Privacy · Effective 2026-09-06
Privacy, explained clearly.
This Privacy Policy explains how ResumeReveal collects, uses, stores, shares, protects, and deletes information when you use resumereveal.com, ResumeReveal Studio, and a website you publish with the service.
1. Scope and service operator
This policy applies to ResumeReveal, the professional website and resume-building application available at resumereveal.com and its Studio. References to “ResumeReveal,” “we,” “us,” and “our” mean the operator of the ResumeReveal application. It does not govern independent websites or services you choose to link from your profile.
2. Google Account data
If you choose “Continue with Google,” Google and our authentication provider, WorkOS, provide only the basic identity information needed to sign you in:
- your Google Account’s unique identifier;
- your name;
- your email address and email-verification status; and
- the standard OpenID Connect authentication result needed to establish a secure ResumeReveal session.
We do not sell Google user data, use it for targeted or personalized advertising, determine creditworthiness, provide it to data brokers, or use it to train generalized artificial-intelligence or machine-learning models. ResumeReveal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3. Information we collect
| Category | Source | Why it is collected |
|---|---|---|
| Account identity | Google, Microsoft, or WorkOS | Sign-in, account ownership, security, and service communications. |
| Resume and profile content | You | Save drafts and render the professional website you design. |
| Headshots and resume files | You | Display or make files available only according to your selected settings. |
| Design and publishing settings | You | Remember templates, colors, typography, layout, site address, and publication state. |
| Consent and account records | You and our systems | Record legal acceptance, optional marketing choice, plan state, and account events. |
| Operational and security data | Your browser, Cloudflare, and our systems | Maintain sessions, prevent abuse, diagnose errors, enforce rate limits, and measure service reliability. |
| Published-site page views | Visitors to a published profile | Maintain privacy-conscious aggregate page-view counts without creating visitor profiles. |
Cookies and local preferences
We use necessary cookies to maintain authenticated sessions, protect sign-in and consent flows, and remember supported preferences such as light or dark appearance. We do not use third-party advertising cookies.
4. How we use information
We use information to authenticate users; create and secure accounts; save, edit, preview, publish, unpublish, and delete professional websites; process requested uploads; provide plan features; send essential service communications; honor optional marketing preferences; monitor reliability and abuse; respond to support and privacy requests; and comply with legal obligations.
Your draft remains private unless you publish it. When you publish, the content and files you selected for public display become available on the public internet and may be indexed or cached by search engines and other third parties.
5. When information is shared
We disclose information only as needed to operate the service, follow your instructions, protect users, or comply with law. Our principal service providers are:
- WorkOS, which processes sign-in and authentication information;
- Cloudflare, which provides application hosting, security, databases, key-value storage, file storage, email delivery, rate limiting, and—when you deliberately use an AI feature—Workers AI and AI Gateway processing;
- professional advisers or authorities when reasonably necessary to meet legal obligations, establish or defend legal claims, or protect the service and its users; and
- a successor in a merger, financing, acquisition, reorganization, or sale, subject to this policy and applicable law.
We do not sell or rent personal information. We do not disclose Google user data to third parties for advertising, data brokerage, credit, lending, or generalized AI-model training.
6. Optional AI features
AI tools run only when an eligible signed-in user deliberately invokes them. Resume import temporarily processes the uploaded PDF or DOCX and extracted text to propose profile fields. AI coaching processes the relevant saved resume text, selected content, and short conversation needed to answer the request. Suggestions are review-only and do not modify a draft until you apply them.
These requests are sent through Cloudflare AI Gateway to Cloudflare Workers AI. ResumeReveal does not persist AI-import source files or AI chat history as separate application records. Gateway logs contain operational metadata such as the authenticated account identifier, name, email, feature, request identifier, model, token usage, status, cost, and duration; prompts, uploaded content, and generated responses are excluded from those Gateway logs, and response caching is disabled. ResumeReveal does not use Google user data or resume content to train generalized AI or ML models.
7. How information is protected
ResumeReveal uses HTTPS encryption in transit, provider-managed encryption for stored data, signed and secure session controls, access checks tied to the authenticated user, restricted production credentials, file-type and size validation, rate limiting, security headers, and private storage bindings. Public profile data is separated from private draft and account data. No online service can guarantee absolute security, but we maintain safeguards designed for the sensitivity and use of the information we process.
8. Retention and deletion
Account, draft, consent, and profile data are retained while your account is active and for only as long afterward as reasonably necessary for security, legal, dispute-resolution, and operational obligations. Published snapshots remain available until you unpublish the site or delete the account. Saved headshots and resume files remain until you replace or delete them or delete the account.
You can permanently delete your account from ResumeReveal’s Account page. The deletion process removes your ResumeReveal database record and associated sites, public route mappings and published snapshots, stored headshots and resume files, and the corresponding WorkOS authentication user. Limited records may remain temporarily in backups, security logs, provider systems, or legal records until their applicable retention periods expire. Search engines and third parties may retain copies of information that was public before deletion.
9. Your choices and controls
- Edit, correct, publish, or unpublish profile content in Studio.
- Control whether supported contact details, headshots, and resume files appear publicly.
- Withdraw optional marketing consent in Account settings without affecting essential service messages.
- Decline optional AI tools and continue using ordinary editing features.
- Delete your account and associated ResumeReveal content from Account settings.
Depending on where you live, you may also have rights to request access, correction, deletion, restriction, objection, or portability of personal information. ResumeReveal will respond to applicable requests after reasonably verifying account ownership.
10. Policy changes
We may update this policy as ResumeReveal changes. The effective date above will be updated when we do. If a change materially affects how account or Google user data is used, we will provide an appropriate notice in the service and request renewed consent when required.
11. Privacy questions and requests
Signed-in users can use the privacy, account-management, and deletion controls in the ResumeReveal Studio. If you cannot access your account, contact the ResumeReveal operator using the developer contact information shown on the verified Google OAuth consent screen and identify the email address associated with your account. We may need to verify account ownership before completing a data request.