Legal
Privacy policy
What tailorurCV collects, why, who else processes it, and how to get a copy or have it deleted. Written to be read, not to be survived.
Effective
The short version
You give us a resume and the job descriptions you are applying to. We store them against your account, send the text to an AI provider to parse, score and rewrite it, and keep the results so they are there when you come back. We do not sell any of it, we do not use it for advertising, and we do not train models on it. Ask and we will delete the lot.
Who is responsible
tailorurCVoperates this service and is the controller of the personal data described here — the “Data Fiduciary”, in the words of India’s Digital Personal Data Protection Act 2023, which makes you the “Data Principal”. Access, correction and deletion do not need a request at all: they are buttons in Settings. For anything else in this policy, or to reach a person, write to connect@tailorurcv.com.
What we collect
Only these, and only for the reasons given:
| Data | Why we have it |
|---|---|
| Your email address, name, and the account identifier from Google or LinkedIn | You sign in with one of them, which returns these. They identify the account. Signing in with either lands on the same account when the verified email matches. |
| Your phone number | Collected once after sign-in and used to identify the account. Not used for marketing. |
| Resumes you upload, and the profile parsed out of them | This is the product. One structured profile is stored per account and reused for every application. |
| Job descriptions and job URLs you paste | Scored against your profile to produce the gap analysis and the tailored resume. |
| Generated resumes, cover letters, interview guides and practice papers | Kept so you can download them again and compare versions. |
| Your application tracker rows — company, role, stage, notes, scores | You authored them. They are the durable record of your search. |
| Session records: IP address, browser user-agent, sign-in and last-seen times | So you can see and end sessions on other devices, and so a stolen token can be revoked. |
| Payment records: order and payment identifiers, amount, currency, status | Proof of purchase and credit accounting. Card and bank details never reach us — see below. |
| AI usage records: which call, how many tokens, what it cost | Fair-use limits and per-account spend caps. |
| A nominee’s name, and their email and relationship if you give them | Only if you nominate someone. It records who we should accept a request from on your behalf — see “If something happens to you” below. |
| Your LinkedIn profile URL | Only if you enter it. It is printed on the resumes you generate. LinkedIn does not give it to us — you type it. |
| A record of your agreement to this notice: which version, when, and from which IP address | The law puts the burden of proving consent on us. A checkbox nobody logged proves nothing. |
We do not ask for and do not want: your date of birth, government identifiers, health data, or anything else in the special-category sense. Please do not put such details in a resume you upload here.
Card details never reach us
Payment is completed on the payment provider’s own hosted checkout. Your card number, CVV, UPI PIN and bank credentials are entered there and are never sent to, seen by, or stored on our servers. What we receive back is an order identifier, an amount, a currency and a success or failure.
This site does not use cookies
Stated plainly because it is unusual and because it is checkable: tailorurCV sets no cookies at all. There is no advertising cookie, no analytics cookie, and no tracking pixel. We do not build a profile of you across other websites.
There is one thing we do ask, and the banner on your first visit is where we ask it: whether we may read two values your browser already knows — the time zone your device is set to, and the language it displays in — to decide which country the resume catalogue opens on. Both are read on your own device and neither is sent to us or to anyone else: no IP lookup, no location service and no third party is involved in reading them.
If you choose Necessary only, neither value is read and the resume catalogue opens on every country. Either way the answer is recorded in your browser’s local storage with the date you gave it and an expiry 180 days later, after which we ask again. You can change or withdraw it at any time from Privacy choices in the footer.
What that choice does not cover is the price you are shown. Pro is sold at an Indian price and an international one, and which of the two applies has to be decided by us rather than by your browser — otherwise the cheaper price would be available to anyone who edited a value on their own machine. So when the pricing page asks our server what Pro costs, the server works it out from the network address the request arrives from, which it sends to the geolocation service ipapi.co to get back a two-letter country code and nothing else. No account details, no name and no email are sent with it, the answer is never stored against you, and if the lookup fails we simply quote the Indian price. This happens on every visit to the pricing page, including before you sign in and whichever banner answer you gave, because it is how the amount on the page is calculated rather than something we gather about you.
What we use your browser’s local storage for, on your own device, is: the signed-in session token, why your last session ended, your light or dark theme choice, the details you typed before signing in, your in-progress workspaces and notes, the privacy choice above, and a custom API address if you set one in Settings — plus, in per-tab session storage, the file you are midway through uploading. None of it is transmitted anywhere by itself, and clearing your browser storage removes all of it.
Advertising
We currently show no third-party advertising. If that changes, this policy will be updated before any ad is served, and it will name the network, the cookies it sets and how to withhold consent — announced here first, not discovered here afterwards.
Where it is stored, and for how long
We do not sell personal data, and we do not share it with data brokers, advertisers or recruiters. If we are ever legally compelled to disclose something, we will tell you unless we are prohibited from doing so.
Data is stored on AWS infrastructure and is processed in the United States and India, which means it may be transferred outside the country you are in.
Your profile, documents and tracker rows are kept until you delete them or delete the account, because the whole point is that they are there next time — the Act asks us to erase personal data once the purpose it was given for is served, and here the purpose lasts as long as you are still applying for jobs. Closing the account ends it, and you can do that yourself in Settings. Sessions expire after seven days of the token’s life and can never be extended past thirty; ending a session invalidates its token immediately. Payment records are kept for as long as tax and accounting law requires, which is longer than the rest and is not something we can shorten on request.
