Home
ATS Checker
Resume Builder
Examples
FAQ

Privacy Policy

Effective date: 23 July 2026 · Operator: Hamza Ghariani

1. Introduction

This Privacy Policy explains how EuropeCV ("EuropeCV", "we", "us", or "our") processes personal data when you visit https://www.europecv.io or use our website, applications, and related services (collectively, the "Service").

This policy should be read together with our Terms of Service at /terms and our Cookie Policy at /cookies.

This Privacy Policy describes our data processing practices. It does not by itself establish that EuropeCV is fully GDPR compliant.

2. Data Controller

For the purposes of applicable data protection law, the data controller is:

EuropeCV

Baden-Württemberg, Germany

Germany

Email: [email protected]

3. Scope

This Privacy Policy applies to personal data processed in connection with:

  • visitors to our website;
  • registered and authenticated users;
  • customers purchasing Credits;
  • users uploading or entering resumes, CVs, or career information;
  • users of the ATS Checker;
  • users of AI Resume Fix / Resume Builder features;
  • users of AI Cover Letter features;
  • users of dashboard intelligence, job-matching, and related career tools;
  • users contacting us for support or other communications.

This policy does not apply to third-party websites, employers, job boards, or services that are not operated by EuropeCV.

4. Controller Role

EuropeCV generally acts as the data controller for personal data processed to operate its own Service.

We do not act as your employer, recruiter, or processor on behalf of employers when you use the Service for your personal job search, unless a separate written agreement states otherwise.

5. Categories of Personal Data We Process

Depending on how you use the Service, we may process the categories of personal data below. We only process data that is relevant to providing and securing the Service.

5.1 Account and Authentication Data

  • Email address.
  • Display name / full name, where provided.
  • Profile picture URL, where provided through OAuth or account settings.
  • Supabase authentication user ID.
  • Authentication provider (email, Google, or LinkedIn).
  • OAuth provider identifiers and authentication metadata managed through Supabase Auth.
  • Email verification status.
  • Account status.
  • Account creation and update timestamps.
  • Last login and last logout timestamps, where recorded.
  • Signup source, first visit page, and UTM campaign/source values, where captured at registration.
  • Timezone and related profile preferences, where provided or inferred from account settings.

5.2 Resume and Career Data

When you upload, enter, or generate career documents through the Service, we may process information contained in your resume, CV, cover letter, or related inputs. This may include, depending on what you provide:

  • Name, contact details, address or location, and profile photo.
  • Professional summary, employment history, education, skills, certifications, languages, and achievements.
  • Job titles, employer names, job descriptions, hiring manager names, company names, and career preferences.
  • Parsed resume structure, extracted text, preview lines, and structured resume data stored in our systems.
  • Other information you voluntarily include in documents or forms.

Resumes and career documents may contain highly personal or professionally sensitive information. We do not treat all resume information as "special category" data under GDPR Article 9 merely because it appears in a CV. However, you should only submit information you are authorized to provide and should avoid submitting unnecessary sensitive information unless required for your application.

5.3 AI-Generated and Analysis Data

  • ATS analysis results, ATS scores, compatibility ratings, and formatting or keyword feedback.
  • Job-description matching results, missing keyword analysis, and related recommendations.
  • Enhanced or rewritten resume content and structured resume outputs.
  • Cover letter drafts and related generated text.
  • Dashboard intelligence outputs, such as profession suggestions, market insights, recommended templates, and career strengths.
  • Other AI-generated summaries, recommendations, or outputs produced by the Service.

5.4 Uploaded Files and Generated Documents

As currently implemented, core authenticated resume processing on the server accepts PDF resume files up to 2 MB.

The Service may also store enhanced resume data as JSON, generated PDF exports, temporary preview images (such as PNG, JPEG, or WebP), and short-lived print-session files in storage systems connected to the Service.

Some public marketing interfaces may allow users to select additional file types in the browser, but server-side authenticated resume processing is currently centered on PDF validation and processing.

Uploaded files and generated documents may be stored temporarily to provide requested functionality and are subject to the retention periods described below.

5.5 Usage and Technical Data

  • IP address, where available from request headers.
  • User-agent string.
  • Browser, operating system, and device type derived from the user-agent.
  • Request and session-related technical metadata used for security, abuse prevention, and service operation.
  • Feature usage information connected to Credits, uploads, and AI requests.
  • Rate-limit and fraud-prevention related technical information where applicable.

6. User Session Data

EuropeCV maintains session-related records for authenticated users.

While you are signed in, an active session record may store login time, last activity time, IP address, browser, operating system, device type, authentication method, and timezone where available.

