Privacy Policy
CvBFF Chrome Extension · Last updated: May 2026
CvBFF ("we", "our", or "the extension") is a Chrome extension that reads job postings and generates tailored CVs and cover letters. This policy explains what data we collect, why, how it is stored, and your rights over it.
1. What data we collect
Account information
- Your email address — used to create and identify your account.
- Your password — never stored or seen by us. It is handled entirely by Supabase Auth using industry-standard bcrypt hashing.
Profile information (entered by you in Settings)
- First name, last name, location, phone number, LinkedIn URL
- Work history: job titles, company names, dates, and role descriptions
- Education: institutions, degrees, years
- Skills and languages
- Optional profile photo
Job posting text
- When you click "Read this page", the text of the job posting currently open in your browser tab is captured and temporarily stored locally on your device. It is sent to our servers only when you click Generate.
Generated content
- The tailored CV and cover letter generated by the AI are stored on our servers until you unlock them. After unlocking, the content is also stored within your Applications history so you can retrieve it later.
Application history
- Job title, company name, fit score, generated CV HTML, and cover letter text for each application you save.
Payment information
- We do not collect or store any payment card details. All payment processing is handled by Stripe. We receive only a confirmation that a payment was completed and the number of credits to add to your account.
Usage data
- Your credit balance and the timestamps of your generations. No browsing history, no tracking pixels, no analytics.
2. How we use your data
- To provide the service — your profile and the job posting text are sent to an AI model to generate a tailored CV. Nothing else.
- To manage your account — your email is used to authenticate you and send any essential account emails (e.g. password reset).
- To process payments — your email may be shared with Stripe to pre-fill the checkout form.
- We do not sell your data. We do not use your data for advertising. We do not share it with any third party except the service providers listed below.
3. Third-party service providers
We use the following providers to operate CvBFF. Each provider processes data only as instructed by us and under their own privacy policies.
- Supabase — authentication, database storage (EU region). Privacy policy
- Cloudflare — API proxy and serverless compute. Job posting text and profile data pass through Cloudflare Workers during generation. Privacy policy
- Anthropic — AI model provider. Your profile data and job posting text are sent to Anthropic's Claude API to generate CV and cover letter content. Anthropic does not use API data to train their models. Privacy policy
- Stripe — payment processing. Card details never reach our servers. Privacy policy
4. Data storage and security
- All data in transit is encrypted via HTTPS/TLS.
- Database access is protected by Row Level Security — each user can only access their own data.
- Session tokens are stored locally in your browser using the Chrome extension storage API and are never transmitted except to authenticate your requests.
- The full content of generated CVs is stored server-side and is only returned after a credit is spent — it is never exposed in your browser before payment.
- We do not retain job posting text beyond the duration of your active session.
5. Data retention
- Your profile and application history are retained for as long as you have an account.
- You can delete individual applications from within the extension at any time.
- To delete your account and all associated data, contact us at the email below. We will process the request within 30 days.
6. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Data portability (receive your data in a machine-readable format)
To exercise any of these rights, email us at the address below.
7. Children
CvBFF is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
8. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. Continued use of the extension after changes are posted constitutes acceptance of the updated policy.