Legal
Privacy Policy
Effective: May 1, 2026 · Last updated: May 2026
We believe privacy is a fundamental right. We do not sell your personal data. We retain and use it only to operate the Service for you, for user and product analytics that help us improve the experience, and for internal training and quality work so we can serve the community better — never for ad resale or data brokerage.
At a Glance
No sale of data; how we use what we store
We store and process the information described in this policy only for the following purposes, each aimed at serving you and the user community better:
- Operating the Service: authentication, saving your resumes and analyses, generating tailored content and PDFs, and support when you contact us.
- User and product analytics: understanding how features are used (including through tools such as Google Analytics 4), so we can fix friction, prioritize improvements, and measure reliability — typically in aggregated or otherwise privacy-preserving form where feasible.
- Internal training and quality improvement: improving prompts, scoring, ATS checks, and related workflows; validating outputs; and building a safer, more accurate experience for everyone. This work uses data only as permitted by this policy and applicable law — not for unrelated commercial exploitation.
We do not use your information for third‑party targeted advertising, and we do not monetize personal data by selling it.
Separate from the above: when you use AI features, portions of your content are sent to Google's Gemini API as described in Section 5. Google processes that traffic under its ownterms and privacy rules — which are distinct from Resunova's no-sale and limited-use commitments in this section.
1. Who We Are
Resunova (“we,” “us,” or “our”) operates the AI resume tailoring platform at www.resunova.io.
For data-related inquiries, contact: privacy@resunova.io
2. Information We Collect
2.1 Account Information
When you sign in with Google, we receive from Google's OAuth 2.0 service:
- Your email address
- Your name
- Your Google profile picture URL
- A unique Google user ID
We use this to create and identify your account. We do not access your Google Drive, Gmail, or any other Google service.
2.2 Resume & Job Content
To provide the core service, we process:
- Uploaded resume PDFs: Text is extracted from your PDF and sent to our AI to generate tailored content. The original PDF is not permanently stored.
- Job descriptions: The text you paste or import is used to tailor your resume. It is stored temporarily during your session.
- Generated resume content: Your tailored LaTeX source and compiled PDFs are stored in Supabase Storage, associated with your account.
- Analysis results: Match scores, criteria breakdowns, ATS reports, and AI rewrite history are stored in our database.
2.3 Usage & Analytics
We use Google Analytics 4 (GA4) to collect anonymous usage data including pages visited, session duration, and general geographic region. This data is aggregated and not linked to your identity.
You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
3. How We Use Your Information
Consistent with the commitments above, we use information only as needed for the Service, analytics, and internal training and quality improvement — never by selling it.
- To deliver the Service: Processing your resume with AI, generating tailored versions, computing match scores, running ATS checks
- To maintain your account: Storing your saved resumes, analysis history, and preferences
- User analytics: Usage patterns and product metrics (including via GA4) help us understand how the product is used and where to invest so we can serve users better
- Internal training and improvement: Calibrating prompts, scoring, ATS checks, and QA workflows using stored content and outcomes where appropriate, so accuracy and safety improve over time for the community
- To communicate with you: Transactional emails only (e.g., password resets if applicable). We do not send marketing emails without your explicit consent
4. Third-Party Services
Purpose: Database and file storage for your account data, saved resumes, and analysis results
Data shared: Email, user ID, resume content, analysis results, generated PDFs
Location: US/EU (varies by Supabase region)
Purpose: Authentication — sign in with your Google account
Data shared: Email, name, profile picture, Google user ID
Location: US (Google LLC)
Purpose: AI large language model used to tailor your resume, rewrite bullets, and generate analysis
Data shared: Resume text, job description text
Location: US (Google LLC)
Purpose: Anonymous usage analytics to understand how the product is used
Data shared: Page views, session data, anonymized device/browser info
Location: US (Google LLC)
We do not sell, rent, or trade your personal data. We do not share it with advertising networks, data brokers, or any other third party for their independent marketing or resale. Processors listed above receive data only to perform services on our behalf (hosting, auth, AI inference, analytics) under contractual and legal safeguards — not so they can sell your résumé or profile.
5. AI Processing Notice
Resunova vs. Google: The commitments elsewhere in this policy — for example that we do not sell your personal data and that we use data stored on our side only to operate the Service, run analytics, and improve quality for users — describe Resunova's practices and our agreements with you. They are not a substitute for Google's terms. When your content is transmitted to the Gemini API, it is processed on Google's infrastructureas an independent service provider; we do not control Google's internal systems, retention windows for transient API traffic, or any product-improvement or safety practices Google applies to its APIs as described in Google's own documentation.
We send Google only what is reasonably necessary to fulfill each AI request (typically the résumé and job-description text you are actively working with). Outputs are returned to Resunova so we can show you results and save them to your account when you choose to save. For the most current rules on what Google does with API inputs and outputs, rely on Google's published terms and privacy materials linked above.
We recommend you do not include sensitive personal information (Social Security numbers, financial account details, passwords) in any content submitted to the Service.
6. Data Retention
We keep personal data no longer than necessary for the purposes in this policy — principally running the Service for you, analytics to improve the product, and internal training and quality work.
- Account data (email, name): Retained until you delete your account
- Saved resumes and analysis history: Retained until you delete individual records or your account
- Uploaded PDF text: Processed in memory during generation; not permanently stored
- Analytics data: Governed by Google Analytics retention settings (typically 14 months)
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Portability: Request an export of your data in a machine-readable format
- Objection: Object to certain types of processing (e.g., analytics)
To exercise any of these rights, email privacy@resunova.io. We will respond within 30 days.
8. Cookies
We use only essential session cookies required for authentication (managed by Supabase) and Google Analytics cookies for anonymous usage tracking. We do not use advertising or tracking cookies.
9. Security
We implement industry-standard measures to protect your data:
- All data is transmitted over HTTPS/TLS
- Database access is controlled by Row-Level Security (RLS) policies — your data is only accessible to your account
- Authentication is handled by Supabase Auth with Google OAuth 2.0
No system is 100% secure. If you discover a security vulnerability, please disclose it responsibly to security@resunova.io.
10. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email (if we have your contact) or a notice on the Service. The “Last updated” date at the top of this page reflects the most recent revision.
Your continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact
For privacy-related questions, data requests, or concerns: