Privacy Policy
Last updated:
This policy explains what Refine CV Builder (“we”, “the app”) collects when you use the mobile app or this website, why we collect it, who else processes it, and how you get rid of it.
1. Who is responsible
Refine CV Builder is the data controller for the information described here. For any question about your data, write to [email protected].
2. What we collect
Account information
When you first open the app it creates a guest account identified by a device identifier, so you can start immediately without signing up. If you later create an account we also store your email address and, if you sign in with Google or Apple, the account identifier and email that provider returns to us. We never receive your Google or Apple password.
The content you write
Everything you put into a CV or cover letter — name, contact details, employment history, education, skills, languages, projects, references, and any photo you upload — is stored on our servers so it is still there when you change or reinstall your phone. This content is yours. We do not sell it, we do not share it with recruiters or advertisers, and we do not use it to train any model.
Device and usage information
To deliver the service we store: platform (iOS/Android), operating system version, device model, app version, language, time zone, and — if you allow notifications — a push token. We also record when your device last contacted us, which is what lets us clean up abandoned installs.
Subscription information
If you subscribe, we store which product you bought, when it started, when it expires and whether it renews. We never see or store your card details — the payment happens entirely inside the App Store or Google Play.
3. Why we are allowed to process it (GDPR / KVKK)
| Purpose | Legal basis |
|---|---|
| Creating your account and storing your CVs | Performance of a contract |
| Generating and delivering PDF exports | Performance of a contract |
| Verifying subscriptions and preventing fraud | Legitimate interest |
| Sending push notifications | Consent (you can revoke it at any time) |
| Product analytics | Legitimate interest |
| Keeping accounting records | Legal obligation |
4. Who else processes your data
We use a small number of processors. Each one receives only what it needs:
| Processor | What it receives | Why |
|---|---|---|
| Our hosting provider | Everything described above | Runs the servers and database |
| RevenueCat | An anonymous account identifier and your purchase events | Verifies subscriptions across App Store and Google Play |
| Google Firebase (Cloud Messaging, Analytics) | Push token, device and app version, anonymous usage events | Delivers notifications and shows us which features are used |
| Apple / Google sign-in | Only what you approve at the sign-in prompt | Lets you sign in without a new password |
Rendering your CV into a PDF happens on our own servers. Your CV content is not sent to any third-party document service.
5. Where data is stored and for how long
Data is stored on servers in the European Union. We keep it for as long as your account exists. When you delete your account, your CVs, cover letters, uploaded photos, generated PDFs and device records are deleted with it. Anonymous accounting records are kept for as long as tax law requires (10 years in Türkiye); these cannot be linked back to you.
6. Your rights
You can request access to your data, correct it, have it deleted, object to processing, or receive a copy in a portable format. The fastest routes are:
- Deletion: in the app under Profile → Delete account, or from our account deletion page.
- Everything else: email [email protected]. We respond within 30 days.
If you are in the EU or the UK you may complain to your local data protection authority; in Türkiye, to the KVKK.
7. Children
The app is meant for people old enough to work and is not directed at children under 13 (16 in the EEA). We do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.
8. Security
Traffic is encrypted in transit (TLS). Passwords are stored hashed, never in plain text. Authentication tokens are held in the device keychain rather than in ordinary app storage. Download links for generated PDFs are signed and expire. No system is perfectly secure, but we design so that a single failure does not expose your documents.
9. Changes
If this policy changes materially we will update the date at the top of this page and, where the change affects how your data is used, notify you in the app before it takes effect.