Privacy policy
Updated: July 2026
Chốt CV is a personal AI CV tool for job seekers. We optimize your resume with human-in-the-loop review — we do not run a job board, and we do not sell candidate profiles to employers.
Who we are
The service is operated as Chốt CV (ChotCV) at the public site URL shown in the product (default brand domain chotcv.com). This policy covers the consumer web app and PWA for individual users. V1 is not a B2B, school, or recruiting platform product.
What we collect
Depending on how you use the product, we may process:
- CV content you type, paste, or upload (PDF/DOCX text and structured resume fields), optional photo for photo-on templates, and job-description text or URLs you provide for matching.
- Account data when you sign in (for example email and session identifiers via our auth gateway) so we can restore “My resumes”, master vs company variants, and entitlements.
- Local workspace drafts on your device (browser storage / IndexedDB) before or without cloud sync.
- Minimal technical logs needed to run the service (timestamps, rough error diagnostics, rate-limit and export-queue signals). We do not treat these as a marketing profile of your career.
- Payment-related identifiers only when billing is enabled and you start checkout (order references via PaymentPort / merchant rails) — not full card PAN stored by Chốt CV itself.
- Product analytics events when Umami is configured (page views and product events such as export or accept-diff), without selling that data to ad networks as a core business.
How we use data
We use the data above to:
- Run interview, parse, JD diagnose, rewrite proposals, template preview, and PDF/PNG export in the workspace.
- Apply human-in-the-loop rules: AI suggestions are proposals; your Accept / Edit / Reject decision controls what is written into the CV.
- Sync cloud resumes after sign-in, show dashboard history, and apply Free/Pro entitlements when PaymentPort is on (Pro = top AI model / interview — not a per-customize meter).
- Keep the service reliable (rate limits, export pool, abuse prevention) and improve product quality from aggregate, non-sale analytics.
- Respond to support, privacy, or security requests you send via Contact.
Retention
Local drafts remain on your device until you clear site data or the app deletes them. Cloud resumes and sessions linked to an account are kept while the account is active and needed to provide “My resumes”, then deleted or anonymized when you request deletion or when we decommission the account under our operational process. Uploaded source files are processed to extract text; we do not promise long-term archival of original binaries beyond the processing need. Technical logs are kept only as long as needed for operations and security. Payment records follow merchant / PaymentPort retention rules when billing is live.
Processors and third parties
To deliver the product we may use infrastructure and gated services, including:
- Hosting, database, and object storage for authenticated cloud features.
- Auth / payment / email rails through our integration gateway (middle-platform-style ports) when those features are enabled — PaymentPort only creates real charges when billing mode allows checkout.
- AI model access through an AI gateway: prompts may include CV/JD excerpts you send so the model can propose rewrites. Model providers act as processors under our configuration; they are not sold your profile as a candidate marketplace listing.
- Export workers (server-side Chromium pool) that render PDF/PNG from your chosen template.
- Umami (when configured) for first-party analytics.
Cookies and analytics
We use session cookies (typically HttpOnly where applicable) to keep you signed in and protect routes. Umami analytics, when enabled via environment configuration, is intended as privacy-friendly product analytics and does not require a marketing cookie wall by itself. If advertising or other non-essential trackers are later enabled for a region that requires consent, a consent banner will be shown as required. You can block scripts or clear cookies in your browser; signed-in features may stop working without session cookies.
Your rights
Subject to applicable law, you may request access, correction, export, or deletion of account-held data via Settings (when available) or the Contact page. You control Accept on AI proposals. You may stop using the service and clear local drafts on your device at any time. For EU/EEA or other jurisdictions with statutory rights, contact us and we will respond within a reasonable period. We will not refuse a deletion request solely because a free plan is in use.
Privacy contact
Questions about this policy, data export, or deletion: use the Contact page. Product name: Chốt CV. We reply during business hours. Open Contact