Privacy Policy
Last updated: July 27, 2026
ResumeME (“we”, “us”) helps you analyze and improve your resume. Because resumes are inherently personal, we designed the service to collect only what it needs, to be transparent about where your data goes, and to give you a way to delete it. This policy explains what we collect, why, who processes it, and your choices. It applies to the website and application at resumeme.io.
What we collect
Account information
- Email address and name — when you sign in with a magic link or Google. If you use Google sign-in, we receive your name, email, and profile picture from Google; we never see your Google password.
Content you provide
- Resumes — files you upload (PDF, DOCX, TXT) or text you paste, plus the structured content we parse from them (work history, education, skills, contact details, and similar resume fields).
- Job descriptions you paste for matching, cover letters you generate, and messages you exchange with the AI assistant.
Usage and technical data
- Product analytics — events such as “resume uploaded” or “analysis run.” Analytics tied to your account are collected only if you opt in (the setting is off by default). Pre-signup page analytics are anonymous and contain no IP address.
- Operational logs — error and security logs (e.g., failed sign-in attempts, rate-limit events) needed to keep the service reliable and safe.
We do not collect payment information; ResumeME is currently free.
How we use your data
- To provide the service: parsing, scoring, rewriting, and exporting your resume.
- To operate your account: authentication, sessions, and email delivery.
- To keep the service secure: abuse prevention, rate limiting, and debugging.
- To improve the product, using aggregated or opted-in analytics only.
We do not sell your personal data, and we do not use your resume content to train AI models.
AI processing
Core features send your resume text, job descriptions, and chat messages to large language models via OpenRouter, which routes requests to model providers (such as Anthropic, OpenAI, or Google) under contractual terms that prohibit using API data to train their models. We send only what the feature needs, and we do not include your account credentials in AI requests. AI outputs (scores, rewrites, letters) are stored with your account so you can revisit them.
Where your data lives
- Neon (PostgreSQL) — account data, parsed resume content, versions, scores, conversations, and settings, encrypted at rest and in transit.
- Cloudflare R2 — your uploaded files and generated exports, in a private bucket accessible only through short-lived signed URLs issued to your session.
- Cloudflare Workers — application hosting and TLS.
- Resend — transactional email (magic sign-in links). Resend processes your email address solely to deliver these messages.
Cookies
We use only essential cookies: a session cookie (HTTP-only, secure) that keeps you signed in, and a CSRF-protection token. We set no advertising or cross-site tracking cookies. If ads are introduced in the future, any advertising cookies will require your consent first and this policy will be updated before launch.
Retention and deletion
- Your content stays in your account until you delete it or delete your account.
- Deleting a resume removes it from your workspace immediately; residual copies leave backups within 30 days.
- To delete your account and all associated data, email privacy@resumeme.io from your account email address. We complete deletion within 30 days and confirm when done. (Self-serve deletion is coming; email works today.)
- Operational logs are retained for up to 90 days, then deleted.
Your rights
Depending on where you live (including under GDPR and CCPA/CPRA), you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can exercise any of these by emailing privacy@resumeme.io. We respond within the timelines your local law requires, and we do not discriminate against you for exercising your rights. You may also lodge a complaint with your local data-protection authority.
Security
All traffic is encrypted with TLS. Stored data is encrypted at rest by our infrastructure providers. Sessions use HTTP-only secure cookies with CSRF protection; uploads and AI requests are rate-limited; admin actions are audit-logged. No system is perfectly secure — if a breach affects your data, we will notify you as required by law.
Children
ResumeME is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
Changes
We will post any changes to this policy here and update the date above. For material changes, we will notify you by email or an in-app notice before they take effect.
Contact
Questions or requests: privacy@resumeme.io.