Last updated: September 28, 2026

This policy explains what personal data OneCV collects, why we collect it, who helps us handle it and the choices you have. The rules for using OneCV are in our Terms of Service.

The short version:

  • We collect what you give us to build your documents, plus the minimum needed to keep your account secure.
  • Your resumes, letters and job entries are private to your account. We don’t sell your data, show ads, or train AI on your documents.
  • We use analytics to improve OneCV. Detailed tracking and session replays start only if you allow them on our cookie banner, and they never include your resume content. There are no advertising trackers.
  • You can delete your account from Settings at any time, and everything in it goes with it.

1. Who runs OneCV

OneCV (onecv.work and app.onecv.work) is run by Bisrat Shibeshi, an individual based in Ethiopia. In this policy, “we” and “us” mean Bisrat Shibeshi as the operator of OneCV. We decide how and why your personal data is used, which makes us its controller.

We handle personal data in line with Ethiopia’s Personal Data Protection Proclamation and, for people in the European Union, the United Kingdom and Switzerland, the GDPR and its UK and Swiss equivalents. Questions about this policy or your data go to [email protected].

2. What we collect

Account details

When you sign up with email, we store your name, your email address and a hash of your password. A hash can’t be turned back into your password, so we never know what it is. If you choose Continue with Google, Google shares your name, email address and profile picture with us, and we store those instead of a password. We also store which plan your account is on.

What you create

We store everything you make in OneCV: resumes, cover letters, job tracker entries with their notes and links, your design choices and your settings. If you add a photo to a resume, we store the image file. A signature you draw is stored inside the document it belongs to.

Files you import

When you import a PDF, JSON or text resume, your browser reads the file on your device. The file is never uploaded. Only the text you keep becomes part of your resume.

Sign-in and security data

Each time you sign in, we record the IP address and browser type (user agent) of that session to protect your account. You can sign out of every other device under Settings, in the Devices card. Our host also records basic details of each request, which can include your IP address, so we can find and fix errors.

How you use OneCV

Cloudflare Web Analytics counts page views on onecv.work without cookies and without identifying you. Our cookie banner lets you allow analytics and session replays separately. With analytics allowed, PostHog records the pages you visit, what you click, your browser and device type and your approximate location worked out from your IP address. With session replays also allowed, it records replays of your sessions.

Replays never contain your content. Every piece of text and every form field is masked in your browser before anything is sent, and photos and signatures are left out. In the app, clicks are recorded without the text of what you clicked. With analytics turned off, PostHog only counts visits without cookies. When you’re signed in and have allowed analytics, this data is linked to your account ID, never to your name or email address.

3. How we use it

  • To run OneCV for you. We use your data to create and protect your account, save your documents, sync them across your devices and turn them into PDFs. This is necessary to provide the service you signed up for.
  • To send account emails. These cover verifying your address, resetting your password, and warning you when someone tries to sign up with your email. Your account can’t work without them.
  • To keep OneCV secure. Session and request data help us spot abuse, stop unauthorized access and fix bugs. We rely on our legitimate interest in running a safe service.
  • To understand and improve OneCV. Analytics show which features people use and where they get stuck. Detailed analytics and replays run only with your consent. The cookieless page view counts rely on our legitimate interest in knowing how the site is used.
  • To send product updates and career tips, only if you turn on “Email me career tips and product updates” in Settings. You can turn it off whenever you like, and each of these emails will include an unsubscribe link.
  • To meet legal obligations, when a law requires us to keep or disclose information.

We don’t sell or rent personal data, we don’t show ads, and we don’t use your documents to train AI models.

4. Who we share it with

We use a small number of service providers to run OneCV. Each one handles data only to provide its service to us, under its own data processing terms.

  • Cloudflare hosts onecv.work and app.onecv.work, delivers them worldwide, blocks attacks, stores the photos you upload, serves our template images and stock photos, and counts page views with Cloudflare Web Analytics. Uploaded photos are stored in Western Europe.
  • Neon runs the database that holds your account and your documents, on Amazon Web Services in the United States (Ohio).
  • Resend sends account emails, such as sign-up verification and password resets, from the United States.
  • Google signs you in, only if you choose Continue with Google.
  • PostHog provides product analytics and session replays, stored in the European Union (Frankfurt, Germany). Your browser sends this data through app.onecv.work, which passes it on to PostHog.

OneCV doesn’t sell anything yet. If we launch paid plans, Polar will handle payments as the merchant of record, and we’ll update this policy before anyone is charged.

We disclose information to authorities only when the law requires it, or when it’s needed to protect people from serious harm.

5. Where your data is stored

Your account and documents are stored in the United States, and your photos and analytics data in the European Union. Both sites are served from Cloudflare’s network, which has data centers around the world. We operate OneCV from Ethiopia and access the data from there.

That means your data can travel outside your country. Where the law requires safeguards for these transfers, we rely on our providers’ data processing terms, including the EU Standard Contractual Clauses where they apply.

6. Cookies and browser storage

  • Session cookie. app.onecv.work sets one cookie that keeps you signed in. Scripts can’t read it, and it stops working when you sign out or after 7 days without use.
  • Security cookie. Cloudflare may set a cookie that helps it tell people from automated traffic.
  • Consent cookie. We remember your cookie choices for 180 days. You make them on onecv.work, and they apply on app.onecv.work too. Until you answer, the app only counts your visits without cookies.
  • Analytics cookie. Only if you allow analytics, PostHog sets a cookie and local storage entry that recognizes your browser between visits. With analytics off, PostHog only stores a note of your choice, with nothing that identifies your browser.
  • Local storage. The app keeps a few interface preferences in your browser, such as whether the sidebar is collapsed. They stay on your device.

OneCV uses no advertising or social media cookies. To change your answer, use Cookie choices at the bottom of onecv.work.

7. How long we keep it

  • Your account and documents stay for as long as your account exists. Deleting a document removes it right away.
  • Deleting your account removes your account, documents and photos right away.
  • Our database provider keeps a short restore history, so deleted data can remain in it for up to 7 days before it’s gone for good.
  • Sessions end when you sign out or after 7 days without use. Request logs are kept for up to 7 days.
  • PostHog keeps analytics events for up to one year and session replays for up to 30 days.
  • Resend keeps delivery records of the emails we send you (recipient, subject and delivery status) for a limited period under its own retention policy.
  • If you email us, we keep the conversation for as long as we need it to help you.

8. Your rights

Depending on where you live, you have the right to:

  • see the personal data we hold about you and get a copy of it in a machine-readable format,
  • correct data that’s wrong, most of which you can edit yourself in the app,
  • delete your data, which you can do yourself with Delete account in Settings,
  • object to or limit how we use your data, and
  • withdraw consent to product update emails or to analytics cookies at any time.

For anything you can’t do in the app, such as getting a full export of your data, email [email protected] from the address on your account. We’ll reply within 30 days. You can also complain to your local data protection authority.

9. Security

Every connection to OneCV is encrypted with HTTPS, passwords are stored only as hashes, and uploaded photos can be opened only by the account that uploaded them. Access to the database is limited to the operator. No system is perfectly secure. If a breach affects your data, we’ll tell you without undue delay.

10. Children

OneCV is for people aged 16 and over. We don’t knowingly collect data from anyone younger. If you believe a child under 16 has made an account, email us and we’ll delete it.

11. Changes to this policy

When we change this policy, we’ll post the new version here and update the date at the top. If a change affects how we use data you’ve already given us, we’ll email you before it takes effect.

12. Contact

Write to [email protected] with any question about this policy or your data. OneCV is operated by Bisrat Shibeshi, Ethiopia.