Privacy Policy

Last updated: 12/12/2025

1. Introduction

Welcome to ResumeTuneUp. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, and safeguard your information when you use our resume improvement service.

2. Information We Collect

When you use ResumeTuneUp, we may collect the following information:

  • Resume documents that you upload for analysis
  • Basic contact information (email address) if you create an account
  • Usage data and analytics to improve our service
  • Technical information such as IP address, browser type, and device information
  • Authentication information when you sign in with Google including your name, email address, and profile picture

3. Legal Basis for Processing

Under GDPR, we process your personal data based on the following lawful bases:

  • Performance of Contract: Processing your resume is necessary to provide the analysis service you've requested
  • Legitimate Interest: Improving our service quality and user experience
  • Legal Obligation: Complying with applicable laws and regulations

4. How We Use Your Information

We use your information to:

  • Analyze your resume and provide AI-powered improvement suggestions
  • Authenticate and create your account when you sign in with Google
  • Communicate with you about your account and our services
  • Improve our service quality and user experience
  • Comply with legal obligations

5. Data Storage and Security

Data Location: Your data may be stored in the United States or European Union on Cloudflare R2 servers. For AI processing, we may use OpenAI, Anthropic, or Google's AI services (primarily US-based). Any international transfers are protected by Standard Contractual Clauses as provided in the applicable provider's Data Processing Agreement.

Data Retention: For guest users, your resume data is stored on our secure servers for a maximum of 7 days to perform the analysis and provide you with recommendations. After this period, guest user resume data is automatically deleted from our systems. If you create an account and choose to save your analysis, your resume data will be retained until you delete your account or request deletion of your data.

Security Measures: We implement industry-standard security measures to protect your data, including encryption in transit and at rest, secure access controls, and regular security audits.

6. Data Sharing

We do not sell your data. We may share your information only in the following circumstances:

  • With your explicit consent
  • To comply with legal obligations or court orders
  • With trusted service providers who help us operate our service (under strict confidentiality agreements)
  • With third-party AI providers (OpenAI, Anthropic, and/or Google) solely to process your resume content and generate analysis results
  • With Google for authentication purposes only, to verify your identity and create your account
  • With Facebook for advertising purposes - we may share hashed email addresses with Facebook to improve ad targeting and measure ad effectiveness
  • With LinkedIn for advertising purposes - we may share hashed email addresses with LinkedIn to track conversions and measure ad effectiveness
  • In the event of a business transfer or merger

7. Your Rights

You have the right to:

  • Access the personal information we have about you
  • Request correction of inaccurate information
  • Request deletion of your personal information
  • Restrict processing of your personal information
  • Object to processing of your personal information
  • Withdraw consent (where consent is the legal basis)
  • Data portability (receive your data in a structured format)
  • Lodge a complaint with your local data protection authority

To exercise these rights, please contact us at support@resumetuneup.ai. We will respond to your request within 30 days as required by GDPR.

8. Children's Privacy

Our service is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

9. Third-Party Services

We integrate with Google's authentication service to allow you to sign in to our service. When you use Google Sign-In:

  • You will be redirected to Google's authentication page
  • Google will share basic profile information (name, email, profile picture) with us after you grant permission
  • Google's privacy policy governs how they handle your data during authentication
  • You can revoke access to your Google account at any time through your Google account settings

We also use third-party AI providers (OpenAI, Anthropic, and Google) to process resume content and generate recommendations:

  • Your resume content may be sent to these providers for processing
  • We minimize the data shared to what is necessary for analysis
  • Processing is subject to the providers' terms and data protection agreements, including Standard Contractual Clauses where applicable

We use ConvertAPI for PDF generation and image conversion to create optimized resumes and generate visual previews:

  • Your resume data is temporarily sent to ConvertAPI for PDF generation and image conversion
  • The converted files are downloaded and stored securely on our servers
  • ConvertAPI processes only the content necessary for document conversion
  • Processing is subject to ConvertAPI's terms of service and privacy policy

We use Hotjar for behavior analytics to understand user interactions:

  • Hotjar collects data about your interactions with our website including mouse movements, clicks, and scrolling patterns
  • This data may include session recordings and heatmaps to help us improve the user experience
  • Hotjar's servers may be located in the EU or USA
  • You can opt-out of Hotjar tracking at: https://www.hotjar.com/policies/do-not-track/
  • Processing is subject to Hotjar's terms of service and privacy policy

We use Facebook Pixel for advertising and conversion tracking:

  • Facebook Pixel tracks page views, conversions, and user interactions to help us measure and optimize our advertising campaigns
  • We may share hashed versions of your email address with Facebook for custom audience matching and to improve ad targeting
  • Facebook may collect additional data such as IP address, browser information, and device type
  • This data is processed according to Facebook's Data Policy
  • You can opt-out of Facebook tracking by adjusting your Facebook ad preferences or using browser extensions that block tracking pixels

10. Cookies and Tracking

We use cookies and similar tracking technologies to improve your experience on our website. You can control cookie settings through your browser preferences.

Analytics Services: We use the following analytics services:

  • Plausible Analytics: A privacy-focused analytics service that does not use cookies and complies with GDPR requirements
  • Hotjar: A behavior analytics service that helps us understand how users interact with our website. Hotjar may use cookies and collect data such as mouse movements, clicks, and scrolling behavior to create heatmaps and session recordings. This data is stored on Hotjar's servers (which may be located in the EU or USA) and is used solely to improve user experience. You can opt-out of Hotjar tracking by visiting: https://www.hotjar.com/policies/do-not-track/
  • Facebook Pixel: Used for advertising measurement and optimization. Facebook Pixel tracks user interactions, page views, and conversions on our website. We may share hashed email addresses with Facebook to create custom audiences and improve ad targeting. You can opt-out through your Facebook ad settings or by using ad-blocking browser extensions.
  • LinkedIn Insight Tag: Used for advertising measurement and optimization. LinkedIn tracks user interactions, page views, and conversions on our website. We also use LinkedIn's Conversions API to share hashed email addresses when purchases occur. You can opt-out through your LinkedIn ad settings.

We use LinkedIn Insight Tag and Conversions API for advertising and conversion tracking:

  • LinkedIn Insight Tag tracks page views, conversions, and user interactions to help us measure and optimize our advertising campaigns on LinkedIn
  • We use LinkedIn's Conversions API to share hashed versions of your email address with LinkedIn when you make a purchase, enabling more accurate conversion tracking
  • LinkedIn may collect additional data such as IP address, browser information, and device type through the Insight Tag
  • This data is processed according to LinkedIn's Privacy Policy
  • You can opt-out of LinkedIn tracking by adjusting your LinkedIn ad settings or visiting LinkedIn's opt-out page

11. Data Breach Notification

In case of a data breach affecting your rights and freedoms, we will notify you without undue delay as required by GDPR.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

13. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us at:

Email: support@resumetuneup.ai

For data protection inquiries, our Data Protection Officer can be reached at the same email address.