Privacy Policy
Last updated: September 16, 2026
1. Scope
This Privacy Policy explains what personal data we collect when you use our resume builder, job-application tracker, job agent and website (together, the "Service"), why we collect it, how long we keep it, and the rights you have over it.
It is written to describe what our systems actually do. For where data is stored, how long it is kept and how to have it deleted or exported, see our Data Policy, which forms part of this policy.
2. Data We Collect
Account data
Your name, email address, username, profile picture (if your sign-in provider shares one) and the sign-in methods you use. You can sign in with email and password, a passkey, or Google, GitHub or LinkedIn. If you enable two-factor authentication, we store the authenticator secret and backup codes.
Content you create
Resume and cover-letter content — which typically includes your name, contact details, work history, education, skills, links and any photo you choose to upload — plus the styling and template choices that go with it, and previous versions we store so you can roll back.
Job-application records you add to the tracker, including the company, role, notes, any job description or document you attach, and any details you enter about other people (for example a recruiter's name, email or phone number). Please only add other people's details where you have a lawful reason to do so.
Job-agent conversations, prompt attachments you upload, and the job-search preferences you give the agent (including location, work mode and salary expectations).
Technical and usage data
Resume view and download counts, the last time a resume was viewed or downloaded, session records (including IP address and browser user-agent), and short-lived technical identifiers used to rate-limit abuse and stop repeated views.
If you use AI features, the prompts and content you send to your chosen AI provider are processed by that provider — see section 5.
3. Why We Use It
- To provide the Service — creating your account, building and exporting resumes, tracking applications, running the job agent.
- To keep your account secure — authentication, session management, two-factor and passkey verification, fraud and abuse prevention.
- To run AI features you ask for — generating and reviewing resume content using the AI provider you configure.
- To operate and improve the Service — aggregate usage counts, error diagnosis, rate limiting, capacity planning.
- To contact you — service messages such as email verification, password resets and (once billing is live) payment, renewal and receipt notices. We currently do not send marketing email or SMS; if we introduce it, we will ask for your consent first and every message will include a one-click unsubscribe.
- To meet legal obligations — for example retaining billing records where tax law requires it.
4. What We Do Not Do
- We do not sell your personal data.
- We do not use your resume content to train AI models, and we do not permit our AI providers to train on it.
- We do not run advertising or third-party analytics trackers on the Service today. If we add any, we will ask for consent first and update this policy before they go live.
5. AI Processing
AI features send the parts of your content needed for that request to an AI model provider. Today you connect your own provider account and API key, so you choose which provider processes your content and you can see that provider's terms directly. Your key is encrypted before it is stored and is never shown back to you in full.
When we move to a built-in AI service, we will name the provider in this policy before it processes any of your content, and we will not use your content to train models.
6. Sharing
We share personal data only with the providers needed to run the Service, and only for that purpose:
| Provider category | What they handle |
|---|---|
| Hosting, database and file storage | All Service data, including your account, resumes and uploads |
| Sign-in providers (Google, GitHub, LinkedIn) | Verifying your identity when you choose social sign-in; they receive the fact that you signed in |
| Email delivery | Sending verification, security and account emails to your address |
| The AI model provider you configure | The content of the AI request you make, processed under that provider's own terms |
We may also disclose data where we are legally required to, or where it is necessary to protect the rights and safety of our users or the public. If we ever share data with a buyer as part of a merger or acquisition, we will tell you before your data becomes subject to a different privacy policy.
7. Cookies
We use a session cookie that keeps you signed in — nothing else is needed for the Service to work, and there are no advertising cookies. You can clear or block cookies in your browser, but you will not be able to stay signed in without the session cookie.
8. How Long We Keep It
We keep your data while your account is active. When you delete your account we delete your account, resumes, applications, job-agent data and uploads, subject to the exceptions set out in our Data Policy (for example billing records that tax law requires us to retain).
9. Your Rights
You can:
- Access and export your data — export is available from your account settings.
- Correct your data — most of it you can edit directly in the builder or your profile.
- Delete your account and the content in it, from your account settings.
- Object to or restrict processing, and withdraw any consent you have given, at any time.
- Complain to us first, and to your data-protection authority (in India, the Data Protection Board; in the EU/EEA, your national supervisory authority).
To exercise any of these, contact us using the details on our Contact page. We respond to verified requests within the timelines required by applicable law (30 days under the EU/UK GDPR, and without undue delay under India's Digital Personal Data Protection Act, 2023).
10. Security
We use encryption in transit, access controls on our production systems, hashed passwords, and AES-256-GCM encryption for stored third-party API keys. No system is perfectly secure, so please use a strong, unique password and enable two-factor authentication or a passkey.
If a breach affects your personal data, we will notify you and the relevant authority as required by law.
11. Children
The Service is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
12. Changes
We will update this policy when our practices change, and we will tell you about material changes by email or in the Service before they take effect. The "last updated" date above always shows the current version.
13. Contact
Privacy questions and data-subject requests: privacy@oxyresume.com. Please see our Contact page for the full list of ways to reach us, including our grievance officer for India.