Privacy Policy

Who is responsible for your data

ResumeFully is the data controller for the personal data described here. In data-protection terms that means we decide what is collected and why, and we are accountable for it.
For privacy questions, data-subject requests, or anything in this policy, write to [email protected]. One named person is responsible for these requests and we answer within one month, which is the period the GDPR allows.
Paddle is a separate controller for the payment data it collects when you buy a subscription. Their handling of your billing details is governed by their own privacy policy, not this one.

What we collect

If you join the waitlist before launch: your email address, and — so we know roughly where interest is coming from — the country Cloudflare reports for the request and a shortened description of your browser. We do not store your IP address. This is deleted once the waitlist has been mailed.
Account and profile data: your email address, authentication credentials, and the entitlement attached to your account.
The content you create: your resumes, the version snapshots that make editing restart-safe, and the job applications and job-description text you track.
Files you upload for import, and the extraction artifacts produced from them. Both are deleted once the import completes or fails — they are not kept as a second copy of your resume.
Documents we render for you, held briefly behind a short-lived signed link and not retained beyond it.
Records of AI operations you run — identifiers, model, token counts, and cost — so credits can be accounted for. These records never contain your resume or job-description text.
Billing and credit ledger records, and the webhook events from Paddle that keep your entitlement correct.
Technical logs and error reports. These are scrubbed by default: they carry request, job, and user identifiers, never resume content and never contact details.

What we do not do

We do not use your resume or job-description content to train AI models, for advertising, for profiling, to rank users, for resale, or for aggregate publication.
There are no third-party trackers and no advertising pixels on this site or in the product. Not on the marketing pages, not behind the login.
We do not ask for, and do not want, special-category data — health, disability, race, religion, political opinion, sexual orientation, or trade-union membership. There is no photo or personal-details section that invites it by default.
We do not make automated decisions about your employability. Where the product scores a document, it shows the rubric and the evidence; it is scoring a document, not judging you.

Why we are allowed to process it

To perform our contract with you: running your account, storing and processing your documents, and delivering the features you ask for.
For our legitimate interests: keeping the service secure, preventing abuse, debugging faults, and understanding aggregate reliability.
To comply with legal obligations: keeping the transaction records that accounting and tax law require.
Where an AI operation sends your content to a third-party provider, that happens because you initiated the operation as part of the service you asked for.

Who else processes your data

We publish a versioned sub-processor register naming every processor that reaches user data, what it is for, which categories of data it sees, and the region it processes in.
The processors in use for the web product are: Supabase for the database, authentication, storage, and serverless functions; Cloudflare for hosting, DNS, and content delivery; Google Cloud for document processing and rendering; Anthropic for AI operations; Resend for transactional email; Upstash for rate limiting; and Paddle for billing.
Anthropic receives resume and job-description text only for an AI operation you started. Their no-training and retention posture for API traffic is what we rely on for the commitment above, and we record it explicitly because it is a claim about a third party rather than about us.
We announce a new sub-processor before your data can cross that boundary — not afterwards.

How long we keep things

Account data, resumes, versions, and application records are kept for the life of your account and deleted when you delete it.
Uploaded files and extraction artifacts are deleted when the import finishes or fails. Rendered exports live only as long as their signed link.
Billing and ledger records are the documented exception. We keep them under accounting and tax law even after an account is erased, minimised to the transaction identifiers, amounts, and dates required.
Logs expire on a fixed retention window set at the provider.
Backups are kept as 30 daily and 12 monthly recovery points.

Your rights, and the two you can exercise yourself

You can export all your data in a structured, portable format, and you can delete your account, from inside the product. Neither requires contacting us or waiting for us to act.
You also have the right to access your data, correct it, object to or restrict processing, and complain to your local supervisory authority. Write to [email protected] for any of these. We log each request and its outcome.
Erasure is real and prompt in the live system: deleting your account removes your profile, resumes, versions, applications, private files, processing artifacts, and render artifacts.

The honest part about backups

Backups are not selectively edited, and any provider claiming otherwise is describing something they do not do.
When you delete your account, your data is removed from the live system promptly, but it can persist inside encrypted backups until those backups age out. The outer bound is the 12-monthly retention window above.
We keep a deletion log and re-apply it after any restore, so restoring a backup can never quietly bring an erased account back.

Security and breaches

Your documents live in private storage reachable only through your authenticated account. Access rules are enforced in the database itself rather than only in application code.
If we suspect a personal-data breach we contain it, assess the scope and who is affected within 24 hours, notify the supervisory authority within 72 hours where the law requires it, and tell affected users when the risk warrants it. We record the incident and our reasoning even when no notification is required.

International transfers and age

The processors above operate across multiple regions, so your data may be processed outside your own country. Where that happens, transfers rely on the legal mechanisms in each processor's data-processing terms, and the sub-processor register records the processing region for each one.
You must be at least 16 to use ResumeFully, or older where local law sets a higher age for consenting to online services. We do not knowingly collect data from anyone below that age.

Changes to this policy

This policy is versioned. The effective date at the top of this page changes when the policy does.
We notify account holders before a material change takes effect — particularly one that widens what we collect or introduces a new category of data leaving the system.

Related pages

Sources

  • Development Plan section 33 — data protection, accessibility, and consumer-law compliance — retrieved 2026-08-28 (https://resumefully.com/trust)