Privacy

The short version: your resume stays in your browser. The only things we receive are your Google sign-in identity and, if you allow it, basic page analytics.

Your resume content

Your typed content never leaves your browser. Names, email addresses, photos, work history, and everything else you put into the builder stays in your browser's memory and local storage. There is no sync, no backend that receives your resume.

Local storage is used so that refreshing the page doesn't lose your work. You can clear it any time by clicking the reset button in the builder, or by clearing site data in your browser.

Your account

Using the builder requires signing in with a Google account, handled by Firebase Authentication (a Google service). When you sign in we receive your basic Google profile: display name, email address, and profile photo. This identifies your account — nothing more. Your resume content is never attached to it or uploaded anywhere.

You can sign out any time from the builder topbar. We keep your account record until you ask us to delete it — email us via the contact page and we'll remove it. Account data is processed by Google Firebase and may be stored outside India.

What we don't do

  • No resume content ever reaches our servers. We have none that store it.
  • No analytics that read or send your resume content.
  • We never send your typed content to any third party. Analytics records page views and a few anonymous product events, described below.
  • No advertising network has access to your typed content.

Analytics

We use two analytics tools to understand how the site is used and which templates people pick, so we can decide what to improve.

Google Analytics 4 runs under Google Consent Mode v2. It records page views plus a few anonymous product events: a template was chosen, the builder was opened, a resume was imported, a PDF was downloaded, and a sign-in happened. These events carry only the template id (for example "atlas") and its category. They never include your name, email, resume text or anything else you typed.

Analytics cookies are set only after you click Accept in the cookie banner. Once you accept, Google Analytics sets cookies (_ga, _ga_*) and records the page, referrer, device type and approximate country. Until you choose, or if you decline, no analytics cookies are set and no identifiers are stored. Consent Mode may still send basic cookieless signals, such as that a page loaded and that consent was not given, with no cookies or identifiers attached. Advertising storage and ad personalization stay off whatever you choose.

Privacy-friendly defaults are on: IP addresses are anonymized, Google Signals (cross-device tracking via your Google account) is off, and ad personalization signals are off. Google Analytics keeps this data for 14 months, then deletes it automatically.

Cloudflare Web Analytics counts page views without cookies. It sets no cookies, stores nothing in your browser and does not identify you, so it runs whatever you choose in the banner.

Changing your cookie choice

You can change your choice at any time: (also linked in the footer of every page) and pick again. This resets only your cookie choice; the resume saved in your browser is not touched. If you switch from Accept to Decline, analytics storage is turned off straight away and the Google Analytics cookies are removed.

You can also block analytics with your browser's tracking protection (Brave, Safari and Firefox Strict mode block it by default), a content blocker such as uBlock Origin, or Google's Analytics Opt-out add-on.

Sign-in

Google sign-in is handled by Firebase Authentication, a Google service. It keeps you signed in using browser storage that Firebase manages; this is needed for sign-in to work and is not used for analytics. See Your account above for what it receives.

Photo uploads

If you upload a profile photo, it is read by your browser only. The image is resized client-side and stored as a data URL inside your browser session. It is never uploaded anywhere.

AI-assisted import

The Import with AI feature works by giving you a prompt file to use with an external AI tool of your choice (ChatGPT, Claude, Gemini, etc.). Your resume is shared with whichever AI tool you pick — under their privacy terms, not ours. We never see your resume; we only parse the JSON you paste back into the import dialog.

Fonts

We load fonts from Google Fonts (fonts.googleapis.com / fonts.gstatic.com). Google receives a request from your browser when fonts are loaded. We do not share any of your typed content with Google.

Hosting

The site is served as static files from Firebase Hosting. Server logs may record IP addresses for the page request, as is standard for any web server. No resume content is ever transmitted.

Changes

If we ever add features that involve sending more data anywhere, we'll update this page first and clearly mark which features are affected.