Privacy
Your data, plainly
Who operates this pilot and how to contact us
David Hall, operator of Evident Career Studio, runs this pilot and is the data controller for the personal data described on this page. To ask about your data or make a privacy request, email evidentcareerhelp@gmail.com or use the on-site form.
Make a privacy requestThe form records your request as a case and gives you a reference and a private key. Keep the key safe — you need both to check the status or delete the case on the case page, and we can't recover a lost key. Giving an email address is optional. Case status updates are shown on the case page and are not emailed automatically. Nobody is assigned to review cases or emails yet, so we can't promise a reply or a response time.
- Your files
- PDF, Word and text files are read inside your browser. The file itself is never uploaded or kept — only the extracted or entered text you choose to analyse is used, and that text is sent to the AI when you ask for questions.
- Where your CV and answers live
- Your CV text, job text, answers, AI-suggested and approved wording, organisation corrections, any application pack choices and your saved complaint references and keys are saved only in your own browser's local storage on this device. We don't hold a copy on a server. Clearing browser data, or the button below, deletes them.
- What goes to the AI
- When you ask for questions, a follow-up or draft wording, the relevant text — which can include your CV, the job text and your answers — is sent to an AI model (from OpenAI) through Lovable's AI service to produce a reply. This app's own code doesn't save that text on our server, doesn't write it to our logs and doesn't put it in analytics. Lovable and the model provider handle it under their own terms, which we don't control — see Lovable's privacy policy (lovable.dev/privacy) and OpenAI's API data policy (openai.com/policies).
- Writing your final CV (Anthropic)
- When you press “Build my CV”, your confirmed CV text, the job advert text and the answers you approved (never ones you marked private) are sent from our server to Anthropic's Claude AI, which writes the CV. This is a different provider from the one above. Anthropic may keep that text for a limited period under its own commercial terms and policies, which we don't control — see anthropic.com/legal. Our server doesn't save it, log it or put it in analytics; the finished CV is kept only in your browser.
- Complaints you submit
- If you submit a complaint, we store on our server: the category, your description, your email if you give one, basic context (which step and item, and your browser type — not the text), and a redacted excerpt only if you tick the box after seeing exactly what will be sent. We also keep a scrambled (hashed) form of your connection's IP address and of your private key, to stop abuse and so only you can open the case. We never store the raw IP address or the key itself.
- Who can see a complaint
- Only someone with both the case reference and the private key, and the site owner through a protected, signed-in owner account. Other visitors cannot list or search cases. At the moment nobody is assigned to review cases, and no automatic emails are sent about cases.
- How long complaints are kept
- A case is deleted automatically 180 days after it was last changed (submitted or updated). The one exception: a case marked “In review” is kept until it leaves review, then the 180 days apply. You can delete your case sooner at any time on the case page. The clean-up runs once a day, so deletion can take up to a day longer.
- How long fair-use records are kept
- Records used for rate limits — a scrambled IP address, the type of request and the time — are deleted automatically after 7 days by the same daily clean-up.
- Where the server is
- Our database runs on Lovable Cloud. Its connection address points to Amazon Web Services' eu-west-1 region (Ireland). We haven't independently confirmed where backups or the AI service process data, so we don't make a wider claim about where data is kept.
- Optional pilot session sharing
- At the end of your CV you can choose to share your full session with David Hall, the pilot operator, so he can see where Evident helped or let you down. Nothing is shared unless you tick the consent box and press Share. A share contains your CV and job text as extracted in your browser (not the files), the questions and why they were asked, your answers and follow-ups (except questions you marked private), wording you approved, edited or rejected, the requirements found, how your CV was built (what was kept, left out and why), your final CV and style, the automatic quality checks, download attempts and the feedback tags you sent, with times. You can update the shared copy later. It is stored in our database (Lovable Cloud, encrypted at rest by the platform), readable only by the protected owner account, never sent to analytics and never used to train AI. It is deleted 30 days after your last update and in any case by 10 November 2026. You can withdraw and delete it at any time from the same place, or ask for deletion using the contact details above.
- AI, not people
- Questions and suggested wording are generated by AI. No person reviews your CV or answers.
- No verification of you
- We never verify employment, attendance, qualifications or dates. Organisation names are picked out of what you wrote, and you can correct them. Links to official registers only help you check an organisation exists.
- Speech input
- Dictation uses your browser's built-in speech recognition, which may be processed by your browser's provider (for example Google or Apple).
- “Helpful?” and “Report a problem” buttons
- These send only a tag: which step you were on (for example analysis or pack), what kind of thing you rated (a question, a suggested claim, a tip or a pack line), the tag you chose (such as “Incorrect quote”), the application type you picked, and which version of our AI instructions, AI model and tips was in use. The tag record itself holds none of your CV, job text, answers, the wording you rated, your name or email. Sending a tag also creates a temporary fair-use record (a scrambled IP address, the request type and the time) that is deleted after 7 days; while it exists, it could in principle be matched to a tag by time. Tags are deleted after 90 days by the daily clean-up. The owner account can see the individual tag records and totals. Tags don't change the AI automatically — they're reviewed alongside regular checks before any change. To explain a problem in your own words, use the optional detailed report on the Help page, which you can delete.
- Fair-use limits on the free AI
- To keep the free journey available to everyone, each AI request records a scrambled (salted, one-way) version of your IP address, the type of request and the time — never your CV, job text or answers. These records are used only to apply hourly and daily limits.
- Payments
- Payments are not live. No checkout exists, no card or billing details are collected, and no payment provider receives any of your data. If paid packs launch, this page will be updated before any charge is possible.
- Analytics
- No analytics service is connected. Nothing you type, upload or say is sent to an analytics or advertising provider.
Delete everything now
Removes your CV text, job text, answers, claims and saved case keys from this browser.
This clears this browser, including saved case keys. To delete a submitted complaint from our server, use the case page first.