ACCOUNT DATA · YOUR CONTROL

Keep the history you need. Remove the rest.

Export scan records in a portable format, remove individual analyses, or close the account entirely. Every destructive action states its scope before confirmation.

PROCESS TRACE · PV-PRIVACY-01
01
READ IN MEMORYNo file written to disk
02
ANALYZEDeterministic scan runs
03
DISCARD FILEOnly redacted text remains

ACCOUNT DATA · YOUR CONTROL

Keep the history you need. Remove the rest.

Export scan records in a portable format, remove individual analyses, or close the account entirely. Every destructive action states its scope before confirmation.

NOT STOREDOriginal PDF or DOCX
REDACTEDContact patterns removed
YOUR CONTROLDelete scans or account
01 · NEVER RETAINED

What we do not store

Your original résumé file—PDF or DOCX.
The text of your résumé, including the plain-text preview shown after a scan.
The job description text you paste.
Name, address, email, phone, LinkedIn, or GitHub fields extracted from the file.
02 · MINIMUM RECORD

What we do store

Scores, identified issues, suggested fixes, and keyword coverage.
Which requirements the job listed and whether your CV met them—without quotes from either.
Filename, account ID, plan tier, and display preferences.
Reports you choose to send (“Something wrong?”): your comment, the score, the finding, and the job’s requirement names—never your CV. Kept until you delete your account.
03 · RETENTION

A clock on every record

FREE90 days
PRO12 months
ACCOUNT DELETIONPurged within 24 hours
04 · AVAILABLE ANY TIME

Your controls

Download all scan data as JSON from Account → Data.
Delete one scan or your entire scan history.
Delete your account with no recovery window.
05 · OUTSIDE SERVICES

Data sharing

We do not sell your data or share résumé content with recruiters, employers, or job boards.
Groq runs the language model that reads the job posting to list its requirements; it receives only the posting.
TypeSafe checks your CV against those requirements. It receives your CV text with your name, email, phone, links, and street address removed, and does not train on it. Parviso keeps none of that text.
Clerk processes authentication. Stripe will process payments when paid plans launch. Each receives only what its function requires.
REVERSIBILITY STANDARD

Export before deletion. Confirm before purge.

Controls use direct language, show the affected record count, and never hide account deletion behind support requests.

Something unclear?privacy@parviso.app →