Legal
Privacy Policy
Last updated 2 August 2026
On this page
CVMiner helps hiring teams turn scattered resumes into a searchable talent database. To do that, the product reads documents you point it at — including, if you choose to connect a mailbox, resume attachments in your Gmail — and uses AI to extract structured candidate profiles from them.
This policy explains exactly what we access, why, where it goes, and how to get rid of it. It applies to the CVMiner web application at app.cvminer.in and this marketing site.
Who we are
CVMiner is operated by the CVMiner team. For any privacy question, or to request deletion of your data, contact cminer.admin@gmail.com. We are the data controller for account data, and act as a processor for the candidate data you ingest.
What we collect
Account data
When you create an account we collect your name, email address, and authentication metadata. Sign-in is handled by Clerk; if you sign in with Google, we receive your name, email address, and profile picture from Google — nothing more. We never see or store your Google password.
Content you provide
Resumes and CVs you upload directly, and any documents retrieved from sources you connect. These files typically contain personal information about job candidates — names, contact details, work history, and education.
Derived data
Structured candidate profiles extracted from those documents: name, email, phone, location, current title and employer, years of experience, skills, education, and a short summary. Plus operational records such as ingestion timestamps and which source a document came from.
Google user data
Connecting a Gmail mailbox is entirely optional. CVMiner works without it — you can upload resumes directly instead. If you do connect one, here is precisely what we request and why.
| Scope | Why we need it |
|---|---|
gmail.readonly | Search your mailbox for messages carrying resume attachments and download those attachments so they can be parsed. Read-only — we cannot send, modify, delete, or label anything in your mailbox. |
userinfo.email | Identify which mailbox was connected, so you can tell your sources apart and disconnect the right one. |
We only fetch messages matching a resume-oriented search — by default, mail with PDF or Word attachments. We do not read your mailbox wholesale, and we do not store the body text of your email. What we retain from a matched message is the attachment and the structured profile extracted from it.
Limited Use disclosure
CVMiner's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means we do not:
- Sell Google user data, ever, to anyone.
- Use Google user data for advertising, retargeting, or personalised ads.
- Use Google user data to train, fine-tune, or improve generalised AI or machine learning models.
- Allow humans to read your Gmail data, except with your explicit consent for a specific support issue, where required by law, or where necessary for security purposes such as investigating abuse.
- Transfer Google user data to third parties except as needed to provide the feature you asked for, and only to the subprocessors named below.
How we use data
- Parse resumes into structured candidate profiles.
- Let you search and filter your talent pool in natural language.
- Show you which sources have been ingested and when.
- Authenticate you and keep your account secure.
That is the complete list. We do not profile you, sell anything, or use your content to build products for anyone else.
Sharing and subprocessors
We do not sell data. We share it only with the infrastructure providers required to run the product:
| Provider | Purpose | What it receives |
|---|---|---|
| OpenAI | Extracting structured profiles from resumes, and ranking search results | Resume document content and candidate profiles |
| Neon | Database hosting | Candidate profiles and account records |
| Vercel | Application hosting | Request data in transit |
| Clerk | Authentication | Name, email address, session data |
Resume content is sent to OpenAI's API to be parsed. Content submitted through the OpenAI API is not used to train their models. We may also disclose data where legally compelled, or to protect the rights and safety of users.
Retention
- Candidate profiles — kept until you delete them or close your account.
- Google OAuth tokens — kept only while a mailbox is connected, and destroyed the moment you disconnect it.
- Account data — kept for the life of the account.
Your choices and deletion
- Disconnect Gmail at any time from the Sources page. This deletes the stored tokens and stops all further access immediately.
- Revoke at Google from your Google Account permissions page — this works even if you cannot reach our app.
- Delete candidates individually from within the app.
- Delete everything by emailing cminer.admin@gmail.com. We will erase your account and all associated data within 30 days.
Depending on where you live, you may also have rights to access, correct, export, or object to processing of your personal data. Email us and we will honour them.
Security
All traffic runs over TLS. Credentials and OAuth tokens are stored encrypted, and access to production systems is limited to the people who operate the service. No system is perfectly secure, but we do not retain more than the product needs, and we request the narrowest Google scope that does the job — read-only.
A note about candidates
Most personal data in CVMiner belongs to job candidates, not to the account holder. If you use CVMiner, you are responsible for having a lawful basis to process those candidates' information and for honouring their rights under applicable law.
If you are a candidate and believe your details are held in a CVMiner account, contact the organisation that holds them, or email us at cminer.admin@gmail.com and we will help route your request.
Changes
We will update this page when our practices change and revise the date at the top. Material changes affecting how we handle Google user data will be communicated to account holders directly.
Contact
Questions, deletion requests, or anything else: cminer.admin@gmail.com