Privacy Policy
Last updated: 2026-06-29
Pasvo LLC ("we," "us," or "our") operates Pasvo (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Geographic scope. Pasvo is intended for and offered only to users located in the United States. The Service is not directed to, and we do not knowingly provide it to, individuals located in the European Economic Area, the United Kingdom, or Switzerland. We use geolocation controls to restrict access from those regions. If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local law.
This Privacy Policy should be read alongside our Terms of Service.
1. Information We Collect
Account Information
When you create an account, we collect information provided through our authentication partner Clerk, including your email address, name, and profile picture. We do not store your password - authentication is handled entirely by Clerk.
Resume & Cover Letter Content
We store the content you create within the Service, including resume sections (work experience, education, skills, certifications, projects, volunteer work), cover letter text, and job descriptions you provide for targeting.
Usage Data
We collect information about how you use the Service, including pages visited, features used, AI generation counts, document exports, and application tracking activity. This data is collected via PostHog analytics with Do Not Track respected.
Payment Information
Payment processing is handled entirely by Stripe. We do not store your credit card number, bank account details, or other financial information. We receive only subscription status and billing identifiers from Stripe.
AI Generation & Activity Data
So the product can remember your work and keep getting better at helping you, we also keep a record of how you use the AI features. You stay in control of it - you can delete it at any time, and it is permanently destroyed when you delete your account (see Account Deletion below). Download My Data includes all of it except the prompt text, for the reason given below. This includes:
- AI prompt & output history: A durable, encrypted record of the prompts you submit and the AI output we produce for you (your tailored bullets, summaries, and cover letters), so we can keep improving how the engine tailors content for you. This text is encrypted at rest. The AI output is included in Download My Data; the prompt text is not. A stored prompt is mostly our own instructions to the model wrapped around your content, so handing it back would tell you how Pasvo works rather than anything about you. Your own content is exported separately in its original form - your resumes, cover letters, and job descriptions you have saved under Jobs. One limitation worth naming: text you type straight into a generation form without saving it as its own record - a job description you paste in but do not save, or a hiring manager's name - is not stored anywhere else, so it is not part of the export. The prompt record is still deleted with your account.
- Activity & event data: Lightweight signals about how you interact with the editor - for example when you accept or dismiss a suggestion, or abandon a generation. These records hold only identifiers, status values, and technical metadata (no free-text content). We also attach an opaque correlation id to our server logs and to these durable activity records so we can trace and fix problems; that id does not identify you.
- Application-status history: When you move a job application between stages (for example, saved to applied to interviewing), we record the change so we can show you your progress over time.
- Resume & ATS snapshots: At key milestones - when you accept an AI optimization, export a document, or mark an application submitted - we keep a point-in-time encrypted copy of the resume along with its numeric ATS score. Only the numeric and structural ATS data is stored alongside the snapshot; we do not store the underlying keyword text.
Log & Technical Data
When you use the Service we automatically collect limited technical data, including your IP address and browser user agent. We use this to apply rate limits, prevent abuse, and keep security and audit logs. IP addresses recorded in our security audit log are retained as described in Data Retention below.
Anonymous Use of the Free ATS Checker
You can use our free ATS Checker without an account. When you do, your uploaded file is processed in memory on our servers to produce your score and is not stored, shared, or retained afterward - we do not save the file or its contents. As with the rest of the Service, we do log technical metadata (such as your IP address) for rate-limiting and abuse prevention.
A Note on Sensitive Information
You are always in control of what you enter. Resumes can sometimes contain sensitive personal information - for example, details that reveal health, religion, ethnicity, or union membership. You do not need to include anything like that to use Pasvo, so as a simple privacy habit we suggest leaving out anything you would rather not have processed. Whatever you do enter is stored on encrypted infrastructure, and anything saved as its own record can be exported or deleted (and permanently destroyed by deleting your account) at any time. This is a tip for your benefit, not a warning that the product is risky.
2. How We Use Your Information
- Service Delivery: To provide resume building, cover letter generation, ATS scoring, and document export features.
- AI Processing: To generate content suggestions, keyword optimization, and ATS analysis using AI models.
- Account Management: To manage your subscription, enforce usage limits, and process payments.
- Analytics: To understand usage patterns, improve features, and fix bugs.
- Error Tracking: To identify and resolve technical issues via Sentry error monitoring.
