ResumeMD
Back to Home

Privacy Policy

Last updated: August 4, 2026

Privacy in plain English

  • Without an account, your resume lives in your browser's local storage and never reaches our servers. PDF export happens in your browser too.
  • With an account, your resumes are stored in our database (Supabase) so they sync across devices. Access rules ensure only you can read them.
  • AI features send your resume text to Anthropic or OpenAI only when you invoke them, and only to produce your result. We never use your content to train models, and we never sell it. Your content is never the product.
  • Payments are handled by Dodo Payments. Your card details never touch our servers.
  • Analytics and advertising tags load on the site but record nothing until you accept cookies. Error monitoring may capture a session replay with all text masked and all media blocked before anything leaves your browser.
  • You can delete your account at any time. Deletion is immediate.

This Privacy Policy explains what we collect, where it goes, and what we will never do with it. Our architecture is local-first on purpose — the less of your data we hold, the less can ever go wrong with it.

1. Information We Collect

1.1 Information You Provide

  • Account Information: Email address, name, and password when you create an account, or your Google/GitHub profile email if you sign in with OAuth
  • How You Found Us: When you create an account, we record the referring site and any campaign parameters (UTM tags, ad click ids) from your first visit. This is noted in your browser until then and attached to your account at signup — it never leaves your browser if you don't create an account
  • Resume Content: The text and formatting of your resumes. Without an account this stays in your browser; with an account it is stored for cloud sync
  • Profile Information: If you set up a public profile — username, headline, bio, avatar, and social links
  • Payment Information: Pro subscriptions are processed by Dodo Payments. We receive your subscription status and billing amounts; we never receive or store your card details
  • Messages: If you use the contact form on a public profile, the message and the contact details you include are stored and emailed to the profile owner

1.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, and interactions with the editor — only after you accept analytics cookies (see Section 5)
  • Log and Security Data: IP addresses appear in server logs and are used transiently for rate limiting (for example, on the contact form and AI endpoints)
  • Error Data: When something breaks, our error monitoring records technical details about the failure (see Section 6)
  • Export Counts: For signed-in users we count PDF exports per month. This is product insight only — exports are never capped

2. How We Use Your Information

  • Provide, maintain, and improve the service
  • Sync your resumes across devices (for account holders)
  • Process subscriptions and manage your account
  • Fulfill AI requests you initiate (see Section 4)
  • Send service communications, and — unless you unsubscribe — occasional product emails (see Section 7)
  • Respond to support requests
  • Detect and prevent abuse, and diagnose technical problems

3. Where Your Data Lives

3.1 Local-First Architecture

Without an account, your resume is stored exclusively in your browser's local storage and is never transmitted to our servers. Editing, preview, and PDF export all run in your browser. You can verify this yourself: open your browser's developer tools, watch the network tab while you type, and no request carries your resume.

3.2 Cloud Storage

If you create an account, your resumes are stored in our database (Supabase, PostgreSQL) to enable cross-device sync. We use encryption in transit (TLS), encryption at rest, and row-level security so that your data is only readable by you.

3.3 Retention and Deletion

  • Deleted resumes move to an archive you can restore from for 30 days, then are permanently deleted. We email you before permanent deletion
  • Account deletion is immediate: deleting your account removes your resumes, version history, preferences, profile, and stored messages. We send one confirmation email. Payment records are retained by Dodo Payments as required for accounting, and email suppression entries (which only prevent us from emailing an address again) may persist
  • Email delivery events (bounces, complaints) and payment webhook logs are retained for 90 days, then deleted

4. AI Features

AI features (content generation, suggestions, job tailoring, cover letters) send your resume text — and, where relevant, the job description you provide — to our AI providers, Anthropic (primary) and OpenAI (fallback), solely to produce the result you asked for. This happens only when you invoke an AI feature, never in the background. We do not use your content to train models, and we do not permit it to be used for anything except fulfilling your request.

5. Analytics, Advertising, and Consent

We use Google Analytics 4 and a Google Ads conversion tag. These tags load on every page so that Google can verify the site, but they are governed by Consent Mode v2 with a default of "denied" — they store no cookies and record no identifiable activity until you accept cookies in the consent banner. If you decline, they stay suppressed.

If you accept, we may also load retargeting pixels from Meta and X. These load only after acceptance, never before. Your consent choice is stored in your browser and you can change it at any time by clearing site data.

We do not sell your personal information, and we never share your resume content with any advertising service.

6. Error Monitoring

We use Sentry to find and fix bugs. When an error occurs, Sentry receives technical details (browser, page, stack trace). Sentry may also record a session replay — for about 10% of sessions, and for sessions where an error occurs — with all text masked and all media blocked before anything leaves your browser. Replays show where the interface broke, not what you wrote.

7. Email

We send email through Resend. Account-critical messages (receipts, payment failures, security notices, data-loss warnings) are sent to all account holders. Product and lifecycle emails carry an unsubscribe link, and unsubscribing stops them. Addresses that hard-bounce or mark us as spam go on a suppression list so we stop mailing them; we record delivery events (bounces, complaints) for 90 days to protect deliverability.

8. Cookies and Local Storage

We use essential cookies and browser local storage to keep you signed in, remember your preferences, and store your resume locally. Analytics and advertising cookies are controlled by the consent banner (Section 5). You can also control cookies through your browser settings — clearing site data removes your local resume, so export it first.

9. Public Pages

Public profiles and shared resume links exist only if you publish them, and you can unpublish at any time. We count views on public pages; we do not record who viewed them. Anything you publish is visible to anyone with the link, including search engines.

10. Information Sharing

We do not sell, trade, or rent your personal information. We share it only:

  • With service providers listed in Section 11, each only to the extent needed to deliver the service
  • When required by law, court order, or governmental authority
  • In a business transfer such as a merger or acquisition — this policy's commitments would bind the successor
  • With your consent, when you explicitly authorize it

11. Third-Party Services

These are the services that process data on our behalf, and why:

  • Supabase: Database and authentication
  • Dodo Payments: Payment processing for Pro subscriptions
  • Anthropic and OpenAI: AI features, only on your request (Section 4)
  • Resend: Email delivery
  • Sentry: Error monitoring and masked session replay (Section 6)
  • Google: Analytics and Ads with Consent Mode (Section 5); optional Google sign-in
  • GitHub: Optional sign-in
  • Meta and X: Retargeting pixels, only after cookie consent (Section 5)
  • Vercel: Hosting and content delivery
  • Upstash: Rate limiting

Each service has its own privacy policy governing its handling of data.

12. Your Rights and Choices

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Delete your account and its data yourself, immediately, from your profile settings
  • Export: Your resume is always recoverable as plain Markdown from the editor, on every tier, and exportable as PDF. Getting your content out never requires payment
  • Opt out: Unsubscribe from product emails at any time; decline analytics cookies in the banner

To exercise these rights, contact privacy@resumemd.pro.

13. Children's Privacy

ResumeMD is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately.

14. International Data Transfers

Your information may be transferred to and processed in countries other than your own — our providers listed in Section 11 operate internationally. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.

15. Changes to This Policy

We may update this Privacy Policy as the service changes. We post updates on this page with an honest "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.

16. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at: