Privacy Policy
Your resume and career history are personal, and you should know exactly what happens to them. This policy explains what ResumePay collects, why, who else handles it, how long we keep it, and the choices and rights you have. It applies to the ResumePay website and app (the “Service”).
1. Who we are
ResumePay (“we”) runs the Service and is responsible for your personal information (the “controller” under laws like the GDPR). Our address is Designed in California, US. For anything about privacy, email [privacy email].
2. What we collect
Information you give us
- Account details: your name, email address, and password. We store only a salted one-way hash of your password (bcrypt), never the password itself. If you sign in with Google, we receive your name, email address, and profile picture link from Google.
- Contact and location, if you add them: a phone number, which new resumes put in their contact line, and a US ZIP code with a distance, which the Internships page uses to show how far each internship is and only the ones near you. Both stay in your account, and you can change or remove them in Settings.
- Preferences: your interface language, time zone, and privacy settings.
- Career information: resumes you upload (PDF, Word, or text files) and the text we read from them; the employment history, projects, achievements, skills, education, and certifications in your profile; your answers when strengthening an achievement; which items you verified, edited, or rejected, with their history; and the links between each item and the words it came from.
- What you create with the Service: resumes and their versions and exports, cover letters, interview stories and questions, job postings you add or analyze and their analyses, and the applications you track, with your notes and dates.
Information created as you use the Service
- Points records: the points you were given, bought, and spent, and on what; the invite codes you made, and whether each was used (not who used it); the code you used, if any; and the customer ID Stripe gives you if you buy points. Card details are entered on Stripe’s pages and never reach our servers.
- Product analytics, only if you turn them on: the name of an action (such as “resume exported”) with a few fixed details (such as a file type), never the content of your profile or documents. This is off unless you switch it on in Settings → Privacy.
- Security records: a log of sensitive actions on your account, such as sign-ins, privacy setting changes, data downloads, billing changes, and deletion requests. When sign-in attempts are rate-limited, the IP address involved is recorded. To limit repeated attempts, we keep short-lived counters keyed by a one-way hash of your IP address or account; they expire within an hour.
- AI usage records: for each AI task, its type, the provider and model used, how many tokens it used, what it cost, how long it took, and whether it succeeded. Not the content sent or received.
- Technical logs: our hosting provider records requests (such as IP address, browser type, and the page requested), and we record technical details of errors, to keep the Service running and secure.
- Cookies: only the ones the Service needs to work. See the Cookie Policy.
We don’t buy information about you, we don’t track you across other sites, and we don’t use advertising cookies.
3. How we use it, and why
| What we do | Information used | Legal basis (EEA/UK) |
|---|---|---|
| Run your account and the features you use: build your profile, write and export resumes, analyze jobs, track applications | Account, preferences, career information, what you create | Performing our contract with you |
| Send parts of your information to an AI provider to do what you ask (section 4) | The career information and postings the task needs | Performing our contract with you |
| Take payments and apply your plan’s limits | Account details, billing records | Performing our contract; legal obligations for financial records |
| Keep the Service and accounts secure, prevent abuse, and investigate problems | Security records, technical logs, AI usage records | Our legitimate interest in a safe, working service |
| Understand how the Service is used, to improve it | Product analytics | Your consent, which you can withdraw in Settings |
| Comply with the law and respond to lawful requests | What the request requires | Legal obligation |
Settings → Privacy also has two switches for improvement uses: “anonymized improvement data” and “AI model improvement”. Both are off by default. Today ResumePay doesn’t use your information for either purpose, whatever these switches say; they record your choice so it governs any such use in future, which we would describe here before starting.
We don’t sell your personal information, and we don’t share it for cross-context behavioral advertising. We don’t send marketing email. We email you only about your account: a link to verify your address when you sign up, and a link to reset your password when you ask for one.
4. AI processing
Reading your resume, analyzing a job, tailoring or localizing a resume, strengthening an achievement, and preparing interview material all use AI models run by AI providers. For each task, we send the provider the part of your information that task needs, such as your resume’s text, the relevant items from your profile, or a job posting, and receive the result. The AI Disclosure explains how this works and what guards the output, and the Subprocessors page names the providers this deployment uses.
