CVSet

Legal

Privacy Policy

What we collect, why we hold it, and what you can ask us to do with it.

Last updated: 9 August 2026

This notice explains how CVSet handles your personal data.

1. Who we are

CVSet is built and run by a two-person team based in London, United Kingdom — a software engineer and a designer. We are not yet incorporated as a registered company. If that changes, we will update this page.

We are the data controller for the personal data described in this notice. That means we decide what is collected and why.

You can reach us about anything in this notice at [email protected], or through the contact page.

2. What this notice covers

This notice covers cvset.io and the CVSet application. It explains what we collect, why we hold it, who we share it with, and what you can ask us to do.

It does not cover other websites you reach from links on our site.

3. What we collect

Account information: your name and email address, which we receive from Microsoft Entra ID when you sign in.

CV content: the CVs you upload, and everything written in them.

Job information: the job descriptions and job adverts you paste in, and the applications you track.

Product activity: the analyses, optimisations and tailorings you run, the results we produce, and how you interact with them.

Messages and attachments: anything you send us through the contact page, including files and screenshots you attach.

Payment information: your purchase history and the record of your pass. Card details are handled by Stripe and never reach our systems.

Technical information: your IP address, browser and device type, and basic usage logs.

4. Where we get it from

Almost all of it comes directly from you — what you type, upload, paste or attach.

Some comes automatically when you use the site, such as technical and usage information.

A small amount comes from our providers: your name and email from Microsoft Entra ID when you sign in, and confirmation of payment from Stripe.

5. Why we use it

To provide the service: analysing, optimising and tailoring your CV, and keeping your work available in your account. Our legal basis is performance of our contract with you.

To take payment and keep records of it. Our legal basis is performance of our contract, and legal obligation for tax and accounting records.

To answer your messages and handle refund requests. Our legal basis is performance of our contract and our legitimate interest in running a supportable service.

To keep the service secure, prevent abuse, and fix faults. Our legal basis is our legitimate interest in protecting the service and our users.

To improve CVSet by understanding which features are used and where they fail. Our legal basis is our legitimate interest in improving what we offer.

Where we rely on legitimate interests, we have considered whether that interest is outweighed by your rights. You can object to any of it — see section 11.

6. Your CV and sensitive information

A CV can reveal more than employment history. Depending on what you have written, it may indicate health or disability, ethnicity, religion, political or trade union involvement, or sexual orientation. Under data protection law these count as special category data and are given extra protection.

We do not ask for this information and we do not use it to make decisions about you. It reaches us only because it happens to appear in a document you chose to upload.

Where special category data is present, we process it only so far as is necessary to provide the service you asked for, and on the basis that you have made it available to us for that purpose.

If you would rather we did not hold something, remove it from your CV before uploading, or delete the CV from your account.

7. How AI is used

CVSet uses AI models to analyse your CV, suggest improvements and produce tailored versions. To do that, your CV content and the job description you provide are sent to the Microsoft Azure OpenAI Service for processing. Uploaded CV files are also read by Azure Document Intelligence so their text can be extracted.

Your CV is never used to train or improve AI models — not ours, and not Microsoft's. Under the Azure OpenAI Service terms, content sent to the service is not used to train Microsoft's models; it may be held briefly for abuse monitoring and is then deleted. We do not retain your CV anywhere beyond your own account.

Scores, suggestions and match percentages are produced automatically. They are advice for you to accept, reject or ignore. They are not decisions about you, they are not shared with employers, and they have no legal effect on you.

Nothing CVSet produces is written for you without your review. You decide what goes into your CV.

8. Who we share it with

We do not sell your personal data, and we do not share it for advertising.

We use a small number of providers who process data on our behalf, under contract and on our instructions:

Microsoft Azure OpenAI Service and Azure Document Intelligence — processing CV and job description content to produce analyses and tailorings.

Microsoft Entra ID — managing sign-in and account security.

Stripe — selling the pass to you as merchant of record, taking payment and holding card details. We never see your card number.

Microsoft Azure — running the service and storing your data, across Azure Container Apps, Azure Database for PostgreSQL and Azure Blob Storage.

Brevo — sending account and support emails.

We may also disclose data where the law requires it, or to establish or defend legal claims.

9. Where your data is held

Your account, your CVs and everything you create are stored in the Microsoft Azure UK South region. AI processing runs in the Azure Sweden Central region, because that is where the models we use are available.

Some of our providers process data outside the UK. Where that happens, we rely on the safeguards permitted by UK data protection law — an adequacy decision covering the destination country, or standard contractual clauses with the provider.

Azure OpenAI Service and Azure Document Intelligence process CV and job description content in Sweden Central, inside the EEA, which the UK recognises as offering adequate protection. Brevo, which sends our email, is also in the EEA and covered by the same recognition. Microsoft Entra ID and Stripe may process limited account and payment data outside the UK; both are covered by standard contractual clauses in their contracts with us.

10. How long we keep it

Account information: for as long as your account is in use. If you do not hold a pass, we email you to say the account will be deleted — 7 days after sign-up if you have never held one, or once your pass ends. We then erase it 30 days after that email unless you buy a pass in the meantime. If the last pass you bought was a Monthly pass, we keep the account for 90 days after that email instead. The email tells you the exact date, and that is the date we act on.

CVs, tailorings and job information: until you delete them, or until your account is erased. Optimisation sessions you do not return to are cleared automatically after 7 days.

Messages and attachments sent through the contact page: 12 months after the request is resolved.

Payment and purchase records: six years, as tax law requires.

Technical and usage logs: 90 days.

You do not have to wait for these periods. You can delete your CVs and your account at any time from Settings.

11. Your rights

You can ask us for a copy of the personal data we hold about you.

You can ask us to correct anything that is wrong.

You can ask us to delete your data. You can also do this yourself from Settings.

You can ask us to restrict how we use your data, or object to us using it where we rely on legitimate interests.

You can ask us to send your data to you, or to another provider, in a portable format.

Where we rely on your consent, you can withdraw it at any time. That does not affect anything done before you withdrew it.

To exercise any of these, contact us at [email protected]. We will respond within one month. There is no charge.

12. Cookies and analytics

We use cookies that are strictly necessary to run the site — keeping you signed in, and keeping your session secure. These do not need your consent.

We do not use analytics, advertising, or any other non-essential cookies.

You can control cookies through your browser settings, though blocking essential ones will stop parts of the site working.

13. How we protect your data

Data is encrypted in transit and at rest. Access is limited to the people who need it to run the service — currently a team of two.

Sign-in is handled by Microsoft Entra ID. CVSet never receives or stores your password.

No system is perfectly secure. If a breach happens that puts your rights at risk, we will tell you and the Information Commissioner's Office as the law requires.

14. Children

CVSet is not intended for children. You must be 16 or over to create an account.

If you believe a child has given us personal data, contact us and we will delete it.

15. Changes to this notice

We may update this notice as the service changes. The date at the top shows when it was last updated.

If a change materially affects how we use your data, we will tell you directly rather than relying on you to check this page.

16. How to complain

If you are unhappy with how we have handled your data, tell us first at [email protected]. We would rather fix it directly.

You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection, at ico.org.uk. You do not have to come to us first.


Question about your data?Contact us