Legal · Privacy
Privacy Policy
We collect what it takes to run your job search, send only what a feature needs to our AI providers, and never sell your data.
We never sell your data
No data brokers, no advertisers, no recruiters. Your job search stays private.
Not used for training
Your resumes and history are never used to train AI models — ours or anyone else's.
Minimal Google scopes
Only your name, picture, and email. No Gmail, Drive, Calendar, or Contacts access.
Delete anytime
Ask us and your account and its content are permanently removed. No questions.
Contents · 11 sections
What we collect
Resume Builder collects what it needs to run your job search and nothing beyond it. There are no advertising trackers on this site and no third-party analytics scripts.
- Account
- Your name, email address, and profile picture, as supplied by Google when you sign in. We also store which plan you are on and internal role assignments that control what you can see.
- Your content
- Everything you create or upload: resumes and their versions, work history, skills, education, projects, cover letters, saved job descriptions, notes, and any resume file you import for parsing.
- Job search data
- Job listings you save, application status and activity, match scores and keyword coverage, company research results, interview preparation notes, and practice-interview questions and answers.
- Audio
- If you use the practice interview or dictation features, your microphone audio is sent for transcription and the resulting text is stored with that session. Audio itself is not retained by us after transcription.
- Usage records
- For each AI request we log the feature used, the model and provider, token counts, estimated cost, latency, and whether it succeeded. We also log document downloads. This is how we manage cost and fair-use limits and diagnose failures.
- Billing
- If you purchase a plan, we store your Stripe customer and subscription identifiers and your plan status. Card numbers go directly to Stripe and never reach our servers.
- Technical
- Standard server logs from our hosting provider — IP address, user agent, request path, timestamp — kept briefly for security and debugging.
How we use it
We use the information above to:
- Run the features you ask for — generating, rewriting, analyzing, and scoring your documents.
- Store your work so it is there the next time you sign in, and export it to DOCX on request.
- Keep your account secure, enforce access rules, and prevent abuse.
- Meter AI usage against plan limits and bill you correctly if you are on a paid plan.
- Diagnose errors, monitor reliability, and understand which features are worth improving.
- Send you service messages — for example, a notice about a change to this policy.
What we never do
AI processing and subprocessors
When you use a feature that writes, rewrites, analyzes, or scores something, the relevant part of your content — a resume section, a job description, a cover letter paragraph — is sent over an encrypted connection to an AI provider, processed, and returned to you. Only what the feature needs is sent, not your whole account.
- OpenAI
- Text generation and analysis; audio transcription for dictation and practice interviews; one of the available text-to-speech voices.
- Anthropic
- Text generation and analysis. Which provider handles a given request depends on how that feature is configured and on provider availability.
- AWS Polly
- Speech synthesis for practice interview questions.
- Cartesia
- An alternative speech synthesis voice, when selected.
- Neon
- Managed PostgreSQL hosting — this is where your account and content are stored at rest.
- Vercel
- Application hosting, serverless compute, and edge delivery.
- Sign-in. The company research feature also queries Google News for public articles about an employer; your personal content is not part of that query.
- Stripe
- Payment processing and subscription management.
- Only if you connect an account: publishing posts you have written and reading back their engagement metrics.
We use these providers under business or API terms that prohibit training on the content we send. They may retain input briefly for abuse monitoring under their own policies. Some of them process data in the United States, so using Resume Builder may involve transferring your information across borders.
We also disclose information if the law requires it, or to protect the rights, safety, or property of our users or of Resume Builder. If the service is ever acquired, your information could transfer as part of that transaction — you would be notified first.
Signing in with Google
Google is the only way to sign in. When you do, we request the minimum standard OAuth scopes: your basic profile (name and picture) and your email address. Nothing else.
What we cannot see
Your email address identifies your account and is how we contact you. You can revoke Resume Builder’s access at any time from your Google account’s security settings, which prevents future sign-ins but does not by itself delete data already stored here — for that, see your rights.
If you separately choose to connect LinkedIn, you grant that connection its own scopes during LinkedIn’s consent flow, and you can disconnect it at any time.
Where your data lives and how long we keep it
Your account and content live in a managed PostgreSQL database hosted by Neon, and the application runs on Vercel. Traffic is encrypted in transit with TLS, and the database is encrypted at rest by our provider.
- Your content is kept as long as your account is active, so your resumes and history are there when you come back.
- Sign-in sessions are stored in the database and expire on their own; signing out ends them immediately.
- Usage and download records are retained for cost accounting and abuse prevention. When an account is deleted, these are detached from it so they no longer identify you.
- Server logs are retained for a short period by our hosting provider and then rotated out.
- Billing records are kept as long as tax and accounting law requires.
Your rights, and deleting your account
Your content is yours, and you can take it or remove it at any time. Depending on where you live, you may also have formal rights to access, correct, export, restrict, or delete your personal information, and to object to certain processing. We honor these requests for everyone, not only where the law requires it.
- Access and correction — everything we hold about your job search is visible and editable in the app.
- Export — resumes and cover letters download as DOCX at any time.
- Deletion — you can delete individual resumes, job listings, and profiles yourself, or email us to delete the whole account.
Deleting your account
We do not discriminate against you for exercising any of these rights. If you believe we have mishandled your information, you may also complain to your local data protection authority.
Security
We authenticate every request to the application, scope database queries to the signed-in account so one user cannot read another’s content, keep provider API keys on the server and never in the browser, and hold secrets in environment configuration rather than in code.
No service can promise perfect security, and we do not. If we ever become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.
Children
Resume Builder is built for people in the workforce and is not directed at children. You must be at least 16 years old — or the minimum age of digital consent where you live, if that is higher — to create an account.
We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
As the product changes — a new feature, a new provider — this policy will change with it. We will update the “last updated” date at the top of the page, and for material changes we will notify you in the app or by email before they take effect.
Changes are never applied retroactively to reduce the protections that applied to information we already hold about you.
Contact
Questions about this policy, a request about your data, or a concern about how something works can go to TODO@example.com. We aim to respond within 30 days.
The Terms of Service cover the rest of the relationship between you and Resume Builder.