superresume.app information
Privacy, plainly.
Draft for product review. This placeholder is not final legal copy and must be reviewed before public launch. superresume.app does not claim legal or GDPR certification.
What this local preview processes
superresume.app processes resume uploads, their parsed content, report findings and scores to provide the review. The PDF or DOCX is staged in a private temporary directory and removed after parsing. If a process stops unexpectedly, the next API startup removes staged files older than the configured one-hour TTL; this is not a scheduled exact-deletion guarantee. The canonical resume and extracted text are stored in the application database. Accounts store an email, password hash and verification state. Unclaimed, unpaid resumes become eligible for deletion after 30 days through an explicit cleanup command; no schedule is configured. Stripe-hosted Checkout handles card entry; superresume.app stores transaction IDs, amount, currency and state, not card numbers or CVC.
How long information remains
You can delete an individual resume and report from the report or account dashboard. Account deletion requires your current password and removes your account, its resume content, versions, analyses, optimization questions and proposals. Transaction and webhook metadata are kept separately with identity and resume links detached where possible; exact accounting retention periods require legal review. Paid anonymous resumes and resumes with active checkout work are protected from automatic cleanup. Unclaimed, unpaid anonymous resumes are eligible for deletion after 30 days. No production backup-retention schedule is configured yet.
AI and external services
Semantic review and paid wording suggestions send only the selected text needed for that operation. During resume upload, the optional AI structuring setting is enabled by default. If enabled, all text extracted from the uploaded resume is sent to OpenAI for section classification and field extraction. This can include contact details, work history, education, skills, projects, certifications, languages, references and third-party personal contact details. The raw PDF or DOCX file is not sent by this structuring step. Uncheck the setting to skip this AI call. AI can make mistakes; review the extracted fields. Uncertain or unsupported text is kept in Additional information. Provider processing terms and data transfers require legal review before launch.
Analytics and access
The product has no configured third-party analytics or advertising trackers. Browser storage is limited to a selected interface-language cookie and tab-scoped resume/editor recovery data; it contains no authentication token, and private drafts are cleared on logout, account deletion, resume deletion and account switching where the browser supports it. Authentication uses server-checked HttpOnly session cookies plus a CSRF cookie; anonymous access uses a separate HttpOnly capability cookie. Verified, allowlisted administrators can see operational metadata. A feature-flagged, read-only content QA view also exists; successful content access is audited and production startup rejects enabling it. The legal entity, privacy contact, legal bases and final retention wording have not been configured and require legal review.