Privacy policy
CVBuddy holds your CV. This page says plainly what we store, who can see it, and how to get rid of it.
Who we are
CVBuddy is built and run by Isocode Labs, and served from cvbuddy.isocodelabs.com. It is made by two students at IIT Kharagpur: Aryan Malhotra (4th year, B.Tech), aryan@isocodelabs.com and Devansh Mishra (4th year, Dual Degree), devansh@isocodelabs.com.
We are independent. We are not IIT Kharagpur, we are not its Career Development Centre, and neither has endorsed or reviewed this tool.
What we collect
- Your account
- Roll number, full name, department, degree type and year of admission. Department and year are decoded from the roll number you give at sign-up rather than asked for separately. Your password is handled by our authentication provider and is stored as a hash — we never see it.
- Your CV content
- Everything you type into the editor: education, internships, projects, skills, positions of responsibility and the rest, including anything you paste in or import from a PDF.
- Usage events
- Which page you were on, what kind of action you took, a session identifier and how long something took. We use this to see which parts of the editor people get stuck in.
- Things you send us
- Bug reports and reviews, along with the account that submitted them.
- Payment records
- If you buy a paid plan, we store the plan, the transaction reference and your credit balance. We never receive your card details — those are entered on Razorpay's own checkout.
We do not ask for your CGPA, your JEE rank or your placement outcomes as separate data — if any of that is in your CV, it is there because you put it in your CV.
Who can read your CV
No one other than you can access your CV. Not even us.
We do not sell it, share it, or show it to recruiters or companies.
The one exception: the AI features
When you ask CVBuddy to format or advise on a section, that section is sent to an AI model to be rewritten. By default that is Google Vertex AI. This only happens when you press the button.
If you would rather no AI model ever sees a particular detail, do not run the AI features on the section containing it. The editor works without them.
You can use your own AI provider key instead, in settings. Your text then goes to that provider under your own account and their terms. Any key you give us is encrypted before it is stored.
A copy is kept on your device
Your CV is also saved in the browser you are working in, so the editor keeps working if your connection drops. It stays on that device until you clear it, so sign out on a shared or lab computer.
Who else can see it
- Our administrators. A small number of named Isocode Labs accounts can see the user list, aggregate analytics, submitted bug reports and reviews, for support and abuse handling.
- Reviews you choose to leave are shown publicly on our home page, attributed to your first name and last initial. Do not put anything in a review you would not want a stranger to read.
- The service providers listed below, each only for the job described.
We do not sell your data, we do not share it with recruiters or employers, and we do not send it to advertisers.
Service providers
- Supabase — Authentication, database and file storage
- Holds your account record and your CV content.
- Google Cloud — Hosting, AI processing and OCR
- The app runs on Cloud Run in the Mumbai (asia-south1) region. Vertex AI performs the formatting work, and Cloud Vision reads scanned PDFs you import.
- Razorpay — Payments
- Handles the card details for paid plans. Those details are entered on Razorpay and never reach our servers.
- Upstash — Rate limiting
- Stores short-lived counters so a single account cannot overwhelm the AI features.
The browser extension
The optional Chrome extension signs in with your CVBuddy credentials, fetches your CV, and types it into the ERP form on erp.iitkgp.ac.in. It reads and writes only that page, only when you click a fill button. It does not read your ERP password and does not send your ERP session anywhere.
How long we keep it
Your account and CVs are kept until you delete them. Deleting a CV removes it from your account; deleting your account removes your profile and CV content. Payment records are kept longer where we are required to retain them for financial and tax purposes. Usage events are kept in aggregate.
What you can ask for
- A copy of the data we hold about you.
- Correction of anything wrong in it.
- Deletion of your account and its contents. You can delete individual CVs yourself from the dashboard.
- Removal of a review you have left.
Write to cvbuddy@isocodelabs.com from the address on your account, or with your roll number, and we will action it.
Security, honestly stated
Passwords are hashed, traffic is encrypted in transit, database access is restricted by row-level security so one account cannot read another's CV, and any AI keys you supply are encrypted at rest. That said, no service can promise perfect security, and we are a small team. We are telling you what we do rather than claiming a guarantee we cannot make.
Children
CVBuddy is intended for university students and is not directed at children under 13.
Changes
If this policy changes in a way that materially affects you, we will update the effective date at the top and note the change in the app. Continuing to use CVBuddy after that means the updated policy applies.
Contact
Privacy questions, data requests, or anything else about CVBuddy: cvbuddy@isocodelabs.com. The terms & conditions cover the rules for using the service.