CVMount

Les textes juridiques ci-dessous sont actuellement fournis en anglais uniquement.

Privacy Policy

Last updated: 2026-08-25

This Privacy Policy explains how personal data is processed when you use CVMount.

Who operates CVMount

CVMount is currently operated as a product without a separate registered legal entity. This section will be updated with the operator's legal identity once that is finalized.

Account information

CVMount stores your email address, an optional display name, your email-verification status, a cryptographically hashed password (if you sign up with a password), and account creation/update timestamps.

CV/resume data

The content of every resume you create is stored so it can be shown back to you, edited, and exported. This may include contact details, a summary, employment history, education, projects, skills, languages, certifications, and other CV fields you choose to enter. Because CV content is user-controlled, you may choose to enter sensitive personal information even though CVMount does not require such information for the service generally. Deleting a resume or your account removes this content.

Uploaded photographs

If you upload a photograph for a resume, CVMount stores the photo along with the technical metadata (such as dimensions and file size) needed to store and display it.

Public CV information

If you publish a resume as a public CV page, CVMount stores the public web address (slug) you choose and which resume it currently points to. Publishing makes the selected resume's content accessible to anyone with its web address; CVMount does not guarantee or control whether search engines index a published page. Unpublishing removes access through CVMount's public-profile route, but copies previously cached, indexed, or otherwise retained by third parties may remain outside CVMount's control.

Premium / early-access data

If you receive complimentary early-access Premium, CVMount keeps a history of when access started, ended, or was revoked, so entitlement can be evaluated consistently. See Terms of Service for the current state of Premium pricing and access.

Why we process data and legal bases

CVMount processes personal data only for the purposes below, each processed on the legal basis noted:

  • Account and authentication — creating and operating your account, and keeping it secure. Basis: performance of the service you request.
  • Resume storage, editing, and export— providing CVMount's core CV functionality. Basis: performance of the service you request.
  • Public CV publishing — publishing a CV when you choose to. Basis: performance of the service you request.
  • Transactional account and security email — email verification and password reset. Basis: performance of the service you request.
  • Security and abuse prevention— rate limiting and protecting the service and its users. CVMount currently relies on legitimate interests for this processing, subject to the required assessment of necessity and users' rights and interests.
  • First-party product analytics— understanding and improving the product (see "Product analytics" below). CVMount currently relies on legitimate interests for this limited processing, subject to the required assessment of necessity and users' rights and interests.

CVMount relies on legitimate interests only where the relevant interests are not overridden by your rights and interests. This Privacy Policy describes the purposes and legal bases relied upon; acknowledging this policy does not itself constitute consent to processing.

Authentication data

If you sign up with email and password, your password is stored only as a one-way cryptographic hash — never in plain text. If you sign in with Google, CVMount receives your name, email, and profile picture from Google under Google's own OAuth flow; CVMount does not receive or store your Google password.

Product analytics

CVMount records a small set of first-party, authenticated, server-side product events (for example, that a resume was created, or a PDF was exported) tied to your account, so the product can be understood and improved. This system intentionally rejects specific sensitive property categories — email, password, tokens, IP address, user-agent, and resume content — at write time, so those categories are never captured by it. This is a statement about that specific analytics system, not a claim about every system CVMount operates (for example, infrastructure-level request logs are a separate system with their own handling).

CVMount also keeps a daily count of how many times each public resume-example page was requested, and how many times one of those pages led into the resume builder. These are plain totals per page per day. They contain no identifier of any kind, set no cookie, use no browser storage, and cannot be linked to you, to a visit, or to any other record. Because they are counted on the server whenever a page is rendered, they include automated traffic such as search-engine crawlers, and are therefore a measure of requests rather than of people.

Service providers and recipients

Depending on how a given deployment of CVMount is configured, it may use the following categories of service providers:

  • A PostgreSQL database host, for application data.
  • Google, for optional sign-in.
  • A transactional email provider, for account and security email (such as email verification and password reset).
  • An object-storage provider, for uploaded photographs.
  • An error-tracking service, to capture unexpected application errors.
  • A log-ingestion service, for operational server-side logs.

These providers are used for operating and maintaining the service, not for advertising or marketing. No claim is made here about where these providers store data geographically, or about completed data-processing agreements, beyond what is stated explicitly.

International transfers

Some service providers may process personal data outside the European Economic Area. Where personal data is transferred outside the EEA, applicable data-protection law may require appropriate transfer safeguards. CVMount's provider and international-transfer arrangements remain subject to final operational and legal review.

Cookies and browser storage

CVMount uses cookies required for authentication, security, and operation of the service (including a brief cookie set during the OAuth handshake when signing in with Google). These cookies are necessary for CVMount to function and are not used for advertising or marketing.

CVMount also stores one language-preference cookie, but only if you actively choose a language using the language selector. It records just the two-letter code of the language you chose (for example fr), contains no identifier or personal data, and is used only to show you that language again when you open CVMount without a language in the address. It is kept for up to one year. If you never use the language selector, this cookie is never set.

CVMount does not currently use analytics or marketing cookies, tracking pixels, or third-party advertising scripts, and does not use browser local/session storage. Because the cookies described above are either required to provide authentication and security functionality or set only to remember a preference you chose yourself, CVMount does not currently display an optional-cookie consent banner.

Data retention

Account, CV, uploaded-photo, public-profile, and Premium-entitlement data is generally retained while your account remains active because it is required to provide CVMount. When you delete your account, this application data is removed through CVMount's account-deletion process as described below.

Account deletion

You can permanently delete your account from Settings. When you delete your account, CVMount's account-deletion process removes your account, resumes, uploaded photos, public profile, Premium access history, and associated product-usage records from the application's active data stores. This action cannot be undone.

Data export

You can download a self-service copy of your account and CV data from Settings ("Your data"). This export includes the account, resume, public-profile, Premium-history, and product-analytics data described above, with internal/security-sensitive fields excluded by design. It is a convenience self-service export, not a formal legal data-access request process — for additional privacy or data-related requests, contact CVMount using the address below.

Your privacy rights

Depending on your circumstances and applicable law, you may have rights to access, correct, erase, restrict, or object to the processing of your personal data, to receive a copy of it in a portable format, and — where consent is the legal basis for a specific processing activity — to withdraw that consent. You may also have the right to lodge a complaint with the competent data-protection supervisory authority.

Many of these rights are available directly through CVMount:

  • Correct your account information from Settings.
  • Download a self-service copy of your data from Settings ("Your data").
  • Delete your account from Settings.
  • Contact CVMount for any other privacy or data-related request.

Security

CVMount uses technical and organizational safeguards intended to protect account and CV data, including password hashing, authenticated access controls, rate limiting, restricted private/public CV access boundaries, and exclusion of security-sensitive fields from the self-service data export. No internet service can guarantee absolute security.

Changes to this Privacy Policy

This Privacy Policy may be updated when CVMount's features, providers, processing activities, or legal requirements change. The "Last updated" date above identifies the current version. Material changes may be communicated separately where appropriate or legally required.

Contact

For privacy and data-related requests, contact CVMount at support@cvmount.com.