Logo Zyiat
Back to Home

Privacy Policy

Last updated: April 22, 2026

CV Punch ("we", "our", "us"), accessible at https://cvpunch.ai and operated by JC Solutions US, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI-powered resume optimization platform and our automated social-media publishing pipeline (the "Service"). By using our Service, you consent to the practices described in this policy.

1. Information We Collect

Account Information: When you create an account on CV Punch (cvpunch.ai), we collect your email address and, if you use OAuth (Google, GitHub), your name and profile information provided by the authentication provider. We use Supabase for authentication and securely store your account credentials.

User Content: When you use our Service, you may upload resumes, cover letters, and job descriptions. These documents may contain personal information such as your name, contact details, work history, education, skills, and other professional information. We process this content solely to provide you with our AI-powered optimization services.

Payment Information: When you purchase credits, payment is processed through Stripe. We do NOT store your credit card number, CVV, or full payment details on our servers. Stripe handles all payment information in accordance with PCI DSS standards. We only receive confirmation of successful transactions and basic transaction metadata.

Usage Data: We collect basic usage data necessary for providing the Service, including login timestamps, features used, credit consumption, and general interaction patterns. We do not currently use third-party analytics or tracking services.

2. How We Use Your Information

We use your information for the following purposes: (a) to provide, maintain, and improve the Service; (b) to process your documents through our AI systems for resume optimization and cover letter generation; (c) to process payments and manage your credit balance; (d) to communicate with you about your account, service updates, and respond to support requests; (e) to detect and prevent fraud, abuse, and security incidents; (f) to comply with legal obligations.

We do NOT use your personal information or document content for: advertising or marketing to third parties; selling or renting to any third party; profiling or automated decision-making that produces legal effects; any purpose unrelated to providing the Service.

3. AI Processing & Third-Party Data Transfer

When you use our AI-powered features (resume optimization, cover letter generation, ATS scoring), the content of your documents is sent to Anthropic, the provider of Claude AI, our third-party AI processing partner. Anthropic acts as a data processor under our instructions and in accordance with our Data Processing Agreement. Your data is sent to Anthropic strictly for the purpose of processing your request and generating the AI output you requested.

We do NOT use your data to train AI models. Anthropic is contractually prohibited from using your data to train, improve, or develop their AI models or any third party's models. Your documents are processed for the sole purpose of delivering the service you requested, and are not retained by AI providers beyond what is necessary for processing.

We do NOT share your personal documents with other users. Each user's documents are processed independently and are never combined with, exposed to, or made accessible to any other user. AI-generated results are returned exclusively to your account.

Data transfers to Anthropic's servers may involve international data transfer, including transfer to servers located in the United States. These transfers are protected by appropriate legal safeguards, including Standard Contractual Clauses (SCCs) and compliance with applicable data protection regulations including GDPR and CCPA where applicable.

4. Social Media Content Publishing via TikTok

CV Punch (cvpunch.ai) operates CVPunch_Publisher, an automated editorial pipeline that publishes original, AI-generated content (job-market news summaries, career tips, resume advice) to TikTok accounts owned and operated by JC Solutions US. To publish on TikTok, we integrate with the official TikTok Content Posting API.

TikTok permissions CVPunch_Publisher requests: user.info.basic — used only to confirm the authenticated TikTok account identity so we upload to the correct account. video.upload — used only to upload our own AI-generated video files to the authorized account's inbox for manual publishing, or to publish directly after review.

What we do NOT do with TikTok: we do not read, collect, or process content from other TikTok users; we do not access followers, direct messages, comments, private videos, or any user data outside of the authenticated account; we do not use any TikTok data to train AI models; we do not share TikTok access tokens or credentials with any third party.

TikTok access tokens are stored encrypted at rest in our Supabase database and rotated automatically via TikTok's refresh-token flow. Tokens are scoped to a single authorized TikTok account. Users can revoke CV Punch's access at any time via TikTok Settings → Security → Manage app permissions, or by contacting [email protected]. Upon revocation, tokens are deleted from our systems within 24 hours.

