Privacy Policy
Last updated 5 October 2026
Your career history is some of the most personal data you have. ArcLucid is built so that your trust isn't something you have to take on faith - it's enforced by how the product works. The summary is below; the full policy follows it.
The short version
We cannot read your CV
Your CV, skills, analyses, and chats are encrypted on your device before we store them. We store an opaque blob of ciphertext and hold no key that can unlock it. When a feature has to read your CV, it reads it in the clear for that job, and the policy below says what is kept and for how long.
The key is yours alone
Your browser turns your password into a key that locks the key to your data. Our database keeps that data key only in its locked form. Your password passes through our server when you sign up, sign in or reset it, so we can check or set it; we never store it or use it to unlock your data.
The AI sees it only to help you
When an AI feature reads your CV, the text it needs is sent to the AI provider for that task. Anything our servers keep of it is wiped automatically, most of it within a day and all of it within thirty days, apart from logs. What our usage records keep is the call itself, its model and its size, never the words.
The honest trade-off
Real privacy has a cost: we do not keep any way to unlock the CV data we store, so we cannot recover it for you. If you forget your password and your recovery phrase, your CV data is gone for good. This is the same trade-off as a password manager - and it is the price of a guarantee that actually holds.
Your measurement choice
The short version
Your CV library is encrypted in your browser before we store it, with a key only your password or recovery phrase can unlock, so we cannot read your stored CV library, apart from a profile you choose to publish. Your password passes through our server when you sign up, sign in or reset it, so we can check or set it; we never store it or use it to unlock your data. (If you sign in with Google, the vault password you create never passes through our server.) Features that must read your CV (importing it, Role Fit, interviews, cover letter reviews, PDF export, share links and the assistant) send the text they need to our servers and to the company doing the work, mostly Google's Gemini AI, and the readable text our servers keep is wiped on a schedule. We do not sell your data, advertise against it, or train AI models of our own on it. You can export your CV data or delete your account at any time in Settings.
Who we are
ArcLucid is operated from the United Kingdom by ARCLUCID LTD (company number 17005341), the "controller" of your data under UK data protection law. For anything here, including your rights, email arclucidm@gmail.com (a Gmail mailbox, so Google holds what you send us).
What we collect and why
- Your account: your email address, a display name (your sign-up name or the start of your email address), a one-way hash of your password (none with Google sign-in, where Google shares your name, email address and picture), and which Terms you accepted and when. Basis: our contract with you.
- Your CV data: everything in your CV profiles (listed field by field in our data manifest), your chats with the assistant and your interview recordings, stored encrypted and read in the clear only when a feature you use needs it. Basis: your consent, recorded with the time when you first use ArcLucid; withdraw it by deleting your CVs, clearing your chats with the assistant, or deleting your account.
- Payments: our ledger of your credits, the customer id our payment processor gives you (from the first time you open checkout or billing) and the purchase terms you accepted; never a card number. Basis: our contract with you; after your account ends, the law's requirement to keep financial records and our legitimate interest in answering refunds and disputes.
- Keeping ArcLucid safe and working: counts of repeated actions in a table
called
rate_limits, keyed on an IP address, your account id or a scrambled form of an email address typed at sign-in. A sweep on an hourly schedule deletes every row more than a day old. Also a bot check at sign-up, sign-in and password reset, server logs, and each CV import's progress (phase, file size and type, time taken). Basis: our legitimate interest in keeping accounts and the service safe and working. - Measurements, only if you accept: page speed (with no account id), more detail about your imports, including a short failure reason, which can be the error message a service we called returned, and a crash diary on your device. Change your answer any time under "Your measurement choice" on this page. Basis: your consent.
- Emails you send us, to reply. Basis: our legitimate interest.
You need an email address and a password, or Google sign-in, for an account; the rest is up to you, though a feature that reads your CV needs it.
