Privacy Policy
Last Updated: July 1, 2026
Encrypted & Secure
Authentication runs on a secure, self-hosted identity system. Data is encrypted in transit (TLS) and at rest.
No Data Brokers
Your resume text, work experience, and profile details belong entirely to you. We never rent or sell your data to brokers.
No Model Training
AI features run on managed cloud AI infrastructure. We never use your content to train third-party models, and we log AI usage as token counts and operational metadata only.
1. Information We Collect
To build, analyze, render, and export your professional resumes or CV layouts, EliteResume AI collects the following:
- Account & Identity Data: Full name, email address, authentication identifiers, and (if you sign in with a third party) your Google, GitHub, or LinkedIn account identifier. Passwords are held by our identity provider, not in plain text. We also store your profile avatar.
- Resume & CV Content: Experience bullets, job titles, education details, certifications, skills, and personal contact information — including any free-text you choose to enter. Please avoid including special-category information (e.g., health, religion, ethnicity, political or trade-union membership) unless necessary for your application.
- Billing Data: When you subscribe, our payment processor (Stripe) handles your card details; we store your Stripe customer/subscription/invoice identifiers and invoice records. We do not store full card numbers.
- Referral Data (if you use the referral program): Referral codes and click records. We never store raw IP addresses or device identifiers for referral tracking — only irreversible cryptographic (HMAC) hashes.
- Usage & Diagnostic Logs: Limited operational logs, security events, diagnostics, performance analytics after consent, and the strictly necessary cookies that keep your session active. We do not use advertising cookies, cross-site ad pixels, session replay, or keystroke logging tools.
2. How We Process Your Data
EliteResume AI uses your data to provide the resume-building features you request:
- Rendering & Export: Transforming your inputs into formatted PDF, Word, and plain-text outputs.
- AI Optimization: To perform AI features you request - resume parsing, bullet and summary rewriting, cover-letter generation, and ATS analysis - the relevant resume or job-description text is sent to large language models running on cloud AI infrastructure, primarily AWS Bedrock. Some legacy, fallback, or development endpoints may use Google Gemini where configured. This text can include personal data, so that you receive accurate, tailored results. We do not use your content to train third-party models, and we record AI usage as token counts and operational metadata only - not the text of your prompts or the AI output.
- ATS Scoring: Resumes are compared programmatically against target job descriptions to calculate keyword matches.
We process this data on the legal basis of performing our contract with you (delivering the Services). Where free-text contains special-category data, we rely on your voluntary provision of it for your own resume.
3. Security & Storage
We implement robust safeguards to keep your information secure:
- Account records are stored in managed cloud databases, and your files (uploaded CVs, exported PDFs, avatars) in cloud object storage (Amazon Web Services). Authentication is handled by a secure, self-hosted identity management system.
- Communication between client, backend, and API layers is encrypted in transit (TLS), and data is encrypted at rest.
- Access to your resumes requires authentication and is restricted to your own account; file links are time-limited and expire automatically.
4. Sub-processors & International Transfers
We share data with trusted service providers only as needed to run the Services: Stripe (payments), Amazon Web Services (AI processing via Bedrock, file storage, infrastructure), Google (optional sign-in, Google Fonts, analytics after consent, and Gemini AI processing where configured), Sentry (error monitoring and diagnostics after consent), Brevo (transactional email), and Cloudflare (security and content delivery). These providers act as our processors or service providers where applicable under data-processing agreements. If you sign in via Google, GitHub, or LinkedIn, those providers act as independent controllers for the sign-in data you authorize.
Some of these providers process data in the United States. Where you are in the EU/UK, such transfers are made under appropriate safeguards (e.g., Standard Contractual Clauses or an applicable adequacy/Data Privacy Framework mechanism).
5. Data Retention
We keep your account and resume content until you delete your account. Uploaded CV files and exported PDFs are deleted once no longer needed or when the related resume/account is removed. AI usage logs and completed background jobs are purged on a rolling retention schedule. Invoices and similar financial records are retained where we are legally required to keep them (e.g., for tax and accounting).
6. Your Rights and Deletion Control
We believe in genuine user ownership of data. You can:
- Access & Export (Portability): Download a complete, machine-readable copy of all your personal data (profile, resumes and versions, cover letters, saved jobs, and billing history) from your account, in addition to exporting individual resumes as PDF/Word.
- Rectify: Edit and overwrite any resume or profile detail directly in the editor.
- Delete (Erasure): Account deletion is a two-step, email-verified process. Confirming it permanently removes your profile, resumes, cover letters, uploaded files, and exports from our systems (subject to records we must legally retain). Any active subscription is scheduled for cancellation.
- Manage Sharing: If you enable a public share link for a resume, you can revoke it or set it to expire; expired and revoked links stop working immediately.
- Object, Restrict & Withdraw Consent: You may opt out of marketing email and, where applicable, object to or restrict certain processing.
- Complain: EU/UK users have the right to lodge a complaint with their local data protection supervisory authority.
To exercise any right not available as a self-service action, contact us at privacy@eliteresume.net.
7. Policy Changes
We may periodically update this policy to reflect changes to our practices, security, or legal requirements. We will record the version in effect when you accept it, and material changes will be communicated where appropriate. Continued use of the Services after an update constitutes acceptance of the revised policy.
8. Cookies, Analytics, Diagnostics & Third-Party Assets
Essential cookies are used for secure sessions, fraud prevention, account continuity, referrals, and core product functionality. Optional analytics and personalization storage are disabled by default and are activated only after you choose Accept all or enable the relevant category in Cookie Preferences. When analytics is enabled, we may load Google Analytics / Google Tag Manager to understand aggregate product usage and Sentry to diagnose browser errors and performance problems. Sentry is configured not to collect request bodies or default user PII, and we suppress query strings, cookies, and request headers before events are sent.
The site may load Google Fonts and Google Sign-In assets from Google-controlled domains. Google Sign-In loads only when needed for authentication. Public resume links, embedded YouTube no-cookie videos, payment flows, and social links may send limited technical information to the relevant third party when you choose to use them. You can change cookie preferences from the footer at any time.
Have privacy questions?
We are dedicated to safeguarding your candidate credentials. Reach out to our legal support desk anytime.