What we collect
- Account information: your email address and name (from sign-up or Google sign-in).
- Content you provide: the resume text, job descriptions, and instructions you submit to tailor a resume.
- The Word file you upload: when you upload a .docx, we read it to recover your text and your formatting, and we do not keep the file. If your tailored resume is returned in your own formatting, we store the document we generated, a copy of your file with the wording changed, so you can download it again. We do not store the uploaded file itself, only the document we generate from it.
- Usage & billing data: run metadata (model, tokens, cost, timestamps), plan, and credit activity.
How we use it
- To provide the service: tailoring resumes and generating career documents you request.
- To enforce plan limits, process payments, and maintain your account.
- To monitor and improve reliability and cost. We do not sell your personal data.
Your content & the “don't save” option
By default, your tailored resumes are saved to your account history so you can revisit them. You can turn “Save my work to history” off in your account settings. When it is off, your resume, job description and results are not written to your history. Two things are still recorded: a billing record for the run (model, token counts, cost and timestamp, linked to your account, containing no part of your documents), and a temporary cached copy of the generated result, described under Cached results below.
The free resume checker at /check
The checker can be used without an account and without giving us an email address. It handles your document differently from a signed-in run, so it is described separately here.
- Files you upload are not stored. A PDF or Word file is read in memory to extract its text and is discarded when the request finishes. It is not written to disk or to our database.
- The extracted text is not written to our database. It is sent to our AI provider to identify weak lines, and it is used to compute your score. A copy is held in a temporary cache, keyed to a one-way hash of the text, so that submitting the same document again does not have to be paid for twice. Cache entries expire on their own within 24 hours.
- Your result is held under a random token so the page can display it and a share link can work. It contains your score and the short lines quoted back to you, not your full resume. These entries expire on their own within 30 days.
- Share links. The link contains a random token and no part of your document. Anyone holding the link can see the score and the quoted lines; without it, the result is not reachable. Treat the link as you would the result itself.
- Sending a job posting from a browser extension. If you use a GroundedResume browser extension, it can send a job posting to us so the tailoring form is ready when you arrive. No account is needed to send one. The posting is held for up to 60 minutes and deleted the first time it is opened, whichever comes sooner. It is not written to our database, and its content is not written to our logs.
- Your IP address is used to apply rate limits on our public endpoints, and to run the bot check described under Service providers. It is held as a short-lived counter rather than as a record of your visit.
If you give us your email address on that page, we store the address, the time you ticked the consent box, and a reference to the result you asked us to send. That is the one thing the checker writes to our database, and it is written only when you ask for it. We use the address to send you your breakdown. We do not sell it or share it for marketing.
To have your address removed, email support@groundedresume.com and we will delete the record. The breakdown we send you does not carry a one-click unsubscribe link, so that address is how to opt out.
AI processing
To generate results, the text you submit is sent to the configured AI model provider(s) for processing. Review the applicable provider's data-handling terms. You may run the platform against a self-hosted local model to keep processing on your own infrastructure.
Service providers we share data with
We do not sell your data and we do not share it for advertising. To operate the service we rely on the providers below, each of which processes only what its function requires:
- Anthropic: receives your resume text, the job description and any instruction you add, in order to generate results. This is the only provider that receives your document content as a matter of normal operation.
- Vercel: hosts the application and processes every request. Operational logs are described below.
- Neon: hosts our database. Saved runs, the tailored documents generated for them, saved resumes and account records are stored there. If you turn off saving, your documents are not written to it.
- Upstash: rate limiting and a short-lived cache of generated results, keyed to your submitted text. Entries expire automatically.
- Stripe: payments. Stripe receives your billing details directly; we do not see or store your card number.
- Resend: sends transactional email such as password resets. Receives your email address, not your documents.
- Sentry: error monitoring, so we find out when something breaks for you. Each error report is assembled from a fixed list of permitted fields: the type of error, the location in our code, the page pattern you were on (with any identifier in the address replaced by a placeholder), and your internal account identifier. The text of your documents is not among those fields, and error messages are replaced with a fixed placeholder before the report is sent. Sentry retains these reports for up to 90 days, which is longer than the 24 hours described under Operational logs below.
- Vercel Web Analytics: counts page views, so we can tell how many people reached a page rather than only how many signed up. It records the page address, the referring site, and coarse device and country information derived from your connection. It sets no cookie, stores no identifier for you, and cannot follow you to another website. There is no profile of you to delete because none is created.
- Cloudflare: runs the bot check on the free resume checker, which is how we tell a person from an automated script without asking you to sign in. The widget loads in your browser from Cloudflare, so it receives your IP address, and we send your IP address again when we ask Cloudflare to confirm the check passed. It receives no part of your resume or any other document, and it returns only whether the check passed.
