Back to Home
Privacy Policy

Your data, explained.

Last updated: July 12, 2026

This policy explains exactly what FitMyCV collects, why we collect it, who we share it with, and what you can do about it. Written to be specific - not to cover ourselves with vague language, but to give you a clear picture of how the product actually works.

What we collect

Account data

When you sign up - via Google or email/password - we store your name, email address, unique user ID, and profile photo URL.

Extended profile (optional)

If you fill out your profile in Settings, we store what you provide: phone number, address, GitHub URL, Instagram URL, and LinkedIn URL. None of this is required to use the product.

Resume & cover letter content

We store the full text and structured JSON of every resume and cover letter you create - including target job descriptions, ATS match scores, version history, and optimization logs.

AI output

We store the results of AI operations: tailored resume bullets, ATS scores (0–100), category breakdowns (keywords, grammar, format, skills, experience, education), and optimization job logs.

Credit & billing data

We store your credit balance, full credit transaction history, plan purchase history, Razorpay payment ID and order ID, amount, currency, and timestamp. We do not store card numbers or CVVs.

Usage data

We track last active timestamp, resume count, tailor run count, analysis run count, and average match score to understand how the product is being used.

Anonymous ATS analyses

If you run an ATS analysis without logging in, we store the resume text and scores with no user ID attached. These records are purged after 90 days.

Campus Ambassador applicants & ambassadors

If you apply to or participate in the Campus Ambassador Program, we collect your name, email, phone, college, branch, graduation year, social profile URLs (Instagram required; YouTube/LinkedIn optional), assigned referral code, link clicks, custom campaign links, and referral count. We do not collect or store any financial or bank details, as the program does not offer cash payouts.

PortfolioKit (published portfolio) data

If you use PortfolioKit, we store your chosen URL handle, selected template, portfolio content (name, headline, bio, photo, contact details, social links, projects, experience, education, services, testimonials, and other sections you add), customization settings (accent color, font, dark mode, hidden sections), publishing status, hosting expiry date, and view count. We also count page views for your analytics dashboard. If a visitor sends a message through your public portfolio's contact form, we store the sender's name, email, message, and read status so you can view it in your dashboard.

How we use your data

We use your data to do exactly what you asked us to do:

  • Authenticate your account and keep your session secure
  • Store and display your resumes, cover letters, and ATS scores
  • Send your resume and job description to AI APIs to generate tailored content
  • Track your credit balance and deduct credits when you use paid features
  • Process payments and issue receipts via Razorpay
  • Apply referral rewards when you or someone you referred completes a qualifying action
  • Send transactional emails - account verification, password reset, payment confirmation
  • Analyze aggregate usage patterns to improve the product (we look at trends, not individual users)
  • Publish your PortfolioKit portfolio as a public web page at fitmycv.site/p/yourhandle when you choose to publish it, and let visitors send you messages through its contact form

We do not use your data for advertising. We do not build profiles to sell. We do not share your resume content with recruiters or employers.

AI data processing

Read this section carefully

FitMyCV uses third-party AI APIs (OpenAI and/or Anthropic) to power its core features. When you use any AI feature, your content is sent to these external services. Here is exactly what gets sent and when:

AI Resume Tailoring:Your full resume text + the target job description
ATS Analysis:Your full resume text
AI Cover Letter:Your resume text + the target job description
AI Bullet Rewriter (editor):The selected resume field text only

We do not use your resume data to train AI models. Your content is sent to the AI API solely to generate the output you requested. We have no control over the internal processing of OpenAI or Anthropic - they have their own privacy policies.

Data sent to AI APIs is transient from our side - we do not store the raw API request beyond what appears in your saved documents. The AI provider may retain inputs per their own data retention policies.

If you are not comfortable with your resume text being sent to a third-party AI API, do not use the AI features. The template editor and PDF export work without AI and do not send data externally.

Payments & billing data

All payment processing is handled by Razorpay. We never see or store your card number, CVV, or bank credentials - those go directly to Razorpay's secure servers.

What we store on our end:

  • Razorpay payment ID and order ID
  • Credit pack purchased and number of credits
  • Amount paid and currency (INR or USD)
  • Payment timestamp
  • Your credit balance and full transaction history

Indian users pay in INR via Razorpay's domestic gateway. International users pay in USD via Razorpay's international card processing. Geo-detection determines which gateway is used at checkout.

All purchases are final. Credits are non-refundable. We encourage you to use the 30 free credits before buying a pack.

Referral system data

FitMyCV has a referral program. Here's what we store and why:

  • Your referral code: A random string tied to your account. Not personally identifiable on its own.
  • Who referred you: The referral code used at your signup, so we can credit the right person.
  • Referral count: How many people signed up using your link.
  • Reward history: Whether rewards were issued and when, so we don't double-credit.

Referral codes are random strings - they don't contain your name or email. We don't share referral data with third parties.

Campus Ambassador Program data

The Campus Ambassador Program is opt-in from your account settings. If you apply or participate as a campus ambassador, we process your profile fields (name, phone, address, college, branch, graduation year, GitHub, Instagram), your referral link activity, and campaign-link clicks to operate the program and recognize top ambassadors. We do not collect, store, or process any payment or payout details, since the program has no cash payouts.

