
last updated august 18, 2026
tailorpilot is bring-your-own-key: the ai generation runs on your own anthropic, openai, or google api key, not ours. that shapes most of what follows. this page explains exactly what we collect, why, who else ever sees it, and how to get rid of it.
account info. your email address, from supabase auth, used to log you in.
profile details. name, email, phone, and location, if you choose to fill them in on the settings page. used for cv exports, optional, never required.
your base cv and achievements bank. the cv text you upload and any achievements you add. this is the source material the tailoring pipeline checks every generated claim against, it's the whole reason grounding works.
tailoring history. each job posting you tailor against, the tailored cv and cover letter it produced, the match score, and which ai models did the writing and the checking.
your ai provider api key. encrypted before it's ever written to the database, and only decrypted in memory for the single outbound call to the provider you gave the key for. we never log it, and it's never sent anywhere except that provider.
the extension's content script reads the visible text of the page you're currently on, on any site, so it can tell whether that page looks like a job posting. that check happens locally in your browser. nothing about the page you're viewing is sent anywhere unless it's actually detected as a job posting and you click "tailor my cv", or you paste text in yourself. browsing pages that aren't job postings sends us nothing.
your chosen ai provider. when you tailor a cv, the job posting text and the relevant parts of your base cv and achievements go to whichever provider (anthropic, openai, or google) you connected a key for, using that key. that provider's own privacy policy governs what they do with a request made using your key, tailorpilot doesn't control that.
supabase. our database, authentication, and file storage all run on supabase. every table is scoped with row-level security, so your data is only ever reachable by your own account, even at the database layer.
hosting providers. the backend and dashboard run on standard cloud hosting. they process requests to keep the service running, they don't get separate access to your stored data beyond that.
we don't sell your data, and we don't use your cv, achievements, or tailoring history to train any model, ours or anyone else's.
provider api keys are encrypted at rest and decrypted only in memory, right before the one outbound call that needs them. every other table is row-level-secured to your account. no security measure is perfect, but this is the actual mechanism, not a general promise.
settings has a "delete my data" control that permanently removes your base cv, achievements, connected provider keys, and full tailoring history. it does not delete your account or profile details, or log you out, since those are handled separately. to delete your account entirely, contact us using the link in the footer.
the dashboard uses a session cookie, set by supabase auth, to keep you logged in. that's the only cookie we set, there's no analytics or advertising tracking on this site.
tailorpilot isn't directed at children, and we don't knowingly collect data from anyone under 16. if you believe a child has created an account, contact us and we'll remove it.
if this policy changes in a way that matters, we'll update the date at the top of this page. continuing to use tailorpilot after a change means you've accepted it.
questions about your data, or a deletion request beyond what the settings page covers, are welcome through the contact link in the footer.
see also our terms of service.