Privacy
How CV Studio handles your CV, job descriptions, and files
This page describes what the application actually does with information. It is the detailed notice for the site. It is not a popup, and it is not a promise that a third party never sees a document you choose to process.
Summary
- CV Studio does not ask you to create an account, and it does not have a user database of profiles, passwords, or email addresses.
- A CV, a job description, a cover letter, and chat messages are processed so the tool can tailor and export a document. That processing happens on the server that hosts this site.
- When an OpenAI API key is configured and the request succeeds, the relevant text is sent to OpenAI. If that call fails, the app continues with its own rules on the server and does not keep retrying that failed call into a training set of its own.
- Saved applications, the open editor draft, and accent-colour history are stored in this browser, not in an account in the cloud.
- Uploaded source files used for a tailoring run are deleted from the server when that request finishes. Generated Word and PDF files written for download are not deleted automatically.
- CV Studio does not sell personal information and does not run an advertising or analytics product inside the app. The page still loads fonts from Google, and the web host can keep ordinary server logs.
Accounts
There is no sign-up, no login, and no profile. The app cannot email you, reset a password, or list “your documents” on another computer. Anything that survives a refresh is either still in this browser or a file the server wrote while handling a request.
Because there is no account, the app also cannot verify that a later visitor is the same person. A download link is addressed by filename. Keep those links private.
Information you choose to provide
You decide what to put in. Typical content includes:
- A resume as pasted text, or a PDF, DOCX, or TXT file you select.
- A job description or vacancy text, including the employer name, role, and requirements if they are in that text.
- Edits you make in the editor: headings, bullets, contact details, dates, skills, colours, fonts, and layout.
- Cover-letter text, and messages you send to the in-editor assistant.
- The document title you type in the navigation bar. That title is used as the download filename after characters that are not letters, numbers, spaces, hyphens, or underscores are removed.
The live demo loads a fictional sample candidate that ships with the app. That sample is not your CV. If you replace it with your own text, the app treats the replacement as your content.
The “paste” control reads the clipboard only after you click it, and only if the browser allows that read. Choosing a file does not upload it until you start tailoring or otherwise submit the form.
What stays in this browser
These copies exist so a refresh can restore your work. They are readable by scripts on this site, and by anyone who can use this browser profile. They are not cookies.
| Place | Name | What it contains |
|---|---|---|
| localStorage | cvStudioEditorDraft |
Resume text, job description, editor HTML, cover letter, template, accent, font, document title, and the last tailoring result when it fits. |
| localStorage | cv_studio_saved_applications |
Applications you save from the editor, including the version content stored with each one. |
| localStorage | cvStudioAccentUsage |
Which accent colours have been used, so the theme row can remember them. This is not your CV text. |
| IndexedDB | cvStudioFiles |
A file-system handle, when the browser supports saving back to a file you already chose. The handle points at a file on your computer. The CV text itself is not copied into this database. |
The draft is written automatically while you edit, including when the tab is closing. Clearing the site’s data in the browser settings removes these stores as well. Another browser, another device, or a private window starts empty.
What is sent to the server
The browser sends content to the CV Studio server only when you take an action that needs it. The main cases are:
- Tailor. The resume file or resume text, the job description, the template, columns, font, and accent colour are posted to
/api/optimize. The server writes a temporary file under anuploadsfolder, runs the pipeline, then deletes that temporary CV file and job-description file when the request ends, including when the request fails. - Cover letter. Generating or exporting a cover letter sends the letter’s text and contact fields needed to build it.
- Assistant and rewrites. A chat message can include resume context, job-description context, tailored-CV context, and cover-letter context. Rewriting a snippet sends that snippet.
- Checks that stay on the server. Section suggestions, the information-loss check, and the quality score run in the application code. Those requests still send the resume text or structured CV you submit, but they do not themselves call OpenAI.
- PDF from the editor. Download PDF posts the HTML of the page you are looking at to
/api/export-print-pdf. When the server can run Chrome or Edge, it returns a PDF file and the browser downloads it. When the server cannot run a browser, the same page is drawn in your browser and that PDF file downloads there. The print dialog is not used.