Who else receives your data
- Cloudflare runs our proxy, which adds our Google key to AI requests and passes them on without your IP address, browser details, cookies or sign-in token. It also makes search vectors from your evidence for Role Fit, prints PDFs you export, loads hard-to-read job pages, and stores your interview replays, encrypted on your device first. It also holds our copy of the teaching and apprenticeship job lists in its database (Cloudflare D1), and searches it with the role and place you search. The same database holds job adverts we collect from employers' own hiring sites, and the names of companies people target or ask about, with no account link.
- Google Gemini, the AI: the text a feature needs, which can include your name, contact details and an imported CV's file name; a CV file we cannot read as text; your voice in a live interview, which goes from your browser straight to Google, not through our proxy, so Google also sees your IP address; an interview recording you ask us to review; and job links you paste, which Google fetches. Under our paid terms Google does not use any of it to improve its products, and keeps it for a limited time only to detect misuse and for disclosures the law requires. When the assistant searches the web for you, Google keeps that request (which can include your target role, location, key skills or other details from your conversation) and its answer for thirty days, to produce and test search results.
- TypeSafe, a second AI that makes quick checks for our features, such as whether a chat message holds a job ad, or which job on your CV an achievement belongs to. Our proxy sends it the text a check needs, without your IP address, browser details, cookies or sign-in token: a chat message you send the assistant, a job ad and the requirements found in a job you target, the roles on your CV (titles, employers, dates, descriptions and achievement bullets), your skills, sentences from a cover letter, your answers in a practice interview, the job title you search for or target, the place you search for jobs, and company names. TypeSafe's privacy policy says it will not train or fine tune any AI or machine learning models on prompts or other input, and that its services are hosted in the United States.
- Supabase, our database and sign-in: your account, your encrypted CV, the readable text we keep for a while and any profile you publish. Supabase sends the emails that confirm your address and reset your password.
- Vercel, our host: every request you make to us, with your IP address, browser details and any CV text or file in it, and, if you accept measurement, its page-speed and visit tools, given the page's template, not its address.
- Stripe, payments: your email address, your account id and the purchase terms you accepted; card details go from your browser to Stripe, never to us. It can pass you to Link, Apple Pay, Google Pay and, for credit packs, Klarna or PayPal; the one you choose receives what it asks you for, under its own terms.
- Job sites and employers' hiring systems: Reed, the government's Teaching Vacancies and Find an apprenticeship services, NHS Jobs once it agrees, and the hiring sites of companies you name (Greenhouse, Workday and others listed under "Technical details"). They get only the role and place you search, or the company you name. Nothing about you is sent when we check a site's public "may we read this?" notice (robots.txt, which may sit on the company's own careers site), copy the teaching and apprenticeship lists, or open a job link you paste, or a job page a search found. Pay figures come from our own copy of official ONS data, so the ONS receives nothing.
- Cloudflare Turnstile, the bot check: your IP address and a check token.
- Google sign-in, if you use it: Google learns you signed in to ArcLucid.
Each service's address is under "Technical details" at the end.
Transfers outside the UK
Some of these companies handle data outside the UK, including in the United States, and Google may hold AI data briefly in any country where it has facilities. Cloudflare, Google (for the AI), TypeSafe, Supabase, Vercel and Stripe do so under the data protection terms each gives its business customers, which include the safeguards UK law requires; Stripe and Cloudflare also use some of this data for their own fraud and bot-detection purposes, as their own privacy notices explain. Email you send us is held in our Gmail mailbox, under Google's terms for that mailbox. Klarna, PayPal, Apple, Google Pay and Link handle a payment you choose to make with them under their own terms.
How long we keep it
Your account and CV data stay until you delete them. One exception: an analysis whose charge cannot be settled when you delete its CV stays until it is (normally about 20 minutes), and any CV text in it goes within thirty days. A CV's interview recordings go with it, retried in the background if our storage is briefly unavailable; if you close that tab or sign out before that finishes, they go when you delete your account. After you delete your account, a copy on another device stays there, locked for good, until that browser's data is cleared. When you delete a CV we keep a note of its random id, with nothing from the CV, so another of your devices cannot bring it back. The notes go when you delete your account.
