Privacy policy
Last updated 2026-01-01.
A job search involves a lot of personal information: where you have worked, what you were paid, who you spoke to, and sometimes what you said out loud in an interview. This page states what Resume Match stores, why, for how long, and how to get it out or have it destroyed.
The short version
- We store your resume content, documents you upload, tailored versions, transcripts, your credit ledger and payment records — because those are the product.
- Interview audio is never stored by default (and it is not switched on in this deployment).
- Logs are redacted: email addresses are masked before they are written.
- You can export everything as JSON, and delete your account outright. Deletion is real.
- Third-party processors receive the minimum needed for the specific operation you asked for.
1. What we store, and why
Account details
Your name, email address, timezone, marketing preference, account status and timestamps. Passwords are stored only as a one-way hash — we cannot read them, and neither can anyone who takes a copy of the database.
Resume content
The structured resume we extract or that you type: contact details, headline, summary, skills, employment history, projects, education, certifications, awards, languages and any other sections you fill in. This is the source of truth everything else derives from.
Uploaded documents
The original file you upload, stored privately and readable only through your own account. It is the most complete copy of your personal data that we hold, which is why deleting a resume deletes the original file too, and why its retention is bounded (§4).
Tailored versions and generated documents
Each tailored resume, the advert it was tailored against, the change log showing what was rewritten or removed, the compatibility report, and any PDF or DOCX generated from it.
Job adverts you paste or fetch
The text of the advert, its title, company and source URL, stored so the version you sent stays attached to the job it was for. Adverts are stored per account.
Applications and interview transcripts
The applications you track (company, role, status, notes, next action dates) and, when interview practice runs, the transcript text that the report is built from, the report itself, and timings.
Credit ledger, orders and usage records
Every credit grant, hold, consumption and refund, with the reason and the reference; the orders you placed with their amounts, currency and status; and per-operation AI usage records (model, token counts, latency, computed cost) which is how we keep the cost of a pack honest.
Security and audit records
An audit trail of actions that affect your data, money or access — a resume was deleted, credits were granted, an account was erased — together with the IP address and user agent of the request. Audit metadata is deliberately scrubbed: free text is truncated and resume content is never copied into it.
2. Interview audio
Interview audio is not stored by default. The setting that would retain it (interview.store_audio) is off in this deployment. What is kept is the transcript text, because the scored report cannot be produced or explained without it.
If an operator switches audio retention on, that materially increases the sensitivity of the data held, and it should be reflected in this policy before it is switched on. The application surfaces the setting where it is relevant rather than leaving it implied.
3. Who else sees your data
We do not sell your data, and we do not share it for advertising. Three categories of processor may receive the minimum necessary to perform an operation you asked for:
- An AI provider (for example OpenAI) — receives the relevant part of your resume and, for tailoring or matching, the advert text, so it can produce the rewrite, the findings or the explanation. Nothing is sent for an operation you did not trigger.
- A job search API (for example JSearch on RapidAPI) — receives the search terms derived from your profile and preferences: target titles, locations, seniority and a few distinctive skills. It does not receive your name, email address, resume document or contact details.
- A payment provider (for example Dodo Payments) — receives the order reference, the pack purchased, the amount and the email address needed for a receipt. Card details are entered on the provider's own hosted page and never reach our servers.
Where an operator runs this deployment with stub providers instead of live ones, nothing leaves the server at all — and the app says so prominently on every screen it affects.
4. How long we keep things
These are the outer bounds applied by automatic cleanup:
- Uploaded source documents
- 365 days (12 months) after upload, or until you delete the resume — whichever comes first.
- Generated exports (PDF/DOCX)
- 90 days, or until you delete the resume or tailored version. Editing a resume also clears its cached exports immediately, so a stale document cannot be downloaded by mistake.
- Resume content, tailored versions, applications
- Kept while your account exists, because they are the product. Deleted immediately when you delete them, and erased with the account.
- Interview transcripts and reports
- Kept while your account exists so you can review them. You can delete them, and account deletion erases them.
- Credit ledger and orders
- Kept while your account exists, because they are your financial record. Erased with the account.
- Audit log
- Kept for security and to evidence requests. The row recording that your account was deleted is retained after deletion — it contains no resume content, and it is the proof the request was honoured.
- Deleted accounts
- Erased at the moment you confirm deletion. Any residual backup copy is purged within 30 days.
5. Logs and PII redaction
Operational logs record what happened, not who you are. Email addresses written to logs are masked (for example j•••@example.com) and long free-text values are truncated before they are stored. We do not log resume content, advert text, transcripts, or passwords, and log entries identify you by internal id rather than by name or address.
6. Your rights
Export
Download everything we hold about you as a single JSON file: account details, resumes, tailored versions with their change logs and reports, applications, job preferences, orders, interview records, the credit ledger and the audit log. Passwords and API credentials are not included. The export is generated in memory and handed straight to you rather than written to disk, so it does not create a new copy to look after.
Correction
You can edit your profile, your resumes and your applications directly. Nothing here requires asking us.
Deletion
Account settings contains a delete form that requires you to type your email address and your password. Confirming it permanently erases your account and, with it, your resumes, tailored versions, generated documents, uploaded files, transcripts, applications and credit history. This cannot be undone.
Objection and portability
You can turn off marketing email at any time from account settings; transactional email about your account is not marketing. The JSON export above is your portable copy.
7. Security
Traffic is encrypted in transit. Passwords are hashed with a modern algorithm. Uploaded files are stored outside the web root and served only through an authenticated route that checks ownership in the database query itself, so a guessed id returns "not found" rather than somebody else's resume. Sessions are regenerated at sign-in and invalidated on password change, and every state-changing request carries a CSRF token.
8. Contact
For any privacy question, an access request, or a deletion you cannot complete through the app: support@example.com.
See also the terms of service.