- Improving the AI engine: To learn from the prompts and output above so the engine gets better at tailoring content and matching you to roles. You can object to this or delete the underlying data at any time.
- Predictive & benchmarking features: We may develop features that help you benchmark your resume and predict how it performs - so you get better matches and clearer guidance. These are forward-looking and you can object to this use.
- Anonymized aggregate insights: To produce statistics that no longer identify anyone - for example, which skills appear most often for a given role. We do this so we can keep offering a free tier and improve match and benchmark accuracy for everyone, and you can object to this use.
Legal Bases for Processing
Pasvo does not currently serve users in the EU/EEA or UK (see "Geographic scope" above). If and when we serve EU/EEA users, the legal basis we would rely on for each purpose, in plain language, is as follows:
- Contract: Delivering the Service - building resumes, generating content, scoring, and exporting documents - is how we perform the agreement you enter when you use Pasvo.
- Legitimate interest (with your right to object): Analytics, error tracking, improving the AI engine with durable training data, developing predictive and benchmarking features, and creating anonymized aggregate insights. You can object to any of these at any time using your rights below.
- Consent (where required): Marketing email and any processing of special-category information. Where we rely on your consent, you can withdraw it at any time.
Automated Decisions & Profiling
We want to be clear about how the automated parts of Pasvo work for you. ATS scoring is algorithmic, and keyword extraction is AI-assisted - both are there to give you suggestions and decision support, not to decide anything for you. Any predictive or benchmarking features we may develop are likewise decision support. You always review and choose what goes into your resume. If and when we serve EU/EEA users, this means you would not be subject to a decision based solely on automated processing that produces legal or similarly significant effects about you.
3. AI Data Processing
When you use AI-powered features (content generation, keyword extraction, cover letter creation), your content is sent to third-party AI providers for processing. Note: ATS scoring itself is algorithmic and does not send your data to AI providers; only keyword extraction from job descriptions uses AI.
- Anthropic (Claude): Used for text generation, keyword extraction from job descriptions, resume bullet optimization, cover letter writing, and - as the primary provider - vision/OCR when importing resumes from images or PDFs.
- OpenAI (GPT-4.1): Used as the fallback vision/OCR provider for resume imports; while we evaluate vision providers, import images may also be sent to OpenAI in a parallel quality-comparison call.
Your content is sent to these providers solely for processing your requests. Per their data usage policies, content sent via API is not used to train their models.
We store AI data in two ways, and you stay in control of both:
- A short-lived cache: To improve performance and reduce costs, AI responses may be cached in our database for up to 7 days, capped at roughly the most recent 1,000 entries per user.
- A durable, encrypted generation log: So we can keep improving how the engine tailors content for you, we also keep a durable record of the prompts you submit and the AI output we produce. This text is encrypted at rest, and you are in control of it - the AI output is included in Download My Data, and the whole record is rendered permanently unreadable when you delete your account (see Account Deletion below). The prompt text is not included in the export, because it is mostly our own instructions wrapped around your content; your own content is exported separately as your resumes, cover letters and saved job descriptions, with the unsaved-form-text limitation noted above. Deleting your account makes your durable data permanently unreadable; the short-lived cache above is cleared by the same automated deletion process.
4. Data Storage & Security
Your data is stored in a PostgreSQL database hosted on infrastructure that provides disk-level encryption at rest. In addition, our durable AI-generation log is encrypted at the application level with a key unique to you (the same key whose destruction makes that data permanently unreadable when you delete your account). Temporary data (sessions, caches) is stored in Redis. Exported documents (PDF/DOCX) are generated on demand and are temporary.
We implement industry-standard security measures including:
- Encrypted data transmission (HTTPS/TLS)
- Row-level data isolation (all queries filtered by user ID)
- Webhook signature verification for all integrations
- No cross-user data access is possible through our API
- Sensitive headers and PII redacted from error reports
If a breach occurs. If we become aware of a security breach that compromises your personal information, we will investigate promptly, take steps to contain it, and notify affected users and any required authorities as required by applicable law, without unreasonable delay.
5. Third-Party Services (Sub-processors)
We use the following third-party services (sub-processors) to operate Pasvo. Each is bound by a data-processing agreement requiring protections equivalent to those described in this policy, and each processes only the minimum data required for its function:
- Clerk - Authentication and user management. Processes your email, name, and authentication credentials.
