What we collect
When you create an account, Currivex stores your display name, email address, a protected password verifier, and the workspace you choose to sync. That workspace can include CV content, job descriptions, application notes, cover letters, and CV Brain training examples.
Currivex uses an essential secure session cookie so your account remains signed in. We do not use advertising trackers on the product pages.
How we use it
We use account information to authenticate you and keep your workspace available across your signed-in devices. We use the workspace only to show and save the features you request. We do not sell personal data or use your CV content to train a third-party AI model.
Local CV Brain
CV Brain’s review, job-match, and guidance logic runs in your browser. Currivex does not send your CV or pasted job description to an AI provider for those features. Your signed-in workspace is still synced to Currivex so you can use it on your own devices.
Your controls
From Account settings you can download a JSON backup, clear the data cached in this browser, end other sessions, update your display name, change your password, and delete your account. Deleting your account removes its cloud workspace, session records, and account record.
Accounts created with Google have no password. Those two actions ask Google to confirm your identity instead, and your account page says so plainly rather than showing a password field that cannot work.
What stays on your device
So the builder opens instantly, your workspace — your CVs, cover letters, applications and job descriptions — is also cached in your browser's local storage. That copy is readable by anything running on your device, and it is not encrypted. It is cleared when you sign out, when you switch accounts, and when you choose Clear local data on this device on the Account page. Anyone with access to your browser profile can read it, so use a private or locked device for job searching.
Your sign-in token is never stored in the browser: it is an HTTP-only cookie that scripts cannot read.
Security and retention
Passwords are transformed in the browser with PBKDF2 before a protected verifier is stored. Secure, HTTP-only session cookies are used for sign-in, and a session that goes unused for two weeks stops working. No online service can promise absolute security, but we limit data collection and protect the account paths with validation and rate limits.
We keep a short security log of sign-ins, password changes, session endings, share-link activity and account deletions, so we can investigate misuse. It stores no IP address — only a one-way hash used for rate limiting — and is deleted after 90 days. Expired sessions, ended share links and used reset links are deleted automatically.
We retain synced data until you delete it through the product or delete the account. If we add email verification, reset links are single-use and expire quickly.
Changes and questions
We will update this page when Currivex’s data practices materially change. The public support channel will be added when JoeTech connects its support domain. Until then, signed-in users can use the in-product account controls to manage their data directly.