Privacy Policy

Last updated: 24 August 2026

Gradovio ("we", "us") helps UK graduates find and apply for jobs, using AI to score matches and generate application content. This policy explains, in plain English, what data we collect, why, and what rights you have over it. It applies to everyone who uses gradovio.com.

What we collect

  • Account details: your email address and password (we never see your password in plain text - it's handled securely by our authentication provider, Supabase).
  • Your CV: the file you upload, the full text we extract from it, and the skills, degree, and experience summary our AI pulls out of it.
  • Saved jobs: the job listings you save (title, company, location, salary, source, closing date if known, and a link to the original posting), plus the status you set (e.g. Applied, Interviewing) and any deadline you add.
  • AI-generated content: match scores and reasons, cover letters, game plans, and interview prep packs we generate for your saved jobs, so we can show them to you again without regenerating them every time.
  • Application answers: the answers you give in our application questionnaire, and - if you use our browser extension - questions and answers it learns from employers' forms as you fill them in, so you do not have to type the same thing on every application. There are things it never saves; see "The Gradovio browser extension" below.

We do not store your job search queries (keyword, location, filters) beyond the single request needed to fetch results - we don't keep a history of what you've searched for.

How we use it

We use your data to run the features you'd expect from Gradovio:

  • Matching you against jobs and showing a compatibility score.
  • Generating tailored cover letters, application game plans, and interview prep.
  • Keeping track of your saved jobs and application progress.
  • Letting you log in securely and access your own data.

Who we share data with

We don't sell your data. We use a small number of service providers to run Gradovio, each only for a specific purpose:

  • Supabase - our database and authentication provider. Your account, CV, saved jobs, and AI-generated content are stored in a Supabase database hosted in London, in the EU/UK region.
  • Anthropic (maker of the Claude AI models) - we send your CV text and profile, along with the relevant job's title/company/description, to Anthropic's API to generate match scores, cover letters, game plans, and interview prep. If you paste in a job URL, the scraped page text is also sent to Anthropic to extract the job details. Anthropic is based in the United States, so this involves transferring data outside the UK/EEA; Anthropic's API terms (at the time of writing) state they do not use API data to train their models. See Anthropic's own privacy policy for their current terms.
  • Adzuna and Reed - job listing providers. When you search, we send them your search filters (like keyword and location) to fetch matching jobs. We do not send them your account details, CV, or saved jobs.
  • Vercel - hosts the Gradovio website itself, as any web host does.
  • PostHog- analytics, but only if you say yes to it in our cookie banner. If you accept, we send page views and actions you take (like uploading a CV or saving a job) to PostHog so we can understand how people use Gradovio and improve it. PostHog processes this data in the United States, so accepting analytics involves transferring data outside the UK/EEA. We don't use it for advertising and we don't sell this data.

The Gradovio browser extension

Our Chrome extension fills in application forms on employers' own websites. Because it runs on other companies' pages, it is worth being precise about what it does and does not do. It is entirely optional - Gradovio works without it.

What it can see, and when

The extension only reads a page when you press a button in it. It does not watch your browsing, and it is not running in the background on pages you have not asked it about. It never submits an application - you review and send every one yourself.

It comes set up for a handful of well-known application systems (Greenhouse, Lever, Ashby, Workable and Reed). To use it on any employer's site, you can grant it permission for all sites - Chrome asks you separately, and you can withdraw it at any time from Chrome's extension settings. Granting it does not change the rule above: it still only reads a page when you ask it to.

What it stores on your own computer

This is held by your browser, not by us, and never leaves your machine except as described below:

  • The answers from your Gradovio questionnaire, so it can fill a form while you are on an employer's site.
  • A record of which of your saved jobs you have prepared documents for.
  • A sign-in token for your Gradovio account, so the extension can reach your data without asking you to log in again on every form. It expires, and signing out or removing the extension discards it.
  • The job advert from the page you came from, so that pressing "Apply" and landing on a bare form does not lose the description the documents are written from. This one is cleared when you close the tab, and in any case when you close the browser.

Removing the extension deletes all of it.

Answers it learns from forms

When you answer a question on an employer's form that Gradovio did not already know - a driving licence, a notice period, which tools you have used - the extension saves that question and your answer to your account, so you do not have to type it again on the next application. You can see, edit and delete every one of these on the Learned answers page in Auto apply.

Some things are never saved, whatever you type into them, and the filter runs both in the extension and again on our server:

  • Passwords, card numbers, security codes, bank sort codes and account numbers.
  • National Insurance numbers, passport numbers and dates of birth.
  • Equal-opportunities monitoring questions - ethnicity, disability, religion or belief, sex, gender identity, sexual orientation, marital or caring status, nationality, veteran status, and socio-economic background. Under UK GDPR most of these are special category data, and the safest thing we can do with them is not hold them at all. The extension will not answer them for you either; you answer those yourself, or leave them, as you prefer.

The extension also refuses to tick declarations, consents and marketing opt-ins on your behalf. Agreeing to something in your name is yours to do.

When something goes wrong

If the extension cannot read a form, it reports the failure so we can fix it. That report contains the website's address (for example jobs.example.com), what went wrong, and the wording of the questions it could not handle. It does not contain your answers, and never the categories listed above.

Where it sends things

To write a tailored CV, cover letter or interview prep, the extension sends the job description - the one shown in its panel, which you can edit or clear - along with your CV and profile, to Gradovio, and Gradovio sends it on to Anthropic, exactly as described in "Who we share data with" above. It does not send anything to the employer's website beyond what you would have typed yourself, and it does not send your data to any other third party.

Cookies

We always use essential cookies to keep you logged in securely. With your consent (via the cookie banner), we also use PostHog analytics cookies to understand how people use the site - you can choose "Essential only" to opt out, and we won't load any analytics unless you accept. We don't use advertising cookies.

How long we keep it

We keep your data for as long as your account is active. If you delete your account (from your Profile page), your CV, saved jobs, all generated content, your application answers and anything the extension learned are permanently deleted from our database straight away. Supabase, our database provider, may retain deleted data in routine backups for a short period afterwards, after which it is permanently removed.

You do not have to delete the whole account to remove a learned answer: the Learned answers page in Auto apply deletes them one at a time, and deleting one there deletes it from our database, not just from view.

Your rights

Under UK GDPR, you have the right to:

  • Access the data we hold about you.
  • Correct inaccurate data - you can do this yourself by re-uploading your CV or editing your saved jobs.
  • Delete your data ("right to erasure") - use the "Delete my account and all my data" option on your Profile page, or email us.
  • Ask us to restrict or object to how we process your data.
  • Receive a copy of your data in a portable format.

Legal basis

We process your data because it's necessary to provide the service you've signed up for (contract), and, in a few places like cookies, because they're strictly necessary for the site to function.

Who this is for

Gradovio is intended for users aged 18 and over who are looking for UK graduate jobs.

Contact us

For any questions about this policy or your data, or to make a data request, email us at gradovioapplications@gmail.com.

Changes

We may update this policy as Gradovio changes. If we make significant changes, we'll update the date at the top of this page.