Last updated: 2026-03-30. Align with GDPR, KVKK, CCPA, or other local rules as applicable; qualified legal review is recommended before relying on this text alone.

Privacy Policy

This policy describes how ResumAI ("we") processes information when you use our website and services (the "Service").

1. What we collect

  • Account data: email address and authentication identifiers from Supabase Auth when you sign in.
  • Content you submit: resume text, job descriptions, and files you upload for analysis or import. These are processed to provide the Service.
  • Usage and technical data: server logs, cookies and similar technologies for sessions, preferences, and rate limits. See our Cookie notice.
  • Payment metadata: transactions are processed by our payment provider; we do not store full card numbers on our servers.

2. How we use data

To operate the Service, authenticate users, provide AI features where enabled, prevent abuse, and comply with law.

3. AI processing

When you use ATS analysis or optional AI-assisted flows, text may be sent to Google Gemini (or another model you configure) to produce scores, suggestions, or structured data. PDF import uses rule-based text extraction and mapping by default; generative AI is not required for that path unless you enable it in server configuration.

4. Storage

Many AI requests are processed in memory for the duration of the request. PDF uploads are handled transiently on the server for import. Account and entitlement data (e.g. credits, plan flags) may be stored in Supabase. Do not submit data you are not allowed to share.

5. Subprocessors (typical stack)

  • Vercel — hosting
  • Supabase — authentication and database
  • Lemon Squeezy — payments
  • Google (Gemini) — AI inference when those features are used

The processors we use may change over time; significant updates will be reflected in this policy where required.

6. Retention and deletion

Retention depends on provider settings and your account. You may request deletion where applicable law requires; some records may be kept for legal, tax, or fraud-prevention reasons.

7. Security

We use industry-standard measures appropriate to the Service. No method of transmission over the Internet is completely secure.

8. International transfers

Subprocessors may process data in the EU, US, or other regions. Use appropriate transfer mechanisms (e.g. SCCs, DPA) where required for your users.

9. Your rights

Depending on where you live, you may have rights to access, rectify, delete, or restrict processing. Contact us at the address below where applicable.

Privacy requests: tevfikuykun@gmail.com

10. Children

The Service is not directed at children under the age required by applicable law.

11. Updates

We may update this policy and will change the "Last updated" date or notify you of material changes where required.

Back to home