The plaintext a job needs is kept only as long as the job. A full read of our database cannot reconstruct a single field of a CV you have not published, apart from one window we would rather name than bury. While a job you asked for is running, and for a short spell after it, the plaintext that job needed is on our servers: a CV import holds the parsed profile until about an hour after it finishes, or a day if it never finishes, and an analysis holds the lines it quoted from your CV until a day after your device collects the result, or thirty days if nothing ever collects it. Then it is wiped automatically, by a sweep on a schedule rather than by anyone remembering to press anything. For a CV file sent to Google, our server asks Google to delete it when the import ends; if that fails, or our server stops first, it stays under Google's terms.
A shared profile lasts while sharing is on, and is deleted together with its CV, or with your account. Its preview picture can still be served from a cache for up to a minute after, and an app that already showed the preview may keep its own copy.
A few things deleting your account does not reach. None of them carries your account id, so nothing can pick out yours: page-performance measurements (the section above explains why); short-lived anti-abuse counters keyed on your IP address, or on an address you signed in with before changing it, which an hourly sweep deletes once they are a day old; and recent job searches, stored by role and location only, which are deleted within about 75 minutes. When you target a company or ask Vera about one, we keep that company's name, without your account or anything else that could point back to you, so we can collect its job adverts.
Performance measurements are kept without a time limit; our records of each AI call (model, feature, size, cost, no account id) for the period Cloudflare sets. Counts and markers that name your account run out on their own: daily PDF and job-page counts in two days, Cloudflare's request count in a minute, and, in our proxy, a marker on each charged AI call after about ten minutes and its in-memory count about an hour after your last request, or, if that copy of the proxy goes quiet, when Cloudflare shuts that copy down. Import diagnostics last until you delete your account.
Logs are kept for the period each hosting provider sets for our account, then deleted. Lines we write leave out your account id and email address; one that must lead back to an account carries a code made from your id with a secret key held on our servers. A line can hold an error message from a service we called, or from the code reading a CV file you import, quoting a fragment of it. Our providers' own logs record each request's address (which can hold a CV's id, a share token or your account id) and IP address.
Money records outlive the account on purpose. When you delete your account your credit ledger is archived, without your user id, because a business has to be able to answer a question about a payment after the account that made it is gone. Stripe also keeps its own customer record for your payments, with your email address and our user id, for the same reason. That record exists even if you never paid. Deleting your account first cancels any subscription you have at that moment, so it does not renew.
Cookies and storage on your device
Cookies here keep you signed in, finish a Google sign-in, show a sign-in error, and, set on the checkout page, run Stripe's fraud checks; none is for advertising or following you elsewhere. Your browser also stores your encrypted CVs and chats, some unencrypted settings and sync markers (a few named with your account id) and, for the tab only, your interview setup, including a temporary key and instructions built from your CV. The app's offline helper caches its code and your library and CV pages, which carry your account id but no CV content. We use no IndexedDB. Signing out or deleting your account clears your account's items from this device. Every name is under "Technical details".
Diagnostics logging
If you accept measurement, a crash diary is kept on your device in
arclucid_monitoring_logs, through the channels error, info and
performance, for seven days. Its lines are written to carry ids, counts,
lengths and code locations rather than your words, and common patterns (most
email addresses, Google API keys, document file names written without spaces,
password fields) are redacted, but it cannot refuse what it is given: a line written to carry a
sentence stores it. Declining deletes it.
Your rights
Wherever you live these are open to you; in the UK and EU they are legal rights. Email us to use any of them; we answer within one month.
- Access and portability: "Export Everything" in Settings downloads your CV data; email us for the records on our server.
- Correction: edit your CV data in the product; email us for the rest.
- Deletion: Settings, then "Delete Account", permanently erases your account, your CV ciphertext, your encryption keys, the caches and usage counters tied to your account, apart from the few that run out on their own as set out above.
- Restriction and objection, including to what we do on the basis of our legitimate interests.
- Withdrawing consent, at any time, as described above.
- Complaint to the Information Commissioner's Office (ico.org.uk), or your data protection authority in the EU.