When you log out, or after approximately one hour of inactivity, the active session may be finalized into a completed session record containing login time, logout time, session duration, IP address, browser, operating system, device type, and authentication method.

Completed session records are used for security, service reliability, and internal operational purposes. As currently implemented, completed session records are deleted by a daily cleanup process that removes all rows from the completed session table.

Inactive sessions expire based on inactivity timing and logout events rather than indefinite retention in the active session table.

7. Credit and Feature Usage Data

EuropeCV processes Credit and feature-usage information to operate its prepaid Credit system. This may include:

  • Current Credit balance stored on your profile.
  • Credit consumption events for paid features such as ATS analysis, AI Resume Fix, cover letter generation, and dashboard intelligence unlock.
  • Credit transaction records, including amount, transaction type, feature name, balance after transaction, and timestamps.
  • References to related service events where needed for billing support, fraud prevention, or dispute handling.

Credit transaction records are not automatically deleted by the current retention jobs and may be retained for accounting, fraud prevention, support, and legal purposes.

8. AI Usage and Cost Logs

When AI features are used, EuropeCV may store server-side AI usage logs for operational, billing, security, and reliability purposes. Depending on the request, these logs may include:

  • User ID associated with the request, where available.
  • Feature name (such as ATS analysis, resume enhancement, cover letter generation, or dashboard intelligence).
  • AI model identifier used for the request.
  • Input, output, and total token counts where returned by the provider.
  • Request status (success or failure).
  • Credit cost associated with the request.
  • Provider name and estimated server-side cost information used for internal operations.
  • Processing timestamp.

These logs are used to monitor service performance, investigate failures, manage provider costs, support refund or Credit restoration decisions, and protect the Service from abuse. They are not published externally and do not include API keys or other secrets.

As currently implemented, AI usage logs are not automatically deleted by the scheduled retention jobs described below.

9. Payment and Billing Data

When you purchase Credits, EuropeCV may process:

  • Purchase history and package selected.
  • Credits added to your account.
  • Payment status and fulfillment status.
  • Stripe checkout session identifiers, payment intent identifiers, and customer identifiers where provided by Stripe.
  • Stripe event identifiers used for idempotent payment fulfillment.
  • Transaction amount and currency.

Stripe processes payment card details and payment authentication. EuropeCV does not store full payment card numbers.

Stripe processes payment information under its own privacy documentation. EuropeCV may retain billing and payment records where necessary for legal, tax, accounting, fraud-prevention, and dispute-resolution purposes.

10. Support Communications

If you contact us at [email protected] or through the signed-in dashboard support form, we may process your email address, account identifiers, message content, attachments, and technical information you provide so we can respond to your request.

The dashboard support form is available to signed-in users and is subject to rate limits to prevent abuse. Email at the address above remains available for general enquiries.

Support communications may be retained as long as necessary to resolve the request and for recordkeeping, legal, security, or dispute-resolution purposes.

11. Sources of Personal Data

  • Directly from you when you register, sign in, upload content, enter forms, purchase Credits, or contact support.
  • From Google OAuth when you choose Google sign-in.
  • From LinkedIn OAuth when you choose LinkedIn sign-in.
  • From Stripe when you complete a payment.
  • From cookies, session technologies, and server request metadata as described in this policy and our Cookie Policy.
  • From automated systems that parse uploaded documents, generate AI outputs, or record feature usage.

12. Purposes of Processing and Legal Bases

We process personal data for the purposes and on the legal bases below. The applicable legal basis depends on the specific processing activity and your relationship with us.

PurposeExamples of data categoriesLegal basis
Account creation and authenticationEmail, name, auth provider, user ID, profile picture URLContract performance; legitimate interests in securing accounts
Providing the ServiceResume data, job descriptions, AI outputs, files, account dataContract performance
Resume parsing, ATS analysis, AI Resume Fix, cover letter generation, PDF generationResume content, job descriptions, generated outputs, file metadataContract performance
Credit management and paid feature accessCredit balance, credit transactions, feature usageContract performance; legal obligation where applicable
Payment processing and purchase fulfillmentPayment status, Stripe identifiers, purchase history, credits addedContract performance; legal obligation
Security, abuse prevention, and fraud preventionIP address, session data, technical logs, rate-limit information, payment eventsLegitimate interests in protecting the Service and users; legal obligation where applicable
Service reliability and operational monitoringAI usage logs, session data, error-related metadata, token and cost logsLegitimate interests in maintaining and improving service reliability
Customer supportContact details, account information, support message contentContract performance; legitimate interests in responding to requests
Legal compliance, tax, and accountingPayment records, transaction history, account identifiersLegal obligation
Defending legal claims and handling disputesRelevant account, payment, usage, and communication recordsLegitimate interests; legal obligation where applicable

13. Legitimate Interests

Where we rely on legitimate interests, those interests may include:

  • Securing the Service and user accounts.
  • Preventing fraud, abuse, and unauthorized Credit consumption.
  • Maintaining service reliability and investigating technical failures.
  • Protecting EuropeCV, users, and third parties from unlawful or harmful use.
  • Defending or exercising legal claims.