- Stripe - Payment processing and subscription management. Processes your payment instrument and billing address; receives a billing identifier from us.
- Anthropic - AI text generation via Claude models. Receives the resume, cover letter, and job description content you submit for AI-assisted generation, optimization, and keyword extraction.
- OpenAI - AI vision and OCR for document import. Receives uploaded resume images and PDFs you submit for parsing.
- Browserless - PDF rendering service. Receives your resume and cover letter content during PDF generation; output documents are produced on-demand and are not retained by Browserless beyond the rendering request.
- Resend - Transactional email delivery. Receives your email address and the message body for account events such as payment failure notifications.
- Railway - Cloud hosting provider, including managed PostgreSQL database and managed Redis cache. Stores your account data, resume content, cover letters, job descriptions, applications, and cached AI responses.
- Cloudflare - Content delivery network, TLS termination, and DDoS protection. Processes request metadata (IP address, user agent) and serves static assets; does not see decrypted application payloads.
- Sentry - Error tracking and performance monitoring. Receives error stack traces and request metadata; sensitive headers and personally identifiable information are redacted before transmission.
- PostHog - Product analytics and feature flags. Receives event metadata about feature usage; respects Do Not Track browser settings.
We encourage you to review the privacy policies of each sub-processor. We will update this list when we add or change sub-processors and will reflect such changes in the "Last updated" date at the top of this policy.
International Data Transfers
Your personal data may be processed in the United States and in other countries where we or our sub-processors operate. Where required, we protect international transfers of personal data using appropriate safeguards, such as Standard Contractual Clauses. Because the Service is currently offered only to users in the United States (see "Geographic scope" above), these transfer safeguards apply to data processed by our sub-processors rather than to EU/EEA user data, and we will formalize Standard-Contractual-Clause-based transfers if and when we extend the Service to the EU/EEA, the United Kingdom, or Switzerland.
6. Data Retention & Deletion
How long we keep your data varies by category. The schedule below sets out each category and how long we keep it.
Retention Schedule
| Data category | How long we keep it |
|---|---|
| Account and active content | For the life of your account |
| Deleted resumes and cover letters (in Trash) | 30 days, then permanently purged |
| Account-deletion grace period (reversible) | 30 days |
| Cached AI responses | Up to 7 days, capped at roughly the most recent 1,000 entries per user |
| Durable AI, activity, application-status, and snapshot data | Kept to develop and improve predictive and benchmarking features; permanently destroyed when you delete your account (crypto-shred) |
| Audit-log entries | Retained for up to 2 years (730 days) for security and legal recordkeeping, including after account deletion (see Account Deletion) |
Content Lifecycle
- Resumes and cover letters - When you delete a resume or cover letter, it moves to Trash and stays recoverable for 30 days from the Trash page (reachable from your dashboard). Items in Trash are not visible in your main dashboard but still free a slot toward any applicable active-document limit. After 30 days, they are permanently purged by an automated process, whether or not your account is deleted.
- Job descriptions, job applications, and share links - When you delete one of these from the dashboard, it is permanently removed immediately.
- Cached AI responses - Cached prompts and responses expire after 7 days; in addition, only the most recent 1,000 entries per user are retained.
- Exported document records - Records of PDF and DOCX exports are retained for usage tracking; the exported files themselves are temporary and are not retained after delivery.
- Audit log entries - Security-relevant events (account login, payment changes, share-link creation, account deletion) are retained for up to 2 years (730 days) for compliance and security purposes, after which an automated process deletes them. Because they are kept for security and legal reasons, some identifying detail may persist in these entries after your account is deleted, up to that 2-year limit (see Account Deletion below for how this is limited).
Account Deletion
You can delete your account at any time from the Settings page. We encrypt your durable data with a key that is unique to you, and when you delete your account we destroy that key - making your durable data cryptographically irreversible in our live systems. As described below, an encrypted backup can retain a recoverable copy for a short backup-retention window; once that window passes, the data is permanently unrecoverable. Account deletion triggers the following process:
- Your account enters a 30-day grace period. During this period you can cancel the deletion request from the Settings page and your account is restored unchanged.
- After the 30-day grace period expires, all your data - including resumes, cover letters, job descriptions, applications, share links, exported document records, AI usage history, cached AI responses, and account information - is permanently and irreversibly removed from our live systems via an automated purge process. Destroying your unique encryption key makes your durable data permanently unreadable; the short-lived AI cache is cleared by the same automated process. Your authentication record at Clerk is also deleted.
