Do private AI assistants keep your CV data safe?
Quick answer: On-device assistants like Underdog do genuinely reduce risk: if inference runs locally and nothing sits on a vendor's server, your CV never leaves your laptop. But "private" is a claim worth testing — many assistants quietly fall back to the cloud, and a policy pledge isn't the same as architecture. Strip your street address, date of birth and any national ID number before any AI tool reads your CV.
Is your CV good enough?
Upload your CV and get an instant AI score out of 100, an ATS-compatibility rating and a breakdown across five categories — free.
What did Underdog and Hark actually announce?
Two privacy-first AI assistants launched on the same day, 6 October 2026, and they take opposite routes to the same promise. Underdog, from Sigil Wen's lab Conway Research, runs entirely on hardware you already own — Macs and Windows PCs today, with Linux, iPhone and Android versions promised — and keeps your context encrypted on the device, with no Underdog server or database holding personal information. It's in invite-only beta, backed by a16z, Khosla Ventures, Hummingbird and Anthology. Hark Pro, from Brett Adcock's year-old startup, went wide the same day across web, iOS and Android, free to use, with the paid tier free for the first 100,000 sign-ups.
The technical approaches are worlds apart. Underdog is built on a home-grown inference engine called Husky, designed to run capable models fast on consumer silicon; Wen's pitch is that frontier-grade intelligence lands on your own devices roughly six months after it appears in the cloud. Hark Pro is built on a model trained specifically for computer use — it operates your browser and apps on your behalf. You connect your email, calendar, hard drive and even payment cards, and it acts. Hark's privacy story is a four-line pledge: your data is yours, it's never sold, it's never shared with advertisers, and you can delete it. Credentials and cards live in an encrypted vault.
Both launches matter to job seekers for one reason: the CV is the single most sensitive document most people hand an AI tool. It carries your full name, address, phone number, email, every employer you've worked for, your dates, often your date of birth, and sometimes your salary history — all in one tidy, machine-readable file. When an assistant claims nothing leaves your machine, that changes the calculation about what you're willing to paste in. So it's worth separating the two kinds of promise on the table. One is an architectural property you can verify. The other is a commitment you have to trust.
Does an on-device AI assistant really keep your CV private?
Yes — if inference truly runs locally and the vendor stores nothing, an on-device assistant is the strongest privacy boundary available to a job seeker right now. Your CV is read by a model sitting on your own disk, no copy travels to a data centre, and there's no vendor-side retention period to worry about and no chance of your employment history drifting into a training set. That's a real, structural difference from pasting the same file into a consumer chatbot. But the word "local" does a lot of quiet work in marketing copy, and almost nothing shipping in 2026 is purely local end to end.
Most mainstream assistants use a hybrid design: easy requests are handled on the device, harder ones are routed to a bigger cloud model. That fallback is usually triggered by things you can't see — the local model isn't installed, your hardware isn't supported, or the task needs more capability than a small model has. A long CV plus a detailed job ad plus a rewrite request is exactly the kind of task that trips the fallback. There's a crude but effective test: switch off Wi-Fi and mobile data, then try the feature. If it still works, it ran on your device. If it stalls, something was leaving.
Local execution also isn't the same as private. Even when a model never phones home, the surrounding app can still produce crash reports, analytics, cached text, chat logs and cloud backups that carry fragments of your CV off the machine. On-device processing shrinks the transit-and-retention risk and shifts it onto the endpoint instead: a stolen laptop, malware or a shared family computer now holds everything. My honest view is that on-device assistants are a genuine upgrade, not an exemption. You still redact. You still lock the device.
- +Your CV is processed on your own hardware, so no copy reaches a vendor's servers
- +No vendor retention window and no risk of your details landing in a training set
- +Works without a connection, which also proves the processing is genuinely local
- +Nothing to chase with a deletion request later
- −Hybrid designs can fall back to the cloud on long or complex tasks without telling you
- −Crash logs, analytics, caches and cloud backups can still carry CV text off the device
- −Device theft, malware or a shared computer becomes the whole attack surface
- −Smaller local models are weaker at nuanced rewriting than frontier cloud models
What should you strip from your CV before any AI assistant reads it?
Cut three things before you upload anything anywhere: your street address, your date of birth, and any national ID number. That combination — full address, date of birth, phone number — is the classic set fraudsters assemble, and none of it helps you get screened in. Replace the address with your city and country, which is all a recruiter needs to judge location and right to work. Drop the date of birth entirely; it invites age bias and adds nothing. And a national ID number has no business on a CV at any stage: not a US Social Security number, not an Indian Aadhaar number, not an Israeli תעודת זהות. Legitimate employers ask for those after an offer, through a payroll system.
Beyond the hard identifiers, trim the details that leak more than they earn. Leave off marital status, number of children, religion, nationality and a photo — in the US, UK, India and Israel, a photo on a CV is a liability rather than a differentiator, and Israeli hiring convention has long treated photo-free, one-to-two-page קורות חיים as standard. Skip your salary history; it's negotiating leverage you're giving away for free. Replace referees' phone numbers with "references available on request" — those are someone else's personal details, and you shouldn't be handing them to a chatbot on their behalf. Use a dedicated job-search email address rather than your work one.
Here's the trick that makes the redacted version actually usable: you don't need your real identifiers in the file to get good AI feedback. A model critiquing structure, keywords, impact statements and parsing doesn't care whether the header says your name or "Candidate." Keep one clean master file with the full contact block for human submission, and one redacted working copy for AI tools. It takes two minutes and it permanently removes the question of what a vendor retained. If you want the safest possible version of this habit, do the redaction before you touch any assistant, not after you've already pasted the original in once.
