Legal

Privacy Policy

Effective date: August 27, 2026.

Who we are

VulcanCV (“we”, “us”) is operated by VulcanCV LLC, a Colorado limited liability company. We provide a resume-driven job-market analysis at vulcancv.ai. This policy explains what we collect, how we use it, and how little we keep.

What we collect

  • Resume content. The resume file you upload and the text extracted from it, plus any target role you enter. This is the sensitive data at the center of the service. For a one-time, no-account analysis it is treated as transient (see Retention); if you save it to an account’s vault, it is retained under your control (see “Accounts & vault”).
  • Payment information. Payments are processed by PayPal. We do not receive or store your card or bank details, only a PayPal order/transaction identifier tied to your purchase.
  • Access tokens. One-time access tokens are stored only as a cryptographic hash, never in plain text.
  • Accounts. If you sign up for an account, we store your email and a hashed password. Administrator accounts (staff only) work the same way.
  • Usage data. If analytics are enabled, Google Analytics collects standard usage data (pages viewed, approximate location derived from IP, device/browser). We also set one essential, signed session cookie to hold your access token during a visit.

How we use it

To run the single analysis you request; to process your payment; to operate, secure, and prevent abuse of the service; and to understand aggregate usage.

What we keep and for how long

For a one-time analysis without an account, your resume text is used only for that single run and hard-deleted the moment it completes, whether it succeeds or fails. A backstop process clears any abandoned resume text within approximately 30 minutes. Completed analysis records are deleted within approximately 24 hours. We never store your original resume file.

We retain minimal operational records, hashed access tokens and payment references, for fraud/abuse prevention, support, and accounting.

Because no-account resume content is not retained after a run, there is typically nothing to export or delete on request once that analysis is complete. If you save resumes or reports to an account, see “Accounts & vault” below for what is retained and your export/delete rights over it.

Accounts & vault

If you create an account, you may optionally choose to save resumes and analysis reports to your account (“the vault”) so you can revisit them later. This is opt-in and separate from the one-time, no-account analysis above. We store the extracted text of resumes you save and the reports we generate for you, never your original resume file. If you use the vault’s “apply” feature to rewrite a saved resume against a saved report’s recommendations, the resulting generated resume is saved to your vault the same way, the same encryption, retention, and export/delete rights described here apply to it, with no separate retention model.

Vault content is encrypted at rest using AWS Key Management Service (KMS) envelope encryption, and is retained until you delete it or delete your account.

Running an apply job transiently holds the suggestions you selected, encrypted, for the duration of that run only, it is cleared the moment the job finishes, whether it succeeds or fails, the same way a one-time analysis’s resume text is cleared (see “Retention” above).

You control what stays in your vault: you can delete any saved resume or report individually at any time, export a copy of everything in your vault, or delete your account outright (which permanently removes all of your saved resumes and reports, including any generated resumes and in-progress apply jobs). Export requires you to re-enter your password as a step-up security check.

Who we share it with (we do not sell your data)

We use these service providers (“sub-processors”):

  • Anthropic (Claude) receives your resume text at run time to generate the analysis.
  • Amazon Aurora DSQL hosts our database. It stores no-account resume text transiently (then hard-deleted), encrypted vault content for account holders, and operational records.
  • PayPal processes payments.
  • Amazon Web Services (AWS Amplify) hosts the application.
  • Google Analytics provides usage analytics (if enabled).

We may also disclose information if required by law. (We scrape public job postings from third-party job boards; that is outbound data collection and does not involve sharing your data.)

Cookies

An essential session cookie (to hold your access token) and, if enabled, Google Analytics cookies. Depending on your location, we will honor applicable consent requirements for non-essential cookies.

Your rights

Depending on where you live (e.g., GDPR/UK GDPR, CCPA/CPRA), you may have rights to access, correct, delete, or restrict processing of your personal data, and to object or lodge a complaint. Contact us at support@vulcancv.ai to exercise them.

If you have an account, you don’t need to wait on us for the vault: you can delete any saved resume or report, export your saved vault content, or delete your account and everything in it, all self-serve from your account settings, as described in “Accounts & vault” above.

Security

Data is encrypted in transit; access tokens and admin passwords are stored only as hashes; no-account resume content is not retained; vault content saved to an account is encrypted at rest via AWS KMS envelope encryption.

International transfers

Our providers process data in the United States; using the service involves transferring your data there.

Children

The service is not directed to individuals under 18, and we do not knowingly collect their data.

Changes

We may update this policy; the effective date above will change accordingly.

Contact

See also our Terms of Service.

© 2026 VulcanCV. All rights reserved.