On this page
LumiCV uses artificial intelligence (AI) to generate suggestions for your resume, cover letters, and interview prep. This page is the single place where we explain what that means in plain language: which features use AI, what data is involved, what is and isn't sent to AI providers, why our AI doesn't make decisions about you, and how to opt out.
This document is required by the EU AI Act Article 50 (transparency obligations, applicable from August 2026) and supplements our Privacy Policy and Terms of Service.
1. TL;DR
- AI is opt-in per click. The Free plan and the resume editor work without sending any of your content to an AI provider.
- The AI generates suggestions; you review, edit, accept, or reject every output before it reaches anyone else.
- The AI does not make hiring decisions, screen candidates, or rank you against other people.
- Our AI provider is Azure OpenAI (Microsoft, EU region — Sweden Central). Requests are processed in the EU; your data does not leave the EU in normal operation, and is not used to train any AI model.
- If our Azure OpenAI capacity is unavailable (regional outage, capacity exhaustion), we may fall back to OpenAI's direct API in the United States — under Standard Contractual Clauses and OpenAI's Data Processing Addendum, with the same no-training guarantee. We tell you in this page when this happens.
- You can stop using AI features at any time and continue using LumiCV with manual editing only.
- If any AI suggestion treats you unfairly, you can request a human at LumiCV reviews it within 14 days at [email protected].
2. Which features use AI
Not every feature in LumiCV uses AI. Here is the exhaustive list:
3. Who runs the AI
Our primary AI provider is Azure OpenAI Service, operated by Microsoft in the European Union (Sweden Central region). We use GPT-class models (gpt-4.1 family) deployed inside our own Azure tenant. We do not currently use Anthropic, Google Gemini, Mistral, or any other production AI provider.
Azure OpenAI requests are processed entirely on EU-resident Microsoft infrastructure. The relevant safeguards are:
- EU data residency — Microsoft's EU Data Boundary commitment for Azure OpenAI keeps prompt and completion data in the EU/EFTA region. No EU→US transfer in normal operation.
- Microsoft Online Services DPA (incorporates SCCs and EU GDPR addendum) — Microsoft acts as data processor; we are the controller.
- No training on customer data — Azure OpenAI is contractually prohibited from using prompts or completions to train any model (Microsoft, OpenAI, or third-party).
- Abuse monitoring opt-out — for the regulated processing of resume / cover-letter content, we operate under Microsoft's modified abuse-monitoring posture; prompts are not retained for human review.
Disaster-recovery fallback
If our Azure OpenAI deployment is unavailable (regional outage, capacity exhaustion, or comparable Microsoft incident), we may fall back to OpenAI's direct API in the United States to keep the service running. This path is governed by:
- Standard Contractual Clauses (SCC Module 2 — controller-to-processor) for the EU→US transfer
- OpenAI's Data Processing Addendum, which prohibits OpenAI from using API data to train their models
- OpenAI's published 30-day abuse-monitoring window, after which the data is deleted
The fallback is only activated when Azure OpenAI cannot serve the request; we do not split traffic between providers in normal operation.
If we ever change primary AI providers or add another, we will update this page and notify users of any material change.
4. What we send and don't send
When you click an AI feature, here's exactly what crosses the network to the AI provider:
What we send
- The relevant portion of your resume content (e.g. for cover letter generation, we send only the parts needed for the prompt — not your billing history, not your saved jobs, not other resumes)
- The job description text you've pasted in
- Your tone / language / writing-style preferences for that specific tool
- A small system prompt describing the task
What we never send
- Your name, email, billing address, or payment details
- Your password, session tokens, or any login credential
- Other resumes, cover letters, or job applications you have in your account
- Your saved-jobs list, notes, follow-up reminders
- Anything from the LumiCV admin database — usage analytics, IP logs, support tickets
- Any other LumiCV user's data, ever
What we keep on our side
Your inputs and the AI's outputs are stored in your LumiCV account so you can return to them, edit them, and download them. They live on EU-resident infrastructure (Microsoft Azure, Sweden Central). They are deleted within 30 days of you deleting your account.
5. Why we don't make decisions about you
This is the most important section for the law and for your peace of mind.
The EU GDPR (Article 22) and the EU AI Act both have rules about AI systems that make decisions about people — for example, AI that screens job applicants, decides whether to hire, or scores someone in a way that affects their career.
LumiCV is not that kind of AI system, by design:
- The AI generates suggestions for your review. You read every output, decide whether to keep it, edit it, or throw it away.
- LumiCV does not screen, score, or rank you against any other candidate for any role.
- The "ATS score" you see in the app is a keyword-match feedback signal for you, calculated by deterministic rules with no AI involved (see Section 2). It is not a decision by us about whether you should apply.
- No AI output of LumiCV's is ever sent automatically to a recruiter. You always export, copy, or share manually.
Because every AI output is reviewable and editable by you before it reaches anyone else, the GDPR Article 22 trigger for "decisions based solely on automated processing… which produces legal effects… or similarly significantly affects" you is not engaged. You can read the formal version of this analysis in Privacy Policy Section 6.
