nudgecv

Privacy Policy

Last updated: 16 June 2026

This Privacy Policy explains what personal data NudgeCV collects, why, who processes it on our behalf, and the choices you have. NudgeCV is operated by Allan Ninal, a sole proprietor registered with the Philippine Bureau of Internal Revenue. We deliberately collect very little.

1. Who this policy applies to

Users who sign up for or pay for NudgeCV from anywhere in the world except the European Union, EEA, United Kingdom, Switzerland, Russia, Belarus, China, Myanmar, South Korea, Turkey, India, and the Canadian province of Quebec. Traffic from those regions is blocked at the network edge because we do not currently operate in compliance with their data-protection regimes (GDPR, UK GDPR, EU AI Act, Korean local-rep rule, Quebec Law 25, India OIDAR, etc.).

2. What we collect

From you, when you sign up:

  • Email address (the only required field).
  • Password, stored as a hash by AWS Cognito (we never see your plaintext password).
  • Country of residence, only to confirm you're outside our blocked regions.

From you, when you use the service:

  • Resume content, cover letter content, LinkedIn profile copy, job descriptions you paste in, interview-prep inputs, keyword-harvest queries. Whatever you type or paste into the editors.
  • Job applications you log in the Kanban tracker.
  • The AI suggestions we generate from your inputs.
  • Export history (which PDFs/DOCX you downloaded and when).

From you, when you pay:

  • We do not see or store your payment card or bank details. PayPal handles all payment data. We store only the PayPal subscription or transaction ID, the plan you chose, your billing status, and the timestamp.

From your browser, automatically:

  • One Cognito session cookie (strictly necessary, expires when you sign out).
  • Standard server logs (IP address, user agent, timestamp, URL) kept for 7 days for troubleshooting and abuse prevention.
  • No tracking cookies, no analytics pixels, no ad-tech. We don't use PostHog, Google Analytics, Meta Pixel, or any third-party tag.

3. Why we collect it

  • To deliver the service you signed up for — generate AI suggestions, render exports, save your work.
  • To bill you and prevent payment fraud (PayPal subscription IDs).
  • To send you transactional emails (welcome, receipts, cancellation confirmations, ready-to-download notifications).
  • To detect abuse and keep the service running (server logs, rate limits).
  • To comply with our Philippine tax obligations (PayPal payment records).

We do not use your content to train AI models. We do not sell your data. We do not share it for advertising.

4. Where it lives

Everything is stored in Amazon Web Services, region us-east-1 (N. Virginia). Specifically:

  • Account + content: Amazon DynamoDB (encrypted at rest with AWS-managed keys).
  • Exports + assets: Amazon S3 (encrypted at rest, private buckets).
  • Email transit: Amazon SES.
  • Sign-in: Amazon Cognito.
  • AI inference: AWS Bedrock (Claude Haiku 4.5). See AI Disclosure.

Backups are point-in-time within DynamoDB; we keep up to 35 days of restore points.

5. Who processes data on our behalf (sub-processors)

Sub-processorPurposeRegion
Amazon Web Services (AWS)Hosting, storage, email, auth, AI inferenceus-east-1
Anthropic (via AWS Bedrock)AI inference (Claude Haiku 4.5)us-east-1
PayPalPayment processingUnited States
Route53 + CloudFront (AWS)DNS + CDNGlobal edge

AWS Bedrock processes prompts in-region and (per Anthropic's Bedrock terms) does not retain prompts or completions to train Anthropic's models.

6. How long we keep it

  • Account + content: as long as your account exists.
  • Server logs: 7 days.
  • Cancelled subscriptions: kept indefinitely for tax records (Philippine BIR requirement: 10 years).
  • Deleted accounts: purged from DynamoDB and S3 within 30 days.
  • One-off Quick Optimize results: 24 hours, then auto-deleted via DynamoDB TTL.

7. Your choices

  • Access your data: email hello@nudgecv.com from your account email and we'll send a full export within 14 days.
  • Correct your data: edit it in-app, or email us if a field isn't editable.
  • Delete your account: email hello@nudgecv.com from your account email. We will purge your content within 30 days and confirm by email.
  • Cancel a subscription: use the single-click cancel button on your billing page. No retention dark patterns.
  • Unsubscribe from emails: we only send transactional emails (receipts, cancellation confirmations, result-ready). There is no marketing list to unsubscribe from.

8. Children

NudgeCV is not directed at users under 16. We do not knowingly collect data from anyone under 16. We picked 16 to match LinkedIn's own age minimum (we optimize LinkedIn profiles) and to keep us comfortably above the US COPPA threshold for children. If you are a parent and believe your child has signed up, email us and we will delete the account.

9. Security

We use AWS-managed encryption at rest, TLS 1.2+ in transit, Cognito for authentication, and scope-limited IAM roles for every Lambda. We do not use a VPC or shared servers — every request runs in an isolated short-lived function.

No system is perfectly secure. If you discover a vulnerability, please report it to hello@nudgecv.com.

10. Changes to this policy

We will email registered users about material changes at least 14 days before they take effect. Minor clarifications may be posted without notice; the "Last updated" date at the top will always reflect the latest revision.

11. Contact

Data Controller: Allan Ninal, sole proprietor, Republic of the Philippines.
Email: hello@nudgecv.com.