Privacy Policy
Last updated: August 2026
Your privacy matters to us. This policy explains what data we collect, why, and how we protect it. EZCV is designed and operated to meet the requirements of the General Data Protection Regulation (GDPR) and to respect your rights over your personal data. To be clear about what that does and does not mean: EZCV has not undergone an independent GDPR certification or third-party compliance audit, and does not claim one.
Who Is Responsible For Your Data
The data controller for EZCV is:
> George-Cosmin Hanta
> Str. Rosia Montana nr. 4, bl. O5, sc. 1, et. 6, ap. 37
> Sector 6, Bucharest
> Romania
> contact@ezcv.app
EZCV is operated by an individual rather than a company. That does not change your rights or our obligations under GDPR in any way.
For anything concerning your personal data — including any request to exercise the rights below — write to contact@ezcv.app. That address reaches the person responsible for handling data subject requests.
We have not appointed a Data Protection Officer. Art. 37 requires one only where the core activity is regular, systematic monitoring of people on a large scale, or large-scale processing of special category data; EZCV generates and hosts documents for individual users and does neither. We are established in the European Union, so no Art. 27 representative is required — that obligation applies to controllers established outside the EU.
Data We Collect
We collect the minimum data necessary to provide the Service:
- Account information: Your name, email address, and profile picture (if using Google OAuth). We do not store your passwords.
- CV and cover letter data: The content you enter into your CVs and cover letters (personal details, work experience, education, etc.). This data is stored in our database to enable the Service.
- Public CV data: If you choose to make a CV public, the CV content and a customizable link slug are stored to enable public access. Public CVs are viewable by anyone with the link.
- Public CV view counts: We track how many times your public CV is viewed. This is an aggregate count and does not store information about who viewed your CV.
- Payment information: If you make a payment, Stripe processes the transaction. We store only the Stripe payment ID and payment date — never your card details.
- Sign-in records: When you sign in we store the date, your IP address and your browser's user-agent string, and we record the date of your most recent sign-in. This is used to keep you signed in, to detect abuse, and to identify accounts that have gone unused (see Data Retention).
- System activity & error logs: We record your activities within the app (e.g., logins, PDF exports, payments, public link changes) and any technical errors you encounter. This diagnostic data is linked to your account to help us debug issues, provide customer support, and maintain platform security.
- Performance data: We measure page-loading performance (Core Web Vitals) using our own systems. These measurements include the page address and your browser's user-agent string, and are linked to your account where you are signed in. They are not shared with any third party.
- Server logs: Our hosting provider, Cloudflare, records each request to the site — including your IP address, the page requested and your user agent — as part of delivering and protecting the service. We use the aggregate view of this data to understand traffic levels.
We do not use advertising networks, third-party analytics scripts, cross-site trackers, or profiling of any kind.
Public CV Sharing
When you enable public sharing for a CV:
- Your CV becomes accessible via a unique link (e.g., EZCV/p/slug)
- Free users get one public CV with a randomly generated link
- Paid supporters can customize their main public CV link with a memorable slug of their choice
- Anyone with the link can view your CV without logging in. Public links are not access-controlled: the address is hard to guess, but it is not a password, and anyone you share it with can pass it on
- We track the number of views but not who viewed it
- You can disable public sharing or change your link at any time for the custom slug
- Deleting your CV or account immediately removes public access
You are responsible for the personal information you choose to make public. Consider carefully what details to include in publicly shared CVs.
Legal Basis for Processing (GDPR)
Each purpose has one legal basis:
- Contract — Art. 6(1)(b). Storing your account, CVs and cover letters, generating PDFs and providing exports. This is what delivers the Service you signed up for.
- Legitimate interests — Art. 6(1)(f). Keeping sign-in records, rate-limiting requests, monitoring errors and measuring performance, so the Service stays secure, available and working.
- Legal obligation — Art. 6(1)(c). Retaining payment records, as accounting and tax law require.
- Consent — Art. 6(1)(a). Publishing a CV at a public link, and allowing search engines to index it. Only if you turn these on yourself.
- Explicit consent — Art. 9(2)(a). Publishing a CV that may contain sensitive details (see below). Only if you turn public sharing on.
Where we rely on legitimate interests, we have considered whether our interest in running a secure and functioning service is overridden by your rights, and concluded it is not; you may object at any time (see Your Rights).
Where we rely on consent, you may withdraw it at any time by turning public sharing or search indexing off in your CV's sharing settings, without affecting anything done beforehand. Withdrawing consent for public sharing does not affect your account or your ability to use the Service privately.
Sensitive (Special Category) Information
CVs often contain information that GDPR treats as a special category under Article 9 — for example health conditions or disabilities, trade union membership, religious or political affiliations implied by an employer or volunteer role, or ethnicity implied by a photograph.
You decide what goes in your CV. We do not ask for this information, we do not analyse it, and we do not use it for any purpose beyond storing and displaying the document you created.
If you make a CV public, you are explicitly consenting to publish whatever it contains, including any such details, to anyone with the link. Please review your CV before sharing it publicly. You can withdraw this at any time by turning public sharing off, which immediately removes public access.
Automated Decision-Making
We do not make any automated decisions that produce legal effects or similarly significantly affect you. Optional AI assistance can draft suggested wording for a new CV based on a job title you type in; the output is a starting point you are free to edit or discard, and it does not evaluate you or make decisions about you.
Your Rights (GDPR)
Under GDPR, you have the right to:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Correct any inaccurate personal data.
- Erasure: Request deletion of your personal data ("right to be forgotten"). Deleting your account removes all your CVs, cover letters, and personal information.
