Skip to content
WhizCV logoWhizCV Early preview
WhizCV logoWhizCV Early preview
  • Features
  • Templates
  • CV Examples
  • Pricing
  • FAQ
  • English
  • Čeština
  • Dansk
  • Deutsch
  • Español
  • Français
  • Italiano
  • Nederlands
  • Norsk bokmål
  • Polski
  • Português (Brasil)
  • Suomi
  • Svenska
  • Български
Sign inGet started
Home›Privacy

Privacy Policy

Last updated 1 August 2026

This policy explains what personal data WhizCV collects, why we collect it, who else processes it, and what you can do about it. It is written to be read, not to be survived.

If anything here is unclear, email support@whizcv.com and a human will answer.

1. Who we are

WhizCV is an online CV and cover-letter builder operated by Yordan Georgiev, an independent software developer based in Sofia, Bulgaria ("WhizCV", "we", "us"), who is the data controller for the personal data described in this policy. WhizCV is in early access; when its operation moves to a registered company, this policy will be updated to name it.

You can reach us at support@whizcv.com for any privacy question, including to exercise the rights listed in section 8.

2. What we collect

We collect four kinds of data, and you control most of it.

  • Account data — your name, email address and a hashed password. If you sign in with Google, we receive your basic Google profile (name, email, profile picture) instead of a password.
  • Document content — everything you put into your CVs, cover letters, career profile, personal pitches, job applications and interview notes. This typically includes your contact details, photo, employment history, education, skills and languages. You decide what goes in; we do not require any particular field.
  • Files you upload — profile photos and images you add to your library, and any CV file (PDF, DOCX or TXT) you import so we can rebuild it as an editable document.
  • Usage data — pages visited, actions taken, browser and device information, and an approximate location derived from your IP address. This is collected only after you accept analytics cookies, and never before.
  • Support and feedback — whatever you choose to send us through the in-app feedback form or by email, including any votes you cast on the public roadmap.

3. What we do not collect

  • We never see or store your card details. Stripe handles payment entry and returns only a transaction reference and status.
  • We do not buy personal data about you from third parties, and we do not build advertising profiles.
  • We do not sell your data to anyone, under any circumstances.

4. Why we use it, and our legal basis

  • To provide the service (contract) — creating your account, storing your documents, rendering and exporting them to PDF, generating share links, and taking payment for a pass.
  • To keep the service working and safe (legitimate interests) — diagnosing errors, preventing abuse and fraud, and maintaining security.
  • To measure and improve the product (consent) — analytics and product-usage measurement. Nothing is collected until you accept, and you can withdraw at any time.
  • To send you email (contract and consent) — account emails such as password resets are necessary to run your account; any newsletter or product-update email is sent only if you opt in, and every one carries an unsubscribe link.
  • To meet legal obligations (legal obligation) — keeping accounting and tax records for payments we receive.

5. AI features — please read this one

When you use the AI copilot, import an existing CV, or translate a document, the relevant text (and, for imports, the file you uploaded) is sent to OpenAI so it can generate the response. This is the only way those features can work.

Content sent through the OpenAI API is processed on our behalf as a service provider and, under OpenAI's API terms, is not used to train their models. Even so: treat AI features as you would any cloud service, and do not paste anything into a document that you would not want processed this way.

AI features are optional. The builder, templates, export and sharing all work without ever invoking them.

6. Who else processes your data

We use a small number of service providers ("processors"). Each one only receives what it needs to do its job, and each is bound by a data-processing agreement.

  • Microsoft Azure — hosting, database and file storage.
  • OpenAI — AI writing suggestions, CV import parsing and document translation (see section 5).
  • Stripe — payment processing.
  • Twilio SendGrid — transactional and opt-in email.
  • Google — sign-in with Google, if you choose it, and Google Analytics after you accept analytics cookies.
  • Microsoft Clarity — product analytics and session replay, after you accept analytics cookies.

7. Where your data lives

The application, your documents and your uploaded files are hosted in the European Union — application and storage in West Europe (Netherlands), and the database in Germany West Central.

Some of the providers in section 6 (OpenAI, Stripe, SendGrid, Google and Microsoft Clarity) may process data outside the European Economic Area. Where they do, transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent approved transfer mechanism.

8. How long we keep it

  • Your account, documents and files — for as long as your account exists. Delete your account and we delete them; residual copies roll out of encrypted backups within 30 days.
  • Payment records — for as long as accounting and tax law requires us to keep them, regardless of whether your account is still open.
  • Analytics data — according to the retention period configured with each analytics provider (Google Analytics currently retains user-level data for up to 14 months).
  • Support and feedback messages — until they are resolved and no longer needed, or until you ask us to delete them.

9. Your rights

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw any consent you have given. Withdrawing consent does not affect processing that already happened.

You can export or delete your documents from inside the app at any time. For anything else, email support@whizcv.com and we will respond within 30 days.

If you think we have handled your data badly, please tell us first — but you also have the right to complain to your local data-protection authority. In Bulgaria that is the Commission for Personal Data Protection (cpdp.bg).

10. Cookies and similar technologies

  • Essential — sign-in and session cookies, your language preference, and a record of the cookie choice you made. These are required for the site to work and are not optional.
  • Analytics — Google Analytics and Microsoft Clarity. These are loaded only after you press Accept on the cookie banner. If you decline or ignore the banner, no analytics script is loaded at all.
  • You can change your mind at any time by clearing this site's data in your browser, which brings the banner back.

11. Security

Data is encrypted in transit with HTTPS and encrypted at rest. Passwords are hashed, never stored in readable form. Access to production systems is limited to the people who need it.

No service can promise perfect security. If a breach ever affects your personal data, we will notify you and the relevant supervisory authority as the law requires.

12. Children

WhizCV is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

13. Changes to this policy

We will update this page when our practices change, and always update the date at the top. If a change materially affects your rights, we will tell you by email or in the app rather than relying on you to re-read this page.

14. Contact

Privacy questions, requests and complaints: support@whizcv.com.

CV Examples · About · Privacy · Terms · · Status

© 2026 WhizCV