Privacy
What happens to your CV and the job description you paste in.
What stays in your browser
Reading your CV, matching it against the job’s criteria, scoring it and running the formatting checks all happen in this browser tab, in code that came down with the page.
The file you choose is never uploaded. It is read locally, and neither the file nor the text pulled out of it is sent anywhere as part of the standard check. Close the tab and nothing of it remains.
What is sent out, and when
Two features send text to OpenRouter, an AI service that routes requests to a language model. OpenRouter processes that text on our behalf. Both features are optional and neither runs unless you start it.
Compare with AI — job description only
If you tick Compare with AI, the text of the job advert is sent to OpenRouter so the criteria can be extracted from it. Your CV is not sent. The route that handles this accepts the job description and nothing else, and rejects text that looks like a CV before making any outbound request.
AI CV review — CV and job description
Your CV text and the job description text are both sent to OpenRouter. This is the one deliberate exception to everything else being local, and it exists because line-by-line rewrite advice cannot be produced by keyword matching.
It is opt-in. The panel will not send anything until you pass the consent step that names what is sent and where, and the server refuses the request outright if that consent is missing. If you never use AI review, your CV never leaves this browser.
This is not anonymous. CV text carries your name, contact details and history, so the text sent for review identifies you.
Analytics and monitoring
- Vercel Analytics — in use now. Aggregate pageviews, referrer and country. It is cookieless, sets no device storage, does not fingerprint you, and receives no CV or job description content.
- Axiom — in use now. Operational logs, so that a fault can be found and fixed. Two kinds: server-side records from the two AI routes (HTTP status, how long the request took, how many suggestions were kept or discarded), and events from this page reporting how far a run got — that a file was read, how long parsing took, how many criteria were found, and whether a step failed.
It records what happened, never what was in your documents. No CV or job description text, no filenames, no scores, no extracted criteria. Sizes are recorded as ranges rather than exact counts, and when something fails the log stores a category of error, not the error text — because an error message can quote the document that caused it.
That is the whole list. No other analytics or tracking tools are used.
Runs are grouped by a random identifier that lasts until you reload the page. It is held in memory only — nothing is written to your device, no cookie is set, and it cannot link this visit to any other.
No accounts, no stored CVs
There are no user accounts and no sign-in. No CV, job description, score or report is stored on a server, so there is no record of you here to look up, correct, export or delete. Nothing is kept between visits.
Your rights under UK GDPR
Rights of access, correction and erasure apply to data that is held. Since nothing is held here, the only place your text genuinely travels is OpenRouter, and only if you use one of the two AI features. Their handling and retention are covered by their own policy: openrouter.ai/privacy.
The practical way to withdraw consent is to decline the AI features: leave Compare with AI unticked and do not start an AI review. The rest of the tool works unchanged, and nothing is transmitted.
Questions about any of this: [contact address to be added].
A note on sensitive information
CVs often mention health, disability, ethnicity or religion — for example a health-related career break, or voluntary work with a faith organisation. If you opt into AI review, that content goes to OpenRouter along with the rest of your CV. If you would rather it did not, use the standard check, which sends nothing at all.