Privacy Policy
Effective September 16, 2026. Operated by MarkKings Group LLC.
Kivoo Apply handles a resume, which is one of the more sensitive documents most people own: full name, home location, phone number, email address, employment history, and often work authorization status. This policy says what happens to it. It describes the system as it is actually built, not as a category.
1. What we collect
- Account data. Email address, a hashed password (we never store the password itself), your name, phone, and location if you provide them, and multi-factor secrets if you enable MFA.
- Resumes and their parsed contents. The files you upload and the structured text extracted from them: employers, titles, dates, skills, summary.
- Application data. Jobs you save, the documents generated for each, your answers to application questions (including answers about work authorization, sponsorship, salary expectations and demographic questions where an employer asks them), approvals, and submission outcomes.
- Recruiter contacts and outreach drafts that you create.
- Operational records. An audit log of actions taken in your account, and an AI usage log recording, per request: the task, the provider, the model, token counts, and computed cost. The usage log does not store prompts or generated text.
- Session data. A session cookie, and the timestamps and counters used to lock an account after repeated failed sign-ins.
We do not use advertising trackers, and we do not sell or rent personal data to anyone.
2. Who your data is sent to, and why
Operating this Service means sending your data to other companies. Each one below receives it for a stated purpose, and nothing else.
- AI providers. To tailor a resume, the model has to be given the resume. Depending on your plan and which provider is available, requests go to OpenAI (primary), Anthropic (fallback), or OpenRouter, which routes to further model providers on its own network. They receive the resume text, the job description, and the instructions for the task.
- Employers and applicant tracking systems. When you approve a submission, your resume file and your answers are submitted to that employer’s system (for example Greenhouse, Lever, Ashby, SmartRecruiters or Workable). Once submitted, that data is held by the employer under the employer’s own privacy policy, and we cannot retrieve or delete it.
- Email delivery. Verification, invitation and notification emails are sent through Resend or a configured SMTP server, which receives your email address and the message.
- Cloudflare Turnstile. The sign-in page uses Turnstile to block automated login attempts. Cloudflare receives the information needed to run that check.
What the AI providers may do with it
On paid API access, OpenAI and Anthropic state that they do not use API inputs or outputs to train their models. Free models accessed through OpenRouter are different: the data policy varies by the underlying provider, and some of them do train on submitted prompts. If your plan uses free models, assume the content of your resume may be used by the underlying model provider. This is why the free tier is labelled as such, and it is a reason to choose a paid tier if that matters to you.
3. Where it is stored
Account and application data is stored in a PostgreSQL database on infrastructure operated by MarkKings Group LLC. Uploaded resumes and generated documents are stored as files on that same infrastructure. Data is held in the United States.
4. How long it is kept
- Account, resume and application data: for as long as your account exists.
- Audit and AI usage logs: retained after the records they refer to are deleted, because they are what allows a billing figure or a security question to be answered later. They identify the account, the action and the cost; they do not contain your resume or generated documents.
- Applications already submitted to an employer: out of our hands entirely. Deleting your account here does not withdraw an application you already sent.
5. Your choices and rights
- Access and correction. Your data is visible and editable in the app.
- Export. You can request a copy of your account data. Write to the address below and we will provide it.
- Deletion. You can request deletion of your account. That removes your account data, resumes, generated documents, application records and recruiter contacts. It does not remove applications already delivered to employers, and it does not remove the audit and usage records described above.
- Withdrawing from AI processing. Generation is the Service. You can stop generating, and you can delete what was generated, but the Service cannot tailor a document without sending it to a model.
Depending on where you live (for example California, or the EU and UK), you may have additional statutory rights, including the right to object to processing and to lodge a complaint with a supervisory authority. Use the contact address below and we will act on such a request.
6. Security
Passwords are stored hashed, not encrypted or in plain text. Multi-factor authentication is available and recommended. Sessions are cookie-based, and repeated failed sign-ins lock an account. The site sends strict transport security, frame-denial and content-security-policy headers. Every action taken in an account is recorded in an audit log.
No system is immune. If a breach affects your personal data, we will notify affected users.
7. Children
The Service is not for anyone under 18 and we do not knowingly collect their data.
8. Changes
If this policy changes materially, the effective date above changes and registered users are notified. We do not edit it quietly.
9. Contact
Privacy questions, export requests and deletion requests: [email protected]. See also our Terms of Service.