The résumé is yours. We act like it.
Hosted in the European Union, encrypted in transit, validated server-side, and free of any tracker. Here is exactly what we do, in plain language.
The practices, in plain English.
Encryption everywhere.
Every connection to BeauCV uses HTTPS with HSTS. Your data is stored on Appwrite Cloud, which encrypts sensitive data and files at rest, in its Frankfurt region.
Sessions done right.
Sign-in uses httpOnly, Secure, first-party cookies. Sign-in attempts are rate-limited by the platform. Production access is limited to the founder and protected by multi-factor authentication.
Your résumé doesn't train anything.
BeauCV does not send your résumé content to any AI provider. Editing, preview and PDF export run in your browser; your content is never used to train any model.
Data stays in the EU.
All account data and résumés live in Appwrite Cloud's Frankfurt region (Germany), in the European Union. No non-EU hosting region is used.
Your work is never lost.
The editor keeps a working draft in your browser, so a connection loss never costs you an edit. Signed in, every change is also autosaved to your account within seconds.
Delete means delete.
When you delete a résumé, it is removed immediately. To delete your account and all associated data, write to privacy@beaucv.fr: verified requests are completed within 30 days.
Every vendor that touches your data, listed.
One vendor stores your data today. We give 30 days' notice before adding any new sub-processor. You may object before it takes effect.
Find something? Tell us.
Responsible disclosure to security@beaucv.fr. We acknowledge within 48 hours, credit researchers (with permission) in our security log, and do not run a paid bounty program at this stage.
Report a vulnerability.
Send a detailed report to security@beaucv.fr: what you found, steps to reproduce, and impact. We acknowledge within 48 hours and keep you posted until the fix ships.