSON, and pasted resume content are used by the editor on your device. Review imported content before exporting because document formats can contain layout artifacts that need correction.

Optional local AI

If you explicitly prepare a local AI model, PrivaCV downloads model files from the listed model hosts into the current browser or desktop profile. The model runs locally in that profile; PrivaCV does not send your resume text to an AI API for that feature.

Optional device-to-device handoff

If you explicitly use the experimental Continue on another device feature, the first browser creates a private random secret shown as a short pairing code and included in the QR link fragment. The browsers derive the temporary room ID and encryption key from that secret; only the derived room ID is sent to the signaling service. A Cloudflare signaling room retains only encrypted WebRTC connection details for up to five minutes and cannot decrypt them. You choose whether to transfer the active resume, the application pipeline, or both. Application transfers can include timeline events, job-description snapshots, and submitted-resume snapshots. That selected data is not sent to or stored in the signaling room; it transfers over the encrypted WebRTC data channel after the devices connect. The browsers also contact Cloudflare's STUN service, which processes network metadata such as IP addresses and ports. When a direct connection is blocked, Cloudflare's TURN service can relay the encrypted WebRTC packets using a ten-minute credential. TURN processes the encrypted packet bytes and connection metadata but cannot read the transferred payload. Anyone with the temporary QR link or pairing code could attempt to join the transfer, so show it only to the intended device.

Limited product metrics

The hosted website records limited metrics for workspace visits, resume exports, local-AI usage milestones, and applications created. These metrics contain no company names, roles, job descriptions, notes, resume content, prompts, or generated text.

Visits to the resume and job application workspaces, each resume export, and each application-creation event include the same randomly generated browser-profile ID. This pseudonymous ID stays in local browser storage across days and sessions, letting us count returning browsers and unique users of these features. It is not derived from your identity, IP address, or device fingerprint. Different browsers, profiles, and devices have different IDs. Public information pages do not record visits, and local-AI events do not include this ID.

We skip visitor, export, and application-creation metrics when Global Privacy Control or Do Not Track is enabled, or local storage is blocked. Desktop builds do not submit these metrics. Delete all data removes the local identifier; future activity gets a new one. Clearing local data does not erase metrics already recorded by Cloudflare.

Your control

You can save portable JSON backups, export the job pipeline as CSV, delete individual applications, or delete all saved data from the current profile. If you share a device, export or back up anything you want to keep before deleting local data.