Privacy Policy
Last updated: 8 July 2026
ChatBotCV ("we", "the service") turns a candidate's CV into a chatbot that
recruiters can question directly. This page explains what data we collect,
why, and how it's handled. If anything here is unclear, contact us using
the details at the bottom.
What we collect
- Candidate accounts. Signing in uses Google or
LinkedIn OAuth, or a one-time code sent to your email address. With
OAuth we receive the name, email address, and a provider identifier for
your account — we never see or store your password for either provider.
With email sign-in we store only the email address you enter and send a
short-lived, single-use code to it.
- CV content. If you upload or paste a CV, we store
its text, split into indexed chunks with vector embeddings, so the
chatbot can retrieve and answer from it. This is only ever shown back
to you (in your private dashboard preview) or to recruiters you
explicitly publish a share link for.
- Recruiter questions. Anyone using a candidate's
public share link can ask questions without an account. We log each
question and the chatbot's answer (including whether it was answered
from the CV or refused) against that candidate's document, so the
candidate can see what recruiters are asking. We also briefly log
the IP address of each request (deleted after 24 hours) purely to
stop abuse of a published link, and keep a one-way cryptographic
hash of each visitor's IP address — never the address itself, and
not reversible back to it — so the candidate can see how many
unique people have used their chatbot. A recruiter may also
optionally tell us their name, company, and role when they
ask — these fields are never required, and if provided they are
stored against that candidate's questions and shown only to that
candidate, so they know who was interested. We collect nothing else
about recruiters, and never anything without them choosing to
provide it.
- Basic analytics. We use Umami, a
privacy-respecting, cookieless analytics tool, to see aggregate page
visit counts. It does not track individuals or store personal data.
How we use it
Data is used only to operate the service: authenticating you, storing
and retrieving your CV content to generate grounded chatbot answers,
and showing you the questions recruiters have asked. We do not sell
data, and we do not use your CV content for anything beyond answering
questions about it.
Who we share it with
To operate the service, data passes through:
- Supabase — hosts our database, authentication, and
file storage.
- Netlify — hosts the site and the serverless
functions that process requests.
- Anthropic (Claude API) and Voyage
AI — process CV content and recruiter questions to generate
embeddings and grounded answers. Neither is used to train models on
your data.
- Google and LinkedIn — provide
sign-in, if you choose to use them.
We don't share your data with anyone else, and never sell it.
Your controls
From your dashboard you can rename or delete your CV at any time —
deleting it also removes its public share link and all indexed
content. To request deletion of your account entirely, contact us
below.
Security
API keys for third-party services are only ever used server-side and
never reach your browser. Access to CV data is restricted by
row-level security so only you (and, for a document you've explicitly
published, anyone with that specific share link) can reach it.
Changes to this policy
We may update this policy as the service changes. We'll update the
"last updated" date above when we do.
Contact
Questions about this policy or your data — reach out via
hello@chatbotcv.com.