Privacy Policy
Last updated: August 2026
1. Information We Collect
For the core CV Builder tool, Yoxon collects only what you actively provide: your CV text, job descriptions you paste or auto-import, and payment confirmation data from PayPal or Stripe. This use of Yoxon remains anonymous — no account or email address is required. If you sign in to Yoxon (currently required only for Apply Pass), we additionally collect the email address you provide, so we can send you a one-time sign-in link and associate your purchased access with your account instead of a browser session. If you unlock a full report on the Ghost Job Detector, we collect the email address you provide to send you that report and occasional job-search tips — you can unsubscribe at any time via the link in those emails. If you're signed in and choose to turn on the weekly job match digest (a separate, explicit toggle on the Matches page — off by default, never bundled into any purchase or sign-in), we use your account email to send that weekly email. Turning it off, or unsubscribing via the link in any digest email, stops it immediately.
2. How We Use Your Information
Your CV and job description text is sent to Anthropic's Claude API solely to generate tailored CV output. This text itself is not stored on our servers after your session ends. Payment processing is handled entirely by PayPal or Stripe — we receive only an order/session confirmation ID to verify your purchase tier, not your card details. If you sign in, your email address is used only to send you sign-in links and, where applicable, purchase-related notices and (only if you separately opt in) the weekly job match digest — never for marketing without your separate, explicit opt-in. If you save your CV/LinkedIn text to your account, we compare its keywords against job listings cached from third-party job-posting APIs (see "Third-Party Services" below) to show you a match score — this comparison happens entirely on our own servers; your CV text is never sent to those job-listing providers, and they never receive any of your personal data. This is the same keyword-matching logic used by the free ATS Checker tool, applied against a stored set of listings instead of one pasted job description.
3. Data Storage
AI CV Studio auto-saves your CV text, job descriptions, and generated documents (tailored CVs, cover letters, interview prep) as you work, so your progress isn't lost if you navigate elsewhere in Yoxon or refresh the page. This autosave is keyed to a random token generated in your own browser, not to your identity — it works whether or not you're signed in, and isn't linked to your account even if you are. Autosaved drafts are automatically deleted after 7 days, and you can clear yours immediately at any time using the "Start over" control in AI CV Studio. Outside of this autosave, a published public profile (see below), payment confirmation data, and (for signed-in accounts) the saved CV text and audit result described in the next paragraph, Yoxon does not otherwise store your CV content in a database. Application Tracker data is stored locally in your browser (localStorage) and never transmitted to our servers. If you sign in to Yoxon, we do maintain a small account database containing: your email address; a record of any active or past Apply Pass purchase tied to your account; and short-lived sign-in tokens (each valid for 15 minutes and usable once) used to confirm it's really you clicking the link we emailed. A used or expired sign-in token can never be used again, though the record of it having existed is retained for security auditing during normal use of your account — deleted, along with the rest of your account data, if you request account deletion (see "Your Rights" below). If you save your CV/LinkedIn text to your account (so you don't have to re-upload it on a future visit) or run a resume audit while signed in, that saved text and the audit's full result are also stored in this account database — each persists until you request its deletion (see "Your Rights" below); the saved audit result specifically is what lets AI CV Studio show you your existing audit regardless of which device or browser tab you return in, not only the one you ran it from. We also keep a lightweight history of your score each time you run a full audit while signed in — just the score and the date, not a second copy of the full report — so we can show how it's changed over time; like the rest of this account data, it's kept until you request deletion, not deleted automatically. Your signed-in session is stored as a cookie in your browser, valid for 30 days, and contains no information beyond an internal account identifier. This account database also stores a single true/false flag for whether you've opted into the weekly job match digest — off by default, changeable at any time from the Matches page. Job listings shown on the Matches page are cached from third-party job-posting APIs (see "Third-Party Services") — this cache contains only the public listing content those providers published, never anything about you. A listing is removed from the cache once the underlying posting expires: using the employer's own expiry date when the provider supplies one, or 30 days after the listing's posting date when it doesn't. Your match score against each listing is calculated fresh each time you view it and is never itself stored. If you choose to publish a public profile page (yoxon.co/u/<handle>), the CV content you select for it is stored until you unpublish or delete it. Publishing is always a separate, explicit opt-in action requiring your consent at the time — never automatic, and never triggered by the autosave described above. Unpublishing hides the page immediately; deleting removes the stored content entirely. Your CV's contact details are only ever published if you choose to publish a public profile page — they are never shown on it otherwise. When you do publish, each contact field defaults independently: your email address, phone number, and location/address are hidden by default (you must explicitly choose to show them); your LinkedIn and website/portfolio links are shown by default, since those are already public professional links you chose to list on your CV. You control every one of these toggles yourself at the time you publish, and can change your mind at any time by unpublishing. CV content and account data described above are stored on US-based infrastructure (AWS us-east-1, via Vercel and Neon).
4. Third-Party Services
We use the following third-party services: Anthropic Claude API (CV generation), PayPal and Stripe (payment processing), Vercel (hosting, serverless functions, and — for signed-in accounts — database storage), Resend (delivery of sign-in emails, the weekly job match digest if you opt in, and — if you unlock a Ghost Job Detector report — your report and occasional job-search tips), Techmap and Jobicy (sources for the job listings shown on the Matches page — these providers only ever send us public listing data; we never send them your CV, profile, or any other personal data), and Cloudflare Turnstile (bot and abuse protection on the interview question generator, resume audit unlock, and CV generation — runs automatically in your browser to verify you're not a bot; Cloudflare may process technical signals such as your IP address and browser characteristics for this purpose, under Cloudflare's own privacy policy). Each service operates under its own privacy policy and only receives the minimum data needed to perform its function.
5. Cookies
Yoxon uses no tracking or advertising cookies. PayPal and Stripe may set their own cookies during the payment flow as required by their platforms. If you sign in, we set a single first-party session cookie (httpOnly, so it isn't readable by page scripts) to keep you signed in — this is functional, not for tracking.
6. Chrome Extension
The Yoxon Chrome extension stores preferences locally on your device. Two user-initiated actions send data to yoxon.co only: clicking "Tailor CV with Yoxon" passes the viewed job posting's title and description to the CV Builder to pre-fill it, and submitting a posting in the Ghost Job Check tab sends it to our API for analysis — the same processing as the website's Ghost Job Detector, handled per this policy. The extension transmits nothing in the background and communicates with no other services.
7. Your Rights
If you have never signed in to Yoxon, there is no personal data tied to you beyond what's described above for anonymous use, and nothing to access, correct, or delete. If you have signed in, you can request deletion of your account and associated data — your email address, purchase records, saved CV/LinkedIn text, and any saved audit result — at any time by contacting us at hello@yoxon.co — we don't yet have a self-serve delete-account button, so this is handled manually on request. The weekly job match digest is self-serve to turn off: use the toggle on the Matches page, or the unsubscribe link included in every digest email, either of which stops it immediately — no need to contact us for this one. If you can't use AI CV Studio's "Start over" control yourself — for example, you switched devices before your autosaved draft expired — contact us at the same address, hello@yoxon.co, and we'll delete it on request if you can supply its draft token (found in that browser's storage). Because this autosave is deliberately not linked to your identity, we have no other way to locate one specific draft among others; without the token, it's still deleted automatically no later than 7 days after your last edit.
8. Contact
For any privacy-related questions: hello@yoxon.co