We don’t give any AI provider permission to use your information to train its models. Anthropic and OpenAI, under the terms of their business APIs, don’t use data sent through them for training.
AI analyses in the Service, such as how strongly your evidence matches a job requirement, are there to help you. ResumePay doesn’t make decisions about you that have legal or similarly significant effects; employers make their own hiring decisions.
5. Internship listings
Internship postings come from employers’ public careers sites and job sites, and aren’t information about you. Matching them to your profile happens on our servers and isn’t shared with anyone. When you analyze a posting, it’s copied into your account as a target job. We don’t send your profile to employers or job sites; you apply on their sites yourself, under their privacy policies.
6. Who we share it with
- Service providers that process information for us under contract, only to run the Service: hosting, database, file storage, email delivery, AI providers, and payment processing. They’re listed on the Subprocessors page.
- Stripe receives your name and email address to create your customer record when you first pay, and processes your payments under its own privacy policy.
- When the law requires it, or to protect the rights, safety, or property of our users, the public, or ResumePay.
- In a business transfer, such as a merger or sale, under this policy’s protections. We’ll tell you before your information becomes subject to a different policy.
You choose who sees your resumes: the Service never sends them to anyone on your behalf.
7. Where it’s processed
The Service and its database run in [data location]. Some service providers process information in other countries, including the United States, and, if a deployment uses DeepSeek as an AI provider, China. The Subprocessors page says where each provider processes information. Safeguards for international transfers: [to be confirmed with counsel, e.g. the EU Standard Contractual Clauses].
8. How long we keep it
- Your account and everything in it: until you delete it. You can delete single items, resumes, jobs, and applications at any time, or your whole account, which happens immediately (see Data Deletion).
- Backups: deleted information can remain in backups of the database and of stored files for up to [number of] days, until they expire. Backups are used only to recover from failures.
- Records that outlive an account lose their link to you when you delete it: AI usage records (for cost accounting), security log entries, and any product analytics events. None contains the content of your profile or documents.
- Payment records are kept by Stripe as the law requires of it.
- Rate-limit counters expire within an hour. Technical logs are kept by our hosting provider for a limited period.
9. Your choices and rights
You can do most of this yourself, in the app:
- See and download your information: Settings → Your data downloads everything we hold about you as a file you can keep or move elsewhere.
- Correct it: edit your profile, items, and settings at any time.
- Delete it: delete items, resumes, jobs, or applications; all your career data at once; or your whole account, in Settings.
- Withdraw consent: turn product analytics and the improvement switches off in Settings → Privacy.
Depending on where you live, you may also have the right to ask for access to, correction or deletion of, or a copy of your personal information; to object to or restrict how we use it; and to withdraw consent at any time, without affecting what we did before. In the European Economic Area and the UK, you can complain to your data protection authority. California and other US state residents have rights to know, delete, and correct their information, and to opt out of its sale or sharing (we don’t sell or share it), and we won’t treat you differently for using them.
To make a request, email [privacy email]. We may need to confirm it’s you before acting, and we respond within the time the law where you live requires.
10. Security
We protect your information with measures including encryption in transit (HTTPS), password hashing, access checks on every request so each account sees only its own data, a private file store reached only through short-lived download links, rate limits on sign-in and other sensitive actions, and logs of sensitive actions. No system is perfectly secure, though. If a breach affects your personal information, we’ll notify you and the authorities as the law requires.
A small number of ResumePay administrators can see account details (your name, email address, sign-in methods, and when you were last active), your points and how you used them, the cost of the AI work done for you, and the security log of your account. They use this to support you, prevent abuse, and keep costs in check, and they can adjust points, suspend an account that breaks the rules, or delete it. The admin area shows only how many profile items, resumes, and documents you have, not their contents. Every admin action is recorded with the admin’s name and the reason.
11. Children
The Service isn’t meant for anyone under 16, and we don’t knowingly collect information from them. If you believe a child has given us information, contact us and we’ll delete it.
12. Changes to this policy
We’ll update this policy when our practices change. The date at the top says when it last changed. For material changes, we’ll give notice in the app, before they take effect where we can, and ask you to review them; we record which version you’ve seen.
13. Contact
ResumePay, Designed in California, US. Privacy questions and requests: [privacy email]. See also the Contact page.