PRIVACY NOTICE · VERSION 2026-08-13

Privacy notice

Last updated: 13 August 2026

SignalCV is a CV guidance and role-research service. It is not an employer, recruiter, or applicant tracking system. This notice explains the processing performed by the live service, including optional Gemini-powered Deep Role Research.

Data we process

We process your email address, password hash, accepted legal-notice versions, profile defaults, CV files and text, structured CV content, job descriptions, target details, analysis findings, revisions, role-research records, generated exports, billing customer and subscription identifiers, credit ledger entries, student campaign claims, and security audit events connected to your account. SignalCV does not store full card details.

We do not ask for protected characteristics and do not use them as scoring inputs. Do not include patient, client, or other third-party identifying information that is not necessary for your CV.

Why we process it

We process account and workspace data to provide the service you request: authenticating you, parsing and editing CVs, comparing them with a target, creating explainable guidance, preserving versions, conducting optional public-source role research, and generating exports. We also process limited security and reliability information for our legitimate interests in preventing abuse and operating a dependable service.

AI and Deep Role Research

Standard CV analysis and the later comparison between a researched role profile and your CV use SignalCV's deterministic processing. If you deliberately start Deep Role Research, SignalCV sends the target role, employer if supplied, industry profile, and up to 30,000 characters of the supplied vacancy to Google's Gemini service. The Deep Role Research request does not send your CV.

Gemini is asked to search public sources and return cited role signals. Its output is treated as untrusted research and is checked before display. Provider interactions are stored so asynchronous research can be retrieved. Provider-side records are governed by Google's applicable API terms and retention controls and may not be erased immediately when you delete your SignalCV account. Do not place candidate secrets or personal data in a job-description field.

Hosting and service providers

The web application is hosted on Vercel. The API and production database are hosted on Heroku services. Google Gemini processes only the optional role-research request described above. When payments are enabled, Stripe processes checkout, payment, subscription, and billing-portal data. These providers may process service data in countries outside your own under their contractual and legal transfer safeguards.

SignalCV does not sell CV data and does not use advertising cookies. We do not use your CV to train a SignalCV model. If that position changes, this notice and the product choice presented to users must change first.

Cookies and security

SignalCV uses an essential secure, HTTP-only session cookie. Passwords are stored as Argon2 hashes, production traffic uses HTTPS, and API records are scoped to the signed-in account. No internet service can guarantee perfect security.

Retention and deletion

Active workspace data remains until you delete it or the service closes the beta after notice where practical. Settings lets you export account data, delete analyses, delete all CVs and their dependent records, or delete the account. Account deletion removes records owned by that account from the live SignalCV database.

Infrastructure backups can retain deleted records temporarily under provider recovery schedules. Reusable public-source role profiles and Gemini provider interactions are not guaranteed to be removed with an account deletion; they are not intended to contain CV data. This limitation is why SignalCV keeps the CV-to-role comparison local.

Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or obtain a copy of personal data and to object to certain processing. You can use the immediate controls in Settings or contact us. UK users may also complain to the Information Commissioner's Office.

Contact

For support, privacy requests, or a concern about research output, email solomon.freelancing@gmail.com. Include a request ID when an error screen provides one, but do not email a CV unless support specifically asks for it.