Policy
Privacy Policy
Effective date: 11 June 2026. Last updated: 11 June 2026.
This Privacy Policy explains what data Tailor (“Tailor”, “we”, “us”) collects when you use the service at tailor-resume.com, why we process it, who we share it with, and the rights you have under UK GDPR and EU GDPR.
1. Who we are
Tailor is operated by Fredrick (John Sydney) Vacher, a sole trader trading as Tailor, based at 18 Caldervale Road, London, SW4 9LZ. The data controller for the personal data described below is Fredrick (John Sydney) Vacher. You can contact us about privacy at fredrick.vacher@outlook.com.
2. What we collect
- Account email. When you sign in, our authentication provider stores your email address and a hashed credential or OAuth identifier so we can recognise you on return visits.
- CV content you provide. The text you paste, upload, or type into the builder — including the target job description — is stored in your account so you can return to it. Internally this lives in our
cv_projects,cv_drafts, andcv_exportsrecords, scoped to your user ID. - Purchase records. When you buy credits we record the purchase metadata (amount, currency, credit quantity, purchase status) in
credit_purchasesand your remaining balance incredit_balances. We never see or store your card details — payment card data is collected directly by Stripe in their embedded checkout. - Usage analytics. We store lightweight product analytics in an
analytics_eventstable. Each event may include the page path you visited, your browser’s user-agent string, the referring URL, a session identifier we generate, and the event name (e.g. “export completed”). We use this to understand how the product is used and to fix problems.
3. AI processing of your CV
The core function of Tailor is to analyse and rewrite your CV against a target job description using a large language model (LLM). To do this, the CV text and the job description you provide are sent to a third-party AI provider so the model can produce the analysis, rewrite, and suggested edits. Without this processing the service cannot function.
We send the minimum text required to perform the task — the CV content, the target description, and prompt scaffolding. We do not send your email address or payment data to the AI provider. See the “Subprocessors” section for the provider(s) used.
4. Why we process this data (lawful bases)
- Contract. To provide the builder, save your projects, run the AI analysis and rewrite, and deliver PDF exports you have paid for.
- Legitimate interests. To keep the product secure, prevent abuse, and improve it through aggregate usage analytics.
- Legal obligation. To retain purchase records for tax and accounting purposes.
5. Subprocessors
We rely on the following third-party processors. Each handles data only on our instructions and under their own data protection terms.
- Database, authentication & hosting: Supabase (supabase.com). Stores your account, CV projects, drafts, exports, credit balance, and analytics events.
- Payments: Stripe. Collects and processes payment card details; returns purchase metadata to us via webhook.
- AI model / gateway: the Lovable AI Gateway (lovable.dev), which routes requests to Google's Gemini models (ai.google.dev). Receives the CV text and target job description in order to generate the analysis and rewrite.
- Site hosting / CDN: Lovable (lovable.dev), which hosts the application on Cloudflare's infrastructure.
6. International transfers
Some of the providers above may process data outside the UK or EEA. Where that is the case we rely on the safeguards published by those providers (such as Standard Contractual Clauses and the UK addendum). See each provider’s own documentation for details, or contact us at fredrick.vacher@outlook.com.
7. Retention
How long we keep each type of data is described in detail on our Storage & retention page. In short: raw uploads are processed in your browser, drafts are kept for 60 days, paid PDF exports stay with your account so you can re-download them, projects you delete are removed immediately, and your account, credit balance, and purchase history persist for as long as your account is active.
8. Your rights
Under UK GDPR and EU GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data. You can delete any saved CV project from your workspace, and you can request full account deletion in-app, which removes your account, projects, drafts, exports, and balance.
- Portability — receive a copy of the CV content you have submitted in a machine-readable format.
- Restrict or object to our processing, including processing based on legitimate interests such as analytics.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk) or your local EU data protection authority.
To exercise any of these rights, email fredrick.vacher@outlook.com from the address linked to your account.
9. Cookies & local storage
We use only the storage we need to run the service:
- Authentication session. A signed session token kept in your browser so you stay signed in.
- Analytics session id. A random identifier kept in your browser to group events from the same visit. It is not linked to advertising.
- Builder state. Draft content may be cached locally so you don’t lose work between page loads.
We do not use third-party advertising cookies.
10. Security
Access to stored data is restricted by row-level security on a per-account basis. Payment card data is handled exclusively by Stripe. Despite reasonable safeguards, no online service can be guaranteed completely secure — please use a strong, unique password and contact us promptly if you suspect any unauthorised access to your account.
11. Changes
We may update this policy as the product evolves. Material changes will be communicated through the app or by email to the account address.
12. Contact
Questions, requests, or complaints: fredrick.vacher@outlook.com, 18 Caldervale Road, London, SW4 9LZ.