The app does not ask you to paste an OpenAI key into the page. The key, when one is used, is configured on the server.
Generated files left on the server
Temporary uploads are removed at the end of a tailoring request. The files produced for you to download are different. Word documents, cover-letter documents, and PDFs created by the server are written into an outputs folder and served by a download address that uses the filename.
Those output files are not tied to an account, and the application does not expire or delete them on a timer. The filename is either a short random id from that run, or your document title after it has been cleaned. Someone who has the exact filename can request that file. Do not share the download address if the document has personal details in it.
The delete button on this page does not remove those server files. If you want a generated file removed from the host, use the contact page and include the filename or the time you created it. Removal depends on the operator still having access to that file.
OpenAI
Tailoring is built to call OpenAI’s API, using gpt-4o-mini unless the server is configured otherwise. The text sent can include your CV, the job description, and the structured fields needed for parsing, rewriting, a cover letter, an interview-prep note, a recruiter-style review, the assistant chat, or a snippet rewrite.
That means OpenAI receives the content of those requests and processes it as their API customer’s input. CV Studio does not sell that content, and it does not keep a separate copy for the purpose of training a model of its own. CV Studio also does not control OpenAI’s systems. OpenAI’s published API policy says that data sent through the API is not used to train OpenAI’s models by default. Their policy can change, and their own privacy terms describe how they handle API data: openai.com/policies/api-data-usage-policies.
If the API key is missing, the quota is exhausted, or the call fails, the app falls back to its own parser and rewriting rules on the server. In that case the failed or skipped call is not replaced with a second copy stored for training.
Do not include information in a CV or chat message that you are not willing to have processed by the host and, when the API is used, by OpenAI.
Fonts
The interface loads typefaces from Google Fonts. Your browser requests those font files from Google’s servers. That request carries ordinary connection data such as IP address and browser type. The text of your CV is not part of the font request.
Hosting and technical logs
The site is served from the operator’s web host. Web servers commonly record the IP address, date and time, browser type, and the address that was requested. CV Studio does not add its own analytics log on top of that, but it also does not disable the host’s logs. Those logs can therefore exist even though the app has no account record of you.
If a request throws an error, the server may write a traceback to its error output. That technical record can include the error text for the failed step. It is for diagnosing the failure, not for a customer database.
How long information stays
- Browser stores stay until you delete them, clear site data, or use the button below. Closing the tab does not remove them. The editor also saves the draft when the tab is closing.
- Temporary uploads are deleted when the tailoring request finishes.
- In-memory work on the server exists for the length of the request. The app does not write your CV into a user table.
- Generated downloads remain in the outputs folder until they are removed by hand. There is no fixed number of days built into the app.
- Host logs follow the host’s own retention. This application does not publish a separate log-deletion schedule.
Deleting information from this browser
The button below removes, from this browser only:
- saved applications (
cv_studio_saved_applications) - the editor draft (
cvStudioEditorDraft) - accent-colour history (
cvStudioAccentUsage) - remembered file handles (
cvStudioFilesin IndexedDB)
It then reloads the page so the open editor cannot immediately write the draft back. It does not delete generated files already stored on the server, it does not delete host logs, and it does not delete anything OpenAI already received from an earlier request. It does not affect another browser or another device.
You will be asked to confirm. The page reloads afterwards.
You can also remove the same browser storage from your browser’s site settings. For a file on the server, write via the contact page.
Children
CV Studio is a resume tool for job applications. It is not directed at children, and it should not be used to upload a CV about anyone under 16. Do not submit another person’s CV, phone number, or address unless you are allowed to share it for this purpose.
Where processing happens
The application is hosted with the operator’s site, tanuisila.dev. Processing of a request happens on that server. When the OpenAI API is used, the text of that request is also processed by OpenAI, which may process API traffic outside your country. Font files are requested from Google.
This notice describes the behaviour of this project. It is not a law-firm opinion and it does not appoint a data-protection officer. If you need a record erased from the host and you believe the server still has it, contact Tanui Sila with enough detail to find the file.
Changes to this page
If the way data is stored or sent changes, this page should change with it. The date at the top is the date of the current description. Continuing to use the tool after an update means the updated page is the one that describes the current version.