Privacy
Last updated 2 September 2026
This product holds people’s job searches. That is sensitive in a specific way: the damage from a leak isn’t identity theft, it’s a current employer finding out. Everything below follows from taking that seriously.
What we collect from you
- Your account — email address, name, and an optional photo. The email comes from signing in and is how we reach you.
- Your evidence base — whatever you import or tell us: roles, projects, achievements, the answers you give in the interview. This is the material your pages are built from.
- Your applications — the postings you paste, the research we do on the company, the pages generated from them, every saved version of each page, and the outcome you record.
- Your invite request — the email, roles, and any note you sent when asking in, plus the country the request came from. Deleted with your account.
What we collect when someone opens a published page
Published pages carry our own analytics and no one else’s. There are no third-party scripts, no advertising pixels, no session recorders, and no cookies set on readers.
- A hashed IP address. The raw address is never stored. It is hashed with a salt that changes daily, so a second read on the same day can be recognised as a return; it cannot be reversed into an address, and it does not link reads across days.
- Country and region only. Never a city, a street, or a coordinate. It exists to answer “which application produced attention”, not “which person”.
- The user-agent string, used to identify automated scanners.
- Interaction signals — time on page, scroll depth, whether a pointer moved, which sections became visible. These feed the score that decides whether a read was a person or a robot.
We do not attempt to identify who read a page, and the product is not built to support it. It reports that a page was read, not by whom.
What we never do
- Sell or rent your data, or share it with advertisers.
- Index your pages. Every published page is served
noindex, nofollow, and there is no public directory. - Use your evidence base to train a model.
- Email you about anything you have switched off in your notification settings.
Who else processes it
Running this needs a small number of suppliers. Each one sees only what it needs:
- Supabase — the database and sign-in, hosted in the United States. Holds your account, evidence and applications.
- Vercel — hosting and content delivery. Sees requests in transit.
- Anthropic — the model that reads your resume, researches the company and drafts pages. Receives the text of your resume at import; the text of a posting when you paste it; the company, role and team during research, which it uses to search the web; and, at selection and generation, the posting, your name, your whole confirmed evidence base, and the interview answers where you said you haven’t done something. Your data is not used to train their models.
- Resend — sends our email. Sees your address and the message.
How long we keep it
Your account and evidence base last until you delete them. Published pages and their read history are kept while your account is open, because “what did they actually receive” is a question people ask months later. Delete an application and its pages and events go with it, immediately and permanently.
Your choices
- Export everything — your evidence base, applications, every saved version of every page, and the read and scan history — as one JSON file, from Settings → Account.
- Edit or delete any evidence snippet from your profile.
- Delete an application, which removes its pages, versions and entire read history.
- Turn off any notification, in the product or by email, in settings.
- Delete your account from Settings → Account, which removes everything above at once, including your photo and your invite request. Your sign-in identity is removed within a few days; until it is, we keep only your account id and email on a deletion list, so that signing in again cannot recreate the account. Write to us if you want the identity removed sooner.
Getting in touch
Questions, requests, or a correction to any of the above: privacy@resumecomputer.com.