Legal

Privacy Policy

Last updated June 4, 2026

This policy explains what Tailored (“Tailored”, “we”, “us”) collects when you use our product at https://cv-ai-app-lac.vercel.app, why we collect it, who we share it with, and the rights you have over it. We've tried to keep it readable. If anything here is unclear, please email gor.mikaelyan.eworld@gmail.com.

1. The short version

2. What we collect

Account information

When you sign in with Google we receive your email address, display name, and profile image from Google. We don't see or store your Google password.

Content you create

Resumes you upload or generate, job descriptions you paste, cover letters, application notes, and your profile photo (if you upload one). We store this so you can access it across sessions and so our AI features can work. We do not train AI models on this content.

Usage analytics

We capture product usage events (page views, button clicks, AI generation counts) via PostHog. These events carry no resume or job-description text — only counts, durations, file types, and anonymous identifiers.

Only if you say yes. PostHog is not loaded at all until you accept on the banner — not loaded and held back, but never started: no script, no request, no identifier. Declining is a complete answer and nothing else about the product changes. If Do Not Track is set in your browser we treat that as a no and never ask.

Page-view counts and loading-speed measurements from Vercel run without asking, because they set no cookie, create no identifier you carry between sites, and record no individual — only totals.

The help assistant

When you ask the in-product assistant a question, we store the question — on its own. Not your name, not your account, not your IP, not the answer, and not the rest of the conversation. It is kept for 30 days and then deleted. We do it so we can see which parts of the product people cannot work out, and it is stored with nothing attached so that it cannot later be connected to you.

The assistant is not given your account or your CV, so it cannot discuss them even if asked.

Billing data

When you buy credits or subscribe to Pro, Stripe processes your card. We never see or store your card number, CVC, or expiry — Stripe handles all of that on PCI-compliant infrastructure. We store a Stripe customer ID and your subscription state (tier, renewal date, cancellation flag).

Technical data

Standard server logs (IP address, user agent, request timestamps) for security and abuse prevention. Logs are retained for 30 days.

3. How we use it

4. Sub-processors

We rely on these services to run the product:

5. Retention

We keep your account data while your account is active. When you delete your account, we delete your resumes, applications, version history, notes, and uploaded photos within 30 days. Stripe transaction records and tax documents are retained for seven years under applicable tax law. Server logs are retained for 30 days.

6. Your rights

Regardless of where you live, you can:

If you are in the European Economic Area, UK, or Switzerland you also have rights under the GDPR including the right to object to processing, the right to portability, and the right to lodge a complaint with your supervisory authority. Our lawful basis for processing is contract performance (running the product you signed up for) and legitimate interest (security, abuse prevention).

If you are in Californiayou have rights under CCPA/CPRA including the right to know what we collect, the right to delete, the right to opt out of “sale” or “sharing” of personal information (which we do not do), and the right to non-discrimination for exercising these rights.

To exercise any right, email gor.mikaelyan.eworld@gmail.com. We'll respond within 30 days.

7. Cookies and local storage

We use a small number of cookies and a localStorage entry:

8. International transfers

Our infrastructure runs in the United States. If you use the product from outside the US, your data is transferred to and processed in the US. We rely on Standard Contractual Clauses for EU/EEA transfers where applicable.

9. Children

The product is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

10. Security

All traffic is encrypted in transit (TLS 1.2+). Data is encrypted at rest in our database. We use industry-standard access controls. No system is perfectly secure — if we ever experience a breach affecting your data, we will notify you without undue delay.

11. Changes to this policy

We'll update this page when we change how we handle data. Material changes will be announced by email (for account holders) at least 30 days before they take effect. The “Last updated” date at the top always reflects the current version.

12. Contact

For any privacy question, email gor.mikaelyan.eworld@gmail.com. For billing-specific questions, our Refund Policy may answer faster.