EU-hosted · Encrypted · Zero trackers

The résumé is yours. We act like it.

Hosted in the European Union, encrypted in transit, validated server-side, and free of any tracker. Here is exactly what we do, in plain language.

EU
EU data residency
Appwrite Cloud · Frankfurt
GERMANY · EU
TLS
HTTPS only
TLS in transit · HSTS
ALL TRAFFIC
GDPR
GDPR-aligned
EU hosting · FR company
DPA PUBLISHED
0
Zero trackers
No ads · no analytics
SESSION COOKIES ONLY
What we do

The practices, in plain English.

🔒

Encryption everywhere.

Every connection to BeauCV uses HTTPS with HSTS. Your data is stored on Appwrite Cloud, which encrypts sensitive data and files at rest, in its Frankfurt region.

in-transit TLS, HTTPS only, HSTS
at-rest Encrypted by Appwrite Cloud
region Frankfurt (Germany, EU)

Sessions done right.

Sign-in uses httpOnly, Secure, first-party cookies. Sign-in attempts are rate-limited by the platform. Production access is limited to the founder and protected by multi-factor authentication.

sessions httpOnly · Secure cookies
abuse Platform rate limiting
prod Founder only · MFA
🚫

Your résumé doesn't train anything.

BeauCV does not send your résumé content to any AI provider. Editing, preview and PDF export run in your browser; your content is never used to train any model.

providers None
training Never
editing In your browser

Data stays in the EU.

All account data and résumés live in Appwrite Cloud's Frankfurt region (Germany), in the European Union. No non-EU hosting region is used.

region Frankfurt (Germany)
jurisdiction European Union
provider Appwrite Cloud (fra)
🧯

Your work is never lost.

The editor keeps a working draft in your browser, so a connection loss never costs you an edit. Signed in, every change is also autosaved to your account within seconds.

local Draft in your browser
cloud Autosave on every change
storage Appwrite Cloud (EU)

Delete means delete.

When you delete a résumé, it is removed immediately. To delete your account and all associated data, write to privacy@beaucv.fr: verified requests are completed within 30 days.

résumés Immediate removal
account Within 30 days
contact privacy@beaucv.fr
Sub-processors

Every vendor that touches your data, listed.

One vendor stores your data today. We give 30 days' notice before adding any new sub-processor. You may object before it takes effect.

Vendor
Purpose
Region
DPA
Appwrite Code Ltd.
Hosting, database, auth, account emails
EU (Frankfurt, Germany)
GDPR terms
Vulnerability reports

Find something? Tell us.

Responsible disclosure to security@beaucv.fr. We acknowledge within 48 hours, credit researchers (with permission) in our security log, and do not run a paid bounty program at this stage.

CRITICAL
24h
RCE, auth bypass, mass data exposure.
HIGH
48h
SQLi, stored XSS in editor, privilege escalation.
MEDIUM
72h
Reflected XSS, CSRF on sensitive endpoints.
LOW
7d
Info disclosure, missing headers.
Responsible disclosure

Report a vulnerability.

Send a detailed report to security@beaucv.fr: what you found, steps to reproduce, and impact. We acknowledge within 48 hours and keep you posted until the fix ships.

$ open mailto:security@beaucv.fr
# describe the issue, steps to reproduce, impact
# PGP encryption available on request
# (ask for our key in your first email)
$ gpg --encrypt --recipient security@beaucv.fr report.txt
→ acknowledged within 48 hours
$ _