You may have the right to object to certain processing based on legitimate interests, as described below.

15. AI Processing

EuropeCV uses AI and automated processing to provide features such as resume analysis, ATS scoring, resume optimization, job-description matching, dashboard intelligence, and cover letter generation.

When you use these features, user-provided content such as resume text, structured resume data, and job descriptions may be transmitted to third-party AI inference providers as necessary to perform the requested functionality.

As currently implemented, EuropeCV uses OpenRouter to send AI inference requests. OpenRouter may route requests to underlying model providers according to its platform configuration and the model selected in our environment.

We do not control all downstream provider systems. Provider-specific retention, logging, and training practices are governed by the relevant provider terms and configuration.

16. AI Model Training

EuropeCV does not state in this policy that user content is never used for AI model training, because provider-side training, logging, and retention practices depend on the relevant provider configuration, contracts, and settings.

Content sent for AI processing may be processed by third-party providers according to their own policies. For details on retention, logging, and training, refer to the applicable OpenRouter and underlying model provider terms.

17. Automated Processing, Profiling, and Article 22 GDPR

EuropeCV uses automated systems and AI to generate scores, recommendations, keyword analysis, resume suggestions, and cover letter drafts.

These outputs are informational tools intended to help you prepare application materials. EuropeCV does not make hiring decisions, does not decide whether you should be hired, and does not determine employment eligibility.

ATS scores and job-matching results are estimates and should not be treated as guarantees.

Whether GDPR Article 22 applies to any specific feature requires legal review. If you believe automated processing affects you in a way that produces legal or similarly significant effects, contact us and we will review your request in accordance with applicable law.

18. Google and LinkedIn Sign-In

If you choose to sign in with Google or LinkedIn, we receive information from the OAuth provider through Supabase Auth. Depending on the provider and your account settings, this may include:

  • Email address.
  • Name or display name.
  • Profile picture URL.
  • Provider user identifier and authentication metadata.

You can choose whether to use social sign-in instead of email and password. The OAuth provider processes your data under its own privacy policy.

19. Third-Party Service Providers

We use third-party providers to operate the Service. As currently implemented, these include:

  • Supabase — authentication, database, and file storage.
  • Stripe — payment processing.
  • OpenRouter — AI inference routing and processing.
  • Google — OAuth sign-in where selected, Google Fonts delivery, and Google Analytics 4 where configured.
  • LinkedIn — OAuth sign-in where selected.
  • Vercel and related hosting/infrastructure providers used to run the application.

These providers process personal data as service providers or independent controllers depending on the service and the applicable legal relationship. Their own terms and privacy policies apply to their services.

We have not listed separate email marketing or error-monitoring providers because no such providers were identified in the current application codebase. If we add them later, this policy should be updated.

20. International Data Transfers

Personal data may be processed in Germany, the European Union, the European Economic Area, and other countries where our providers or infrastructure operate.

Some providers may process data outside your country, including outside the EEA. This may include the United States or other jurisdictions.

Where required by law, transfers rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms as provided by our service providers.

Do not assume that all personal data remains in the EU at all times.

21. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by law.

As currently implemented, automated retention includes approximately:

  • Uploaded original resume files and related saved records — 24 hours.
  • Enhanced resume files, related saved records, and associated generated files in scope of that retention job — 7 days.
  • Cover letter records — 7 days.
  • Dashboard intelligence data — 3 days, after which dashboard intelligence content may be cleared and dashboard access may be locked again.
  • Completed user session records — removed by a daily cleanup process that deletes all completed session rows.

Account profile data, authentication records, Credit balances, credit transaction records, AI usage logs, payment event records, and support communications are not automatically deleted by the current scheduled retention jobs and may be retained longer where necessary for providing the Service, security, fraud prevention, accounting, tax, legal compliance, or dispute resolution.

Deletion from active systems does not necessarily mean immediate deletion from all backups, logs, provider systems, or disaster-recovery copies. Residual copies may persist for a limited period where technically necessary or legally required.

22. Resume and File Storage

As currently implemented, EuropeCV uses Supabase Storage and related database records to store files and metadata connected to the Service.

