Whitebox CVBack to Home

Privacy Policy

Last updated: August 2026

1. Information we collect

Whitebox CV collects and processes information needed to operate the service. Depending on how you use the product, this may include:

  • Account information, including email address and optional name
  • Authentication information, including a hashed password and session tokens stored in your browser
  • Resumes and uploaded files, including extracted resume text and, when file storage is configured, original file copies
  • Job descriptions, job titles, company names, and job URLs you provide or save
  • Saved jobs, scan history, and analysis results, including match scores, skills, suggestions, ATS audit information, and optimized resume content
  • Sharing information, such as share-link settings, optional share passwords, and optional expiration
  • Subscription and customer identifiers used to manage paid plans
  • Technical information that may appear in server or hosting logs, such as IP address, when requests are made to the service

We do not collect payment-card numbers. Cover letters generated by the service are returned to you and are not stored in the application database.

2. How we use information

We use information to:

  • Create and manage accounts and authenticate users
  • Analyze resumes and compare them with job descriptions
  • Identify keywords, skills, and gaps, and generate recommendations
  • Generate optimized resume content and cover letters
  • Provide job-search functionality, history, and saved jobs
  • Provide sharing functionality that you choose to enable
  • Process subscriptions and send transactional emails such as verification and password-reset messages
  • Maintain security, prevent abuse, and operate and maintain the service

Whitebox CV does not sell your personal information and does not use it for third-party advertising.

3. AI-powered processing

Whitebox CV uses an OpenAI-compatible API integration to analyze resumes and generate content. Depending on configuration, this may involve OpenAI or OpenRouter.

Resume text and job-description text may be transmitted to that provider so the service can produce analysis, recommendations, optimized resume content, and cover letters. Generated output is returned to Whitebox CV. Optimized resume results may be stored with your analysis. Cover letters are generated but are not stored in the database.

Whitebox CV does not currently have an identified pipeline that uses user resumes to train or improve AI models. How the AI provider handles data is subject to that provider’s terms and privacy practices. We do not control, and do not make claims about, that provider’s own retention or training practices.

4. Third-party services

Whitebox CV relies on third-party services to operate. Depending on configuration and the features you use, these may include:

  • OpenAI and/or OpenRouter for AI processing
  • Stripe for subscriptions
  • Resend for transactional email
  • PostgreSQL hosted by Neon for application data
  • Azure Blob Storage for uploaded resume files when that storage is enabled
  • Vercel to host the website
  • Render to host the application programming interface
  • Job-search providers, which may include Adzuna, RapidAPI JSearch, TheirStack, and/or Bright Data, depending on configuration
  • Google Fonts and Material Icons to display type and icons

Not every listed job-search provider is necessarily active in every deployment. Those services process information as needed to provide their functions, under their own terms and privacy practices.

5. Payments

Pro subscriptions are processed through Stripe using Stripe-hosted checkout. Whitebox CV does not store payment-card numbers. Whitebox CV stores the subscription and customer identifiers needed to manage your plan.

6. Job search and external services

Job-search features may retrieve listings through third-party job-search providers, depending on configuration. If you provide a job-posting URL, Whitebox CV may fetch that page to extract a job description. Third-party job information may be incomplete or inaccurate.

7. Sharing

You may create a share link for an analysis. Depending on the share configuration, a link may be public, password-protected, and/or set to expire.

A share link can expose analysis results, match scores, skills, suggestions, ATS audit information, and optimized resume text. Shared results are not private by default. Anyone who obtains an unprotected share link may be able to view the information available through that link. You are responsible for deciding whether to share this information and for how you configure the link.

8. Browser storage

Whitebox CV uses browser storage (such as localStorage and sessionStorage) for authentication and session information and certain preferences, including theme and onboarding state. These are not first-party cookies.

No first-party analytics or tracking cookies were identified in the current implementation. The site loads fonts and icons from Google, which may receive standard browser request information.

9. Storage and retention

Application data is stored in PostgreSQL. Original resume files may be stored in Azure Blob Storage when that option is configured; otherwise temporary or local file storage may be used.

Whitebox CV does not currently apply a fixed retention period such as 30, 60, or 90 days for accounts, resumes, job descriptions, analyses, logs, stored files, or backups. Information is retained as needed to provide the service, maintain your account, maintain security, operate the service, process billing, and comply with legal obligations.

Deleting information in the application does not necessarily mean immediate deletion from infrastructure backups or from third-party systems.

10. Security

Whitebox CV uses reasonable technical and organizational safeguards to protect information. Passwords are hashed with bcrypt. Access and refresh tokens are stored in your browser rather than in first-party authentication cookies.

No method of transmission or storage is completely secure. You are responsible for keeping your account credentials confidential.

11. Account deletion

You can delete your account in settings. When you do, application content such as resumes, job descriptions, saved jobs, and analyses is removed through the application’s deletion mechanisms.

The current implementation may retain your email address and usage counters so that the same address cannot be used to reset free-plan limits by registering again. Deletion from the application is not a promise of immediate, permanent erasure of every copy from backups, logs, or third-party services (for example Stripe or an AI provider).

12. Privacy rights and requests

You may contact Whitebox CV about access, correction, deletion, privacy questions, or privacy concerns. Email support@whiteboxcv.com.

Depending on applicable law, additional rights may apply. This policy describes how Whitebox CV handles information; it is not legal advice.

13. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Continued use of the service after an update means you should review the revised policy.

Questions: support@whiteboxcv.com.