Privacy
What Cursus holds, and what it does with it.
Cursus is a CV builder, so nearly everything it keeps is something you typed into a CV. This says what that is, where it sits, who else sees it, and how to be rid of it.
Last updated 23 August 2026
Who is responsible
Cursus runs this service and decides what happens to the data on it, which makes it the controller under UK data protection law. Anything on this page, write to privacy@getcursus.app.
What is held
- Your account. The email address you signed in with. If you came through Google, GitHub or LinkedIn, also the name and profile picture they hand over.
- Your CVs. Everything you wrote in them. Names, addresses, phone numbers, employers, dates, and whatever you put in the free text.
- Share links. A snapshot of the CV as it stood when you made the link, and the name and words of anyone who left a comment on it. The link’s own address, and its passcode if it has one, both in the clear, so the card can show them to you again. A link also counts how many times it has been opened, and when it was last opened, so that its owner can see whether anyone read it. Nothing is kept about who did.
- Sign-in links. The address a link was sent to, and a hashed copy of the link. The link stops working after fifteen minutes, and the record is cleared within a couple of hours.
- Your IP address, briefly, so sign-in requests and feedback can be rate-limited.
- What you tell us is missing. If you use the What’s missing? link, the words you wrote, the page you wrote them on, and your account if you were signed in. Sent signed out, it is tied to nobody. The page is the route rather than the address, so a CV of yours reads as
/resume/[id]and never a link anyone could follow. - Eight counts. That you signed up and which provider you used, that a CV was created and whether it came from the wizard, an import or a blank page, that a PDF or a Word file was downloaded, how many of the ATS checks a CV passed, that a share link was made, that somebody commented on one, and that somebody said what was missing. Six of them also carry which language you read the site in, and the four about a CV carry which country’s conventions that CV follows, so we can tell whether the French version of Cursus is any use. Neither is a word of your CV: they are a choice of language and a choice of country. Seven of the eight can carry your account number and nothing else, feedback among them when you were signed in to send it. The comment is left by somebody who needs no account, so it carries instead the throwaway identifier their visit to that link was given, which is new every time the link is opened and is tied to no person at either end. Feedback sent signed out carries a throwaway identifier in the same way, new every time. None of the eight carries a word of what anybody wrote.
- The shape of a CV you imported. When you bring in a PDF or a Word file, we keep a note of how it was built so we can make the reader better: the file type, its size, how many pages it had, the language you were reading the site in and which country’s conventions the CV followed, each heading it carried and what we took that heading to mean, whether you turned that section off, which layout rules the reader had to fall back on, and counts of the sections, entries and bullets. Not a word of the CV itself: no employers, no dates, no contact details, no profile, and never the file. A heading that carries your name or your email address is stored as “(redacted)” instead. The note is written when the file is read, so we learn something even from an import you decide not to keep; one you do keep is attached to the CV it made and goes when that CV does. One you abandon is attached to nothing at all.
- Four tallies, of nobody. To learn whether people who arrive ever get as far as a finished CV, we count four things on our own server and nowhere else: that the front page was opened by somebody signed out, that the wizard was started, and that a PDF or a Word file was downloaded. Each one adds one to a number kept per day and per language. There is no account number, no throwaway identifier, no address and no page beyond the front page, so there is nothing in them to point back at you even in principle, and nothing to ask us to delete. They never leave our database.
A CV can carry more than a CV needs to. If you write about your health, your religion, a trade union or anything else the law treats as special, it is stored like the rest of it. That is your choice to make, and worth making deliberately.
Where it lives
In a Postgres database in London, and nowhere else on our side. Your CVs are also kept in your own browser so the editor works offline; clearing your browsing data removes that copy and leaves the one on the server alone. If you comment on somebody else’s shared CV, the name you gave is kept in your browser too, so you need not type it again.
Four things do leave the UK. The address a sign-in link is sent to goes to Resend, who deliver the email. If you sign in with Google, GitHub or LinkedIn, that happens on their systems, under their own privacy policies rather than this one. And the typefaces these pages are set in are served by Google, so your browser tells them your IP address each time a page loads. Those three run wherever their provider runs, which we do not pin and will not pretend to.
The fourth is the counts, which go to PostHog, and that one we do pin: the EU region, served from Frankfurt, written into the code as a fixed address rather than a setting, so no deployment can quietly move it. They are sent by our own servers, never by your browser, so PostHog never learns your IP address and never sees a page you are on. Session recording is not merely switched off: the part of PostHog that could record a screen is not in this site at all, so a replay of you writing your CV cannot be made.
What never leaves your device
When you import an existing CV, the PDF or Word file is read in your browser. The file itself is never uploaded. Only the text you keep after the review screen is saved, and only once you save it. What does leave your device is a note about the shape of the file rather than its contents, described above under what is held.
Who else sees it
- Google, GitHub or LinkedIn, if you choose one, and only to confirm who you are.
- Resend, who send the sign-in email.
- Google, who serve the typefaces these pages are set in.
- Neon, who run the database, and Vercel, who run the site.
- PostHog, who hold the eight counts above, and nothing from inside a CV.
Nobody else. Nothing is sold, nothing is handed to recruiters, and nothing is used to train anything.
Why we are allowed to
Holding your account and your CVs is what you asked us to do, so the basis is the contract between you and Cursus. Rate-limiting sign-ins and keeping accounts from being taken over is our legitimate interest in the service not being abused. So is counting the eight things above, which is how we learn whether anything here works. If you would rather not be counted, write to us and we will stop.
How long it is kept
- Your account and your CVs, until you delete them.
- A CV you delete stops appearing everywhere at once, but the row is marked rather than removed, so your other devices learn it has gone. Deleting your account clears it for good.
- A sign-in link stops working after fifteen minutes, and its record is cleared within a couple of hours. Deleting your account forgets any that are still outstanding, at once.
- Deleting your account removes the account, the profile, every CV, every share link and every comment left on one, at once and for good.
- What you told us was missing, until we have acted on it. Deleting your account does not delete it, because it is about the product rather than about you. Your account is detached from it, so what stays is the words alone, attached to nobody. Ask and we will remove it outright.
- The note about an imported CV, for exactly as long as that CV. Deleting the CV deletes the note with it, and deleting your account removes both. Nothing has to run for that to happen; it is the database that enforces it. A note left by an import you never turned into a CV is attached to no account and no CV, so there is nothing in it to point back at you and nothing to ask us to delete.
- The eight counts, for as long as the PostHog project holds them. They carry an account number, or a throwaway identifier where there was no account, rather than a name or an address, so once the account is deleted they point at nobody. Ask and we will clear them too.
What you can do about it
- Download every CV you have written, from Settings, under Account and data.
- Delete your account outright, from the same place.
- Ask for a copy of everything else, including your profile, your share links and any comments people left on them and anything you sent through What’s missing?, by writing to privacy@getcursus.app. The law allows a month; it will not take that.
- Complain to the Information Commissioner at ico.org.uk if we get it wrong. We would rather you told us first.
Cookies
Three, and each of them is doing a job you asked for.
- Staying signed in. One cookie, for seven days. It cannot be read by scripts, and it goes when you sign out.
- Signing in with GitHub or LinkedIn. A cookie for ten minutes while you are away at their site, so we can tell that the person coming back is the person who left.
- Opening a share link. A cookie for that one link, for seven days, holding nothing but that link’s session. Every share link you open sets one, whether or not it has a passcode.
There is no advertising, and no third-party script counting you. Nothing PostHog does happens in your browser: it sets no cookie here, and it cannot see what you type.