Automated decisions
We make no decisions about you by automated means that have legal or similarly significant effects. The AI features give you suggestions, such as how well your CV fits a job, for you to use as you choose.
Technical details
Services and their addresses.
arclucid-proxy.mayur-vekaria.workers.dev- our proxy, on Cloudflare, with Workers AI, Browser Rendering and R2 behind it. It logs no prompts or responses, and publishes that commitment at/ai/proxy-policy.jsonon that host.- Google Gemini -
generativelanguage.googleapis.com. - TypeSafe -
api.typesafe.ai, reached only from our proxy. - Vercel - Web Analytics at
/_vercel/insightsand Speed Insights at/_vercel/speed-insights, both on this site. - Stripe -
js.stripe.com,api.stripe.com,hooks.stripe.com; Linklink.com; Apple Payapple-pay-gateway.apple.com; Google Paypay.google.com. - Job sites and hiring systems -
www.reed.co.uk,teaching-vacancies.service.gov.uk,api.apprenticeships.education.gov.uk,boards-api.greenhouse.io,api.lever.co,api.eu.lever.co,api.ashbyhq.com,apply.workable.com,{board}.teamtailor.com,{board}.pinpointhq.com,{board}.recruitee.com,{board}.jobs.personio.de,{board}.jobs.personio.com,{employer}.fa.{region}.oraclecloud.com,{employer}.wd{n}.myworkdayjobs.com,wd{n}.myworkdaysite.com,api.smartrecruiters.com(SmartRecruiters; switched off, and its robots.txt currently forbids our reading it),www.jobs.nhs.uk(NHS Jobs, with links tobeta.jobs.nhs.uk; switched off unless its operator has agreed in writing),index.commoncrawl.org(Common Crawl's list of its crawls) anddata.commoncrawl.org(Common Crawl's published index files, read weekly under Common Crawl's own access guidance to find employers' job feeds; nothing about any user is sent),jobs.workable.com(Workable's public job search, used to find employers hiring in the UK),www.gov.ukandassets.publishing.service.gov.uk(GOV.UK's copy of the Home Office's public register of visa sponsors, used to mark employers that can sponsor a visa). - Cloudflare Turnstile -
challenges.cloudflare.com.
Cookies. sb-...-auth-token (Supabase sign-in, in parts, each set for
400 days and renewed when it changes, holding your sign-in tokens and account
details, cleared when you sign out); cookies ending code-verifier (a
one-time value set for a Google sign-in); arc_oauth_terms (the Terms version you
accepted, 10 minutes); arc_signin_error (a sign-in error code, 2 minutes);
__stripe_mid (365 days) and __stripe_sid (30 minutes), Stripe's fraud
cookies, set on the checkout page. This list is kept by hand.
Browser storage. Encrypted with your vault key: arclucid-storage: (your
CVs, named with your account id, or arclucid-storage from an earlier version), arclucid:chat: (chats), arclucid:campaigns: (your job campaigns),
arclucid:memory: (the assistant's notes on you), arclucid:telemetry:v1 (the
assistant's tool log), arclucid:consent: (your consent record), arclucid:vec:
and arclucid:dedup: (Role Fit helpers). Unencrypted:
arclucid:chat-adopted: (a moved-chat marker), arclucid:pending-creations:
and arclucid:pending-pushes: (changes not yet synced, named with your account
id), arclucid:cv-bases: (which saved version each CV on this device came from,
named with your account id), arclucid:analytics-consent:v1 (your measurement answer), arclucid-theme
(dark mode),
arclucid_monitoring_logs (the crash diary), arclucid_welcome_seen and
arclucid_chatbot_hint_ (one-time flags), arclucid:importTelemetry:v1 (each
CV import's file size and type, its timings, counts,
processing path and outcome, with no CV text or file name) and
__test (a probe, removed at once). For the tab
only: arclucid:interview:start (your interview setup, removed once read),
arclucid:pending-cv-writes: (changes not yet synced) and
arclucid-perf-session (the per-tab id on performance measurements).