Worth noting on the Israeli side: if you're applying through AllJobs, Drushim or straight into Comeet, the same rule holds. Your ID number never belongs in the CV file, even though you'll hand it over later for onboarding.
| Detail on your CV | What to do before an AI tool reads it | Why |
|---|---|---|
| Street address | Cut to city and country | Address plus date of birth plus phone is the standard identity-fraud bundle |
| Date of birth | Remove | Fuels age bias and fraud; no screener needs it |
| National ID number (SSN, Aadhaar, תעודת זהות) | Never include at all | Requested only after an offer, through payroll — never at application stage |
| Photo | Remove for US, UK, India and Israel | Not expected in these markets and invites bias |
| Salary history | Remove | Hands over negotiating leverage before anyone has made an offer |
| Referee names and numbers | Replace with "references available on request" | You'd be sharing someone else's personal data without asking |
| Work email or work phone | Swap for a job-search-only address and number | Your current employer may monitor both |
Is your CV good enough?
Upload your CV and get an instant AI score out of 100, an ATS-compatibility rating and a breakdown across five categories — free.
How do you check a tool's data handling before you upload?
Ask four concrete questions, and treat anything vaguer than a clear answer as a no. First: is my upload used to train the model, and is that on by default? On consumer plans of the big chatbots, training on your content is typically opt-out, not opt-in — the setting usually sits under data controls and reads something like "improve the model for everyone." Business, enterprise, education and API tiers generally don't train on your content by default. Second: how long is the file retained after I close the chat, and can I delete it myself? Third: can human reviewers see it? Fourth: does any of this reach a third-party model?
That last question is where privacy claims get interesting. Hark, for example, says the third-party models it uses operate under zero data retention — which is a meaningful commitment, but it's a contractual one, not a physical limit. Underdog's claim is a different species: there's no server holding your data because the architecture doesn't have one. When you're comparing tools, sort their promises into those two buckets. Policy promises can change with a terms-of-service update; architecture can't be revised by a lawyer. Neither bucket is worthless. But if you're uploading a document with your employment history in it, knowing which you're relying on tells you how much to redact first.
One more thing people forget: the recruiter's side of the pipeline has its own retention clock, and it's shorter than you'd guess. Under GDPR there's no fixed number, but UK guidance generally points to around six months for unsuccessful applicants, tied to the window for bringing a claim. Talent pools kept longer need your explicit, withdrawable consent. Erasure requests must be answered within a month. So you have real leverage on the employer side — and almost none with a chatbot you pasted your CV into eighteen months ago and forgot about. Act accordingly: the upload you never made is the one you never have to chase.
Which AI workflow is safest for tailoring your CV to a job?
The safest workflow is narrow and deliberate: redact the file, use a purpose-built CV tool for the analysis and rewriting, and keep the general-purpose assistant for research and drafting prose. General assistants are extraordinary at tone and phrasing, and genuinely poor at the thing that actually decides your application — whether the file survives extraction. A chatbot reads the text it was handed. It can't see that your two-column layout collapsed into nonsense, that your dates landed out of order, or that your skills block got swallowed by a text box. That blind spot is why a privacy-first assistant alone won't get you interviews, however well it protects you.
So split the job. Paste the job ad into whichever assistant you trust for brainstorming and ask it to pull out the real requirements, the implied seniority and the vocabulary the team uses. Then run the actual CV through a tool built to see the document the way automated screening does. On HRLens, a free CV analysis gives you a score out of 100, five category scores covering experience, tech stack, impact and ownership, clarity and structure, and ATS compatibility, plus a visual layout analysis — the parts a text-only chatbot structurally cannot judge. Paste the job description in and the analysis lists the skills you're missing.
One habit worth adopting whichever tools you use: never apply from a file you haven't seen parsed. If you'd rather start clean than patch an old document, a chat-based CV builder produces an ATS-friendly file in six templates with PDF and Word export, and Hebrew CVs are written in Hebrew and exported right-to-left. And if you've been weighing which general assistant to trust with the writing, our head-to-head on ChatGPT versus Claude for CV work covers where each one helps and where both fall short. The privacy rule stays the same across all of it: redact first, then optimise.
Frequently asked questions
Is it safe to give AI your resume?
It's safe enough once you redact it. Remove your street address, date of birth and any national ID number, keep city and country, and use a job-search-only email. On consumer chatbot plans, check whether training on your uploads is switched on by default and turn it off. Then delete the chat when you're done. A redacted CV gives you nearly identical feedback with a fraction of the exposure.
Does an on-device AI assistant mean my CV never leaves my computer?
Only if the feature you're using truly runs locally. Many assistants are hybrid: simple requests stay on the device, harder ones route to a cloud model, and a long CV plus a job ad is often harder. Test it by turning off Wi-Fi and mobile data — if the feature still works, it ran locally. Also remember that crash logs, analytics and cloud backups can carry text off the device even when the model doesn't.
What's the difference between Underdog's and Hark's privacy claims?
They're different kinds of promise. Underdog runs on your own Mac or PC and says it keeps your context encrypted on-device with no server or database holding personal information — that's an architectural property. Hark Pro pledges your data is yours, never sold, never shared with advertisers and always deletable, and says third-party models it uses have zero data retention — those are contractual commitments. Policies can be updated; architecture can't be rewritten by a lawyer.
How long do employers keep my CV after I apply?
Less time than most people assume. GDPR sets no fixed period, but UK guidance generally points to about six months for unsuccessful applicants, matching the window for bringing a claim. Holding your details in a talent pool beyond that needs your explicit, withdrawable consent. You can request erasure and must get a response within one month. That leverage applies to employers and agencies — not to a chatbot you uploaded your CV into last year.
Is your CV good enough?
Upload your CV and get an instant AI score out of 100, an ATS-compatibility rating and a breakdown across five categories — free.