Privacy & Cookie Policy
This policy explains what ResumeHQ does with your personal data. It describes how the product actually works, not a generic template — including the one cookie we set and the single case where your resume text leaves our servers.
Last updated
The short version
The detail matters and the rest of this page provides it, but here is the substance in five lines:
- We collect the minimum to run an account — your email, your name, and whatever you type into your resume.
- We do not sell your personal data, and we do not share it with advertisers or data brokers.
- We set one cookie, and its entire value is the digit
1. No analytics cookies, no advertising pixels, no third-party trackers. - Your resume text is sent to a third-party AI provider only when you press an AI button, and is never used to train models.
- You can have all of it deleted by asking us through our contact form.
What we collect
We hold four categories of data. Only the first is required to have an account at all.
Account data
| Data | Required? | Source |
|---|---|---|
| Email address | Required | You, or your Google / LinkedIn profile if you sign in that way |
| Full name | Optional | You, or your social profile |
| Password | Required for email sign-up | You. Stored only as a salted cryptographic hash — we cannot read it, and neither can anyone who obtains our database |
| Phone number | Optional | You, if you add it to your profile |
| Profile picture | Optional | You, if you upload one |
| Email-verified status | Automatic | Set when you confirm your address |
Resume and cover letter content
Everything you enter into the builder: your work history, education, skills, contact details, and any text you write. This is the most sensitive data we hold, because a resume is a dense collection of personal information by design. It is stored so that you can come back and edit it, and it is visible only to you unless you deliberately generate a share link.
Usage and technical data
| Data | Why it exists |
|---|---|
| Web server logs — IP address, browser user agent, requested URL, timestamp | Generated automatically by our web server. Used for security investigation, abuse and rate-limit enforcement, and debugging errors |
| AI usage records — which feature you used, token counts, timestamps | Enforces the monthly fair-use quota on AI features and lets us detect abuse. We record the volume of your AI usage, not a copy of the text |
| Export records | Tracks background PDF and Word export jobs so you can download the result |
| Sign-in timestamps | Standard account security — lets us and you spot unexpected access |
Messages you send us
When you write to us through our contact form we store the submission so we can answer it and keep a record of the correspondence. You do not need an account to contact us.
| Data | Required? | Why |
|---|---|---|
| Your name | Required | So we can address you properly |
| Your email address | Required | This is how we reply. Without it, an enquiry from someone who has no account would be unanswerable |
| Mobile number | Optional | Used only if your enquiry is genuinely easier to resolve by phone. We try email first |
| Subject and message | Required | The enquiry itself, and how it is routed to the right person |
| IP address | Automatic | Stored with the message and used only to investigate spam and abuse of the form. It is not used to profile you |
Please do not include passwords or payment details in a message — we never need either.
Ratings and testimonials
If you submit a rating, we store the rating, your comment, and the account it came from. This one does require an account, deliberately: ratings tied to a verified user are the only kind worth publishing. Highly-rated testimonials may appear on the site after review, attributed to your first name and last initial only — never your email address. You can change or withdraw yours at any time.
Why we process it
Under the UK/EU GDPR these are our lawful bases. If you are in India, the equivalent under the Digital Personal Data Protection Act is your consent, or a legitimate use where the Act allows one.
| Purpose | Lawful basis |
|---|---|
| Creating your account, saving and exporting your resumes | Performance of a contract — this is the service you asked for |
| Sending verification, password-reset and other transactional email | Performance of a contract |
| Running AI writing features when you invoke them | Performance of a contract, at your request |
| Keeping the service secure, preventing abuse, enforcing rate limits | Legitimate interests — keeping a free service available to everyone |
| Fixing bugs and improving the product | Legitimate interests |
| Publishing your testimonial | Consent, which you give by submitting it and can withdraw |
We do not carry out automated decision-making that has a legal or similarly significant effect on you. The ATS score is advisory feedback on a document you control — nothing acts on it but you.
AI features and your resume content
This is the one place your content leaves our infrastructure, so it deserves to be stated plainly rather than buried.
When you use an AI feature — rewriting a bullet point, generating a summary, suggesting skills, checking grammar, or running an AI ATS review — the relevant section of your resume is transmitted to a third-party AI provider to generate that response. Depending on our configuration, that provider is Google (Gemini) or OpenAI, or an equivalent API-compatible provider.
What we commit to for these requests:
- Only the text needed for the request is sent — not your whole account, and not your email address.
- Your content is not used to train AI models. We use these providers under API terms that exclude training on submitted data.
- We store the metering of the request — which feature, how many tokens, when — to enforce fair-use quotas. Not a copy of the text.
- Providers may retain request data briefly for their own abuse monitoring, under their terms. Google’s and OpenAI’s respective privacy terms govern that processing.
If you would rather no third party ever sees your resume text, the builder works fully without the AI features. Nothing is gated behind them.
