Legal · Privacy

Privacy Policy

Last updated

We collect what it takes to run your job search, send only what a feature needs to our AI providers, and never sell your data.

We never sell your data

No data brokers, no advertisers, no recruiters. Your job search stays private.

Not used for training

Your resumes and history are never used to train AI models — ours or anyone else's.

Minimal Google scopes

Only your name, picture, and email. No Gmail, Drive, Calendar, or Contacts access.

Delete anytime

Ask us and your account and its content are permanently removed. No questions.

Contents · 11 sections
  1. 01What we collect
  2. 02How we use it
  3. 03AI processing and subprocessors
  4. 04Signing in with Google
  5. 05Where your data lives and how long we keep it
  6. 06Cookies
  7. 07Your rights, and deleting your account
  8. 08Security
  9. 09Children
  10. 10Changes to this policy
  11. 11Contact
01

What we collect

Resume Builder collects what it needs to run your job search and nothing beyond it. There are no advertising trackers on this site and no third-party analytics scripts.

Account
Your name, email address, and profile picture, as supplied by Google when you sign in. We also store which plan you are on and internal role assignments that control what you can see.
Your content
Everything you create or upload: resumes and their versions, work history, skills, education, projects, cover letters, saved job descriptions, notes, and any resume file you import for parsing.
Job search data
Job listings you save, application status and activity, match scores and keyword coverage, company research results, interview preparation notes, and practice-interview questions and answers.
Audio
If you use the practice interview or dictation features, your microphone audio is sent for transcription and the resulting text is stored with that session. Audio itself is not retained by us after transcription.
Usage records
For each AI request we log the feature used, the model and provider, token counts, estimated cost, latency, and whether it succeeded. We also log document downloads. This is how we manage cost and fair-use limits and diagnose failures.
Billing
If you purchase a plan, we store your Stripe customer and subscription identifiers and your plan status. Card numbers go directly to Stripe and never reach our servers.
Technical
Standard server logs from our hosting provider — IP address, user agent, request path, timestamp — kept briefly for security and debugging.
02

How we use it

We use the information above to:

  • Run the features you ask for — generating, rewriting, analyzing, and scoring your documents.
  • Store your work so it is there the next time you sign in, and export it to DOCX on request.
  • Keep your account secure, enforce access rules, and prevent abuse.
  • Meter AI usage against plan limits and bill you correctly if you are on a paid plan.
  • Diagnose errors, monitor reliability, and understand which features are worth improving.
  • Send you service messages — for example, a notice about a change to this policy.

What we never do

We never sell your personal information, never share your resumes or job search with employers, recruiters, data brokers, or advertisers, and never use your content to train AI models.
03

AI processing and subprocessors

When you use a feature that writes, rewrites, analyzes, or scores something, the relevant part of your content — a resume section, a job description, a cover letter paragraph — is sent over an encrypted connection to an AI provider, processed, and returned to you. Only what the feature needs is sent, not your whole account.

OpenAI
Text generation and analysis; audio transcription for dictation and practice interviews; one of the available text-to-speech voices.
Anthropic
Text generation and analysis. Which provider handles a given request depends on how that feature is configured and on provider availability.
AWS Polly
Speech synthesis for practice interview questions.
Cartesia
An alternative speech synthesis voice, when selected.
Neon
Managed PostgreSQL hosting — this is where your account and content are stored at rest.
Vercel
Application hosting, serverless compute, and edge delivery.
Google
Sign-in. The company research feature also queries Google News for public articles about an employer; your personal content is not part of that query.
Stripe
Payment processing and subscription management.
LinkedIn
Only if you connect an account: publishing posts you have written and reading back their engagement metrics.

We use these providers under business or API terms that prohibit training on the content we send. They may retain input briefly for abuse monitoring under their own policies. Some of them process data in the United States, so using Resume Builder may involve transferring your information across borders.

We also disclose information if the law requires it, or to protect the rights, safety, or property of our users or of Resume Builder. If the service is ever acquired, your information could transfer as part of that transaction — you would be notified first.

04

Signing in with Google

Google is the only way to sign in. When you do, we request the minimum standard OAuth scopes: your basic profile (name and picture) and your email address. Nothing else.

What we cannot see

Resume Builder has no access to your Gmail, Google Drive, Calendar, or Contacts. We never receive your Google password, and we do not request permission to act on your Google account.

Your email address identifies your account and is how we contact you. You can revoke Resume Builder’s access at any time from your Google account’s security settings, which prevents future sign-ins but does not by itself delete data already stored here — for that, see your rights.

If you separately choose to connect LinkedIn, you grant that connection its own scopes during LinkedIn’s consent flow, and you can disconnect it at any time.

05

Where your data lives and how long we keep it

Your account and content live in a managed PostgreSQL database hosted by Neon, and the application runs on Vercel. Traffic is encrypted in transit with TLS, and the database is encrypted at rest by our provider.

  • Your content is kept as long as your account is active, so your resumes and history are there when you come back.
  • Sign-in sessions are stored in the database and expire on their own; signing out ends them immediately.
  • Usage and download records are retained for cost accounting and abuse prevention. When an account is deleted, these are detached from it so they no longer identify you.
  • Server logs are retained for a short period by our hosting provider and then rotated out.
  • Billing records are kept as long as tax and accounting law requires.
06

Cookies

Resume Builder sets only the cookies it needs to work. There are no advertising cookies, no cross-site tracking pixels, and no third-party analytics.

Session
Identifies your signed-in session so you are not asked to sign in on every page. Set HTTP-only and secure.
CSRF
A short-lived token that protects the sign-in flow against cross-site request forgery.
Callback
Remembers where to send you after Google returns you to the app.

Blocking these cookies in your browser will prevent you from staying signed in. Some preferences — such as an open panel or a draft in progress — are kept in your browser’s local storage on your device and are never sent to us as a cookie.

07

Your rights, and deleting your account

Your content is yours, and you can take it or remove it at any time. Depending on where you live, you may also have formal rights to access, correct, export, restrict, or delete your personal information, and to object to certain processing. We honor these requests for everyone, not only where the law requires it.

  • Access and correction — everything we hold about your job search is visible and editable in the app.
  • Export — resumes and cover letters download as DOCX at any time.
  • Deletion — you can delete individual resumes, job listings, and profiles yourself, or email us to delete the whole account.

Deleting your account

Email TODO@example.com from your account address and we will delete your account and its content. Deletion is permanent and cannot be undone, so export anything you want to keep first. We will not ask you to justify the request, and we will not charge for it.

We do not discriminate against you for exercising any of these rights. If you believe we have mishandled your information, you may also complain to your local data protection authority.

08

Security

We authenticate every request to the application, scope database queries to the signed-in account so one user cannot read another’s content, keep provider API keys on the server and never in the browser, and hold secrets in environment configuration rather than in code.

No service can promise perfect security, and we do not. If we ever become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.

09

Children

Resume Builder is built for people in the workforce and is not directed at children. You must be at least 16 years old — or the minimum age of digital consent where you live, if that is higher — to create an account.

We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.

10

Changes to this policy

As the product changes — a new feature, a new provider — this policy will change with it. We will update the “last updated” date at the top of the page, and for material changes we will notify you in the app or by email before they take effect.

Changes are never applied retroactively to reduce the protections that applied to information we already hold about you.

11

Contact

Questions about this policy, a request about your data, or a concern about how something works can go to TODO@example.com. We aim to respond within 30 days.

The Terms of Service cover the rest of the relationship between you and Resume Builder.