Legal
Privacy policy
Last updated: 29 August 2026
This notice explains how Resumea processes personal data under the GDPR. Resumea is the controller for account, CV, vacancy, support, and service-usage data. Contact the controller at support@resumea.ai.
1. Data we process
- Account: name, email address, authentication identifiers, account timestamps, and language preferences.
- Career and CV: contact details, work history, education, skills, languages, certifications, projects, work-authorisation information, uploaded photo, edits, and generated CV versions.
- Vacancy and application: job links, copied descriptions, employer and role information, match analysis, interview preparation, salary guidance, and application status.
- Payment and contract: selected pass, amount, currency, payment status, provider order identifier, acceptance timestamp, and contract version. Revolut handles full payment-card details.
- Technical and support: IP address and request metadata in provider logs, browser/device information, security events, error records, and messages you send to support.
PDF and DOCX files are read in your browser. Only extracted text and the information needed for the feature are sent to the AI service; the original CV file is not intentionally uploaded to OpenAI. A photo is stored with your CV in Resumea but is not sent to the text-generation model.
2. Purposes and legal bases
- Provide the service
- Account creation, CV storage, AI generation, editing, export, and support — necessary to perform the contract or take requested pre-contract steps (GDPR Article 6(1)(b)).
- Payments and records
- Process purchases, refunds, disputes, tax, and accounting records — contract and legal obligations (Articles 6(1)(b) and 6(1)(c)).
- Security and reliability
- Prevent abuse, protect accounts, debug failures, and defend legal claims — legitimate interests in operating a secure service (Article 6(1)(f)).
- Optional communications
- Marketing will be sent only with a valid consent or another legal basis permitted by applicable law. No marketing programme is active at launch.
Providing account, CV, and vacancy information is optional, but Resumea cannot create or save the requested output without the relevant information. Payment data is required only for a paid pass.
3. AI processing and automated decisions
Resumea sends relevant extracted CV text, career-profile data, vacancy text, and instructions to the OpenAI API to produce the features you request. API content is not used by OpenAI to train its models by default. Resumea requests that generated responses are not stored as long-term application state; background processing still requires short temporary storage, and standard abuse-monitoring logs may be retained by OpenAI for up to 30 days unless different approved controls apply.
Resumea does not make a solely automated decision that produces legal or similarly significant effects. Match scores and suggestions are advisory. You choose what to accept, and an employer—not Resumea—makes recruitment decisions.
4. Service providers and recipients
- Supabase: authentication, database, and account storage.
- Netlify: website hosting, serverless functions, delivery, and operational logs.
- OpenAI: AI text processing for requested features.
- Revolut: hosted checkout, payment processing, refunds, and fraud controls.
- Cloudflare cdnjs: delivery of browser libraries used to read documents and create PDFs.
We may also disclose data to professional advisers, public authorities, courts, or law enforcement where necessary and lawful. We do not sell personal data.
5. International transfers
Some providers or their sub-processors may process data outside the EEA. Where required, transfers rely on an adequacy decision, the European Commission’s Standard Contractual Clauses with appropriate supplementary measures, or another lawful transfer mechanism. Contact the controller for information about the safeguards relevant to the deployed provider configuration.
6. Retention
- Account, career profile, saved CVs, jobs, and applications are kept until you delete them or ask for account deletion, unless a legal claim requires limited longer retention.
- Payment and contract records are kept for the statutory tax and accounting period applicable where Resumea’s operator is established.
- Support correspondence is normally kept for up to 24 months after the matter is closed, unless needed for a claim.
- Operational and security logs follow provider settings and are normally kept only as long as needed for security and debugging; content in OpenAI abuse-monitoring logs may be retained for up to 30 days.
- Unsaved local drafts and preferences remain on your device until the product clears them, you sign out where applicable, or you clear browser storage.
Backups are deleted on the provider’s rolling schedule. Deleted data may remain in a protected backup until that backup expires and is not restored except for disaster recovery.
7. Your GDPR rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time where consent is used, without affecting earlier lawful processing. Requests are free unless manifestly unfounded or excessive.
Send requests to support@resumea.ai. We may ask for proportionate proof of identity. You may complain to the data-protection authority in the Member State of your residence, workplace, or the alleged infringement.
8. Security
Resumea uses encrypted transport, account authentication, row-level database access controls, server-side payment verification, restricted credentials, and usage guards. No internet service is risk-free. Use a unique password and do not include unnecessary sensitive information in a CV.
9. Children
Resumea is intended for adults and is not directed to anyone under 18. Contact us if you believe a minor has created an account so the data can be reviewed and, where appropriate, deleted.
10. What is stored on your device
Resumea does not use advertising cookies or analytics cookies at launch. It uses browser storage needed to keep the service, account, preferences, drafts, and checkout continuation working.
- Authentication
- Session and refresh information used to keep you signed in securely and restore your account session.
- Preferences
- Interface language, CV language, and related choices you explicitly make.
- Draft recovery
- An unsaved CV draft so accidental refreshes or closing the browser do not immediately destroy work.
- Navigation
- Short-lived state needed to restore the correct step without repeating an AI request.
- Checkout return
- The selected application, pass, and intended action so Resumea can continue after hosted payment.
11. Why no consent banner appears
At launch, device storage is used only where necessary to provide a feature you request, authenticate you, keep the service secure, remember an explicit preference, or recover your work. Resumea therefore does not present a banner asking for optional tracking consent when there is no optional tracking to accept.
If analytics, advertising, or another non-essential technology is added later, it must remain disabled until you make a real choice, and rejecting it must be as easy as accepting it.
12. Third-party resources
Resumea loads document-reading and PDF-generation libraries from Cloudflare cdnjs. Requesting those files discloses ordinary connection data such as your IP address and browser user agent to the delivery provider. Hosted payment runs on Revolut’s page and is subject to Revolut’s own storage and cookie information.
13. Your controls
You can clear Resumea site data using your browser’s privacy or site-storage settings. Doing so may sign you out and remove local preferences or an unsaved draft; saved account data remains until deleted separately. Blocking all storage may prevent sign-in and draft recovery from working.
14. Changes and contact
Material changes will be announced in the service or by email when appropriate. The effective version will remain available here. Questions and privacy requests can be sent to support@resumea.ai.