Storage used by the Service includes:

  • A resumes storage bucket for current/original resume PDFs and related saved resume records.
  • An enhanced-resumes storage bucket for enhanced resume JSON, generated PDFs, temporary preview images, and short-lived print-session files.
  • Database tables such as users_resumes, cover_letters, and dashboard_intelligence for structured content and metadata connected to user documents and analyses.

Core authenticated resume uploads are validated as PDF files up to 2 MB. The enhanced-resumes bucket currently allows additional file types such as JSON and image formats up to a higher storage limit for generated or temporary assets.

Legacy storage buckets that are no longer part of active product flows may still be subject to cleanup processes if residual files remain.

23. Data Deletion and Account Closure

You may request deletion of your account or personal data by contacting [email protected]. A self-service account deletion feature may not yet be available in all parts of the Service.

Upon request, we will take reasonable steps to delete or anonymize personal data in accordance with applicable law, subject to exceptions for data that must be retained for legal, tax, accounting, fraud-prevention, security, or dispute-resolution purposes.

Automated deletion of resumes, enhanced resumes, cover letters, and dashboard intelligence occurs according to the retention periods above. Earlier deletion requests will be handled where technically feasible and legally permitted.

Account closure does not necessarily require deletion of all information. For example, payment records and legally required billing information may be retained.

24. Your Rights

Depending on your location and the applicable legal basis for processing, you may have some or all of the following rights:

  • Right of access.
  • Right to rectification.
  • Right to erasure.
  • Right to restriction of processing.
  • Right to object to certain processing.
  • Right to data portability.
  • Right to withdraw consent where processing is based on consent.
  • Right to lodge a complaint with a supervisory authority.
  • Rights relating to automated decision-making where applicable.

To exercise your rights, contact [email protected]. We may need to verify your identity before responding. Rights are not absolute and may be subject to exceptions under applicable law.

25. Right to Object

Where we process personal data based on legitimate interests, you may have the right to object to that processing in certain circumstances.

If we process personal data for direct marketing, you have the right to object to such marketing at any time. As currently implemented, EuropeCV does not describe a separate direct marketing email program in the application codebase.

26. Personal Data Breaches

We maintain technical and organizational measures designed to protect personal data, but no system is completely secure.

If a personal data breach occurs, we will handle it in accordance with applicable legal obligations, including notification to supervisory authorities and affected individuals where required by law.

27. Security

We use appropriate technical and organizational measures designed to protect personal data, including measures such as:

  • Authentication and access controls for user accounts.
  • Server-side authorization and Credit validation.
  • Database row-level security for certain user-owned data, where implemented.
  • Encryption in transit through HTTPS for website and API communications.
  • Secure payment processing through Stripe rather than storage of full card details on EuropeCV systems.
  • Rate limiting and abuse-prevention controls on certain API routes.
  • Scheduled retention and cleanup jobs for certain document and session data.

We do not describe specific internal security configurations in this policy because doing so could create unnecessary risk.

28. Cookies and Similar Technologies

We use cookies and similar technologies as described in our Cookie Policy at /cookies.

As currently implemented, this includes Supabase authentication cookies, limited browser local storage for interface convenience, remote loading of Google Fonts from Google servers, and Google Analytics 4 when a measurement ID is configured.

Google Analytics may set analytics cookies such as `_ga`, `_gid`, and `_ga_<container-id>` as described in the Cookie Policy.

EuropeCV provides a cookie consent banner and preference center for optional analytics technologies. See the Cookie Policy at /cookies for details.

29. Communications

We may send service-related communications about your account, purchases, security, or support requests.

We do not describe a separate promotional marketing email program in the current application codebase. If we introduce marketing communications in the future, we will do so in accordance with applicable law and, where required, with your consent.

30. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us, contact us so we can take appropriate steps.

This minimum age is consistent with our Terms of Service.

32. Supervisory Authority

You have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

For EuropeCV, based in Germany, you may contact the supervisory authority responsible for your place of residence or the authority competent for Baden-Württemberg. A list of EU data protection authorities is published by the European Data Protection Board at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

33. Changes to This Privacy Policy

This Privacy Policy is effective as of 23 July 2026 and was last updated on 25 July 2026.

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email where appropriate and required by law.

34. Contact

EuropeCV

Baden-Württemberg, Germany

Germany

Privacy contact: [email protected]

Cookie Preferences

Choose which optional technologies EuropeCV may use. Necessary cookies are always active because they are required for sign-in, security, and core functionality. Learn more in our Cookie Policy and Privacy Policy.

Necessary

Required for sign-in, session management, security, and core site functionality. These cannot be disabled.

Always on

Analytics

Helps us understand how visitors use EuropeCV through Google Analytics 4 and Vercel Web Analytics when enabled. Disabled by default until you consent.