Privacy · 2026-08-17 · 12 min read
Privacy when using AI on your CV: what you share and what you do not
What happens to your résumé when you use AI? What data is sent, what we do not store, and how to review your CV with ClarCV — no card, no mandatory signup.
Uploading a CV to an AI product is a fair privacy question. A résumé is not an anonymous comment. It includes your name, career, and sometimes phone, email, and a photo. ClarCV treats it as personal data, not as “text to train a model”.
This guide explains what happens when you run analysis or generate a new CV: what is sent, to whom, for what, what is not done with that content, and what stays in your account so you can edit and download. The privacy policy is the legal text. This is the plain-language version.
The short promise
- We send the CV content needed to an AI provider (OpenAI, via API) only to fulfil your request: ATS analysis or a rewrite into a template.
- That content is not used to train general-purpose AI models.
- We do not sell your data or use it for targeted ads.
- We do not paste your CV into consumer ChatGPT (chatgpt.com). It goes through the business API, with a data-processing addendum (DPA).
- ClarCV does store what the product needs (account, file, results) while your account is active. You can request access or deletion at privacy@clarcv.com.
Be precise about “not stored”. OpenAI processes the request to return a result. We do not use it to train models and we do not authorize that use. ClarCV still needs to keep your account and uploaded CV; otherwise the editor and PDF download cannot exist. “Nothing is stored on any server” would be false. “Not used for training and not sold” is what we configure and can state.
What is sent (and what is not)
When you accept consent and start analysis or a rewrite, the backend extracts text from the PDF or Word file and sends that content to OpenAI. Where possible we reduce contact identifiers in the copy sent to the model (email, phone, profile links). We do not send your password or payment details. Stripe handles Pro checkout; card numbers do not sit on our servers.
If the PDF is an image (scan or flattened redaction), we may read the page as a picture to recover text. That is still for your request, not a public dataset. If you do not want a profile photo to travel, omit it or upload a file without an image.
Why sending is required
Useful ATS feedback and rewriting need the real text: roles, dates, achievements, skills. A model that cannot see your experience can only give generic advice. ClarCV tries to comment on THIS CV. That means transmitting content. Explicit consent exists for that reason: there is no silent AI analysis.
If you do not tick the box, the AI is not called. You can still read the guides, view pricing and templates, and upload nothing.
Model training: what we locked down
OpenAI’s platform API does not, by default, use customer API data to train general-purpose models. ClarCV’s organization also has input/output sharing for model improvement turned off, and a signed DPA: OpenAI is the processor; ClarCV is the controller. In practice your CV is used to produce YOUR report or YOUR template, not to “teach” ChatGPT your career.
That does not make AI a notary. Always review generated text (employer names, figures, tools) before you apply. Models can soften or invent a detail; you own the facts.
What ClarCV keeps in your account
So the product works across sessions: email (account), the file or extracted content, analysis results, chosen template, and download history depending on plan. That is your workspace, not “OpenAI keeps the CV forever for training”. If you close the account or request deletion, we handle it under the privacy policy and legal duties (billing records, and so on).
- Account: email and hashed password.
- Product: uploaded CV, analysis, editable content, generated PDF.
- Payment: Stripe (we do not store the card number).
- Measurement: Google Analytics 4 in aggregate (pages, not CV body text).
How to verify this inside ClarCV
Before analysis you will see a consent checkbox that names OpenAI and states the purpose (analysis or improvement), not training. The footer links the privacy policy, including the AI section. If something here does not match what you see, email privacy@clarcv.com. We prefer an awkward question to vague copy.
If you are data-sensitive (ClarCV or any tool)
- A job CV rarely needs national ID, exact home address, or social-security numbers.
- A photo is optional in many markets; skip it if it adds nothing.
- Use a PDF or Word with selectable text, not a scan of a paper full of extra data.
- Read consent. If a site will not say who receives the CV, do not upload a file with your phone and email.
- Keep your own original. The tool is an editor, not the only copy of your career.
A calm way to decide
ClarCV sends the CV to OpenAI to do the job you asked for. We do not sell it. We do not authorize training use. We keep account data so edit → template → PDF can exist. That is “safe” as in transparent and scoped, not magic: the internet still involves a provider. If that trade-off is not for you, do not upload; the templates and guides remain useful without AI.
FAQ
Does OpenAI train ChatGPT on my CV?
That is not authorized. We use the API, with training-sharing off, plus a DPA. Content is for your analysis or rewrite, not to train general models.
Does ClarCV sell my data?
No. We do not sell personal data or résumé content.
Is the file deleted the moment analysis ends?
Not necessarily. We keep it in your account so you can edit and download. You can request deletion at privacy@clarcv.com.
Can I use ClarCV without sending the CV to AI?
Yes: do not tick consent and do not start analysis. Creating from scratch or reading guides does not require an OpenAI call.
Where is the legal text?
In the Privacy Policy (AI section) and the Terms of Use. This guide is the plain explanation; the OpenAI contract is the processor DPA.