Privacy Policy
Last updated: August 2026
Rezumable ("we", "our", or "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights as a user.
1. What data we collect
- Account information · your email address and, optionally, your name and location when you create an account.
- Resume content · the text of any resume you upload. This is stored in your profile so you don't have to re-upload it every session. You can delete it at any time from your Profile page.
- Job descriptions · the job description text you paste into the analyzer. This is used only to generate your analysis and is not stored long-term beyond the 7-day analysis cache described below.
- Analysis results · the full structured output from each resume analysis (scores, bullet suggestions, dealbreaker check) is stored in your account so you can revisit and act on it at any time. This includes any revision decisions you make (Accept/Edit/Skip per bullet and summary).
- Resume library · metadata about resume files you upload (filename, extracted skills, years of experience estimate). The extracted metadata is used to power the resume picker and soft-match scoring. We do not retain the raw file content after parsing; only extracted structured data is stored.
- Job pipeline activity · which jobs you save, dismiss, analyze, or mark as applied, including any notes you add and the date you applied, so we can track your active job pipeline and application history.
- Usage metadata · how many analyses you run (for rate-limiting purposes), your browser fingerprint (hashed, unauthenticated guests only), and your IP address (hashed, never stored in plain text).
- Billing information · if you subscribe to a paid plan, checkout is handled by Dodo Payments, our merchant of record, who collects your email, billing country, and payment details. We never see or store your card number. We store your plan tier, your Dodo Payments customer and subscription identifiers, and subscription-event records (plan changes, cancellations) needed to run your account.
2. How we process your resume
When you run an analysis, your resume text and job description are sent to Anthropic's Claude API to generate structured feedback. Anthropic's API terms prohibit using API inputs to train their models, so your resume text is not used to train any AI model.
The raw LLM output is cached for up to 7 days so that re-running the same resume against the same job description doesn't consume unnecessary API calls. Cached results are keyed by a SHA-256 hash of the combined text and are automatically deleted after the TTL expires.
3. Anonymized knowledge extraction (opt-in)
If you opt in via the Help improve Rezumable toggle in your Profile → Data & Privacy settings, we extract anonymized, aggregated patterns from your analyses, for example:
- Which skills are frequently missing for a given role (e.g. "Product Manager")
- Which certifications are commonly required but absent
- Common missing themes in job descriptions for certain roles
- High-quality, anonymized experience bullet patterns (stripped of names, companies, and dates)
These patterns are stored in aggregate knowledge tables and are used to improve search quality and coaching tips for all users. No personal details, resume text, or identifying information is ever stored in these tables.
You can withdraw consent at any time by toggling the setting off. This does not affect any data already anonymized and stored in aggregate tables.
4. Data sharing
We do not sell your personal data. We share data only with:
- Anthropic (Claude API) · resume and JD text, solely to generate analysis results. Governed by Anthropic's API data processing terms.
- Supabase · our database and authentication provider. Data is stored in EU/US regions depending on your account location.
- Apify · job search queries (keywords and location only, never your resume or personal details) to fetch job listings.
- Dodo Payments · our payments provider and merchant of record. Receives your email and billing details when you purchase a subscription, governed by Dodo Payments' privacy policy. Dodo Payments never receives your resume or analysis data.
5. Cookies and local storage
We use session-only cookies to keep you logged in. We do not use advertising, tracking, or analytics cookies.
We use browser localStorage to remember your last job search terms across page navigations (cleared when you clear your browser data) and your GDPR banner acknowledgement.
6. Data retention
- Account and profile data · retained until you delete your account.
- Analysis cache · automatically deleted after 7 days.
- Job pipeline · retained until you delete individual jobs or your account.
- Anonymized knowledge data (opt-in only) · retained indefinitely in aggregate form; cannot be individually identified or deleted once anonymized.
7. Your rights (GDPR / CCPA)
Depending on your location, you have the right to:
- Access · export your data from Profile → Data & Privacy
- Rectification · update your profile at any time
- Erasure · delete your account from Profile → Data & Privacy (all personal data removed within 30 days)
- Portability · export your data as JSON from Profile → Data & Privacy
- Withdraw consent · toggle the knowledge extraction opt-in off at any time
To exercise any right not covered by the self-service tools, email us at privacy@rezumable.com. We will respond within 30 days.
8. Security
All data is transmitted over HTTPS. Passwords are never stored. We use Supabase's email magic-link and OAuth authentication. Database access is row-level secured so each user can only read their own data.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. Continued use of Rezumable after the effective date constitutes acceptance of the updated policy.
10. Contact
For privacy questions or requests, contact us at privacy@rezumable.com.