Privacy
ResumeAI is document-native and guest-first: the first result is private and evidence-grounded, and identity follows first value.
What ResumeAI stores
- Documents you upload — resume (PDF/DOCX) and target-job text — and the artifacts derived from them (extraction, analysis, generated documents) are stored privately in Cloudflare R2 under a per-review namespace. All such data carries the CAREER_RESTRICTED privacy class.
- Database records hold review state, extraction summaries, analysis results, confirmed career facts, generated document bodies, and ATS scan results. The ATS scan record stores the scorer's output (statuses, counts, observations, offsets) and content hashes — never resume text, bullet text, contact details, or a network identity.
What is never stored or shared
- Raw network identity is never joined to your documents: the anonymous ATS rate limit keys on an HMAC of the caller IP, and the raw IP is never persisted.
- Documents are never published, indexed, or shared with third parties; the site disables search indexing.
- Private resume and job text never appears in logs, URLs, analytics, or public storage.
- Stripe receives only email, amount, and an opaque purchase ID — never resume, job, or application content.
Retention and deletion
- Guest reviews expire: the guest capability lasts 24 hours, and an hourly reconciliation deletes expired reviews with all their private artifacts and records.
- You can delete a review in-app. Deletion removes the private R2 artifacts and the database records — source, target, extraction, analysis, capabilities, claims, confirmed facts, generated documents, and ATS scans. The review ledger retains only the DELETED state marker.
- If you create an account and claim a review, it becomes account-owned and follows the account lifecycle; account deletion removes claimed data.