- Google: optional sign-in. If you choose to sign in with Google, Google learns that you are signing in to this service, and returns your email address, name and profile picture to us. This is the one entry in this list where information travels in both directions: the others receive data from us, while Google also supplies data about you. No part of your documents is involved.
Cookies and browser storage
We use a small number of cookies and browser storage entries, and all of them exist to run the service. None of it is used for advertising, and we do not use advertising or cross-site tracking cookies.
- Keeping you signed in. Signing in sets a session cookie so you stay signed in as you move between pages. It is readable by our server rather than by scripts running in your browser, it expires after 30 days without use, and signing out clears it.
- Where a signup came from. If you arrive from a campaign link, one carrying tags such as
utm_source,utm_campaignorref, we store those tags in a cookie for 30 days. It holds the campaign labels that were in the address you arrived on, and nothing about you: no name, no email address, no record of the pages you visit. We check whether it is there so that a later visit does not overwrite it, and we read what is in it once, at the moment an account is created, to record which campaign that account came from. If you do not create an account, its contents are not used. Arriving without those tags sets no cookie at all. - The free resume checker. While you are using the checker, the text you pasted and your most recent result are kept in your browser’s session storage, so that leaving the page and coming back does not lose them. That copy stays in the tab you are using and is not sent to us, and closing the tab clears it. Starting another check clears the stored result at once.
- Unsent drafts, once you have an account. A resume or job posting you have typed into the app but not yet submitted is saved in your browser’s local storage, so that reloading the page does not lose your work. Unlike the checker above, this survives closing the tab. It stays in your browser until you submit the draft or discard it, and saving it does not send it to us.
- Your appearance setting. Whether you chose the light or dark theme is stored in your browser, so the page does not show the wrong one while it loads.
The bot check on the free checker is provided by Cloudflare and may set its own cookie in order to tell people from automated traffic. It is a security control rather than an advertising or analytics one.
Our page analytics, described under Who else processes your data above, sets no cookie and is not listed here for that reason: it counts a page view without storing anything in your browser and without an identifier that could recognise you on a later visit. It is not shared with an advertising network.
Operational logs
Our hosting provider records diagnostic logs for every request. These contain technical information only: timings, status codes, error types and an internal account identifier. They are retained for up to 24 hours and then deleted automatically, and are accessible only to the operator of this service.
We do not write the content of your documents to these logs. Database and file-parsing errors are deliberately reduced to a type and a location before they are recorded, so that a failure while handling your resume does not put the resume itself into a log. We treat any exception to that as a defect and fix it.
Data retention & deletion
Deleting your history removes every saved run from your account: the resume text, job description, instruction and generated result.
Documents in your own formatting. When a tailored resume is produced in your original formatting, the generated file is stored alongside that run so you can download it again. We keep it for 90 days, then delete it. The run itself stays in your history. It is removed sooner if you delete that run or your account, and it is not written at all if “Save my work to history” is off.
Deleting your account erases:
- your account details: name, email, password or connected Google sign-in
- every saved resume, every run, and every generated result, including the contact details extracted from your resume
- career-tool output: cover letters, interview answers, LinkedIn and recruiter text
- your saved job applications, batch runs, and active sessions
What we keep, with your user ID removed so the records are no longer linked to you: billing and usage records: the model, token counts, cost, which part of the product was used, and timestamps. These contain no part of your resume or job descriptions. We keep them because they are our accounting records and reconcile against the invoices we pay our AI provider.
Cached results. So that an identical request does not have to be paid for twice, generated results are held in a temporary cache for up to 24 hours. When you delete your account we remove the cached entries recorded against it. Entries created before we began recording them cannot be located this way; those expire on their own within 24 hours.
Job postings sent from a browser extension: held for up to 60 minutes, and deleted the first time they are opened.
Database backups. Our database provider keeps a 6-hour change history so the service can be restored after a failure. Deleted records may persist in that history for up to 6 hours, after which they age out. Backups are not used to serve the product and are not searchable by us in normal operation.
Error reports. When something breaks, a diagnostic report goes to our error-monitoring provider carrying the internal account identifier, an opaque string, not your name or email. Those reports sit with that provider rather than in your account, so deleting your account does not reach them. What deletion changes is what that string is worth: with the account row gone, it no longer corresponds to any record we hold. The reports age out on the provider's own schedule, within 90 days.
Deletion runs immediately when you confirm it. We do not offer account recovery, and we cannot restore a deleted account for you.
Contact
For privacy questions or data requests, contact us at support@groundedresume.com.