Short answer
Safe for the work. Not automatically safe for the candidate. A CV is personal data from the first line to the last. Uploading it to an AI account means a third party now holds a copy; on consumer plans it may be used to improve models unless you have switched that off; and files you upload can outlive the chat you uploaded them in.
If you strip the identifiers first, keep the rest, and use a plan or setting where your data isn't used for training, you keep almost all of the usefulness and remove most of the exposure. The rest of this page is how.
What actually happens when you upload a CV
The honest answer depends on the plan you're on and the settings you've left at their defaults. As of August 2026, per the providers' own published policies:
- ChatGPT consumer plans (Free, Plus, Pro and similar). Chats — including what you attach — can be used to improve OpenAI's models unless you turn off “Improve the model for everyone” under Settings → Data Controls. Chats are kept until you delete them. A Temporary Chat is not used for training, is not saved to your history, creates no memories and is deleted from OpenAI's systems within 30 days. Files you upload are saved to your Library where that feature is available, and deleting the chat does not delete the file — you remove it from Library separately. (Source: OpenAI Help Center — Data Controls FAQ and Chat and File Retention Policies.)
- ChatGPT Business, Enterprise, Edu and the API. Not used for training by default; Enterprise and Edu workspaces control their own retention. (Source: Enterprise privacy at OpenAI.)
- Claude (Anthropic). On consumer plans (Free, Pro, Max) your chats are used to improve Claude if you allow it in Privacy Settings, if you give a chat a thumbs-up or thumbs-down, or if a chat is flagged for safety review; Incognito chats are never used for training. Claude for Work and the API are governed by commercial terms. (Source: Anthropic Privacy Center — Is my data used for model training?)
- Whatever the plan: the CV now exists on someone else's infrastructure, under their retention rules and their sub-processors. That is a disclosure to a third party, and it is the part no setting undoes.
Policies change — check the linked pages before relying on a detail here, and see our companion guide on what ChatGPT does with uploaded files.
Three things that make a CV different from an ordinary document
- It is 100% personal data. There is no neutral paragraph: every line is about one identifiable human. Even with the name removed, a specific sequence of employers and dates can identify someone in seconds.
- It often carries sensitive data by accident. A photo, date of birth, nationality, marital status, military service, union roles, or a health-related gap explanation are all common on CVs — and all land in categories the law treats as special (GDPR Article 9; “data of special sensitivity” under Israel's amended Protection of Privacy Law).
- The candidate sent it to apply for a job — not to be pasted into a third party's model. If your candidate privacy notice doesn't mention AI tools, the candidate has no way of knowing.
Under the GDPR that combination means the usual requirements bite: a lawful basis (Art. 6), transparency to the candidate (Art. 13), data minimisation (Art. 5), and a processor contract where the AI vendor acts as your processor (Art. 28). In Israel, Amendment 13 to the Protection of Privacy Law (in force since 14 August 2025) defines personal data as “any data relating to an identified or identifiable person” and gives the Privacy Protection Authority administrative-fine powers. We describe the rules; for what they require of you specifically, ask whoever handles data protection for your business and read the regulator's own guidance — ICO: AI and data protection, EDPB, Israel's Privacy Protection Authority on Amendment 13.
The manual way to do it properly
These are the complete steps. They work with any AI tool and cost nothing but time.
-
Pick the right account and setting
ChatGPT: Settings → Data Controls → turn off Improve the model for everyone, or open a Temporary Chat for each CV; better still, use a Business or Enterprise workspace. Claude: Settings → Privacy → make sure model improvement is off, or use an Incognito chat. Gemini: review your Gemini Apps Activity settings.
-
Make a working copy — never edit the original
If the CV arrived as a PDF you can select text in, open it in Word (File → Open; Word converts it) or ask for a
.docx. If it is a scan or a photo of a page, you will have to transcribe the parts you need — there is no shortcut for text inside a picture. -
Replace the header block with placeholders
Name → [PERSON_1], phone → [PHONE_1], email → [EMAIL_1], address → [ADDRESS_1], LinkedIn and portfolio links → [URL_1]. Delete the photo, the date of birth and any ID number outright — you don't need them to screen. Use Find & Replace → Replace All so the same value gets the same placeholder everywhere.