6. How to opt out
You can use LumiCV without AI features. Here's how:
- Stay on the Free plan — Free includes the resume builder, the country CV formats and ATS templates, PDF downloads, and job-application tracking. AI features are present but require a click; if you never click them, no resume content is sent to any AI provider.
- If you're on a Pro plan — same applies. AI features are opt-in per click. The presence of credits doesn't auto-spend them.
- Cancel your account — you can delete your LumiCV account at any time from Account Settings → Delete account. We hard-delete your data (no soft-delete, no anonymisation that retains the record) within 30 days. Billing records are kept 7 years per Dutch tax law (Art. 52 AWR).
7. Right to human review
If any AI suggestion treats you in a way that feels inaccurate, biased, or unfair — for example, if it omits relevant experience, mischaracterises your background, or uses language that misrepresents you — you have the right to ask a human at LumiCV to review it.
How: email [email protected] with:
- Your account email
- The feature you used (e.g. "Tailor", "Cover Letter")
- What was wrong with the AI's output, in your own words
We will respond within 14 days with an explanation, a corrected output if applicable, and the option to delete the AI-generated content from your account. This SLA is shorter than the 30-day GDPR Article 12 default because we believe AI-related concerns deserve faster turnaround.
8. We don't use your data to train AI
Neither LumiCV, Microsoft (Azure OpenAI), nor OpenAI (the disaster-recovery fallback) uses your resume content, job descriptions, AI prompts, or AI outputs to train any AI model. This is contractually prohibited by:
- The Microsoft Online Services DPA and Azure OpenAI's published service terms, which exclude customer prompts and completions from any model-training pipeline (Microsoft, OpenAI, or third-party)
- OpenAI's API Terms of Use and Data Processing Addendum (covering the DR fallback path), which exclude API data from being used in model training
- Our own Terms of Service Section 5
If LumiCV ever wants to train a model on customer data — we don't have any plans to — that would require explicit, separate, opt-in consent from each user. No such program exists today.
9. Known limitations
It would be dishonest to claim AI suggestions are perfect. They aren't. Some honest caveats:
- Probabilistic output. The same input may produce different suggestions on different days. We don't promise specific outcomes ("this resume will get an interview").
- Inherited bias. The underlying AI models are trained on internet-scale text, which carries the biases of that text. We mitigate by framing all outputs as suggestions for human review (you make the final call), and by not surfacing the AI's score as a "you should/shouldn't apply" decision. But we cannot guarantee outputs are bias-free.
- Limited domains. AI suggestions perform best on common job categories (software, marketing, sales, ops) where training data is rich. They may underserve very specialised or non-Western career paths. Manual editing and a human eye are recommended.
- Inaccuracy risk. The AI may invent details or misremember context from the JD. Always verify against your own truth before sending anything to a recruiter. Our Terms of Service Section 5 assigns this review responsibility to you explicitly.
If you spot a recurring problem with an AI feature, we want to hear about it: [email protected].
10. EU AI Act & GDPR posture
For users, regulators, and B2B buyers who want the formal answer:
- EU AI Act Article 50(1) (inform users they are interacting with AI): satisfied by the explicit "AI Tailoring" / "AI Cover Letter" / "AI Toolbox" naming throughout the product, plus this page, the privacy policy Section 6, and the ToS Section 5. Reasonably observant users cannot mistake the AI features for human work.
- EU AI Act Article 50(2) (machine-readable marking of AI-generated text): in progress. AI-generated content in your account is marked at the database and PDF-metadata level so any external auditor or downstream tool can detect it programmatically.
- EU AI Act Article 50(4) (deepfake disclosure): not applicable. LumiCV does not generate audio, image, video, or impersonation content.
- GDPR Article 22 (no solely-automated decisions with significant effect): not engaged for the reasons in Section 5 above.
- GDPR Article 35 (DPIA for high-risk processing): we maintain a Data Protection Impact Assessment for our AI processing. It is not published publicly (it contains internal risk analysis), but is available to data protection authorities and qualifying B2B buyers on request.
- GDPR Article 30 (Records of Processing Activities): we maintain a ROPA on the same access basis.
- EU AI Act conformity assessment (Annex III high-risk AI): not currently applicable to LumiCV's B2C product because we do not deploy AI for hiring or eligibility decisions. The recruiter-facing product (LumiCV Hire, in development) is being designed to meet Annex III obligations from day one — see the recruiter portal's separate compliance documentation.
11. Contact us
Questions about how LumiCV uses AI:
- Plain questions or feedback — [email protected]
- Privacy / GDPR questions, human-review requests — [email protected]
- Security concerns — [email protected]
Our controller establishment is in the Netherlands. If you are in the EEA and believe we have not adequately addressed your concerns, you can lodge a complaint with your local data protection authority. The Dutch Autoriteit Persoonsgegevens (AP) is the lead supervisory authority for LumiCV.