Privacy Policy
Privacy Policy
Last updated: May 27, 2026 Effective date: May 27, 2026
MyCV ("we", "us", "our", or "the Service") is a free, self-hosted resume builder. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described below.
1. Summary (Plain English)
- We do not sell, rent, trade, or monetize your data.
- We do not run ads, trackers, or analytics.
- We do not care about your data for any purpose other than making the site work and keeping it secure.
- We collect IP addresses strictly to detect and block malicious actors (e.g., DDoS attacks, spam bots).
- Guest (unregistered) resumes are automatically deleted after 30 days.
- Temporary export files (PDF / DOCX / JPEG) are automatically deleted within 10 minutes of being generated.
- If we ever change this policy in a way that affects how your data is used, we will email registered users at least 10 days before the change takes effect.
2. Information We Collect
2.1 When you create an account
| Data | Why we need it |
|---|---|
| Email address | To verify your account, sign you in, and send password-reset links. |
| Password (stored as a salted scrypt hash) | To authenticate you. We never store or see your plaintext password. |
| User ID (random string) | Internal identifier to link your resumes to your account. |
| WhatsApp phone number (optional) | Only if you verify it. Used solely to add a trust badge to public profiles. |
2.2 When you use the resume builder
| Data | Why we need it |
|---|---|
| Resume content (text, images, links) | We store this so you can edit and download it later. We do not analyze or process this data. |
| Uploaded photos | Stored on the server to display your resume. |
2.3 Security Logs (The "We Don't Care" Clause)
To protect the Service from abuse, we maintain strict security logs. This is the only reason we look at technical metadata:
| Data | Why we need it |
|---|---|
| IP address | To identify abusive traffic patterns and block attacks (e.g., scraping, brute-force). |
| Timestamps & Request paths | To audit security incidents and ensure server stability. |
| User-Agent string | To distinguish between human users and automated bots. |
We do not use these logs to track your behavior, build user profiles, or for any commercial purpose. If an IP is blocked, it is because the system determined it was acting maliciously, not because of who you are.
3. How We Use Your Information
We use the information we collect only for two reasons:
- Functionality: To allow you to build, save, and export resumes.
- Security: To prevent attacks on the infrastructure that keeps this service free.
We never use your data for:
- Advertising or marketing.
- Analytics or usage profiling.
- Selling to third parties or data brokers.
- Training AI models.
4. Who Can See Your Data
4.1 Your private resumes
Only you. We do not have a team that reads user resumes.
4.2 Your public resumes
If you explicitly choose to publish a resume, it becomes publicly accessible on the internet. We warn you before you do this. You are responsible for what you publish.
4.3 Infrastructure Providers
To operate the Service, we rely on third-party providers. We share only the data strictly necessary for them to function:
- MongoDB: Stores your resumes and account data (encrypted in transit and at rest).
- Resend: Sends transactional emails (verification/password reset). They process your email address solely to deliver these messages.
- Cloudflare / Proxy: We may use a reverse proxy to manage traffic. It processes your IP address to provide the security features mentioned in Section 2.3.
We do not share data with advertisers, analytics companies, or data brokers.
5. Data Retention
We do not hoard data. We delete it as soon as it is no longer needed.
| Data | Retention |
|---|---|
| Guest Resumes | 30 days after the last update, then permanently deleted. |
| Registered Resumes | Kept until you delete them or your account. |
| Export Files (PDF/DOCX) | 10 minutes, then permanently deleted. |
| Security Logs | Retained for a limited period (typically 30 days) for incident response, then purged. |
| Email Verification Tokens | Expire after 24 hours and are purged. |
6. Your Rights
Since we don't care about your data and don't want to keep it longer than necessary, you have full control:
- Delete: You can delete any resume at any time. You can delete your entire account (and all data) by contacting [email protected].
- View/Export: You can download your resume data in PDF or DOCX format at any time.
- Guest Mode: You can use the service without giving us any personal data (Guest Mode). Note that these resumes are temporary.
7. Security
We take security seriously so you don't have to worry about us.
- Passwords are hashed using scrypt with unique salts.
- Sessions are managed via HTTP-only, secure cookies.
- We use strict rate limiting to prevent abuse.
- Our servers are configured to reject unauthorized access attempts.
8. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect data from children.
9. Changes to This Policy
If we change how we handle data (e.g., if we start collecting more than just security logs), we will notify you via email at least 10 days in advance. You can then choose to stop using the Service if you disagree.
10. Contact
If you have questions about this policy or want your data removed, contact us at: Email: [email protected]
We aim to respond within 14 days.
Thank you for using MyCV. Build something you're proud of.