  • Application data: Name, email, phone, college, branch, graduation year, and social URLs - used to review your profile and manage your status.
  • Performance metrics: Link clicks and signups attributed to your code - used to display your stats on the settings dashboard and track referral count.
  • Attribution cookies: When visitors use your ?ref= link or custom campaign link, a cookie may be set so signups can be attributed to you (see Cookies section).

Ambassador performance data is accessible only to you (via the settings dashboard) and FitMyCV administrators. We retain it while your account is active and for a reasonable period afterward for legal and fraud-prevention purposes.

Data sharing & third parties

We do not sell your data. We do not share it with advertisers. Here is the complete list of third parties that touch your data:

Google OAuthPrivacy policy ↗

Authentication - verifies your identity when you sign in with Google. We receive your name, email, and profile photo.

MongoDB AtlasPrivacy policy ↗

Database - stores all your account, resume, cover letter, and billing data.

OpenAI / Anthropic

AI processing - receives resume text and job descriptions when you use AI features. See the AI section above.

Payment processing - handles card data and payment verification. We only receive the payment confirmation.

Cloudflare / AWSPrivacy policy ↗

Hosting - serves the application. May log request metadata (IP, user agent) per their infrastructure policies.

We may also disclose data if required by law or court order. We'll tell you if we can.

Data retention

Active account data

Retained for as long as your account exists. Resumes, cover letters, scores, billing history - all kept until you delete them or close your account.

Deleted account

When you request account deletion, your account is placed in a scheduled-deletion state for a 90-day grace period. During this time, you can cancel the request. After 90 days, all personal data, resumes, cover letters, portfolio content, published handle data, and profile records are permanently erased from our databases within 30 days. Anonymized aggregate analytics (no personal identifiers) may be retained.

Anonymous ATS analyses

Records from unauthenticated analyses (resume text + scores, no user ID) are retained for 90 days, then permanently purged.

Payment records

Transaction records may be retained longer than 30 days where required by financial regulations.

Your rights & controls

These aren't just legal checkboxes - they're real controls you can use right now.

Access your data

View all your resumes, cover letters, scores, and billing history from your dashboard at any time.

Export your data

Download any resume or cover letter as PDF, or export your entire personal account data (JSON) once per calendar month.

Delete your data

Delete individual resumes, cover letters, or request account deletion from Settings (with a 90-day cancellation grace period).

Correct your data

Update your name, email, phone, and profile links at any time from Settings.

Opt out of emails

Opt out of non-essential emails from notification settings. Transactional emails cannot be disabled.

Request information

Email us at fitmycv.team@fitmycv.site to ask what data we hold about you or how it's being used.

GDPR compliance (EU/EEA users)

If you are a resident of the European Union, European Economic Area (EEA), or the United Kingdom, you have specific rights under the General Data Protection Regulation (GDPR) and UK Data Protection Act:

  • Right of Access: You can request copies of the personal data we hold about you.
  • Right to Rectification: You have the right to request that we correct any inaccurate or incomplete information.
  • Right to Erasure ('Right to be Forgotten'): You can request that we erase your personal data under certain conditions.
  • Right to Restrict Processing: You have the right to object to or restrict the processing of your data.
  • Right to Data Portability: You can request to export your data in a structured, machine-readable format.
  • Consent Withdrawal: Since we only load analytical tracking scripts (like Google Analytics and Microsoft Clarity) after your explicit consent, you can withdraw your consent at any time via the cookie settings panel.

For any GDPR-related requests, or to exercise your rights, please email us directly at fitmycv.team@fitmycv.site. We will respond to your request within 30 days.

Cookies & tracking

We keep this simple because we don't do much here.

Essential session cookies

FitMyCV uses a secure session cookie (__session) to keep you logged in. Without it, the app cannot authenticate you. You can clear it by logging out or clearing browser storage.

No advertising cookies

We do not use Google Ads, Meta Pixel, or any third-party advertising trackers. There are no retargeting cookies on this site.

No cross-site tracking

We don't track you across other websites. What happens on fitmycv.site stays on fitmycv.site.

We may use localStorage to cache things like your country/currency preference and template selections. This data stays in your browser and is not sent to our servers.

Children's privacy

FitMyCV is a career tool for adults. The service is not intended for anyone under 16 years of age.

We do not knowingly collect personal data from minors. If you believe a child under 16 has created an account, contact us at fitmycv.team@fitmycv.site and we will delete the account and all associated data promptly.

Changes to this policy

If we make material changes to this policy - changes that affect how we collect, use, or share your data - we'll notify you by email and update the "Last updated" date at the top of this page.

Minor changes (fixing typos, clarifying language without changing substance) will be updated silently. The current version is always at fitmycv.site/privacy.

Continuing to use FitMyCV after a policy update means you accept the updated terms. If you don't agree, you can delete your account from Settings.

Contact us

Questions about this policy, data requests, or anything else privacy-related - reach us directly:

fitmycv.team@fitmycv.site

We aim to respond within 2 business days. For account deletion requests, include the email address associated with your account.