Privacy Policy
Last updated: July 2026
Introduction
CVite is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our job application workflow to build, tailor, and send applications. We follow a local-first approach, meaning your data stays on your device by default.
Information We Collect
We collect minimal information necessary to provide our services. This includes: account information (email address) when you sign in with Google or GitHub, usage analytics to improve our service, and technical information like browser type and device information for troubleshooting.
Local-First Storage
Your resume data is stored locally on your device by default. We cannot access, read, or modify your resume content unless you explicitly enable cloud sync. This ensures your personal and professional information remains private and under your control.
Cloud Sync (Optional)
If you choose to enable cloud sync, your resume data will be stored on our secure servers powered by Supabase. This data is encrypted in transit and at rest. You can disable cloud sync at any time, and we will delete your cloud-stored data upon request.
Connected AI Clients and MCP
When you connect an AI client through CVite's MCP integration, that client can access only the capability groups you approve, such as resume content and layout, ATS results, job information, previews, or exports. CVite stores the connected client identifier, client name, approved permissions, and grant timestamps so it can enforce and revoke access. That record is kept until you disconnect the client or delete your account. Authentication tokens expire according to the authorization server's lifetime. Technical security and troubleshooting logs may be retained for up to 30 days; CVite does not intentionally log access tokens or complete resume content. CVite does not expose your password to the client. Data returned to a connected AI client is also handled under that client's privacy terms. You can deny a connection or revoke its access at any time.
AI Features
When you use our AI writing features, the text you submit is processed by Google's Gemini AI to generate suggestions. This data is not stored permanently and is only used to provide the requested AI assistance. We do not train AI models on your personal data.
Cookies and Analytics
We use essential cookies for authentication and session management. We may use analytics services like PostHog to understand how users interact with our application. You can opt out of analytics tracking through your browser settings.
Third-Party Services
We use the following third-party services: Supabase for authentication and optional cloud storage, Google Gemini for AI features, and PostHog for analytics. Each service has its own privacy policy governing how they handle data.
Data Security
We implement industry-standard security measures to protect your data, including HTTPS encryption, secure authentication protocols, and regular security audits. However, no method of transmission over the Internet is 100% secure.
Your Rights
You have the right to access, correct, or delete your personal data at any time. You can export your resume data, disable cloud sync, revoke connected AI clients, or delete your account entirely. Contact us at support@cvite.app for any privacy-related requests.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the 'Last updated' date.
Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us at support@cvite.app.