← ReadPulse.cv

Privacy Policy

Last updated 5 October 2026

ReadPulse.cv lets you upload PDFs and get AI explanations of passages you highlight. That means we hold documents you consider private, so this page says plainly what we store, who else sees it, and how to get it removed.

What we collect

Your account. Your email address and a password, handled by our authentication provider. We never see your password in readable form.

Your documents. The PDF files you upload, and the text extracted from each page so that highlighting, search and AI actions can work. Also any highlights, underlines, notes and drawings you add.

Your AI conversations. The passages you select, the questions you ask, and the answers you receive, so a conversation continues where you left off.

Usage records. For each AI action: which action, which model, token counts and the associated cost. This enforces plan limits and shows you your own usage. It does not include the content of the request.

Reading position. The page and scroll position in each document, so you can pick up where you stopped.

Support and sales messages. If you contact us: your name, email, optional company size, and your message.

Billing. If you subscribe, our payment provider collects and holds your payment details. We never receive or store your card number. We keep only a subscription reference, your plan, its status and renewal date.

AI providers, and what they get

When you run an AI action, we send the passage you selected plus a window of surrounding text from that page to the model provider you chose. We do not send the whole document.

Your documents are not used to train AI models. We use these providers through their APIs, where submitted content is not used for training by default. They process the request, return an answer, and retain it only as long as their own API terms require.

If a passage is confidential enough that no third party should see it, do not run an AI action on it. Reading, highlighting and annotating never leave our systems.

Why we hold it

To run the product: store your library, extract text, answer your questions, remember your place, enforce plan limits, take payment, and reply when you contact us. We do not sell your data, and we do not use it for advertising.

Who else processes it

We use a small number of providers, each only for the purpose listed:

  • Supabase — accounts, database and file storage
  • Amazon Web Services — application hosting and PDF text extraction
  • Upstash — caching and rate limiting
  • Vercel — website hosting, and page-view analytics if you allow it
  • OpenAI and Anthropic — the AI models that answer your questions
  • Dodo Payments — subscriptions, as merchant of record
  • Notion — only if you connect it, and only to write the highlights you export

Where it is stored

Our application and database are hosted in the United States (AWS us-east-1). If you are outside the United States, using ReadPulse.cv means your data is transferred there and to the providers listed above, which operate in several countries.

How long we keep it

Documents, highlights and conversations are kept until you delete them or ask us to close your account. Deleting a document removes the file, its extracted text and its annotations.

Usage and billing records are kept longer, because we need them for accounting and tax. Support messages are kept so we have the history of a conversation with you.

Your choices

You can delete any document from your library at any time, and disconnect Notion whenever you like.

For a copy of your data, correction of anything wrong, or deletion of your account and everything in it, email us at readpulsecv@gmail.com or use the support form. Account deletion is handled by request today rather than by a button in the app; we will confirm once it is done.

Depending on where you live you may have additional rights over your personal data, including to object to or restrict how it is processed. Contact us and we will honour them.

Security

Traffic is encrypted in transit. Files are stored in access-scoped storage, every API request is tied to an authenticated account, and all data is scoped to the account that owns it. Credentials are held in a managed secrets store rather than in code.

No system is perfectly secure. If you find a vulnerability, please report it to readpulsecv@gmail.com rather than disclosing it publicly, and we will work with you on it.

Cookies, local storage and analytics

Strictly necessary. Sign-in cookies, without which you cannot stay signed in.

Functional. Your theme, your open tabs, your chosen model and whether you have seen the selection hint, kept in your browser's local storage. These never leave your device.

Analytics. We use Vercel Web Analytics to count page views and unique visitors, so we know whether anyone is finding the site. It is cookieless and does not identify you or follow you across other sites. You are asked before it loads, and declining genuinely prevents it from running — you can change your mind by clearing this site's data in your browser.

We do not use advertising or cross-site tracking cookies, and we do not sell data to anyone.

Children

ReadPulse.cv is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.

Changes

If this policy changes in a way that materially affects you, we will update the date at the top and, where the change is significant, tell you by email.

Contact

Questions about this policy, or about your data: readpulsecv@gmail.com.

© 2026 ReadPulse.cv