Cookie Policy
One cookie to keep you signed in, some browser storage so the editor does not lose your work, and a short list of the companies a page contacts.
Updated September 12, 2026
The short version
Resume X sets one cookie of its own, and it is there to keep you signed in. Everything else it puts on your device is browser storage rather than a cookie, it stays on your device, and it is there so the editor does not lose your work between page loads.
There is no advertising cookie, no cross-site tracking pixel, and nothing that follows you to another site.
The sign-in cookie
When you sign in, an authentication cookie is set by NextAuth. It holds a signed token identifying your account and your current plan status, so the server can tell whether to open the editor without reading the database on every request.
It is required. Blocking it means sign-in cannot complete, and with it the editor, downloads and the dashboard are all unreachable.
It is cleared when you sign out. Signing out also clears the browser storage described below, so a shared or public computer is not left holding the last person's draft.
What the editor keeps on your device
These are browser storage, not cookies. They are never sent to the server on their own, and they are readable only by this site in the browser that wrote them.
"resume-storage" holds the resume you are editing along with your template, colour, font and photo choices. It exists so that a reload does not lose an unsaved draft, and so the preview can paint immediately rather than after a round trip.
"resume-import-pending" holds a CV you uploaded before creating an account. It is what lets you upload first and sign up afterwards, rather than being asked for an account before the product has shown you anything.
"ai_suggestions" and "ai_target_role" hold the state of an AI review while you are deciding on it, so moving between tabs does not discard the suggestions you have not answered yet.
"editor-tab" remembers which editor tab you had open, so returning to the editor puts you back where you were.
You can clear all of this at any time through your browser's site-data controls. Doing so loses any draft that has not been saved to your account, and nothing else.
Requests a page makes to other companies
Some pages load resources from third parties, and those companies can see the request, which means your IP address and browser.
Checkout is hosted by Stripe. Starting a purchase sends you to Stripe's own page, where Stripe sets its own cookies under its own policy. Card details are entered there and never reach Resume X.
Fonts are loaded from Google Fonts, on the site and inside generated PDFs.
Signing in with Google is optional and only contacts Google if you choose it.
The landing page loads illustrative avatar images from an external avatar service. They are decorative and carry no account information.
Analytics
Resume X sets no analytics or advertising cookies of its own.
Where the application is deployed behind a platform that provides its own request logging, that platform may record standard access information such as IP address, path and user agent. That is infrastructure logging rather than a cookie, and it is not used to build a profile of you.
Managing all of it
Every browser can block or clear cookies and site data, usually under privacy or site settings, and can do so for this site alone.
Blocking the sign-in cookie prevents sign-in, checkout and every paid feature from working. Clearing browser storage is safe for anything already saved to your account and loses only unsaved local drafts.
Changes
If the storage this site uses changes, this page changes with it. The date below is the last time it was revised.
Questions about anything here can be sent to the support address on the site.