Privacy Policy

Last updated July 3, 2026

Cvali is an ATS resume scanner and job-search toolkit. This page explains what we collect, why, and where it lives - in plain language, not legalese.

What we collect

  • Your resume file (PDF or DOCX) when you scan it, build one, or generate a cover letter.
  • The job description text you paste or that gets pulled from a job posting.
  • Your email address, only if you create an account (Google sign-in).
  • A hashed version of your IP address for anonymous scans, used only to apply fair-use scan limits - never stored as your raw IP.

Why we collect it

To compute your ATS match score, generate a tailored resume or cover letter, and - if you're logged in - save your scan history and job tracker so you can come back to it.

Where it's stored

Resumes and scan results are stored in Supabase (Postgres database + file storage), the backend Cvali runs on. Account login is handled by Supabase Auth via Google OAuth - Cvali never sees or stores your Google password.

AI processing

Your resume text and the job description are sent to the DeepSeek API to generate the match score, keyword analysis, rewritten resume content, or cover letter. This text is processed to return a result to you and is not used by Cvali to train any model.

The Chrome extension

The extension stores your resume and applicant profile locally in your browser, on your device. Nothing is uploaded anywhere except to the Cvali scan API at the moment you run a scan. Autofill only touches the page you're on - it never sends form data anywhere else.

What we don't do

No ads, no ad trackers, no selling your data to third parties. Cvali doesn't currently run any third-party analytics.

Your data, your control

Cvali is early - a self-serve delete option isn't built yet. Until it is, email support@cvali.com to request access to or deletion of your data, and it'll be handled directly.