Privacy Policy

Last updated: 3 September 2026

What we collect

When you create an account we store your email, display name, phone number, and a hashed password (argon2id, never the plaintext).

We also store a SHA-256 hash of each resume, the text extracted from it, and the analysis results attached to your account.

We do not store the original resume file. The PDF or DOCX you upload is parsed in memory and the binary bytes are discarded the moment text extraction is complete.

We also record some technical details about your connection when you sign up and sign in.

This is how we tell real students from bots and duplicate accounts, which keeps the free AI credits available for people who need them.

WhatWhy
IP addressSpotting bulk or automated sign-ups
Country, and approximate region or citySpotting sign-ups from places our users are not. City is often wrong on mobile networks, so we treat it as a hint, never as identification.
Time zone and postal code, where availableSame purpose, and to read your activity times correctly
Your network operator (for example Jio, or a data centre)The most useful bot signal we have. It identifies a network, not a person.
Sign-in times and last-seen timeShowing you your own activity, and spotting shared accounts

We do not collect GPS or precise location, track you across other websites, or sell any of this to advertisers.

We compare resume hashes between accounts to find duplicate sign-ups.

Ask us and we will tell you exactly what is stored against your account, or ask for it to be erased.

How we use your data

  • To authenticate your sessions and keep your analyses private to your account.
  • To run ATS scoring, keyword analysis, and rule-based feedback, entirely with local, deterministic rules on our own servers. No resume text leaves our infrastructure for this step. If you never use the AI features, no third party ever sees your resume content.
  • To generate AI rewrites and suggestions, only when you explicitly tap those buttons. Before any text is sent to either AI provider, we automatically redact email addresses, phone numbers, and URLs (including LinkedIn and GitHub links) and replace them with placeholders. We restore them only when displaying results back to you.
  • To send a one-time email verification code when you register.

How the AI features work, full disclosure

Two AI providers handle different features, and both receive the same PII-redacted text. Honest details so you can make an informed choice:

  • Groq (Llama 3.3 70B) powers bullet rewrites and resume suggestions. It is used because it is several times faster, which matters for features you wait on.
  • Google (Gemma and Gemini models, via AI Studio) powers cover letters, interview prep, JD extraction and LinkedIn improvements, and is the automatic fallback if Groq fails. Which model handles which feature changes as we tune for speed and quality; the provider does not.
  • What we send: Snippets of your resume text and (where relevant) the job description you pasted, after redaction.
  • What we now strip: Your own name, taken from your resume header, in addition to emails, phones and URLs.
  • What we still do not strip: Names of schools and companies, and other people's names. Rewriting a bullet about an employer needs to know which employer it is. The model is also instructed not to address you by name.
  • Free-tier reality: Google's free tier may use the prompts we send for service improvement, including model training. We are on the free tier because it lets us offer AI features to students at no cost. The redaction step means what Google could see is anonymized fragments, not your full identified resume, but we want you to know exactly what the trade-off is.
  • If you would rather not: Just don't use the "Improve weak bullets" or "Get AI suggestions" buttons. The ATS score, keyword analysis, formatting checks, and rule-based feedback are always available with no AI provider in the loop.

What we do NOT do

  • We do not sell, rent, or share your data with recruiters, employers, or data brokers.
  • We do not train our own AI models on your resume data, we don't train models at all.
  • We do not run advertising or install tracking pixels.
  • We do not store the original resume file after parsing.
  • We do not send any resume content to an AI provider when you are only using the ATS score and rule-based feedback, those run entirely on our servers.

Third-party services

We use the following third-party services. Each operates under its own privacy policy:

  • Google AI Studio (Gemma and Gemini models), cover letters, interview prep, JD extraction and LinkedIn improvements, and the fallback if Groq fails. Only PII-redacted snippets are sent, and only when you explicitly trigger an AI feature. Free-tier prompts may be used by Google for service improvement. Google's privacy policy and AI Studio terms apply.
  • Groq, AI bullet rewrites and resume suggestions. Only PII-redacted resume snippets are sent, and only when you explicitly trigger one of those two features. Groq's privacy policy applies.
  • Neon Postgres, hosted database for account and analysis storage.
  • Render, backend hosting. Your data is processed within Render infrastructure.
  • Cloudflare, DNS, CDN, and bot protection (CAPTCHA) for the API.
  • Vercel, frontend hosting.
  • Brevo, transactional email (verification codes and account notifications only). This replaced Resend at the optiresume.in migration; the policy named the old provider until 2026-08-14.
  • Google Workspace (Apps Script, Sheets and Gmail), used only when you send us something: a support query, feedback, or a credit request. Your name, email, message and current credit balance are written to a private sheet and emailed to Yash, so the request can be answered. Nothing is sent here unless you press send.
  • Sentry, error monitoring, so crashes get noticed and fixed. It is configured with personal data collection turned off, so it receives the technical details of a fault, not your resume or your profile.

Data retention and deletion

We keep your data for as long as your account is active. There are two ways to leave, and they do different things.

Deactivate, yourself, from Settings → Danger zone. This signs you out everywhere and blocks sign-in. Your data is retained, and your email and phone stay reserved so the account cannot be re-created.

Full erasure, on request to support. An operator runs it, and it is irreversible. It removes:

  • your resume text, every analysis, and everything derived from one
  • your applications, academic profile, LinkedIn imports and skill proofs
  • all preparation progress, test attempts and certificates
  • your password, name, phone, Google link, IP addresses and location data

Your email is released, so the same address can register again as a new account. What remains is an anonymous record that an account once existed, plus usage metrics with no personal data in them.

Cookies and sessions

We use one HttpOnly, Secure, SameSite=Lax cookie for your refresh token, scoped only to the auth endpoint. No advertising cookies, no cross-site trackers.

Access tokens live in browser memory only, never in localStorage or IndexedDB.

For analytics we use a cookieless service that counts aggregate usage: which pages are visited, whether a resume was analyzed. No cookies, no personal data, no profile of you across the web. It cannot identify you individually.

Contact

Questions or requests? Reach us at support@optiresume.in or via https://yashadake.com.