This policy explains how Quvon Labs (Sole Proprietorship) (“we”, “us”), the operator of BurntCV at https://burntcv.fun, collects and uses personal data. We act as the data fiduciary for the limited data we handle. It should be read with our Terms of Service.
//1. What we do NOT store
We do not store your résumé or LinkedIn profile file or its text on our servers. When you upload a PDF, it is parsed in your browser — the file itself is not uploaded to us. Only the extracted text needed to produce the roast leaves your device, and only to the AI provider described next.
//2. How a roast is generated (the data flow)
- Your PDF is read locally in your browser; we extract the text there.
- That text is sent to our AI provider, Anthropic (the Claude API), purely to generate your roast. If you use your own API key (BYOK), this call is made directly from your browser to Anthropic under your own account.
- Under Anthropic's API terms, inputs and outputs are not used to train its models. We do not retain the résumé text after your roast is returned.
//3. What is stored on your device
For the app to work, we save some data locally in your browser's storage (never transmitted to us):
- Your roast history (the roast text — not the résumé) and simple usage counters.
- Your Pass status, Pass token, and restore code, if you've purchased.
- Your AI provider API key, if you chose BYOK — this stays on your device only.
You can delete all of this at any time by clearing your browser's site data for BurntCV.
//4. What we collect on our servers
- IP address — used transiently to rate-limit roasts and prevent abuse (via Upstash).
- Purchase details — if you buy a roast or a Pass, your payment is handled by Razorpay, which shares limited transaction metadata (such as order ID, status, and the email you provide) with us so we can grant and restore your entitlement. We never receive or store your full card/UPI credentials.
- Anonymous usage analytics — aggregate, privacy-friendly metrics via Vercel Analytics. No advertising cookies, no cross-site tracking.
//5. Third parties we rely on
- Anthropic (Claude API) — generates the roast from your text.
- Razorpay — processes payments.
- Vercel — hosts the site and provides anonymous analytics.
- Upstash — rate-limiting / abuse-prevention.
- Fontshare — serves the site's font; loading it shares your IP with the font CDN, as is standard for web fonts.
//6. Cookies & local storage
We don't use advertising or cross-site tracking cookies. We use your browser's local storage to run the app (as in section 3) and essential / analytics technology to keep the Service working and measure aggregate usage.
//7. Where your data is processed
Some of our providers (including Anthropic, Vercel, and Upstash) process data on servers that may be located outside India. By using BurntCV you consent to this cross-border processing. Payment data is handled by Razorpay in line with applicable Indian regulations.
//8. How long we keep things
- Résumé / profile text: not retained after your roast is generated.
- IP / rate-limit data: short-lived, only as long as needed to prevent abuse.
- Purchase records: kept as long as needed to honour your entitlement and to meet tax/legal obligations.
- On-device data: stays until you clear your browser storage.
//9. Your rights
Under India's Digital Personal Data Protection Act, 2023 and the rules made under it, you can request access to, correction of, or erasure of the personal data we hold about you, and you can raise a grievance. Most of your data lives on your own device, so you can delete it directly by clearing your browser storage. For anything we hold server-side, contact us using the details below.
//10. Grievance Officer
For privacy questions, requests, or complaints, contact our Grievance Officer:
- Ayush Verma
- quvonlabs@gmail.com
We aim to acknowledge grievances within 48 hours and resolve them within 30 days. If you're not satisfied with our response, you may approach the Data Protection Board of India.
//11. Children
BurntCV is intended for users aged 18 and over and is not directed at children. We don't knowingly collect data from anyone under 18.
//12. Security
We serve the Service over HTTPS with a strict content-security policy and deliberately collect as little personal data as possible. No method of transmission or storage is perfectly secure, but keeping your résumé off our servers is a core part of how we protect it.
//13. Changes & contact
We may update this policy; the “last updated” date above reflects the latest version. Questions? Email quvonlabs@gmail.com or visit our Contact page.