PRIVACY NOTICE · VERSION 2026-09-04.2
Privacy notice
Last updated: 4 September 2026
SignalCV is a CV guidance and role-research service operated by Osamudiamen Osayande Johnson. It is not an employer, recruiter, or applicant tracking system. This notice explains the processing performed by the live service, including Gemini-powered CV tailoring and optional Deep Role Research.
Data we process
We process your email address, password hash, accepted legal-notice versions, profile defaults, CV files and text, structured CV content, job descriptions, target details, analysis findings, revisions, role-research records, generated exports, billing customer and subscription identifiers, credit ledger entries, student campaign claims, and security audit events connected to your account. If you use browser autofill, we also process the basic contact, address, link, work-authorisation, availability, compensation, and optional date-of-birth values you deliberately save. SignalCV does not store full card details.
We do not ask for protected characteristics and do not use them as scoring inputs. Do not include patient, client, or other third-party identifying information that is not necessary for your CV.
Job discovery
When you search for jobs, SignalCV sends the search terms, location, and filters—not your CV or identity—to Adzuna and temporarily caches the resulting public job advertisements to reduce provider requests. When you save a listing, its title, employer, location, description, provider identifier, link, and available salary or contract information are stored in your private application workspace. Tailoring begins only when you choose a CV.
Browser autofill extension
The optional browser extension retrieves your saved autofill profile through a scoped, revocable connection key. SignalCV stores only a hash of that key. The extension stores the key in your local browser profile and receives read-only access to the autofill profile—not your password or general SignalCV account.
Autofill runs only after you click the extension on the current page. It does not collect browsing history, upload a CV, write a cover letter, complete protected-characteristic or legal-declaration fields, or submit an application. Date of birth and calculated age are excluded unless you enable sensitive filling for that individual page. You can revoke a browser connection from Settings at any time.
Why we process it
We process account and workspace data to provide the service you request: authenticating you, parsing and editing CVs, comparing them with a target, creating explainable guidance, preserving versions, conducting optional public-source role research, and generating exports. We also process limited security and reliability information for our legitimate interests in preventing abuse and operating a dependable service.
AI tailoring and Deep Role Research
Standard CV analysis uses SignalCV's deterministic processing. When you click to create an AI-tailored CV, SignalCV sends the selected master CV's structured content, the target role and employer, and the confirmed vacancy description and requirements to Google's Gemini service. Gemini is instructed to change wording only where the master CV supports it. SignalCV validates the returned structure, rejects unsupported new numbers, preserves the master, and presents the proposed version for your factual review.
If you deliberately start Deep Role Research, SignalCV separately sends the target role, employer if supplied, industry profile, and up to 30,000 characters of the vacancy to Gemini; that research request does not send your CV. All Gemini output is treated as untrusted and checked before display. Provider-side processing is governed by Google's applicable API terms and retention controls and may not be erased immediately when you delete your SignalCV account. Do not include unnecessary sensitive information in a CV or job-description field.
Hosting and service providers
The web application is hosted on Vercel. The API and production database are hosted on Heroku services. Adzuna supplies live job advertisements and receives the job-search terms and filters you submit. Google Gemini processes AI-tailoring requests and optional role-research requests as described above. When payments are enabled, Stripe processes checkout, payment, subscription, and billing-portal data. These providers may process service data in countries outside your own under their contractual and legal transfer safeguards.
SignalCV does not sell CV data and does not use advertising cookies. We do not use your CV to train a SignalCV model. If that position changes, this notice and the product choice presented to users must change first.
Cookies and security
SignalCV uses an essential secure, HTTP-only session cookie. Passwords are stored as Argon2 hashes, extension keys are stored as one-way hashes on SignalCV, production traffic uses HTTPS, and API records are scoped to the signed-in account. Protect the local browser profile that holds your extension connection. No internet service can guarantee perfect security.
Retention and deletion
Active workspace data remains until you delete it or the service closes the beta after notice where practical. Settings lets you export account data, delete analyses, delete all CVs and their dependent records, or delete the account. Account deletion removes records owned by that account from the live SignalCV database.
Infrastructure backups can retain deleted records temporarily under provider recovery schedules. Reusable public-source role profiles do not contain CV data. Gemini provider processing records, including those created by a tailoring request, are governed by Google's retention controls and are not guaranteed to disappear immediately when you delete the local SignalCV account.
Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or obtain a copy of personal data and to object to certain processing. You can use the immediate controls in Settings or contact us. UK users may also complain to the Information Commissioner's Office.
Contact
For support, privacy requests, or a concern about research output, email solomon.freelancing@gmail.com. Include a request ID when an error screen provides one, but do not email a CV unless support specifically asks for it.