ResumeHQ — free ATS resume builder

Privacy & Cookie Policy

This policy explains what ResumeHQ does with your personal data. It describes how the product actually works, not a generic template — including the one cookie we set and the single case where your resume text leaves our servers.

Last updated

The short version

The detail matters and the rest of this page provides it, but here is the substance in five lines:

  • We collect the minimum to run an account — your email, your name, and whatever you type into your resume.
  • We do not sell your personal data, and we do not share it with advertisers or data brokers.
  • We set one cookie, and its entire value is the digit 1. No analytics cookies, no advertising pixels, no third-party trackers.
  • Your resume text is sent to a third-party AI provider only when you press an AI button, and is never used to train models.
  • You can have all of it deleted by asking us through our contact form.

What we collect

We hold four categories of data. Only the first is required to have an account at all.

Account data

DataRequired?Source
Email addressRequiredYou, or your Google / LinkedIn profile if you sign in that way
Full nameOptionalYou, or your social profile
PasswordRequired for email sign-upYou. Stored only as a salted cryptographic hash — we cannot read it, and neither can anyone who obtains our database
Phone numberOptionalYou, if you add it to your profile
Profile pictureOptionalYou, if you upload one
Email-verified statusAutomaticSet when you confirm your address

Resume and cover letter content

Everything you enter into the builder: your work history, education, skills, contact details, and any text you write. This is the most sensitive data we hold, because a resume is a dense collection of personal information by design. It is stored so that you can come back and edit it, and it is visible only to you unless you deliberately generate a share link.

Usage and technical data

DataWhy it exists
Web server logs — IP address, browser user agent, requested URL, timestampGenerated automatically by our web server. Used for security investigation, abuse and rate-limit enforcement, and debugging errors
AI usage records — which feature you used, token counts, timestampsEnforces the monthly fair-use quota on AI features and lets us detect abuse. We record the volume of your AI usage, not a copy of the text
Export recordsTracks background PDF and Word export jobs so you can download the result
Sign-in timestampsStandard account security — lets us and you spot unexpected access

Messages you send us

When you write to us through our contact form we store the submission so we can answer it and keep a record of the correspondence. You do not need an account to contact us.

DataRequired?Why
Your nameRequiredSo we can address you properly
Your email addressRequiredThis is how we reply. Without it, an enquiry from someone who has no account would be unanswerable
Mobile numberOptionalUsed only if your enquiry is genuinely easier to resolve by phone. We try email first
Subject and messageRequiredThe enquiry itself, and how it is routed to the right person
IP addressAutomaticStored with the message and used only to investigate spam and abuse of the form. It is not used to profile you

Please do not include passwords or payment details in a message — we never need either.

Ratings and testimonials

If you submit a rating, we store the rating, your comment, and the account it came from. This one does require an account, deliberately: ratings tied to a verified user are the only kind worth publishing. Highly-rated testimonials may appear on the site after review, attributed to your first name and last initial only — never your email address. You can change or withdraw yours at any time.

What we deliberately do not collect: we run no analytics platform, no advertising or conversion pixels, no session recording, and no cross-site tracking. We do not ask for your date of birth, government identifiers, or payment details — the service is free, so we never handle card data.

Why we process it

Under the UK/EU GDPR these are our lawful bases. If you are in India, the equivalent under the Digital Personal Data Protection Act is your consent, or a legitimate use where the Act allows one.

PurposeLawful basis
Creating your account, saving and exporting your resumesPerformance of a contract — this is the service you asked for
Sending verification, password-reset and other transactional emailPerformance of a contract
Running AI writing features when you invoke themPerformance of a contract, at your request
Keeping the service secure, preventing abuse, enforcing rate limitsLegitimate interests — keeping a free service available to everyone
Fixing bugs and improving the productLegitimate interests
Publishing your testimonialConsent, which you give by submitting it and can withdraw

We do not carry out automated decision-making that has a legal or similarly significant effect on you. The ATS score is advisory feedback on a document you control — nothing acts on it but you.

AI features and your resume content

This is the one place your content leaves our infrastructure, so it deserves to be stated plainly rather than buried.

When you use an AI feature — rewriting a bullet point, generating a summary, suggesting skills, checking grammar, or running an AI ATS review — the relevant section of your resume is transmitted to a third-party AI provider to generate that response. Depending on our configuration, that provider is Google (Gemini) or OpenAI, or an equivalent API-compatible provider.

This only happens when you ask for it. Simply typing in the editor, saving, previewing, or exporting sends nothing to any AI provider. If you never press an AI button, your resume content never leaves our servers.

What we commit to for these requests:

  • Only the text needed for the request is sent — not your whole account, and not your email address.
  • Your content is not used to train AI models. We use these providers under API terms that exclude training on submitted data.
  • We store the metering of the request — which feature, how many tokens, when — to enforce fair-use quotas. Not a copy of the text.
  • Providers may retain request data briefly for their own abuse monitoring, under their terms. Google’s and OpenAI’s respective privacy terms govern that processing.

If you would rather no third party ever sees your resume text, the builder works fully without the AI features. Nothing is gated behind them.

Who we share data with

We share data with a small number of service providers who process it on our behalf, under contract, and only for the purpose listed. We do not sell personal data, and we do not disclose it for advertising.

