Privacy Policy

This Privacy Policy explains how we collect, use, protect, and share your personal data under the General Data Protection Regulation (GDPR) and Polish law.

1. Introduction

MIVIA SP. Z O.O. ("we," "us," or "our"), a company registered in Poland, operates CVRocket.app, an AI-powered platform to help job seekers create resumes, motivation letters, track applications, and prepare for interviews. This Privacy Policy explains how we collect, use, protect, and share your personal data under the General Data Protection Regulation (GDPR) and Polish law. By using CVRocket.app (https://cvrocket.app), you agree to this policy.

2. Data We Collect

dataWeCollectTitle

dataWeCollectDescription

  • Account Information: Email, username, password (if you sign up).
  • CV and Job Data: Resume content (e.g., job titles, skills), job descriptions, and inputs for CV analysis, motivation letters, or interview prep.
  • Usage Data: App interactions, IP address, device info, analytics.
  • Payment Data: Billing details (processed by Stripe) for paid plans.
  • Public Social Media Data: Publicly available usernames, posts, or mentions from X, LinkedIn, and Facebook accessed via their APIs for promotional bot replies (e.g., responding to job-related posts). We do not use CVRocket.app registered user data for this—only public social media data.

3. How We Use Your Data

howWeUseDataTitle

howWeUseDataDescription

  • Provide CVRocket.app services (e.g., AI resume generation via Grok-2 in private mode).
  • Improve our platform (e.g., analytics).
  • Communicate (e.g., updates).
  • Promote CVRocket.app via bots that reply to public posts on X, LinkedIn, and Facebook (e.g., "@User, check CVRocket.app!"). This uses only public social media data, not CVRocket.app user data from our database, though coincidental overlap may occur if a registered user's public post is replied to.
  • Meet legal duties (e.g., Polish tax law).

Legal bases (GDPR):

legalBasesTitle

legalBasesDescription

  • Consent (e.g., optional features).
  • Contract (e.g., service delivery).
  • Legitimate interest (e.g., security, public social media promotion).

4. Data Sharing

We share with:

serviceProvidersTitle

serviceProvidersDescription

  • xAI (Grok-2): Processes CV/job data in private mode—no data is stored by xAI.
  • Railway.app: Hosts data on US servers in AWS cloud.

Legal Authorities: If required by Polish/EU law.

We do not sell your data.

5. Data Storage and Security

Data is stored on US servers through Railway.app, which manages servers in the AWS cloud, using encryption and access controls. CV/job data is kept only as needed (e.g., until account deletion + 30-day backup), or longer for legal reasons (e.g., 5 years for payment records under Polish law). xAI's private mode ensures no data retention by them.

6. Your Rights (GDPR)

You can:

yourRightsTitle

yourRightsDescription

  • Access, correct, delete your data.
  • Restrict/object to processing.
  • Request data portability.
  • Withdraw consent.
  • Complain to Poland's UODO.

Email: [email protected].

7. Cookies and Tracking

We use cookies for logins and analytics (e.g., Google Analytics, anonymized). Manage via browser. Bot activity on X, LinkedIn, and Facebook may involve their cookies—see their policies.

8. Third-Party Services

thirdPartyServicesTitle

thirdPartyServicesDescription

  • xAI (Grok-2): Processes data in private mode—no storage occurs—see xAI's terms.
  • Railway.app: Hosts data on AWS US servers—see Railway's privacy policy.
  • Stripe: Processes billing data—see Stripe's privacy policy.
  • X.com, LinkedIn, Facebook: Provide public data for bot promotion via their APIs—see their terms. We do not use CVRocket.app user data for this.

9. International Transfers

Data is transferred to the US via Railway.app (AWS servers) and Stripe, and processed by xAI in private mode. Public data accessed via X, LinkedIn, and Facebook APIs may also involve US transfers. We use GDPR safeguards (e.g., Standard Contractual Clauses) to ensure compliance. xAI's private mode minimizes transfer risks.

10. Children's Privacy

CVRocket.app is not for users under 16.

11. Changes

We may update this policy. Check here for changes; major updates notified via email/app.

12. Contact Us

MIVIA SP. Z O.O.

ul. Świerkowa 6, 19-300 Woszczele, Polska

NIP: PL8481890223

REGON: 540026889

KRS: 0001135201

Email: [email protected]

Last Updated: March 02, 2025