Privacy Policy
Last updated: July 2026
CallbackCV (by Tekivex) helps you build ATS-friendly resumes, track job applications, and measure which resume version actually gets callbacks. This policy covers the web app, mobile apps, the CallbackCV browser extension, and the CallbackCV MCP server.
What we collect
- Account data: your email address and authentication credentials.
- Resume content: everything you add to a resume, plus files you upload for parsing.
- Job-search data: job applications you save, their status, and the resume version used.
- Usage data: minimal operational logs needed to run and secure the service.
How your data is stored and protected
Your resume and account data are stored in your CallbackCV account on our servers, encrypted in transit (HTTPS) and at rest. They follow you across devices when you sign in. You may also enable an optional zero-knowledge encrypted backup, which is encrypted with a passphrase only you hold.
What we do NOT do
- We do not sell your data.
- We do not use your resume to train AI unless you explicitly opt in (Settings → Training data).
- We do not share your data with third parties except the infrastructure and payment providers needed to run the service.
AI features
AI features (resume critique, tailoring, JD match, mentor, and others) send the relevant resume/job text to an AI provider to generate a response. If you supply your own AI key (BYOK), requests use your key. This processing generates your result and is not used to train our models.
Browser extension
The CallbackCV browser extension stores your API base URL and access token in your browser’s local storage (chrome.storage.local) on your device. It reads a job posting only on the job-board pages you visit and only to capture the job description and details you choose to save. That data is sent solely to your own CallbackCV account to create or update a job application. The extension does not sell data, does not track your browsing, and requests access only to the supported job boards and the CallbackCV API.
MCP server (AI assistant access)
The CallbackCV MCP server lets an AI assistant (e.g. Claude, ChatGPT) act on your behalf using a token you paste from Settings → API access. An assistant using it can do only what you can do in the app; your plan limits and quotas still apply. The token is stored in your MCP host’s configuration on your device.
Data retention
- Resume and job-search data: kept for as long as your account exists. Deleting a resume removes it; deleting your account removes your account data.
- Access tokens: expire automatically (about 7 days). Logging out invalidates active tokens immediately.
- Payment records: retained as required for accounting, tax, and legal obligations, even after account deletion. Card details are held by the payment provider (Razorpay/Stripe), never by us.
- Operational logs: kept only briefly for security and debugging, then discarded.
Your controls
- Delete any resume, or your entire account, at any time.
- Log out to invalidate active access tokens.
- Opt in or out of AI training on your data in Settings.
Contact
Questions or data requests: novaai0401@gmail.com.