Privacy
Privacy Policy
Policy version: 2026-09-v1
Last updated: 2026-09-25
Who we are
Wovy (wovy.ai) is a resume tool. It helps you turn your work history into resumes tailored to specific jobs. This policy explains what personal information Wovy handles, why, who else receives it, and what you can do about it.
Operator: Yves Jiang (individual developer), based in Shanghai, China
Privacy contact: support@wovy.ai
What we collect
We collect what you give us and what the service needs to run:
- Account details. Your email address. If you sign in with Google, GitHub or Microsoft, we also receive the basic profile that service shares at sign-in (such as your name and email address). We never receive your password for those services.
- Resume content. Everything you paste, upload or type about your work history, such as experience, education, skills and contact details, and a profile photo if you add one.
- Job descriptions. The job postings you paste in, with the job title and company name.
- Generated content. The resume versions our AI drafts for you, your edits to them, and the PDF files you export.
- Product activity. Records of actions you take in the product (for example choosing a template, editing a version or starting an export), stored with your account.
- Analytics. If you are signed in, PostHog records how you use the product: named product events, clicks within the app (its automatic click capture is on, which can include the text of the button or link you clicked), and the search terms you type into your submission history search. If you are not signed in, PostHog is not loaded at all and we use only Vercel Web Analytics, which does not use cookies.
- Error reports. When something breaks, an error report is sent to Sentry. Before a report leaves our systems we remove cookies, authorization headers, request bodies, and sign-in codes or invite tokens in web addresses. Session replay is turned off.
- Consent records. When you agree to AI processing, we store that you agreed, which policy version you agreed to, the language you were using, and when.
- Abuse-prevention data. To enforce usage limits we count requests per account, and for some actions (sending a sign-in code, opening an invite link, redeeming a voucher) per IP address.
How we use it
- To run the service: sign you in, store your resumes, tailor them to jobs, and produce PDF files.
- To send your resume content and job descriptions to AI models that analyze the job and draft tailored versions. This happens only after you consent (see below).
- To send you service emails, such as sign-in codes and account approval or welcome emails.
- To understand how the product is used and to fix errors.
- To enforce usage limits and prevent abuse.
We do not sell your personal information and do not use it for advertising.
Who receives your data, and where
Wovy runs on the services below. They are located outside mainland China, so using Wovy means your information is transferred to and processed in other countries or regions. This is the cross-border transfer we ask you to agree to before any resume content is sent to an AI model.
- OpenAI (AI models). Receives the resume content, job descriptions and instructions needed for each AI step, such as analyzing a job, importing a resume or drafting versions, and returns the result. Location: United States.
- Vercel AI Gateway (AI request routing). Our requests to AI models are routed through Vercel AI Gateway. Every AI step currently uses OpenAI models; if we add another provider, we will update this policy first.
- Supabase (database, sign-in and file storage). Stores your account, resumes, job descriptions, generated versions, exported PDFs, profile photo, product activity and consent records Sign-in emails are triggered by Supabase and delivered through Resend (see below). Location: Singapore.
- Vercel (website hosting and visitor analytics). Every request to wovy.ai, including the content you submit, passes through Vercel. Its Web Analytics counts visits without cookies. Location: our servers run in Singapore; requests first reach the Vercel edge location nearest you.
- Fly.io (PDF rendering). When you export, the resume version being exported is sent to our PDF rendering service. It builds the PDF and deletes its working files after each job. Location: Singapore.
- Upstash (usage limits and short-lived working data). Holds request counters keyed by your account ID or IP address, AI generation progress (expires after 10 minutes), and, for troubleshooting, copies of AI requests and responses, which contain resume and job-description content and expire after 2 hours. Location: Singapore.
- Inngest (background jobs). Runs AI steps in the background. Job messages include job-description text and, for resume import, the resume text you submitted. Location: United States. Job records are kept for up to 90 days.
- Resend (email delivery). Receives your email address and the email content in order to send sign-in codes and links, account approval and welcome emails. Location: Japan (Tokyo).
- Sentry (error reporting). Receives error details and technical context, after the removals described above. A 10% sample of page loads and requests is also sent for performance tracing. Location: United States.
- PostHog (product analytics, signed-in users only). Receives the usage data described above. We do not link these events to your name or email address. Location: United States.
- Our team. Authorized Wovy administrators can view account data and AI request records in an internal admin console, to review access requests, support you and troubleshoot problems.
Your consent to AI processing
Before Wovy sends any of your resume content to an AI model, we ask you to agree to this cross-border processing. We record your agreement against the policy version shown at the top of this page.
When the policy version changes, we ask you again before your resume content is next sent to an AI model.
You can withdraw consent at any time by emailing us (see Your rights); a person on our team handles it. Once withdrawn, we stop sending your resume content to AI models, which means you cannot use the AI features: AI resume import, job analysis and tailored versions.
Cookies and browser storage
- Sign-in cookies keep you signed in.
- While you sign in with an email code, your email address is kept in a cookie for up to 15 minutes, sent only to the sign-in pages.
- Your language choice is kept in a cookie.
- Signed-in users only: PostHog stores an analytics identifier in your browser. When you sign out, PostHog stops recording and stops storing data. It also honors your browser's Do Not Track setting.
- Some interface preferences, such as the sign-in method you last used, are kept in your browser's local storage.
- Signed-out visitors get no analytics cookies.
How long we keep it
Your account, resumes, job descriptions, generated versions, exported PDFs, profile photo and consent records are kept until you ask us to delete them. There is currently no automatic deletion of this data and no self-service button to delete your account.
Some records are cleaned up automatically. Product activity records are deleted after 30 days. The stored copies of AI requests and responses are cleared after 30 days; a summary of each AI call (such as timing and usage counts) is kept. Troubleshooting copies in Upstash expire after 2 hours, and the PDF service deletes its working files after each export.
To delete your data, email us from the address you sign in with. We will delete it within 30 days. Copies in database backups are kept for up to 7 more days; copies in error reports, product analytics and background-job records are kept for up to 90 days and then deleted automatically.
Your data is stored with our database provider, Supabase, and protected by the security measures that provider offers.
Your rights
You can ask us to:
- Access: tell you what personal information we hold about you and give you a copy.
- Correct: you can edit most of your resume and profile yourself in Wovy. For anything else, ask us.
- Delete: delete your account and data.
- Withdraw consent: stop sending your resume content to AI models. You will no longer be able to use the AI features.
To use any of these rights, email support@wovy.ai from the email address on your account. We will reply within 15 business days. If you are not satisfied with our reply, you can complain to the personal-data protection authority where you live.
Changes to this policy
When this policy changes, we update the version and date at the top of this page. When the version changes, we ask for your consent again before your resume content is next sent to an AI model.