Your CV is processed on your device. NullifyCV also uses online services for payment, licence verification, analytics and error reporting. These activities are different from uploading a CV for redaction.
NullifyCV is operated from the Netherlands. Contact support@nullifycv.com for service and privacy questions.
The redaction workflow reads PDF/DOCX files and produces output in your browser. It does not send CV files or extracted document text to our redaction servers; there is no server-side document-processing step.
When you start checkout, we temporarily save your selected CV and settings in this browser using IndexedDB so you can resume when you return. The temporary copy is deleted after restoration. If checkout is abandoned, it is deleted on your next visit after 24 hours. Closing the browser alone does not trigger deletion; you can clear site data yourself at any time.
Single-CV purchases are associated with a file fingerprint stored only in your browser. This fingerprint is not sent to our server or Stripe. A random purchase/workflow reference is sent to create and verify checkout. Licence records and file fingerprints remain in browser storage until removed. Clearing this storage may require support to restore access.
Stripe processes payments and handles card details. We can access purchase information such as email, billing information, purchased product, amount, payment status and transaction identifiers through Stripe. We use this information to deliver the service, administer subscriptions, provide receipts, handle support, prevent misuse and maintain accounting records.
Our server functions communicate with Stripe to create checkout and confirm what was purchased. A signed licence is stored in your browser and sent to our server for verification. It includes plan, timestamps, checkout reference and, for new purchases, a random workflow reference. New paid access is rechecked online; annual access follows the paid subscription period.
Payment and licence processing supports performance of the purchase contract. Accounting records are retained for the applicable statutory period; the current accounting policy retains required payment records for seven years. We do not use checkout email addresses for promotional mailing lists. Stripe has its own privacy and payment practices: Stripe privacy policy.
We use Vercel Analytics to understand page visits and how features are used. Instrumentation includes page/referrer and device information and events such as mode selection, file format, processing completion, detected-item counts, audit download, upgrade-dialog interactions and checkout clicks. It is not intended to include CV text or filenames in those custom analytics events.
Cookieless analytics is still usage measurement. We therefore do not describe the site as having no tracking or no network activity. We use analytics to improve the service, on the basis of our legitimate interest subject to applicable privacy requirements. See Vercel Analytics privacy information.
We use Sentry to help diagnose application errors. Error reporting can include error messages, stack traces, page URLs, browser/device information and diagnostic context. Do not include sensitive document information when reporting a problem. We do not intentionally attach CV files to error reports. No promise is made here that an error-reporting loader makes no requests unless an error occurs.
Vercel provides hosting and server functions; external providers also deliver fonts and JavaScript libraries. These requests expose ordinary connection information such as IP addresses and user-agent information to the provider. Hosting and payment services may retain security, access and operational records. See Sentry privacy information and Vercel privacy information.
If you email us, we process your address and message to respond. Our support retention policy is two years. Do not attach a real CV unless you have independently decided it is appropriate; use a synthetic example when reporting a detection issue.
We retain required payment records for accounting and keep licence-related records needed for access and support. Provider-held analytics, diagnostics and operational records follow the configured provider retention settings and applicable requirements. Contact us for information about the settings applying to your request. Deletion requests are subject to legal retention duties and the records needed for an active purchase.
Paid access is remembered in the browser where it was activated. Automated licence recovery and device transfer are not currently available; contact support with your Stripe receipt so we can verify the purchase and explain the available options.
Our current analytics integration is cookieless. Necessary browser storage remembers access and temporarily restores checkout work. Stripe's hosted checkout may use cookies and other technologies under its own policies. This site does not promise that third-party checkout is cookie-free.
Providers may process data internationally. Applicable safeguards and provider arrangements apply; an EU contracting entity does not mean all processing remains within the EU.
Depending on the applicable law, you can request access, correction, deletion, restriction or portability of personal data, and object to processing based on legitimate interests. Email support@nullifycv.com. We respond to GDPR requests within the applicable time limits, normally one month. You can complain to the Dutch Data Protection Authority.
Reducing identifiers does not guarantee that a CV is anonymous or that your hiring process meets every legal requirement. Review outputs and apply your own retention and access rules. We update this policy when the service changes. The service is not directed at children under 16.