- Audit log entries that reference your account are retained for security and compliance recordkeeping for up to 2 years (730 days), after which an automated process deletes them. The foreign-key reference to your user identifier is removed; identifying details (such as your email address) may be retained inside the audit-log entry's old-values payload for fraud-investigation and security purposes during that period, and are accessible only to authorized Pasvo personnel responding to security incidents or lawful legal process.
For disaster-recovery purposes we keep encrypted backups of our database for a limited retention window (currently no more than 30 days, depending on our infrastructure provider's backup schedule). Data you delete - including an account you remove - is purged from our live systems on the schedule above, and any residual copy in an encrypted backup ages out and is overwritten within that backup-retention window. Backups are used only to restore the Service after an incident, and we re-apply your deletions to any restored data so removed content does not return.
You may also export your data before deletion using the "Download My Data" feature in Settings to receive a JSON archive of your account, profile, resumes, cover letters, saved job descriptions, applications, document records, and your AI activity history (see AI Generation & Activity Data above for what that includes).
7. Cookies & Tracking
We use the following cookies and local storage:
- Clerk Session Cookies: Required for authentication. These are essential cookies that cannot be disabled.
- PostHog Analytics: Used for product analytics and feature flags. Respects Do Not Track browser settings.
- Theme Preference: Stored in local storage to remember your light/dark mode preference.
8. Your Rights
GDPR Rights (EU/EEA Residents)
Pasvo does not currently serve users in the EU/EEA or UK (see "Geographic scope" above). We describe the rights below because we intend to extend the Service to those regions in the future; if and when we do, EU/EEA and UK residents will have the following rights:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data.
- Portability: Receive your data in a structured, machine-readable format.
- Restriction: Request limitation of processing.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where we rely on your consent (for example, marketing email or any special-category processing), you can withdraw it at any time. Withdrawing your consent does not affect any processing we carried out before you withdrew it.
- Lodge a complaint: You have the right to lodge a complaint with your local data protection supervisory authority.
EU/UK representative.Because the Service is offered only to users in the United States (see "Geographic scope"), we are not currently required to appoint an EU or UK representative under Article 27 GDPR / UK GDPR, and we have not appointed one. If we extend the Service to the EU/EEA or UK, we will appoint and identify a representative here before doing so.
CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know: What personal information we collect and how it is used.
- Delete: Request deletion of your personal information.
- Opt-out: Opt out of the sale of personal information. We do not sell your personal information.
- Non-discrimination: Exercise your rights without discriminatory treatment.
- Limit sensitive personal information:Resumes may contain what California law calls "sensitive personal information." You can ask us to limit our use and disclosure of your sensitive personal information to what is necessary to provide the Service.
To exercise any of these rights, use the data management features in your Settings page or contact us at [email protected].
Verifying your identity. To protect your information, when you ask us to access, delete, or export your data, we will take reasonable steps to verify your identity before acting - typically by confirming the request comes from the email address associated with your account, or by asking you to sign in and use the data tools in your Settings. We cannot fulfill a request we are unable to reasonably verify.
Anonymized, Aggregated Insights
Pasvo reserves the right to create, retain, use, and commercialize anonymized, aggregated insights derived from how the Service is used - for example, aggregate statistics about which skills appear most often for a given role. We do this so we can keep offering a free tier and improve match accuracy for everyone. These insights are stripped of anything that identifies you and cannot be traced back to you.
We do not sell your personal information. We treat the sharing of these anonymized, aggregated insights as not constituting a "sale" or "share" of personal information, because they are de-identified and aggregated so that they no longer reasonably identify, relate to, or could be linked to you, and we contractually and operationally commit not to attempt to re-identify them. We make this determination in good faith; it is our position, and the law in this area continues to develop.
What we will never do
- We will never sell your personal information, your resume or cover-letter content, or anything that identifies you to third parties, nor share it for cross-context behavioral advertising.
- We will never use your content to train third-party AI models.
- The reservation above is strictly limited to anonymized, aggregated data - it never extends to data that identifies you.
9. Children's Privacy
Pasvo is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete that information promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Information
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
- Email: [email protected]
- Company: Pasvo LLC
Ready to build your ATS-optimized resume?
Create Your Free Account