-
Check the places people forget
The header and footer (names repeat there), the file name (
Dana_Cohen_CV.docxsays it all), and the document properties: File → Info → Inspect Document → Document Properties and Personal Information → Remove All. Accept or discard tracked changes and delete comments. -
Decide what else to remove for this task
For a first-screen summary, employer names usually stay — they are how you judge experience. For a blind or fairness-oriented screen, also strip university names, graduation years and anything that signals age, gender, ethnicity or religion. See AI screening, bias and blind CVs.
-
Save as a new file and upload that
candidate-a.docx, notDana_Cohen_CV_redacted.docx. Upload the copy; leave the original where your candidate data already lives. -
Keep the key yourself
A one-line note mapping [PERSON_1] to the real candidate, stored in your ATS or drive — not in the AI tool, not in the chat.
-
Afterwards, clean up
Delete the chat and, in ChatGPT, the file from your Library. Don't let a shared workspace quietly accumulate a year of CVs.
What the manual method costs
- Per CV
- 5–8 mina careful pass incl. header, footer, properties
- At 20 CVs a day
- ≈ 2 hoursevery day, before any screening happens
- What leaks
- The bits you forgota second phone number, the footer, the file name
Our estimates for a recruiter working carefully in Word; your numbers will differ. The pattern doesn't: the cost is per CV, every time, and the misses are the unglamorous ones.
What this doesn't solve
- Re-identification from the rest of the CV. A unique career path, a small employer, a rare combination of skills can still point at one person. Pseudonymised is not anonymous — see pseudonymisation vs anonymisation.
- Your legal footing. Placeholders reduce what you disclose. They do not create a lawful basis, write your candidate privacy notice, or sign a processor agreement for you. No tool makes you compliant with anything.
-
Scans and images. Sunda reads Word, text and text-layer PDFs — the
kind you can select text in. A scanned or photographed CV has no text to read, so
Sunda refuses it rather than hand you a blank-looking “redacted” file; the manual
steps above are the method for those. A PDF whose text is Hebrew, Arabic or another
non-Latin script is refused too — protect it as a
.docxinstead. And a redacted PDF is rebuilt from the text it contained, so it keeps the words and the page breaks but not the layout, fonts or columns: right for feeding an AI, wrong for forwarding to a client as-is. - Perfect detection. Structured data — emails, phone numbers in common formats, card numbers and checksum-valid Israeli ID numbers — is caught reliably by rules. Passport, NI and licence numbers are not detected; delete those by hand. Names and addresses depend on the optional on-device model and will miss some. Read the output before you share it.
Questions recruiters ask
Does ChatGPT train on the CVs I upload?
On consumer plans, chats — including what you attach — can be used to improve OpenAI's models unless you turn off “Improve the model for everyone” in Settings → Data Controls, or use a Temporary Chat. ChatGPT Business, Enterprise, Edu and the API are not used for training by default. In every case the file is still stored on OpenAI's systems under its retention rules, and files saved to your Library are not deleted when you delete the chat.
Is a Temporary Chat enough to protect a candidate?
It is a good default: not used for training, not saved to history, no memories, deleted from OpenAI's systems within 30 days. But the CV still travels to and sits on a third party's servers for up to 30 days, and you have still disclosed it. Strip the identifiers first regardless.
Is it legal under GDPR to put a candidate's CV into an AI tool?
It can be. A CV is personal data, so the GDPR's usual requirements apply: a lawful basis, transparency to the candidate, data minimisation, security, and a processor contract where the vendor acts as your processor. Regulators such as the UK ICO and the EDPB publish guidance on AI and personal data, and systematic AI-assisted screening may call for a data protection impact assessment (Art. 35). This guide describes the rules; it is not legal advice.
What about Claude, Gemini or Copilot?
The same logic applies: check whether your plan uses your data to improve models, check how long files are kept, prefer a business tier with data controls, and strip identifiers before uploading. Claude's consumer plans use chats for training if you allow it in Privacy Settings, if you give thumbs-up or thumbs-down feedback, or if a chat is flagged for safety review; Incognito chats are never used, and Claude for Work and the API are governed by commercial terms.
If I remove the name, is the CV anonymous?
No. Replacing identifiers with placeholders is pseudonymisation: the data can still be linked back to the person, so under the GDPR (Art. 4(5), Recital 26) and under Israel's Protection of Privacy Law it remains personal data. That is fine — pseudonymisation is exactly the safeguard regulators recommend — but it is not anonymisation, and a distinctive career history can still identify someone.