RecipientWhat they receiveWhy
Our hosting providerAll data, as the infrastructure it runs onRunning the servers and database
AI provider (Google or OpenAI)Only the resume text in an AI request you initiateGenerating the AI response you asked for
Our email providerYour email address and the message contentSending verification and password-reset email
Google / LinkedInOnly what you authorise at sign-inSocial sign-in, if you choose it

We may also disclose data where we are legally required to — a valid court order or a binding request from a competent authority — or where it is necessary to investigate fraud or protect someone’s safety. If ownership of the service changes, your data may transfer as part of that, and this policy continues to apply until you are told otherwise.

Cookies and local storage

Our cookie use is unusually small, so we can list it exhaustively rather than describing categories.

Cookies we set

NameValuePurposeLifetime
rb.session1Tells our own server you are probably signed in, so it can send you to your dashboard instead of a sign-in page. Holds no token, no identifier, and nothing about you.7 days
rb.admin.session1The same hint for the separate administrator area. Only ever set for staff accounts.7 days

Both are strictly necessary for the service to function, are set with SameSite=Lax so they are not sent on cross-site requests, and are removed when you sign out. Because neither is used for analytics, advertising, or profiling, no consent banner is required for them under the EU cookie rules — and we would rather not show you one.

Browser local storage

Local storage is not a cookie, but it is stored on your device, so you should know about it. We keep your sign-in tokens there instead of in cookies:

  • A short-lived access token — valid for 30 minutes.
  • A refresh token — valid for 7 days, rotated each time it is used, with the old one immediately invalidated so a captured token cannot be replayed.
  • Your light/dark theme preference.

Signing out clears the tokens. Clearing your browser’s site data removes all of it.

Third-party cookies

None from us. If you sign in with Google or LinkedIn, that provider may set its own cookies on its own domain during the sign-in flow — that is their processing, governed by their privacy policy, and outside our control.

How long we keep it

DataRetention
Account dataFor as long as your account exists, then erased on request
Resumes and cover lettersUntil you delete them. Note that deleting a resume in the app initially marks it as deleted and hides it, so it can be recovered if you did it by accident — it is then purged. To have content erased immediately and irreversibly, ask us through the contact form
Web server logsA rolling short-term window, then rotated out. Kept longer only where an active security investigation requires it
AI usage recordsRetained as long as needed for quota enforcement and abuse detection
Published testimonialsUntil you withdraw them
Please note: there is currently no self-service “delete my account” button in the app. Until there is, account deletion goes through our contact form — write in from the address on your account with “Delete my account” as the subject. We will verify it is you, then erase your account and content. We treat that as a priority request, not a formality.

Your rights

Depending on where you live you have some or all of the following rights. We honour all of them regardless of where you are, because maintaining two standards would be worse than maintaining one.

  • Access — get a copy of the personal data we hold about you.
  • Correction — fix anything inaccurate. Most of it you can edit yourself in your profile.
  • Deletion — have your account and content erased.
  • Portability — receive your data in a machine-readable format. Your resumes can also be exported as PDF or Word at any time from the app.
  • Objection and restriction — object to processing based on legitimate interests, or ask us to restrict it while a dispute is resolved.
  • Withdraw consent — for anything based on consent, such as a published testimonial.
  • Complain — to your local data protection authority. In the UK that is the ICO; in the EU, your national authority; in India, the Data Protection Board. We would appreciate the chance to resolve it first.

To exercise any of these, send us a message through our contact form using the email address on your account, and say which right you are exercising. We will respond within 30 days, and we will not charge you or make you justify the request. We may need to verify your identity first — that protects you from someone else requesting your data.

How we protect it

  • All traffic is encrypted with HTTPS, and browsers are instructed to refuse an unencrypted connection to us.
  • Passwords are stored as salted cryptographic hashes. We cannot see or recover your password — which is why a reset link is the only route back in.
  • Sign-in tokens are short-lived and rotated, so a captured token has a small window and cannot be reused after rotation.
  • A strict Content Security Policy restricts what the site can load or connect to, which limits the damage a script-injection attempt could do.
  • Access to production data is restricted to the people who need it to operate the service.

No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your personal data, we will notify you and the relevant regulator as required by law.

International transfers

Our service providers — hosting, email, and AI — may process data outside your country. Where data leaves the UK, EU, or India, we rely on the transfer mechanisms those laws provide, such as Standard Contractual Clauses or an adequacy decision, so your protections travel with your data.

Children

The service is not intended for children. You must be at least 16 to create an account, or older if your country sets a higher age for consenting to data processing. We do not knowingly collect data from children — if you believe a child has created an account, tell us through our contact form and we will remove it.

Changes to this policy

When we change this policy we update the “last updated” date at the top. If a change materially affects your rights — a new category of data, a new recipient, a new purpose — we will tell account holders by email rather than relying on you to notice. Your continued use after a change means you accept the updated policy.

Contacting us

ResumeHQ is operated by ResumeHQ, [Registered address — replace before launch]. For anything about your personal data, including all the rights above, and for every other enquiry, use our contact form lists the right route. Your use of the service is also governed by our Terms of Service.