Last updated: July 8, 2026

Privacy Policy

localCV is a local-first, privacy-focused resume builder. Your resume and profile data is stored on your own device by default, not on our servers. This policy explains exactly what data we process, why, where it goes, and what choices you have.

1. Information We Collect

We collect different data depending on how you use localCV:

  • Local resume and profile data: Your profile details, resume content, company-specific resumes, ATS scoring results, and job application tracker entries are stored in your browser's local database (IndexedDB) on your device. We do not store this data on our servers unless you explicitly enable GitHub Backup & Sync (see Section 3).
  • Account information (GitHub sign-in): If you sign in with GitHub, we receive your GitHub username, public profile information, and email address for authentication purposes only.
  • AI provider API keys: If you configure an AI provider (e.g. OpenAI, Anthropic, Google) to use AI features, your API key is encrypted and stored locally in your browser. We do not retain a copy of your API key on our servers.
  • Usage analytics: We use Microsoft Clarity to understand how the app is used (e.g. clicks, page views, scrolling behavior) so we can improve the product. See Section 6 (Cookies & Analytics).

2. How We Use Information

We use your information to:

  • Generate, edit, and export resumes and related documents.
  • Provide AI-assisted refinement, tailoring, cover letter generation, ATS scoring, and resume parsing features.
  • Authenticate you and, if you opt in, back up your local data to a private repository in your own GitHub account.
  • Improve app reliability, security, and user experience.

3. OAuth, Account Access & GitHub Backup

localCV supports sign-in with GitHub. When you sign in, we request the following OAuth scopes: your basic profile and email (read:user, user:email) and repository access (repo). The repo scope is used only for the optional GitHub Backup & Sync feature, which, if you turn it on, creates a private repository (localcv-backup) in your own GitHub account and uploads an export of your local data (profile, resumes, ATS results, job applications) to it. This data is stored in a repository you own and control, not on localCV infrastructure. Your GitHub access token is held only in your session (JSON Web Token) and is not written to a persistent server-side database.

4. AI Features & Third-Party AI Providers

localCV's AI features (resume tailoring, ATS scoring, cover letter generation, section refinement, and CV parsing) use a "bring your own key" model: you choose an AI provider (such as OpenAI, Anthropic, or Google) and supply your own API key. When you use an AI feature, the relevant resume content, job description, or uploaded CV text is sent through our server to your chosen AI provider to generate a response. We do not store this content in a database — it is used only in memory to process your request and is discarded once the response is returned. Use of AI features is subject to the privacy policy and terms of your chosen AI provider, and standard usage limits or costs that provider may charge to your API key.

5. Data Sharing

We do not sell your personal information. We share data only in the following circumstances:

  • With the AI provider you configure, solely to process the AI requests you initiate (Section 4).
  • With GitHub, solely to authenticate you and, if enabled, to back up your data to a repository you own (Section 3).
  • With Microsoft Clarity, our analytics provider, for aggregate usage analytics (Section 6).
  • With infrastructure and hosting providers necessary to operate the app, under appropriate contractual safeguards.
  • Where required to comply with applicable law.

6. Cookies & Analytics

We use essential cookies to maintain your sign-in session. We also use Microsoft Clarity, a third-party analytics service, which may set cookies and use local storage to record aggregate usage patterns (such as clicks, scrolling, and navigation) to help us improve localCV. Microsoft Clarity processes this data subject to its own privacy policy. You can control cookies through your browser settings, though disabling essential cookies may affect sign-in functionality.

7. Data Retention

Local resume, profile, and job-tracker data remains in your browser's IndexedDB until you delete it or clear your browser storage. If you enable GitHub Backup & Sync, backup data persists in your own GitHub repository until you delete it there. Session data (e.g. your GitHub sign-in token) is retained only for the duration of your active session. We do not maintain a server-side database of user accounts or resume content.

8. Security

AI provider API keys are encrypted before being stored in your browser, and are only decrypted transiently on our server to process an AI request. We apply reasonable administrative and technical safeguards to protect data in transit and while processed on our server. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Since most of your data lives on your own device, you are also responsible for the security of your browser and device.

9. Your Choices

You can control your data by editing or deleting locally stored content at any time, disconnecting GitHub sign-in or Backup & Sync, removing your AI provider API key, deleting the backup repository in your GitHub account, clearing your browser's local storage, or discontinuing use of the app. You may also contact us for privacy-related requests.

10. Children's Privacy

localCV is not directed to children under 13 (or the minimum age required by your jurisdiction), and we do not knowingly collect personal information from children.

11. Contact

For privacy questions or data requests, contact: tusharvashisth4@gmail.com

12. Updates to This Policy

We may update this policy from time to time to reflect changes in the app or applicable law. Material changes will be reflected by updating the date at the top of this page.