Privacy policy
Last updated 25 September 2026
This policy explains what personal data SikerCV collects, why, who it goes to, how long we keep it, and the rights you have. It covers the SikerCV website, the app, and CV reviews booked through it.
The short version: we keep what we need to build your CV, run your account and your reviews, and keep the service safe. We do not sell your personal data, and there are no ads in the app.
1. Who we are
SikerCV is run by [Company name], [Registered address], company number [Company registration number] ("we", "us"). We are the controller of the personal data described in this policy.
For anything about your data, write to [privacy@yourdomain].
2. What we collect, and where it comes from
Most of it comes from you. Some comes from the services you choose to use with SikerCV, and some is recorded automatically when you use it.
- CVs made without an account. The content of the CV you type in, including any photo you add. Your browser keeps a random key that links the CV to it. We do not learn your name or email this way, unless you type them into the CV.
- Account details. Your email address, your password (stored only as a salted hash, never in readable form), and which sign-in providers you have linked.
- Sign-in providers. If you sign in with Google, GitHub or LinkedIn, the provider tells us your email address, whether it has verified it, and an ID for your account there. We do not receive your password for those services.
- Your CVs and documents. Everything you put in a CV (which often includes your name, contact details, work history, education and a photo), your saved styles, and any share links you create.
- ATS checks. The CV or file you check (a PDF, Word or text file is read during the check and not stored) and the job posting you paste or link to.
- CV reviews. Your bookings, the CV you attach, messages with the reviewer, the reviewer's notes, and the times and status of each session.
- Reviewer details. If you apply to review CVs: your display name, headline, bio, where you are based, the languages you review in, your experience, your prices, availability and time zone, your meeting link, and your Stripe payout account ID. If you connect Google Calendar, an access token for it.
- Payments and plans. Your plan, subscription status, and a reference to your Stripe customer and payments. Card details go to Stripe directly; we never see or store them.
- Emails. The emails we send you, kept in our outbox with their status.
- Activity and security records. What you do in the app (for example: a CV made, downloaded or shared, an ATS check run, a booking made), sign-in events, and for each session the IP address and browser used.
- Cookies and similar technology. See Cookies below.
- The waitlist. Before launch, the website may offer a waitlist form. If you join it, we receive the email address you give.
Please do not put special categories of data (such as health, religion or political views) in a CV unless you want an employer to read them.
3. Why we use it, and our legal basis
We only use personal data where the law gives us a basis for it. Under the GDPR these are:
| What we do | Legal basis |
|---|---|
| Build, store, preview and export your CVs, with or without an account | Contract: it is the service you asked for |
| Create and run your account, and sign you in, including with Google, GitHub or LinkedIn | Contract |
| Run the ATS check, including fetching a job posting from a link you give | Contract |
| Arrange CV reviews: bookings, messages, meeting links, calendar invites, payments, refunds and reviewer payouts | Contract |
| Sell and manage paid plans and add-ons | Contract |
| Send emails about your account, bookings, messages and payments | Contract |
| Keep the service secure: sign-in limits, IP blocks, session records, and investigating abuse | Legitimate interest in protecting you, other users and the service |
| Understand how features are used, from the activity log, to fix problems and improve SikerCV | Legitimate interest in running and improving the service |
| Decide a reported session, answer support requests, and enforce our terms | Legitimate interest, and contract |
| Measuring which pages and features are used, through Google Tag Manager and Google Analytics | With your consent, using analytics cookies. Without it, counts with no cookies or identifiers, on our legitimate interest in knowing what is used |
| Tell you when we open, if you joined the waitlist | Consent |
| Keep payment and tax records, and answer lawful requests from authorities | Legal obligation |
Where we rely on legitimate interest, we have weighed it against your rights, and you can object (see Your rights). We do not use your data for decisions that have legal or similarly significant effects on you by automated means alone. The ATS check is automatic keyword matching; it is a guide for you and is not shared with employers.
5. Transfers outside the EU
Some of the providers above (Google, Stripe, Cloudflare, Daily.co, Formspree, GitHub, LinkedIn) may process data outside the European Economic Area, mainly in the United States.
Where that happens, the transfer is covered by an adequacy decision of the European Commission (such as the EU-US Data Privacy Framework, for companies certified under it) or by the Commission's Standard Contractual Clauses, with extra safeguards where needed. You can ask us for a copy of the safeguards that apply.
6. How long we keep it
| Data | Kept for |
|---|---|
| A CV made without an account | 48 hours after its last save, then deleted automatically. Signing in moves it into your account instead. |
| Your account and CVs | While your account is open. You can delete any CV at any time. |
| A closed account | [Retention period for closed accounts], or erased sooner when you ask (see Your rights) |
| Sign-in session | Up to 30 days; it ends after 30 minutes without activity |
| Session records (IP address and browser) | 5 years from the session's start, or cleared sooner on request |
| Activity log (holds no IP address) | Currently kept with no set end date |
| A job posting fetched from a link | Used for 7 days, then fetched again and replaced. It is the public posting text, not linked to you. |
| Password reset links | 1 hour |
| Download links for a PDF | About 2 minutes, and they work once |
| Bookings, messages and review notes | While the account of either side is open |
| Payment and tax records | [Number] years, as required by [Country] law |
| Sent emails in our outbox | [Retention period for emails] |
| Blocked IP addresses | While the block lasts, and a record of it for [Retention period for blocks] |
| Encrypted database backups | Up to 30 days |
| Waitlist emails | Until we open, or until you ask us to remove yours |
8. Your rights
Under the GDPR, you have the right to:
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate data corrected. You can edit most of it yourself in the app.
- Erasure: have your data deleted. You can delete any CV yourself. Deleting your account in the app closes it at once, cancels open bookings (refunding any held payment) and ends any paid plan. To have the data erased as well, not only the account closed, write to us.
- Restriction: ask us to limit how we use your data, for example while a correction is checked.
- Portability: receive the data you gave us in a structured, machine-readable format.
- Objection: object to our use of your data based on legitimate interest. We then stop, unless we have compelling grounds, or need it for a legal claim.
- Withdraw consent: at any time, for anything based on consent, such as analytics cookies (use "Cookie settings"). This does not affect what was done before.
- Complain: to a data protection supervisory authority, in particular in the country where you live or work, or where you think the problem happened. Ours is [Supervisory authority]. We would like the chance to help first.
To use a right, write to [privacy@yourdomain], if you can from the email on your account. We answer within one month. We may ask you to confirm who you are. Using your rights is free.
9. Children
SikerCV is not meant for anyone under 16, and we do not knowingly collect their data. If you believe a child under 16 has given us personal data, write to us and we will delete it.
10. Security
We protect your data with measures that fit the risk, including:
- Encrypted connections (HTTPS) everywhere.
- Passwords stored only as salted hashes (scrypt).
- Google Calendar tokens stored encrypted (AES-256-GCM).
- A sign-in cookie scripts cannot read, sessions that end when idle, and limits on sign-in attempts.
- Backups encrypted before they leave our server.
- Admin access only for people who need it, with every admin action logged.
No system is perfectly secure. If a breach puts your rights at risk, we will tell you and the supervisory authority as the law requires.
11. Changes to this policy
When this policy changes, we update the date at the top of this page. If a change matters for how we use your data, we will also tell you by email or in the app before it takes effect.
12. Contact
[Company name], [Registered address]. Email: [privacy@yourdomain].