Privacy Policy
Last updated: 11 May 2026
This Privacy Policy explains how CleverTailor handles your personal data. CleverTailor is operated by Sarvesh Muralitharan, a sole trader based in the United Kingdom (the "Operator", "we", "us"). We can be contacted at support@clevertailor.com.
What data we collect
When you use CleverTailor, we collect:
- Account information you provide when signing up: email address, password (stored hashed), and your name.
- CV content you upload to be analysed and tailored. This includes any personal information present in your CV (employment history, education, contact details, etc.).
- Job descriptions you paste into the product.
- Payment information if you subscribe to Pro. We never see your full card details — payment is handled by Stripe.
- Usage data: pages you visit, features you use, errors you encounter. This is collected via standard server logs and Supabase analytics.
- Cookies strictly necessary for authentication and session management. We do not use advertising or tracking cookies.
How we use your data
We use your data to:
- Provide the CV tailoring, project recommendation, and tutorial generation features you signed up for.
- Process payments and manage your subscription.
- Send you transactional emails (account confirmation, password resets, billing receipts).
- Improve the product by understanding how it's used in aggregate.
- Comply with legal obligations.
We do not sell your data. We do not use your CV or job descriptions to train AI models. We do not share your data with advertisers.
Where your data goes
CleverTailor uses third-party services to operate. Your data may be processed by:
- Supabase (database and authentication) — data stored in EU/UK data centres.
- Anthropic (AI provider for analysis and tutorial generation) — your CV text and job descriptions are sent to Anthropic's API for processing. Anthropic does not retain or train on this data per their commercial terms.
- Stripe (payments) — payment information processed by Stripe under their privacy policy.
- Resend or similar (transactional email) — for sending account-related emails.
How long we keep your data
- Account data: retained while your account is active. Deleted within 30 days of account deletion.
- CV uploads and analyses: retained while your account is active so you can revisit Match History. Deleted on account deletion.
- Payment records: retained for 6 years after your last transaction, as required by UK tax law.
Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Object to or restrict our processing.
- Receive your data in a portable format.
- Withdraw consent for processing where consent is the legal basis.
To exercise any of these rights, email support@clevertailor.com. We'll respond within 30 days.
Data security
We use industry-standard security: encrypted connections (HTTPS), hashed passwords, role-based database access controls, and regular security reviews. No system is completely secure, but we take reasonable steps to protect your data.
Data breaches
If a data breach occurs that's likely to result in risk to your rights and freedoms, we'll notify the UK ICO within 72 hours and notify affected users without undue delay.
Children
CleverTailor is not directed to anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we'll delete it.
ICO registration
CleverTailor will be registered with the UK Information Commissioner's Office (ICO) as a data controller. Our ICO registration is in progress and will be confirmed shortly.
Changes to this policy
If we make material changes to this policy, we'll notify you by email and update the "Last updated" date above.
Contact
Questions about this policy: support@clevertailor.com
You also have the right to lodge a complaint with the UK ICO if you believe we've mishandled your data: ico.org.uk/concerns.