LEGAL
Privacy Policy
Last updated: on deployment — contact the operator for the current date
1. What we collect
If you create an account, we store your email address, display name, and a password hash handled by our authentication provider (InsForge). If you sign in with Google or GitHub, we store the identifier and email returned by that provider.
The resume content you write or upload — which typically includes your name, contact details, work history, education, and skills — is stored in a hosted Postgres database as the documents you save. Your documents are access-controlled so that only your account can read or modify them.
2. Third-party AI processing
Some features (resume import extraction, achievement rewrites) send excerpts of the text you provide to a third-party AI language-model API. This processing happens only when you trigger the feature, and only the relevant excerpt is sent. If you prefer not to send text to the AI provider, every such feature has a deterministic offline fallback — simply avoid triggering the AI-assisted action.
3. Guest mode
Guest sessions are device-local: guest resume data is stored only in your browser's local storage and is never uploaded. Clearing your browser data erases it permanently.
4. Cookies
We set only the cookies required for authentication (session and CSRF protection). We do not use advertising or cross-site tracking cookies.
5. Data retention & deletion
Your saved resumes persist until you delete them or delete your account. Deleting a resume removes it and its version history.
6. Your rights
You can export your data at any time (PDF/DOCX download). For access, correction, or erasure requests, contact the site operator through the account email you registered with.