Privacy Policy
This policy explains what personal data resumus.io processes, why, for how long, and what you can do about it. The controller of your data is the operator of resumus.io; contact: hello@resumus.io.
1. What we process
- Account: your name, email address, a hash of your password or the identifier of the sign-in provider you chose, and your interface language.
- Resumes: everything you enter into a resume, including contacts and a photo if you add one. Photos are cropped, reduced and stripped of their metadata (such as GPS coordinates) when you upload them.
- Payments: your plan, purchases and the identifiers Paddle gives us for your customer record and subscription. Card data never reaches us.
- Public pages: the content you publish and a count of views per day. We do not store the IP addresses or identities of people who view a page.
- Technical data: session cookies, and the IP address and browser of your sessions, which we use to keep accounts safe and to limit abuse.
- Usage and errors: anonymous product events (for example "a PDF was downloaded") without cookies, and error reports that help us fix bugs.
A guest resume (made without an account) stays only in your browser until you sign up.
2. Why we process it
- To provide the service you asked for (a contract): your account, resumes, PDFs, public pages, payments and service emails such as email confirmation or a payment notice.
- Our legitimate interest in a safe and working service: security, abuse prevention, anonymous statistics and error reports.
- Legal obligations: Paddle keeps invoices and tax records as the law requires.
We do not sell your data, do not show advertising and do not use your resumes to train AI models.
3. Public pages
A page you publish is visible to anyone who has its address. By default it asks search engines not to index it; you can allow indexing, hide your email and phone, or take the page down at any time in its settings.
4. Who receives your data
We use these processors, each only for its task:
| Processor | Task |
|---|---|
| Vercel | hosting |
| Neon | database |
| Cloudflare | file storage and DNS |
| Resend | sending email |
| Paddle | payments, invoices and taxes (as Merchant of Record) |
| PostHog | anonymous product statistics, without cookies |
| Sentry | error reports |
If you sign in with Google, LinkedIn or GitHub, that provider tells us your name and email address.
Your data is stored in the European Union. Where a processor handles data outside the EU, it does so under the standard contractual clauses of the European Commission.
5. Cookies
We use only the cookies the service needs to work: your session, your language and similar settings. There are no advertising or tracking cookies, which is why there is no cookie banner.
6. How long we keep it
- Your account and resumes: until you delete them.
- When you delete your account, resumes, files and public pages are deleted at once; the rest within 30 days.
- Backups are kept for 14 days.
- Paddle keeps payment records for as long as tax law requires.
7. Your rights
You can:
- export all your data as JSON in Settings → Security;
- correct it in your profile and in the editor;
- delete your account in Settings → Security;
- object to processing or ask us to restrict it by writing to us;
- complain to the data protection authority of your country.
We answer requests within 30 days.
8. Children
The service is not meant for people under 16, and we do not knowingly collect their data.
9. Changes
If this policy changes in a way that matters, we tell you by email or in the app before the change takes effect.
Last updated: September 30, 2026