QuickCV
AI-powered resume builder for iOS
Last updated: 7 June 2026
This policy describes how QuickCV ("we", "our", "the app") handles your information. We've written it in plain English because we want you to actually read it.
QuickCV is operated from Ireland. We've designed the app and this policy with the EU General Data Protection Regulation (GDPR) in mind.
We've tried to make QuickCV one of the most privacy-respecting CV apps you can use. The short version:
The rest of this document explains the details.
QuickCV is operated by ZBR Technologies, based in Ireland. For privacy questions or data requests, contact [email protected].
Under GDPR, ZBR Technologies is the data controller for the limited data we process (analytics events, App Attest device records, and purchase-verification records). For CV content stored in your iCloud, Apple is the processor and you control access. For CV content sent to Vertex AI for processing, we use Google Cloud as a sub-processor under standard data-processing terms.
When you build or import a CV, QuickCV stores on your device (and in your private iCloud — see below) the text you enter: your name, contact details, work history, education, skills, professional summary, target role, and cover letter content. This content is entered voluntarily by you and remains yours.
The app records a small set of anonymous usage events to help us understand how the app is used and to fix problems:
app_launchednew_cv_started (with path: scratch / import / duplicate)section_completed (section name only — e.g. "experience", not section contents)ai_polish_completedexport_attemptedexport_successfulpaywall_reachedpurchase_completedrenewal_completedNo CV content, name, email, or any personally identifiable information is included in these events. Events are batched and sent to our analytics endpoint when a batch of 10 is reached or when the app moves to the background.
We use Apple's App Attest framework to verify that requests to our backend come from genuine QuickCV installations on real Apple devices (not scripts or modified copies). This involves generating a device-specific cryptographic key pair. The public key is registered with us; the private key never leaves your device's Secure Enclave. No personal information is associated with this key — it's a random per-installation identifier.
When you make a purchase, your device generates a random purchase token (a UUID — not your Apple ID, name, or email) and attaches it to the transaction. To confirm the purchase is genuine and to honour your edit and renewal window, our backend verifies the Apple-signed transaction and stores a small record containing: the random purchase token, the product identifier (e.g. quickcv.create), the Apple transaction identifiers, the purchase date, the calculated edit-window expiry, the App Store environment, and a status (active / expired / refunded). This record contains no name, email, payment details, or CV content. See the "Backend records" and "Deleting your data" sections for retention and deletion.
If the app crashes, Apple's MetricKit framework collects diagnostic information (a crash trace, performance metrics) and makes it available to us through Xcode Organizer. These reports do not contain CV content and are not transmitted to our servers — Apple is the processor.
Your CVs are stored using SwiftData on your device. If you are signed in to iCloud, they sync automatically to your private iCloud CloudKit database, which is associated with your Apple ID. We have no access to your iCloud data — Apple is the processor for this. See Apple's Privacy Policy.
When you use AI features (parse imported PDF, keyword match, gap detection, polish content, generate summary, generate cover letter), your CV content and target role are sent over HTTPS to our Cloud Function backend (hosted on Google Cloud, region: europe-west1), which passes them as a stateless request to Google's Vertex AI (Gemini 2.5 Flash) for processing.
This is a stateless pass-through. We do not store your CV content on our servers. The request is forwarded, the AI response is returned to your device, and nothing is retained on our side.
We minimise what we send. For all AI calls other than parse-resume, our system strips out your personal contact information (name, email, phone, address) before sending the content to Vertex AI. The contact info stays on your device; only your professional content (work history, education, skills, summary) is processed.
For parse-resume specifically (when you import an existing PDF), we send the full extracted text because that's the only way to identify what's in the PDF. The parsed result returns to your device and the request is not retained.
Google Cloud / Vertex AI acts as a sub-processor for this processing. Data is processed in the EU (europe-west1, in Belgium). See Google Cloud's Privacy Notice and Vertex AI's data governance terms.
