Last updated: September 28, 2026
This policy explains what personal data OneCV collects, why we collect it, who helps us handle it and the choices you have. The rules for using OneCV are in our Terms of Service.
The short version:
- We collect what you give us to build your documents, plus the minimum needed to keep your account secure.
- Your resumes, letters and job entries are private to your account. We don’t sell your data, show ads, or train AI on your documents.
- We use analytics to improve OneCV. Detailed tracking and session replays start only if you allow them on our cookie banner, and they never include your resume content. There are no advertising trackers.
- You can delete your account from Settings at any time, and everything in it goes with it.
1. Who runs OneCV
OneCV (onecv.work and app.onecv.work) is run by Bisrat Shibeshi, an individual based in Ethiopia. In this policy, “we” and “us” mean Bisrat Shibeshi as the operator of OneCV. We decide how and why your personal data is used, which makes us its controller.
We handle personal data in line with Ethiopia’s Personal Data Protection Proclamation and, for people in the European Union, the United Kingdom and Switzerland, the GDPR and its UK and Swiss equivalents. Questions about this policy or your data go to [email protected].
2. What we collect
Account details
When you sign up with email, we store your name, your email address and a hash of your password. A hash can’t be turned back into your password, so we never know what it is. If you choose Continue with Google, Google shares your name, email address and profile picture with us, and we store those instead of a password. We also store which plan your account is on.
What you create
We store everything you make in OneCV: resumes, cover letters, job tracker entries with their notes and links, your design choices and your settings. If you add a photo to a resume, we store the image file. A signature you draw is stored inside the document it belongs to.
Files you import
When you import a PDF, JSON or text resume, your browser reads the file on your device. The file is never uploaded. Only the text you keep becomes part of your resume.
Sign-in and security data
Each time you sign in, we record the IP address and browser type (user agent) of that session to protect your account. You can sign out of every other device under Settings, in the Devices card. Our host also records basic details of each request, which can include your IP address, so we can find and fix errors.
How you use OneCV
Cloudflare Web Analytics counts page views on onecv.work without cookies and without identifying you. Our cookie banner lets you allow analytics and session replays separately. With analytics allowed, PostHog records the pages you visit, what you click, your browser and device type and your approximate location worked out from your IP address. With session replays also allowed, it records replays of your sessions.
Replays never contain your content. Every piece of text and every form field is masked in your browser before anything is sent, and photos and signatures are left out. In the app, clicks are recorded without the text of what you clicked. With analytics turned off, PostHog only counts visits without cookies. When you’re signed in and have allowed analytics, this data is linked to your account ID, never to your name or email address.
3. How we use it
- To run OneCV for you. We use your data to create and protect your account, save your documents, sync them across your devices and turn them into PDFs. This is necessary to provide the service you signed up for.
- To send account emails. These cover verifying your address, resetting your password, and warning you when someone tries to sign up with your email. Your account can’t work without them.
- To keep OneCV secure. Session and request data help us spot abuse, stop unauthorized access and fix bugs. We rely on our legitimate interest in running a safe service.
- To understand and improve OneCV. Analytics show which features people use and where they get stuck. Detailed analytics and replays run only with your consent. The cookieless page view counts rely on our legitimate interest in knowing how the site is used.
- To send product updates and career tips, only if you turn on “Email me career tips and product updates” in Settings. You can turn it off whenever you like, and each of these emails will include an unsubscribe link.
- To meet legal obligations, when a law requires us to keep or disclose information.
We don’t sell or rent personal data, we don’t show ads, and we don’t use your documents to train AI models.
5. Where your data is stored
Your account and documents are stored in the United States, and your photos and analytics data in the European Union. Both sites are served from Cloudflare’s network, which has data centers around the world. We operate OneCV from Ethiopia and access the data from there.
That means your data can travel outside your country. Where the law requires safeguards for these transfers, we rely on our providers’ data processing terms, including the EU Standard Contractual Clauses where they apply.
7. How long we keep it
- Your account and documents stay for as long as your account exists. Deleting a document removes it right away.
- Deleting your account removes your account, documents and photos right away.
- Our database provider keeps a short restore history, so deleted data can remain in it for up to 7 days before it’s gone for good.
- Sessions end when you sign out or after 7 days without use. Request logs are kept for up to 7 days.
- PostHog keeps analytics events for up to one year and session replays for up to 30 days.
- Resend keeps delivery records of the emails we send you (recipient, subject and delivery status) for a limited period under its own retention policy.
- If you email us, we keep the conversation for as long as we need it to help you.
8. Your rights
Depending on where you live, you have the right to:
- see the personal data we hold about you and get a copy of it in a machine-readable format,
- correct data that’s wrong, most of which you can edit yourself in the app,
- delete your data, which you can do yourself with Delete account in Settings,
- object to or limit how we use your data, and
- withdraw consent to product update emails or to analytics cookies at any time.
For anything you can’t do in the app, such as getting a full export of your data, email [email protected] from the address on your account. We’ll reply within 30 days. You can also complain to your local data protection authority.
9. Security
Every connection to OneCV is encrypted with HTTPS, passwords are stored only as hashes, and uploaded photos can be opened only by the account that uploaded them. Access to the database is limited to the operator. No system is perfectly secure. If a breach affects your data, we’ll tell you without undue delay.
10. Children
OneCV is for people aged 16 and over. We don’t knowingly collect data from anyone younger. If you believe a child under 16 has made an account, email us and we’ll delete it.
11. Changes to this policy
When we change this policy, we’ll post the new version here and update the date at the top. If a change affects how we use data you’ve already given us, we’ll email you before it takes effect.
12. Contact
Write to [email protected] with any question about this policy or your data. OneCV is operated by Bisrat Shibeshi, Ethiopia.