Skip to content

Last updated: 2026-09-24

Privacy

The short version: what the product needs to work is stored, none of it is ever sold, and the first-party cookies and browser signals used by this site are named below.

What we store

Account: your email address, a hash of your password (never the password), and your selected app language. If you sign in with Google, we also keep the Google account ID, name and profile picture link Google sends us (the openid, email and profile permissions). Related account evidence can include referral attribution, generation wallet records and review-task records.

Profile: the career history, projects and evidence you give us. This is the input every CV is written from, so it is stored until you delete it or close your account.

Criteria: the roles, seniority, locations and companies you track, plus which matches you have seen or dismissed.

Documents: the CVs we generate for you and the artifacts of each run, kept so you can download them again.

Purchases: what you bought, when, and the reference the payment processor gives us. Card details never reach our servers.

Messages and sessions: if you contact us or sign in, we may receive the connection facts that came with the request: your IP, browser user agent, approximate country, browser language and timezone. The customer portal may also send a shared random device ID and an optional browser-fingerprint signal; the fingerprint library's monitoring is disabled.

What never happens to it

Your data is never sold, rented, traded or shared for advertising.

Your profile and your CVs reach an employer only through the applications we file for you. Automatic applications are on by default; switch them off in Settings and nothing is sent.

Public models are never trained on your profile. It is read to write your documents and for nothing else.

Blog articles and their images come from our own content service, not from an advertising network.

Cookies, browser signals, analytics and advertising

This site uses Google Analytics 4 to count visits and a Meta advertising pixel to measure which ads bring people here. Both set cookies in your browser.

Our first-party acquisition cookies are cvr_anon (90 days), cvr_click (first touch, 90 days), cvr_click_last (last marked touch, 90 days), and cvr_oppref_candidates (ordered referral candidates, 30 days). Older portal sessions may also contain the legacy cvr_oppref referral hint; the server validates it at signup. They are shared with my.cvrocket.ai, the same product on a second hostname.

The shared cvr_device_id cookie is a random browser UUID kept for two years on .cvrocket.ai. IndexedDB keeps a recovery copy. The portal may send that ID and an optional FingerprintJS browser signal to our server; FingerprintJS monitoring is disabled, and the signal is omitted when collection fails.

We do not sell any of it. What the product itself needs in order to work is described above and is unchanged.

The job postings we collect

The market corpus is made of job postings published by employers on public career boards. It is data about jobs, not about you, and it exists whether or not you sign up.

Who else processes your data

Payments: Stripe, which handles the card and tells us only that a purchase succeeded.

Email: our transactional email provider, for verification, receipts, digests and the message telling you a CV is ready.

AI models: the model providers that draft and review your CV receive the material needed to do that. They are not given your account credentials or your purchase history.

Reply suggestions: to draft a reply to an employer's message in your inbox, OpenAI reads that conversation and your profile, and a draft is never sent until you press Send.

Voice input: when you dictate a reply, your browser records the audio and sends it to OpenAI to be turned into text, and we do not store the recording.

Contact form: LeadPending, which receives what you wrote so we can answer it. The form posts to this site's own server; your browser never talks to them.

Hosting: our own servers and object storage, where your profile and documents live.

Google Calendar: if you connect it, Google receives the interview events we add to your calendar.

Google Calendar

Connecting Google Calendar is optional, and only you can do it: from the calendar step when you set up your account, or from Google Calendar in Settings, on Google's own consent screen. If you never connect it, nothing in this section applies to you.

The connection asks Google for openid and email, so we know which Google account you connected, and for https://www.googleapis.com/auth/calendar.events.owned, which lets an app create, change and delete events in calendars you own.

We use that access for one thing. When an employer schedules an interview with you by writing to the address we receive mail at for you, we add the interview to your primary calendar, move it when they reschedule and remove it when they cancel. To find that event again, we look up that one interview by its own identifier. We only change events we created: if the employer's own invitation is already in your calendar, we leave it alone. We never read, change or delete any other event, and we do not read your schedule. Adding an event sends no email to anyone.

What we keep: the address and ID of the Google account you connected, the permissions Google granted, and one refresh token, encrypted at rest with AES-256-GCM. Access tokens are made from it each time one is needed and are never stored. For every interview we put in your calendar, we keep a record of the event (time, title, meeting link, organizer, guests and Google's ID for it), which message created or changed it, and when you connected and disconnected the calendar. Every change we make to your calendar is written, with the reason for it, to a log we never edit; the latest changes and their reasons are listed under Google Calendar in Settings, and the log is erased with the rest of your account's data when you ask us to delete your account.

Data we receive from Google is never sold, never shared with third parties, never used for advertising, and never used to train or improve AI or machine-learning models.

To disconnect, press Disconnect under Google Calendar in Settings. That revokes our access at Google and deletes the stored token. Interviews already added stay in your calendar. Deleting your CV Rocket account revokes the access the same way within a day. You can also remove CV Rocket's access yourself at myaccount.google.com/permissions; we delete the token the next time Google refuses it.

CV Rocket's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Notifications

You choose the channels: email, Telegram, or neither. Turning digests off stops the messages and leaves the account open.

Keeping and deleting

We keep your data while your account is open. Ask us and we will export it or delete it; deleting the account deletes the profile and the generated documents.

Records kept for accounting (that a purchase happened, and for how much) outlive the account, because tax law says so.

Contact

Privacy questions and deletion requests: our contact form.