- Data portability: Export your CV data in a standard format.
- Restriction: Request restriction of processing in certain circumstances.
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Turn off public sharing or search indexing at any time.
Access and portability are available immediately and without asking: sign in and use Export my data in your settings to download everything we hold about you as a JSON file. Deleting your account is likewise self-service, in the same place.
For anything else, contact us at the address below. We respond within one month, as required by Art. 12(3).
You also have the right to complain to a supervisory authority. If you are in Romania, that is the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest — . If you live elsewhere in the EU or EEA, you may complain to your own country's authority instead.
Data Storage & Security
Your data is stored in Cloudflare D1, with generated PDFs cached in Cloudflare R2. Both are provisioned in the European Union. All traffic uses encrypted connections (HTTPS/TLS). Every request for your data is checked against your signed-in session, so one account cannot read another's CVs, cover letters or billing records. Administrative access is a separate, explicitly granted permission held by the operator alone, and is used only for support, troubleshooting and security.
Critical paths — signing in, editing, exporting and public sharing — are covered by automated tests that run against a staging deployment before any release reaches this site. Testing reduces risk; it cannot guarantee that software will never contain a vulnerability, and we would rather say so than imply otherwise. If you believe you have found a security issue, see Reporting a security issue below.
Our administrators can access account data, activity logs and CV content, solely to provide support, resolve technical problems and keep the platform secure.
We never sell your personal data, and we do not share it for advertising.
Who Else Processes Your Data
We use a small number of service providers. Each processes data on our behalf under appropriate data-protection terms, and each is used only for the purpose listed:
- Cloudflare — hosting, database, file storage, security and request logs. Receives all Service data, along with your IP address and user agent. Our databases and file storage are provisioned in the European Union.
- Stripe — payment processing. Your payment details go directly to Stripe; we never see or store your card number. Transfer safeguard: EU–US Data Privacy Framework.
- Resend — sending email, as a fallback when our primary route fails. Receives your email address and the message. Transfer safeguard: Standard Contractual Clauses.
- Sentry — error monitoring. Receives technical error reports. Personal data is stripped before an error leaves our servers: request bodies, cookies and captured local variables are dropped entirely, and recognisable values such as email addresses and access tokens are redacted. That filter is covered by automated tests. Transfer safeguard: EU–US Data Privacy Framework.
- Google — optional AI drafting assistance. Receives only the job title you type when asking for a starter CV — never your CV content. Transfer safeguard: EU–US Data Privacy Framework.
International Transfers
Your CVs, cover letters and account data are stored in the European Union. Some processing nonetheless takes place in the United States, because Stripe, Resend, Sentry and Google are established there.
Transfers to US processors rely on the EU–US Data Privacy Framework adequacy decision and on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, as listed against each provider above. You may request details of these safeguards using the contact address below.
Data Retention
We keep personal data only as long as it serves a purpose:
- Your account, CVs and cover letters — until you delete them, or until your account is deleted for inactivity (below).
- Unused accounts — deleted after 12 months without a sign-in. We email you a warning 30 days beforehand and a final reminder 7 days beforehand. Signing in at any point cancels the deletion and resets the clock.
- Sign-in sessions — removed once they expire.
- Activity and error logs — 90 days.
- Payment webhook records — 30 days, after which the personal details are erased and only the transaction reference is kept.
- Performance measurements — 7 days.
- Cached PDF exports — 60 days, or immediately when you delete the document or your account.
- Database backups — 30 days. Backups exist so we can restore the Service after a failure. Because a backup is a snapshot, data you delete may persist in one until it expires; we do not use backups for any other purpose. If we ever restore one, deletions are re-applied automatically — we keep a record of which accounts have been erased, checked nightly, so a restore cannot quietly bring one back.
- Erasure records — 120 days. When an account is deleted we keep an internal note that it was deleted: an anonymous internal identifier and a date, with no name, email or content. Its only purpose is to make sure a deleted account stays deleted, and it is kept longer than our backups so it always outlives them.
Deleting your account removes your profile, CVs, cover letters, connected sign-in methods, sessions, reviews and any cached PDF exports.
Billing records are the one exception. Accounting and tax law requires us to keep proof of transactions for several years, and Art. 17(3)(b) GDPR provides that the right to erasure does not apply where processing is necessary to comply with a legal obligation. So when you delete your account we keep a minimal billing record — the transaction reference, amount, currency, date, and the billing address if Stripe supplied one — and nothing else. It holds no link to your account, no CV or cover letter content, and no profile data. It is used solely to satisfy those statutory obligations and for no other purpose. Stripe separately retains its own invoice records as required for billing compliance.
Cookies
We use only essential cookies, for signing you in and keeping you signed in. We use no advertising cookies, no tracking cookies and no third-party analytics cookies. Because these cookies are strictly necessary to provide a service you asked for, no cookie banner is required.
Children
The Service is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
Reporting a security issue
If you believe you have found a security or privacy vulnerability, please email the address in the Contact section below with enough detail to reproduce it. We will acknowledge your report and tell you what we find.
Please give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly, and please do not access, modify or delete data belonging to anyone else while investigating — use an account you control. We do not operate a paid bug bounty, and we will not pursue anyone who reports a genuine issue in good faith under these terms.
Changes To This Policy
If we change how we handle your data, we will update this page and change the date at the top. Where a change materially affects your rights, we will tell you by email.
Contact
For any privacy-related question, or to exercise your GDPR rights, contact us at . Full controller details are at the top of this policy.