Legal

Privacy Policy

Last updated: July 17, 2026

MemoryCV is operated by TwinBruhs LLC. Here’s what we collect, the providers that process it on our behalf, and how to get your data out or delete it. It applies alongside the Terms of Service.

What we collect

Everything below is data you give us to build your profile; we do not buy data about you or track you across other sites.

  • Account details: your name, email address, and password. The password is stored only as a salted hash, never in plain text.
  • Career history facts you add through text chat, voice conversations, or profile editing: roles, projects, skills, education, credentials, and preferences.
  • Links you choose to make between a skill and the work that demonstrates it, picked from your own career facts. These are candidate-provided examples; we never present them as employer-verified.
  • Voice intake audio and the conversation transcripts derived from it.
  • Resume files (PDFs) you upload for fact extraction.
  • Content the product derives from your facts: generated resumes, grounded application materials, job-match scores, and application records. An application record can include status and timeline events, private notes and contacts, submitted material, and the source and time you confirm.
  • Immutable application evidence snapshots: the exact stored job and resume versions, selected export-readback evidence, and bounded copies of the career-fact excerpts, generated artifacts, and contact involvement needed to show what you say was submitted. Private jobs you capture also retain their owner-scoped company identity and assignment history.
  • Bounded machine-readback reports for resume exports, including the format, an exact file fingerprint, recovered-field counts, and any issue codes, short labels, or bounded expected-content excerpts needed to explain a missing or reordered result. We do not store the exported file or its recovered full text.
  • If you connect the Chrome extension: the profile-bound connection record; the current job page URL and title; job title, company, description, location, work setup, employment type, source, canonical, and apply links; observation time and extraction method; your edits to those fields; and explicit save, generation, and application-stage actions. The extension does not collect general browsing history, cookies, form entries, screenshots, or raw page HTML.

How we use it

Your data is used to run the product: extracting career facts, generating resumes that stay grounded in those facts, matching you against job postings, and tracking your applications. We do not sell personal data and we do not use it for advertising.

AI processing

Fact extraction, resume generation, and job matching are performed by external AI APIs (Anthropic for text processing, OpenAI for embeddings). Under those providers’ API terms, API inputs and outputs are not used to train their models by default. Their published standard API terms may retain inputs and outputs for up to 30 days for service and abuse-monitoring purposes, subject to our account settings, a different agreement, or legal requirements. Voice conversations are handled by ElevenLabs, which processes the audio and produces the transcripts we extract facts from.

Chrome extension

MemoryCV Companion reads a job page only after you check that page once from the toolbar or allow jobs on that exact HTTPS site in Chrome. A one-time check does not enable later pages. An allowed site can check recognized job postings automatically until you remove its permission in the companion or Chrome settings. Broader Chrome-managed site grants are ignored for automatic checks and can be removed from the companion.

Before you save, the extracted job fields are sent to MemoryCV so Anthropic can extract requirements and OpenAI can embed those requirements for comparison with the connected profile. This pre-save check does not create a saved job. The extension gets at most 24 requirement rows and evidence snippets capped at 140 characters, without profile fact identifiers or raw fact records.

Chrome local storage holds one scoped connection token and an isolated workspace for each open Chrome window. Depending on the current step, a workspace can contain page and job fields, observation metadata, bounded requirement and evidence rows, the saved job reference, current application stage, and resume-generation progress or destination path. Closing a window deletes its workspace. The token can save and score jobs, generate for the connected profile’s own captured jobs, and update their application stage. It cannot list or read profile facts, resume text, application notes or history, billing, settings, or other account data.

Chrome Web Store Limited Use

MemoryCV Companion’s use of information received from browser permissions complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use and transfer that data only to provide or improve the companion’s disclosed job-fit, capture, generation, and tracking purpose. We do not sell it, use it for personalized advertising or credit decisions, or let people read it except with your specific consent for support, when needed for security or law, or as aggregated and anonymized data for permitted internal operations.

Providers that process your data

We use a small set of service providers. Each receives only what its column describes, only to provide that service.

Anthropic

AI text processing

Career facts, resume text, uploaded resume content, and job-posting text when you ask MemoryCV to extract, compare, generate, or revise content (Claude API).

OpenAI

Vector embeddings

Career-fact, job-posting, and extracted requirement text converted to embeddings for search, matching, and extension fit checks.

ElevenLabs

Voice conversations

Your microphone audio and the resulting conversation transcripts during voice intake.

Stripe

Billing

Name, email, and payment details if you start a paid subscription. We never see your card number.

Apify / Fantastic Jobs

Job-posting data

Nothing about you. They supply the public job postings we match your profile against.

Brandfetch

Company logos and firmographics

When a catalog job or company page shows a Brandfetch logo, your browser requests it directly from Brandfetch's CDN using the company's public domain. Brandfetch may receive that domain and ordinary request metadata sent with the request, such as your IP address, browser user agent, and referrer. Private jobs you add do not use Brandfetch logo hotlinks. Separate server-side company enrichment sends public company domains, not your career profile or resume.

Railway

Hosting

Request data (such as IP address) as the platform serving the app, and the profile, job, resume, and application data stored in managed Postgres.

Cookies

We set a single essential session cookie so you stay signed in. There are no analytics cookies, advertising cookies, or third-party trackers. Some catalog job and company pages make the direct Brandfetch logo request described above; MemoryCV does not use that request for analytics or advertising.

Retention

Your data is kept for as long as your account exists. Facts, resumes, and applications you delete inside the product are removed from your profile. A confirmed submission is historical evidence: deleting or editing a source fact or resume does not silently rewrite the bounded copy already frozen in that application snapshot. Those copied excerpts remain until you delete the containing application or your account. Working resume-export readback reports are shorter-lived: we keep no more than the newest three for the same document version and analysis method, and delete all such working reports after 30 days. Facts extracted from an uploaded resume wait for your review: if you never accept that review, we delete the extracted review facts and the upload record after 30 days. A Chrome extension token expires after 90 days and can be revoked sooner in Settings. Disconnecting the extension clears its token and all panel workspaces from Chrome; exact-site permissions remain separately visible and revocable in the companion or Chrome settings, and uninstalling clears the extension’s local data and permissions. Saved jobs, resumes, and application records remain in your MemoryCV account until you delete the relevant record or account. Providers listed above retain data under their own published policies. For voice intake that includes transcripts held by ElevenLabs.

Deleting your account

You can delete your account yourself at any time from Settings. Deletion cancels active billing first, then removes your application evidence in an explicit order before removing your account and its remaining data: profile, facts, voice transcripts, uploaded files, resumes, resume-export readback reports, owner-private job and company records, extension connections, job matches, applications, sessions, and any subscription.

Access and export

You can download a machine-readable JSON copy of your data yourself at any time from Settings. For help with an export, or to ask what we hold about you, email support@memorycv.com from your account address.

Changes to this policy

If this policy changes, we update this page and the date at the top. Material changes will be flagged in the product before they take effect.

Contact

Privacy questions go to support@memorycv.com.