Summary

  • We store your account, your resumes and your ATS reports so you can use them. We don't sell data or use it for advertising.
  • There are no analytics, advertising or tracking scripts. The only cookie is the sign-in session.
  • Uploaded files are read and then discarded; only the extracted content is kept.
  • Your name and contact details are removed before resume content is sent to an AI provider.
  • Cover letters aren't stored on our server.

Account information

When you register we store your email address (lower-cased), an optional name, a bcrypt hash of your password (never the password itself), when the account was created, and your role. We also store your AI settings if you change them. Email addresses aren't verified, and we don't send marketing email.

Resumes and documents

Resumes you create or import are stored in our database with their title, content, design settings, timestamps and latest ATS score. For an imported resume, the original file name is stored; the file itself is read in memory and discarded. To show resume thumbnails, a rendered image of each resume's first page is cached on the server (up to the 500 most recent images across all users).

Cover letters are generated and returned to your browser without being saved on the server. Your draft is kept in your browser tab's session storage until the tab closes. Job descriptions you paste into the editor are also kept only in session storage.

ATS checks

The ATS score is calculated on our server by fixed rules, without AI. When you check an uploaded file, the report (score, findings, file name) is saved to your history. Checks of a resume you're editing update that resume's latest score. We keep your most recent 100 reports and delete older ones automatically.

AI processing

AI is used only for features you start: importing a file, AI parsing of an uploaded file for the ATS check, rewrites, whole-resume improvements, the optional recruiter review, cover letters and optional AI ranking of job results.

Rewrites, review, cover letters
Your resume content (headline, summary, roles, employers, dates, bullets, education, skills, projects, certifications, languages, custom sections), plus any job description and instructions you type. Your name, email, phone, address, website, LinkedIn and GitHub are removed first. Cover letters use a placeholder for your name, filled in on our server.
Import and file checks
The text extracted from your file, after emails, phone numbers, links and your name are replaced with placeholders such as [EMAIL_1]. The original values are restored on our server afterwards.
Job ranking (optional)
Listing titles and snippets, and from your resume only the headline, the first 600 characters of the summary, up to four job titles and your skills.

Requests go to the AI provider configured by the service administrator, from our server. The provider handles the data it receives under its own terms, including how long it keeps it; we don't control that. AI suggestions are shown for your review before they change your resume, and details your resume doesn't state are flagged rather than added.

Job search

Job searches are run from our server through a self-hosted metasearch engine, which sends the query to public web search engines (such as Google, Bing, DuckDuckGo, Brave and others). The query contains the role, the location or “remote”, site filters and up to two of your skills. It doesn't include your name, contact details or resume text. Results are cached for one hour under your account. When you open a listing, you visit the job site directly, under that site's own privacy policy.

Mock interviews

We store each interview you take: the role, the questions, your answers, the grades and the integrity counts (paste attempts and tab switches). To prepare and grade questions, the role, job description you provide, your resume without its contact block, and your answers are sent to the AI provider. Topic scores (for example “sql joins: 72”) are kept in a graph database linked to your account id, so later interviews and voice calls can focus on your weak topics. It holds no names, emails or answer text.

Voice tutor calls

Your microphone is used only while a call is on, after you allow it in your browser. Call audio travels through LiveKit (our real-time audio provider) to Google's Gemini Live models, which speak with you and transcribe what you say. We don't record or store the audio. We store the call's text transcript, the notes taken during it and its report. The tutor receives the context you chose for the call: the target role and job description, your resume without its contact details, and results from the interview you picked. During and after the call, the transcript is sent to the AI provider to take notes and write the report.

Payments

Payments are processed by Razorpay. Your card, UPI and bank details go to Razorpay, not to us. We keep the order details (plan, amount, currency, coupon, payment id and status) to apply your plan and for our records.

Cookies and browser storage

rf_session (cookie)
Keeps you signed in. HttpOnly, Secure, SameSite=Lax, expires after seven days or when you sign out.
Local storage
Your theme choice and whether the sidebar is collapsed.
Session storage
Cover letter drafts, pasted job descriptions, the job you chose to tailor to, and scroll position. Cleared when the tab closes.

We don't use analytics, advertising or social media cookies. Fonts are served from our own server. The site is delivered through Cloudflare, which may set its own security-related cookies.

Logs

Our web server keeps standard access logs: your IP address, the date and time, the page or API route requested, the response status, the referring page and your browser's user agent. The application logs record routes, errors and internal IDs, never request bodies, resume text, AI prompts or output, passwords, session tokens or API keys. IP addresses are also used briefly as keys for rate limits. Logs are kept for as long as the server keeps them; a fixed retention period isn't configured yet.

Who else processes data

  • Cloudflare, which delivers the site and sees standard connection data such as your IP address.
  • The AI provider configured by the service administrator, for AI features you start.
  • LiveKit and Google (Gemini Live), for voice tutor calls you start.
  • Razorpay, for payments.
  • Public web search engines and job APIs (such as Adzuna), for job-search queries as described above. Public company careers feeds are read directly and receive nothing about you.

We don't sell or rent personal data, and we don't share it with employers, recruiters or advertisers.

Retention

Account and resumes
Until you delete them, or the account is deleted.
Mock interviews and voice call transcripts
Until you delete them, or the account is deleted. Call audio isn't stored.
Payment records
Kept for accounting even after an account is deleted, marked as belonging to a deleted account.
ATS reports
Your latest 100; older ones are removed automatically.
Resume thumbnails
Cached images of the newest 500 renders; older images are removed as new ones are made.
AI review and job-search caches
6 hours and 1 hour.
Signed-out session records
Until the session would have expired, at most seven days.
Server logs
No fixed retention period is configured yet.

Database backups may be made to protect against data loss and can contain deleted data until they're replaced.

Deletion

You can delete any resume yourself. Deleting a resume doesn't delete ATS reports already made from it. Accounts are deleted by an administrator; there's no self-service option yet. Deleting an account removes the account, all its resumes, ATS reports, mock interviews, voice call transcripts and topic progress, and its cached data, and ends its sessions immediately. A cached thumbnail image may remain on the server until it's replaced by newer ones. To request deletion, email ranjan_j@icloud.com.

Your choices

You can view and edit everything in your resumes at any time, export them as PDF, or avoid AI features entirely. For access or deletion requests we can't handle through the product, email ranjan_j@icloud.com. Depending on where you live, you may have further rights under local data-protection law.

Changes

We update this policy when the product's handling of data changes, and revise the date at the top.