5. Data Sharing & Third Parties

We share your data only with the following categories of service providers, strictly for the purposes described: Anthropic (Claude AI) — for AI document processing, as described in Section 3; Stripe — for payment processing; Supabase — for authentication, database, and file storage; TikTok — only when you authorize publishing to your own TikTok account, as described in Section 4. Each provider processes data under our instructions and in accordance with their respective privacy policies and our data processing agreements.

We do NOT sell, rent, or trade your personal information to any third party for marketing, advertising, or any other commercial purpose. We may disclose your information if required by law, court order, or government regulation, or if necessary to protect the rights, property, or safety of CV Punch, our users, or the public.

6. Data Retention

We retain your account information and uploaded documents for as long as your account is active or as needed to provide the Service. If you delete a specific document, it is removed from our active systems. If you delete your account, we will delete all your personal data and uploaded documents within 30 days, except where we are required by law to retain certain information.

AI-generated results (optimized resumes, cover letters, analysis scores) are stored in your account for your convenience and remain available until you delete them or close your account. Credit transaction records may be retained for accounting and legal compliance purposes even after account deletion.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data: Right of Access — You can request a copy of the personal data we hold about you; Right to Rectification — You can request correction of inaccurate data; Right to Deletion — You can request deletion of your data ("right to be forgotten"); Right to Data Portability — You can request your data in a structured, machine-readable format; Right to Object — You can object to certain processing of your data; Right to Restrict Processing — You can request that we limit how we use your data.

For users in the European Economic Area (EEA), we process your data under the following legal bases: contractual necessity (Article 6(1)(b) GDPR) for providing the Service; legitimate interest (Article 6(1)(f) GDPR) for improving and securing the Service; consent (Article 6(1)(a) GDPR) where applicable; legal obligation (Article 6(1)(c) GDPR) for compliance requirements.

To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days. For California residents (CCPA): You have the right to know what personal information we collect, request deletion of your data, and opt out of the sale of personal information (note: we do not sell personal information).

8. Cookies & Local Storage

We use a minimal number of cookies and local storage mechanisms, strictly for functional purposes: NEXT_LOCALE cookie — stores your preferred language (en, pt-BR, es); Supabase authentication cookies — maintain your login session securely; Local storage — stores UI preferences such as sidebar position and theme selection.

We do NOT currently use third-party tracking cookies, advertising cookies, or analytics services that track your behavior across websites. If we introduce analytics tools in the future, we will update this Privacy Policy and, where required, obtain your consent before deploying such tools.

9. Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include: encryption of data in transit (TLS/SSL); secure authentication through Supabase with support for two-factor authentication (2FA); encrypted storage of third-party access tokens (TikTok, Stripe, Supabase); access controls limiting data access to authorized personnel; regular security reviews of our systems and practices.

While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data. You are responsible for maintaining the confidentiality of your account credentials and for any activity that occurs under your account.

10. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a child under 18, we will take steps to delete such information promptly. If you believe a child under 18 has provided us with personal information, please contact us at [email protected].

11. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence, including the United States, where our AI processing partner Anthropic operates servers, and where TikTok and Stripe operate. These countries may have data protection laws that differ from those in your jurisdiction.

Where we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, compliance with the EU-US Data Privacy Framework where applicable, and data processing agreements with all third-party service providers. These safeguards ensure your data receives an adequate level of protection regardless of where it is processed.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last updated" date at the top of this policy and notify you through the Service or via email.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy. If you do not agree with the changes, you should discontinue use of the Service and request deletion of your account.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: [email protected]. We are committed to resolving any privacy concerns and will respond to your inquiry within 30 days.

This Privacy Policy applies to CV Punch (https://cvpunch.ai), operated by JC Solutions US, 100 East Pine Street, Suite #110, Orlando, FL 32801, USA.