Privacy Policy
Last updated: 9 September 2026
Overview
Currvae (“we”, “our”, “us”) is committed to protecting your privacy. This policy explains how we collect, use, and protect your personal information.
What We Collect
We collect the following types of information:
- Account information: Email address, name, and authentication credentials.
- Career documents: Resumes, cover letters, certificates, and other documents you upload.
- Extracted data: Structured information extracted from your documents (skills, experience, education).
- Job applications: Job advertisements you paste and application materials you create.
- Usage data: Feature usage for the purpose of enforcing fair-use limits.
How We Use Your Data
We use your data to:
- Provide the core service: document analysis, career profile building, and document generation.
- Authenticate your session and protect your account.
- Enforce usage limits and prevent abuse.
- Understand feature usage, investigate failures, and improve the service using account-linked or aggregated operational data.
AI Processing
When you use AI features, the career documents, job advertisement text, and prompts needed for that feature may be sent to AI service providers and model hosting providers so they can process the request. Our current AI gateway is OpenRouter, and the underlying model provider may vary depending on the configured model.
We use these providers only to deliver AI features. We store AI outputs only as needed to display results, maintain generated documents, and provide your account history. Provider handling, retention, and training practices can vary by provider and model; we aim to use provider configurations that limit retention and training where available.
Early Access Requests
If you request early access, we store your email address, the time you agreed to be contacted, and the version of that consent. We use these details only to manage beta invitations, not for newsletters or marketing. Submitting a request does not create an account or grant access to AI features.
Requests expire after 180 days and are removed by scheduled cleanup. You can withdraw sooner by contacting support@currvae.com. We also use short-lived, keyed hashes of request network addresses and email addresses to limit abuse.
Data Storage
Account and application data is stored in PostgreSQL, while uploaded files are stored in Cloudflare R2. We use private access controls and encrypted transport. Authorised service components and processors can access data only as needed to operate the Service.
Data Retention
Account-linked data is retained while your account is active. You can request deletion from Settings. Currvae verifies stored-file removal before deleting the account database record; service-provider logs and backups may remain for their documented security and retention periods.
Data Sharing
We do not sell your personal data. We disclose it to service providers only as needed to operate the Service, including AI processing, hosting, database, file storage, email, authentication, observability, and payment services when enabled. Providers may process data in other countries under their applicable terms.
Current Service Providers
Current or planned infrastructure and processing providers include OpenRouter and its configured model providers for AI, Cloudflare R2 for private file storage, Railway and Neon for application/database hosting, Amazon SES for transactional email, Google for optional OAuth, and Stripe when payments are enabled. A provider is used only when its related feature is configured.
Your Rights
You have the right to:
- Access your data through the application.
- Correct your career profile at any time.
- Delete your account and associated data from the active Service, subject to the provider-log and backup retention described above.
- Export your generated documents.
- Contact us with privacy concerns at support@currvae.com.
Changes
We may update this policy from time to time. Material changes will be communicated via email or in-app notification.