Lawful basis under GDPR: our lawful basis for processing your CV content through Vertex AI is performance of a contract (GDPR Article 6(1)(b)) — you provide the content to use the AI-assisted CV-building service you purchased. We do not rely on consent, because consent would imply you could withdraw it while continuing to use the service. If you don't want your CV content processed by AI, simply don't use the AI features — the rest of the app (manual editing, export) works fully without them.
All purchases are handled by Apple via StoreKit. We never see your payment card details, address, or any other payment information. To validate that a purchase is genuine and to honour the 72-hour edit window and renewals, our backend verifies the Apple-signed transaction server-side and stores the small purchase-verification record described above (a random purchase token, product ID, transaction IDs, dates, and status — no personal information). Our lawful basis for this limited processing is performance of a contract (GDPR Article 6(1)(b)) — it is necessary to deliver the purchase you made — and our legitimate interest in preventing fraudulent or duplicated purchases (Article 6(1)(f)). See Apple's Privacy Policy.
Our Cloud Function logs contain operational metadata for each request: the action name (e.g. "detect-gaps", "polish-content"), a per-device rate-limit counter, error codes, and aggregate metrics such as input and output character counts, the number of keywords or gaps processed, the cover-letter tone selected, and the StoreKit transaction ID for purchase validation. They contain no CV text, no AI response content, no personal contact information, and no personally identifiable information. Logs are retained for 30 days per Google Cloud's default policy and are used only for debugging, operational health, and abuse prevention.
Our backend keeps a few small types of persistent records, each keyed by a cryptographically random identifier — never your Apple ID, name, or email:
Retention. Device attestation and rate-limit records are retained for the lifetime of your app installation. Purchase-verification records are retained only as long as needed to validate the purchase, honour the edit and renewal window, and handle any refund — after which they are deleted automatically. We apply an automatic time-to-live (TTL) policy so these records are purged once they are no longer needed (and in any case within 12 months). If you delete the app, your device's keys are destroyed and the records on our end become unreachable; the purchase-verification records then expire and are deleted automatically. You can also request deletion at any time — see below.
When you use AI features, your CV content is sent to Google's Vertex AI service. Although the processing region is set to europe-west1 (Belgium), Google Cloud is a US-headquartered company and data may transit infrastructure outside the EU. International transfers from the EU are made under appropriate safeguards, including the EU-US Data Privacy Framework (where Google participates) and Standard Contractual Clauses where applicable.
If you do not want your CV content processed under these arrangements, you can use QuickCV without using the AI features — the app's manual editing and export functions work fully offline.
If you are in the EU, UK, or another GDPR-equivalent jurisdiction, you have the following rights under data protection law:
To exercise any of these rights, contact us at [email protected]. We will respond within one month, as required by GDPR.
You also have the right to lodge a complaint with a supervisory authority. In Ireland, this is the Data Protection Commission (DPC) at www.dataprotection.ie. If you are in another EU member state, you may complain to your local supervisory authority.
To delete all your CV data:
After these two steps, no CV content of yours exists anywhere — not on your device, not in your iCloud, and not on our servers (since AI processing is stateless and we never stored your CV).
The small purchase-verification records on our backend (a random purchase token, product ID, transaction IDs, dates, and status — no personal information) are deleted automatically once they are no longer needed to honour your edit window or a possible refund, and in any case within 12 months. If you want them deleted sooner, email [email protected] and we will action the request within 30 days. The same applies to the device attestation key, rate-limit counters, and any anonymous analytics events from your installation (analytics events are automatically deleted after 30 days regardless).
QuickCV is not directed at children under 16. We do not knowingly collect personal information from children under 16. If we learn that a child under 16 has provided personal information, we will delete it.
We use industry-standard security practices to protect data in transit and at rest:
No system is perfectly secure, but we take reasonable care commensurate with the limited sensitivity of the data involved.
We may update this policy as the app evolves or as data protection requirements change. The "Last updated" date at the top will reflect any material changes. We will notify users of significant changes via an in-app notice. Continued use of the app after changes constitutes acceptance.
For any privacy questions, data subject requests, or general questions about this policy:
Email: [email protected]
We will respond within one month of receiving a request, as required by GDPR. For most requests, we respond much faster than that.