Privacy Policy

Last updated: 1 May 2026

1. Who We Are

CV Human (cvhuman.co.uk) is operated by Luke Rawnsley. If you have any questions about this policy, contact us at [email protected].

2. What Data We Collect

When you use CV Human, we collect:

  • Account data: name, email address, and encrypted password if you register
  • CV data: the CV documents and text you upload for scanning
  • Usage data: scan history, page visits, and feature interactions
  • Technical data: IP address, browser type, device information

3. How We Use Your Data

  • To provide and improve the CV scanning and analysis service
  • To process payments and manage your subscription
  • To send service-related communications (not marketing)
  • To detect and prevent abuse of our platform

4. Legal Basis (GDPR)

We process your data under the following legal bases:

  • Contract: processing is necessary to provide the service you signed up for
  • Consent: where you have opted in (e.g., cookies)
  • Legitimate interests: improving our service, preventing fraud

5. AI Processing & Data Sharing

Your CV text is sent to our AI provider (Ollama Cloud) for analysis. We do not use your CV data to train AI models. CV data is processed temporarily in memory and not stored by third parties. Your CV text is stored in our database to enable scan history and rewriting features.

6. Data Retention

We retain your account data for as long as your account is active. CV scan data is retained for 12 months after your last activity, or until you delete it via your dashboard. You can request deletion of all your data at any time by contacting us.

7. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing

To exercise any of these rights, email [email protected].

8. Cookies

We use essential cookies for authentication and session management. We use Cloudflare for CDN and security, which may set analytics cookies. See our Cookie Policy for details. You can manage cookie preferences via the cookie consent banner.

9. Third-Party Services

  • Ollama Cloud: AI analysis (CV text sent for processing only)
  • Cloudflare: CDN, DNS, DDoS protection
  • Railway / VPS: hosting infrastructure
  • Stripe: payment processing (we never store card details)

10. Security

We encrypt data in transit (TLS 1.3) and at rest. Passwords are hashed using bcrypt. We implement rate limiting and input validation to protect against abuse. However, no online service is 100% secure — we recommend using strong, unique passwords.

11. Contact

Data controller: Luke Rawnsley
Email: [email protected]

12. Changes to This Policy

We may update this policy. Material changes will be notified via email or a notice on the website.