Who we share data with
We share data with a small number of service providers who process it on our behalf, under contract, and only for the purpose listed. We do not sell personal data, and we do not disclose it for advertising.
| Recipient | What they receive | Why |
|---|---|---|
| Our hosting provider | All data, as the infrastructure it runs on | Running the servers and database |
| AI provider (Google or OpenAI) | Only the resume text in an AI request you initiate | Generating the AI response you asked for |
| Our email provider | Your email address and the message content | Sending verification and password-reset email |
| Google / LinkedIn | Only what you authorise at sign-in | Social sign-in, if you choose it |
We may also disclose data where we are legally required to — a valid court order or a binding request from a competent authority — or where it is necessary to investigate fraud or protect someone’s safety. If ownership of the service changes, your data may transfer as part of that, and this policy continues to apply until you are told otherwise.
Cookies and local storage
Our cookie use is unusually small, so we can list it exhaustively rather than describing categories.
Cookies we set
| Name | Value | Purpose | Lifetime |
|---|---|---|---|
| rb.session | 1 | Tells our own server you are probably signed in, so it can send you to your dashboard instead of a sign-in page. Holds no token, no identifier, and nothing about you. | 7 days |
| rb.admin.session | 1 | The same hint for the separate administrator area. Only ever set for staff accounts. | 7 days |
Both are strictly necessary for the service to function, are set with SameSite=Lax so they are not sent on cross-site requests, and are removed when you sign out. Because neither is used for analytics, advertising, or profiling, no consent banner is required for them under the EU cookie rules — and we would rather not show you one.
Browser local storage
Local storage is not a cookie, but it is stored on your device, so you should know about it. We keep your sign-in tokens there instead of in cookies:
- A short-lived access token — valid for 30 minutes.
- A refresh token — valid for 7 days, rotated each time it is used, with the old one immediately invalidated so a captured token cannot be replayed.
- Your light/dark theme preference.
Signing out clears the tokens. Clearing your browser’s site data removes all of it.
Third-party cookies
None from us. If you sign in with Google or LinkedIn, that provider may set its own cookies on its own domain during the sign-in flow — that is their processing, governed by their privacy policy, and outside our control.
How long we keep it
| Data | Retention |
|---|---|
| Account data | For as long as your account exists, then erased on request |
| Resumes and cover letters | Until you delete them. Note that deleting a resume in the app initially marks it as deleted and hides it, so it can be recovered if you did it by accident — it is then purged. To have content erased immediately and irreversibly, ask us through the contact form |
| Web server logs | A rolling short-term window, then rotated out. Kept longer only where an active security investigation requires it |
| AI usage records | Retained as long as needed for quota enforcement and abuse detection |
| Published testimonials | Until you withdraw them |
Your rights
Depending on where you live you have some or all of the following rights. We honour all of them regardless of where you are, because maintaining two standards would be worse than maintaining one.
- Access — get a copy of the personal data we hold about you.
- Correction — fix anything inaccurate. Most of it you can edit yourself in your profile.
- Deletion — have your account and content erased.
- Portability — receive your data in a machine-readable format. Your resumes can also be exported as PDF or Word at any time from the app.
- Objection and restriction — object to processing based on legitimate interests, or ask us to restrict it while a dispute is resolved.
- Withdraw consent — for anything based on consent, such as a published testimonial.
- Complain — to your local data protection authority. In the UK that is the ICO; in the EU, your national authority; in India, the Data Protection Board. We would appreciate the chance to resolve it first.
To exercise any of these, send us a message through our contact form using the email address on your account, and say which right you are exercising. We will respond within 30 days, and we will not charge you or make you justify the request. We may need to verify your identity first — that protects you from someone else requesting your data.
How we protect it
- All traffic is encrypted with HTTPS, and browsers are instructed to refuse an unencrypted connection to us.
- Passwords are stored as salted cryptographic hashes. We cannot see or recover your password — which is why a reset link is the only route back in.
- Sign-in tokens are short-lived and rotated, so a captured token has a small window and cannot be reused after rotation.
- A strict Content Security Policy restricts what the site can load or connect to, which limits the damage a script-injection attempt could do.
- Access to production data is restricted to the people who need it to operate the service.
No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your personal data, we will notify you and the relevant regulator as required by law.
International transfers
Our service providers — hosting, email, and AI — may process data outside your country. Where data leaves the UK, EU, or India, we rely on the transfer mechanisms those laws provide, such as Standard Contractual Clauses or an adequacy decision, so your protections travel with your data.
Children
The service is not intended for children. You must be at least 16 to create an account, or older if your country sets a higher age for consenting to data processing. We do not knowingly collect data from children — if you believe a child has created an account, tell us through our contact form and we will remove it.
Changes to this policy
When we change this policy we update the “last updated” date at the top. If a change materially affects your rights — a new category of data, a new recipient, a new purpose — we will tell account holders by email rather than relying on you to notice. Your continued use after a change means you accept the updated policy.
Contacting us
ResumeHQ is operated by ResumeHQ, [Registered address — replace before launch]. For anything about your personal data, including all the rights above, and for every other enquiry, use our contact form lists the right route. Your use of the service is also governed by our Terms of Service.
