Privacy Policy

Last updated: April 12, 2026

Introduction

Welcome to Rezume (“we,” “our,” or “us”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our resume building and job research platform available at rezume.page (the “Service”).

By accessing or using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

Information We Collect

Personal Information You Provide

We collect information that you voluntarily provide to us when you:

  • Create an Account: Email address, name, and authentication credentials
  • Build Your Resume: Professional information including work experience, education, skills, projects, contact information, and any other data you choose to include
  • Upload Files: Resume content from PDF or DOCX files that you upload for parsing
  • Profile Customization: Profile picture, tagline, bio, custom username, and social media links
  • Research Job Postings: Job posting URLs you submit for analysis, along with the scraped job description content used for ATS scoring, resume tailoring, cover letter generation, cold email generation, and company research
  • Application Tracking: If you use the application tracker, we store job application records including company name, role title, and the status you assign (e.g., Applied, Interview, Rejected, Offer)
  • NFC Cards: If you order or activate an NFC card, we store your card configuration, public profile link, and activation status
  • Payment Information: When you subscribe to a paid plan, billing details are collected and processed by our payment provider (see Third-Party Services below). We store your subscription status, plan type, and billing interval but do not store credit card numbers or bank details directly
  • Communications: Any information you provide when contacting us for support

Information Collected Automatically

When you or others access pages on our Service, we automatically collect certain information:

  • Profile Analytics: When someone views your public profile, we record the event along with the country (derived from IP address), referring URL, and the hour of the visit. We also track PDF downloads and link clicks on your profile
  • Privacy-Safe Visitor Counting: To count unique visitors without storing personal identifiers, we hash the visitor’s IP address together with a daily-rotating salt. The resulting hash cannot be reversed to recover the original IP address, and old hashes become meaningless the following day when the salt changes. We do not store raw IP addresses for analytics purposes
  • Device Type: We determine whether a visitor is on a mobile, tablet, or desktop device using the User-Agent string sent by their browser. The raw User-Agent string is used only for device classification and is not stored
  • Referrer Data: We categorize where your profile visitors come from (e.g., LinkedIn, Google, Twitter, direct) based on the HTTP Referer header
  • Engagement Metrics: For profile views, we record approximate session duration and scroll depth in bucketed ranges (e.g., 0–10 seconds, 25% scrolled). These are stored as aggregate counts and do not identify individual visitors
  • Usage Data: Information about how you interact with our Service, including research queries submitted, content copied, and features used

How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To create, maintain, and provide access to your resume, profile, and research data
  • Authentication: To verify your identity and secure your account
  • AI Research Features: To analyze job postings you submit, including ATS compatibility scoring against your resume, generating tailored resume suggestions, creating cover letters and cold emails, and compiling company intelligence. Your resume data and the job description are sent to AI services for processing
  • Company Research: To scrape and analyze publicly available information about companies from job postings you submit, including company overview, culture, recent news, and interview preparation materials
  • Resume Parsing: To parse uploaded resumes and enhance content using AI when you explicitly request these features
  • PDF Generation: To create downloadable PDF versions of your resume, including tailored versions optimized for specific job applications
  • Public Profiles: To display your resume on a custom URL when you choose to claim a username
  • Analytics Dashboard: To provide you with aggregated, privacy-safe analytics about who views your public profile, including visitor counts, geographic distribution, referral sources, peak viewing times, and conversion rates
  • Subscription Management: To process payments, manage your subscription status, and enforce usage limits based on your plan
  • NFC Cards: To link your NFC card to your public profile and manage card activation
  • Service Improvement: To analyze usage patterns and improve our Service
  • Security: To detect, prevent, and address security issues or abuse
  • Communications: To respond to your inquiries and provide support
  • Legal Compliance: To comply with applicable laws and legal processes

How We Share Your Information

Public Information

If you claim a custom username, your resume will be publicly accessible at rezume.page/[username]. This includes all information you have added to your resume sections. You control what information is included by managing your resume content and privacy settings. You can restrict your profile to be visible only via your NFC card if you have one activated.

Third-Party Service Providers

We share your information with trusted third-party service providers who assist us in operating our Service:

  • AI Processing (OpenAI): Resume data and job descriptions are sent to OpenAI for ATS analysis, resume tailoring, cover letter and cold email generation, and company research. Data is processed per OpenAI’s data usage policies
  • Web Scraping (Parallel.ai): Job posting URLs you submit are sent to Parallel.ai to extract the job description content for analysis
  • Payment Processing (Dodo Payments): When you subscribe to a paid plan, your billing information is processed by Dodo Payments. We share your email address and user identifier with Dodo Payments to create and manage your subscription
  • Database (Supabase): All user data — including your profile, resume, research history, application records, and analytics — is stored in a Supabase (PostgreSQL) database with row-level access controls
  • Hosting (Vercel): The Service is hosted on Vercel. Request metadata such as country of origin is derived from Vercel’s infrastructure headers
  • Authentication & Image Storage (Firebase): Account authentication is handled by Google Firebase Authentication. Profile images are stored in Firebase Storage

These service providers are obligated to protect your information and use it only for the purposes we specify.

Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities, or to protect our rights, your safety, or the safety of others.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your information becomes subject to a different privacy policy.

Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption of data in transit using TLS/SSL
  • Secure authentication with token-based access control
  • Access controls to ensure you can only access your own data
  • Privacy-safe analytics that avoid storing personally identifiable information about your profile visitors
  • Daily-rotating salts for IP hashing to prevent long-term tracking
  • Input validation to prevent security vulnerabilities

However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request access to the personal information we hold about you
  • Correction: Update or correct inaccurate information through your profile settings
  • Deletion: Delete your account and associated data through the Settings page. This removes your profile, resume, research history, analytics data, and NFC card associations
  • Data Portability: Download your resume data as a PDF
  • Privacy Controls: Manage who can view your profile through privacy settings (public, private, or NFC-card-only access)

To exercise these rights, you can manage your data directly through your account or contact us at hi@rezume.page.

Data Retention

We retain your personal information for as long as your account is active. When you delete your account:

  • Your profile, resume data, research history, analytics, and associated information will be permanently deleted
  • Your subscription will be cancelled (no further charges)
  • We may retain certain information if required by law

Analytics data about your profile visitors is retained for as long as your account is active. Hashed IP addresses used for unique visitor counting expire daily due to the rotating salt mechanism.

Children's Privacy

Our Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at hi@rezume.page, and we will delete such information.

International Users

Our Service is available worldwide. By using our Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence. We use service providers that implement appropriate safeguards to protect your information.

Cookies and Tracking

We use cookies and similar technologies for:

  • Essential Cookies: Required for authentication and basic functionality
  • Local Storage: To store user preferences and session data

We do not use third-party tracking cookies or advertising trackers. Profile analytics are collected server-side without cookies. You can control cookies through your browser settings, but disabling essential cookies may affect the functionality of the Service.

Third-Party Links

Our Service may contain links to third-party websites (such as social media links in your resume). We are not responsible for the privacy practices of these third parties.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

This Privacy Policy is part of our Terms and Conditions. Please also review our Terms and Conditions.