This Cookie Policy explains what cookies and similar tracking technologies are used by LumiCV ("we", "our", or "us") on lumicv.com and app.lumicv.com, and how you can control them.
1. What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They help websites remember your preferences, keep you logged in, and collect analytics data. Similar technologies include local storage, session storage, and pixel tags.
2. Types of Cookies We Use
Essential Cookies
These cookies are necessary for the Service to function. They cannot be disabled without breaking core functionality such as authentication and session management.
| Cookie | Purpose | Duration |
|---|---|---|
lumicv_session | Keeps you logged in to your account (Laravel Sanctum SPA session) | Session / 30 days |
XSRF-TOKEN | Prevents cross-site request forgery attacks | Session |
Functional Cookies
These cookies remember your preferences and settings to provide a better experience.
| Cookie | Purpose | Duration |
|---|---|---|
lumicv_onboarding_done | Remembers whether you have completed the onboarding wizard | 1 year |
lumicv_theme | Stores your UI theme preference (if applicable) | 1 year |
lumicv_cookie_consent | Stores your cookie consent choice (necessary only / accept all) | 1 year |
Analytics Cookies
These cookies help us understand how visitors use the Service so we can improve it. Data is aggregated and anonymized where possible.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
ph_* | PostHog | Product analytics hosted in the EU (eu.i.posthog.com). Tracks anonymized usage across lumicv.com and app.lumicv.com. Only active when you accept analytics cookies. Session recordings are disabled on blog pages and mask all input fields elsewhere. | Up to 1 year |
Payment Cookies
When you complete a payment, Stripe may set cookies to detect fraud and ensure a secure transaction.
| Cookie | Provider | Purpose |
|---|---|---|
__stripe_mid, __stripe_sid | Stripe | Fraud prevention and secure payment processing |
Error Monitoring
We use Sentry for error tracking and performance monitoring. Sentry helps us detect and fix technical issues. Sentry does not set cookies directly - error data is sent server-side through our own API tunnel. Personal data is not included in error reports by default.
3. How to Manage Cookies
Withdraw or change your consent: to withdraw consent to analytics or change your cookie choice at any time, click here or use the "Cookie preferences" link in the site footer. Withdrawing consent is as easy as giving it, and withdrawal does not affect the lawfulness of processing based on consent given before its withdrawal.
You can also control and delete cookies through your browser settings. Here are links to cookie management guides for common browsers:
Please note that disabling essential cookies will prevent you from logging in and using the Service.
4. Third-Party Cookies & Services
Some cookies and tracking technologies on our Service are set by third-party services. These third parties have their own privacy policies governing their data use:
- Stripe Privacy Policy - payment processing and fraud prevention
- Google Privacy Policy - Google OAuth
- PostHog Privacy Policy - product analytics (EU-hosted)
- Sentry Privacy Policy - error monitoring
- Resend Privacy Policy - transactional email delivery
Browser Extension & Job Board Platforms
Our optional browser extension operates on the following third-party job boards and applicant tracking systems to extract job descriptions and autofill application forms:
The extension also operates on Greenhouse, Lever, Workday, and SmartRecruiters application forms for autofill functionality.
What the Extension Does & Does Not Do
- Extracts job title, company name, location, and description text from job listing pages you visit on supported platforms.
- On LinkedIn, may read your public profile data (name, headline, experience, education, skills) if you use the LinkedIn Profile Optimizer feature.
- Autofills application forms using your LumiCV profile data (name, email, phone, location).
- Stores an authentication token and cached preferences in your browser's local storage.
- Does not set cookies on any third-party website.
- Does not track your browsing history or monitor pages outside of supported job boards.
- Does not collect or store your job board passwords or login credentials.
- Does not access private messages, connection lists, or non-public data on any platform.
Job description data extracted by the extension is sent to LumiCV for AI-powered resume tailoring and saved to your job tracker. You can delete this data at any time from your account, or by deleting your account entirely.
5. Updates to This Policy
We may update this Cookie Policy as we add or change the cookies we use. We will post updates on this page with a revised "Last updated" date.
6. Contact Us
If you have questions about our use of cookies, please contact us at [email protected].