Who processes it with us
We use these companies to run the service. Each one only receives what its job requires, and none of them is permitted to use it for their own purposes.
| Who | What they get, and why |
|---|---|
| Amazon Web Services (US, India) | Hosting, databases and file storage. Everything described above physically sits here. |
| OpenAI | The resume text and job descriptions you submit, so they can be parsed, scored and rewritten. Sent through the API, which is not used to train their models. |
| Only what sign-in needs: they confirm your identity to us. They do not receive your resume or anything else here. | |
| The same, and only if you choose to sign in with them: your name and verified email, nothing more. They do not receive your resume. | |
| Razorpay | Payment processing. Your card and bank details go to them directly and never to us — see above. |
This list changes only by us changing it, and this page changes in the same commit. If we ever add a processor that receives your resume or job descriptions, it will be named here before it does.
What we rely on to process it
Consent, for everything except the parts the law obliges us to keep. You gave it when you created the account and agreed to this notice; you can take it back. Under India’s Digital Personal Data Protection Act 2023 we are the Data Fiduciary and you are the Data Principal, and this section is the notice section 5 of that Act requires.
Withdrawing consent is one click, because the Act requires it to be as easy as giving it was. Deleting your account in Settings withdraws it and erases what it covers, in the same action. There is no form to fill in and nobody to email first.
The exception, stated plainly: payment records. Tax and accounting law requires a seller to keep a record of what was sold and for how much, and section 8(7)(a) of the Act exempts retention the law requires. Those rows survive deletion with the amount, currency, status and dates intact — and with every field that names you removed from them.
Your rights, and how to use them
Depending on where you live these are legal rights — under the Digital Personal Data Protection Act 2023 in India, and under the GDPR in the EEA and UK — but we do not ask which apply to you before honouring a request.
| Right | How to use it |
|---|---|
| Get a copy of everything we hold (DPDP s.11, GDPR art.15) | Settings → Download your data. It is one file, produced immediately, with every field from every table. No request, no waiting. |
| Have it corrected (DPDP s.12, GDPR art.16) | Your profile is editable in the app. For anything you cannot reach, write to us. |
| Have it erased (DPDP s.12(3), GDPR art.17) | Settings → Delete this account. Immediate and irreversible, and it reports back exactly what went and what was kept. |
| Nominate someone to act for you (DPDP s.14) | Settings → Nominate someone. See below. |
| Withdraw consent (DPDP s.6(4)) | Deleting the account does both at once. There is nothing else we process you can withdraw separately, because there is nothing we do with your data that the service itself does not need. |
| Complain, and escalate (DPDP s.13) | Write to the Grievance Officer below. If we do not resolve it, you may complain to the Data Protection Board of India. |
| Object, or ask us to restrict a use (GDPR arts.18, 21) | Write to us. We answer within 30 days. |
Nothing here is behind a support queue that can quietly not answer: the two that matter most — a copy of your data, and its deletion — are buttons you press yourself. For everything else, email connect@tailorurcv.com from the address on the account and we will answer within 30 days.
If something happens to you
Section 14 of the DPDP Act lets you nominate someone to exercise these rights for you if you die or become incapacitated. You can name them in Settings.
What that does and does not do: it records who we should accept a request from. It does not tell them, it does not give them access to your account, and it does not hand over your data on its own. We would still ask them to show the circumstances — a death certificate, or a court order — before acting. Automating that part would be pretending the hard part is automated.
Grievance Officer
Section 13 of the DPDP Act requires us to publish a person who answers questions and complaints about your data, and to respond to them. That is:
Grievance Officer
We answer within 30 days. If we do not, or the answer is unsatisfactory, you can complain to the Data Protection Board of India. Naming that route here is part of what section 13 asks for; we would rather you use the address above first.
Security
Every account’s data is partitioned rather than filtered: your rows sit under your own account identifier in the database, and your files under your own storage prefix, so one account’s data is not a query away from another’s. Traffic is encrypted in transit. Downloads are authenticated per request rather than served from a guessable public link.
No system is beyond compromise. If a breach affects your data, section 8(6) of the DPDP Act requires us to notify both the Data Protection Board and every affected Data Principal — not one or the other, and not only if we judge the risk to be high. We will tell you what happened, what of yours was involved, what we have done, and what you should do, at the email address on your account. The GDPR’s 72-hour regulator deadline applies to us as well where it applies to you.
Children
This service is not for anyone under 18, and we do not knowingly collect their data. If you believe a minor has an account here, write to us and we will remove it.
Section 9 of the DPDP Act would require verifiable parental consent before processing a child’s data, and forbids tracking them, advertising to them behaviourally, or processing anything likely to harm them. We do none of those things to anyone of any age — there is no tracking, no advertising and no behavioural profiling here at all, which is why there is no separate children’s regime to describe. What we do not have is age verification, which is the honest reason the service is for adults rather than a claim that we have checked.
Changes to this policy
When it changes materially, the effective date at the top moves and we will say what changed. Continuing to use the service after that means the new version applies. The terms of service are a separate document and change on their own schedule.
Something here unclear?
A privacy policy nobody can get an answer out of is decoration. Ask and we will answer.