Help Center
account

Data Privacy and Security

February 23, 2026 4 min read

Data Privacy and Security

Your resume contains sensitive personal information — your contact details, work history, and career aspirations. Krokanti CV Builder is built with privacy and security as foundational requirements, not afterthoughts.

Data Encryption

All data in Krokanti CV Builder is encrypted in transit and at rest:

  • In transit: All connections between your browser and our servers use TLS 1.3. Any attempt to connect over HTTP is redirected to HTTPS automatically.
  • At rest: Your resume data is stored in a Neon Postgres database with encryption at rest enabled at the infrastructure level. Uploaded files (attachments, profile photos) are stored in Cloudflare R2 with server-side encryption.
  • Passwords: Passwords are hashed using bcrypt with a cost factor of 12 before storage. We never store plaintext passwords.

Two-Factor Authentication (2FA)

Two-factor authentication adds an extra layer of security to your account. Even if your password is compromised, an attacker cannot access your account without your second factor.

To enable 2FA:

  1. Go to Settings > Security
  2. Click Enable Two-Factor Authentication
  3. Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, or any TOTP-compatible app)
  4. Enter the 6-digit code from the app to confirm
  5. Save your backup codes in a safe place — these let you recover access if you lose your authenticator device

Once enabled, you will be prompted for a 6-digit TOTP code on every new login.

What Data We Collect

  • Account data: email address, name, hashed password, account creation date
  • Resume data: all content you enter into your resumes
  • Usage data: page views, feature interactions, error logs (anonymized where possible)
  • Payment data: billing address and email. Full card details are handled exclusively by Stripe — Krokanti never sees or stores card numbers.

We do not sell your data. We do not use your resume content for advertising. We do not share your data with third parties except as described in our Privacy Policy (processors like Stripe for payments, Brevo for transactional email, Cloudflare for infrastructure).

GDPR Compliance

Krokanti CV Builder is operated from the European Union and is fully compliant with the General Data Protection Regulation (GDPR).

Your rights under GDPR include:

  • Right of access: You can request a full export of all data we hold about you
  • Right to rectification: You can correct inaccurate data at any time through your account
  • Right to erasure: You can request full account deletion, which permanently deletes all your resumes and personal data
  • Right to data portability: You can export your resume data in JSON format (Pro) or request a machine-readable archive
  • Right to object: You can opt out of non-essential processing (e.g., analytics) via the cookie settings banner

To exercise any of these rights, contact privacy@krokanti.com or use the self-service tools in Settings > Privacy.

Exporting Your Data

You can download a complete archive of your account data at any time:

  1. Go to Settings > Privacy
  2. Click Download My Data
  3. We will prepare your archive (this can take up to 15 minutes for large accounts)
  4. You will receive an email with a secure download link valid for 48 hours

The archive includes all your resumes in JSON and PDF format, your account details, and a log of logins.

Account Deletion

To permanently delete your account:

  1. Go to Settings > Privacy
  2. Click Delete Account
  3. Enter your password to confirm

Account deletion is permanent and irreversible. All resumes, account data, and billing history are deleted within 30 days in accordance with our data retention policy. Active subscriptions are canceled automatically at deletion.

Reporting Security Issues

If you discover a security vulnerability in Krokanti CV Builder, please report it responsibly to security@krokanti.com. We aim to acknowledge reports within 24 hours and resolve confirmed issues within 72 hours.

Was this article helpful?

Need more help? Contact us at support@krokanti.com

Related articles