Privacy Policy
What Resume X stores, what reaches an AI model and when, who else receives anything, how long it is kept, and how to have it deleted.
Updated September 12, 2026
What this covers
Resume X is a resume builder. You give it the contents of your CV so it can lay them out, improve them and export them, and most of what it stores is therefore information you typed or uploaded on purpose.
This page says what is kept, where it goes, how long it stays, and what you can ask for. It describes the software as it is actually built.
What is stored
Your account: email address, name, an optional profile image, and a password stored only as a bcrypt hash. If you sign in with Google, no password exists at all. Whether your email has been confirmed is recorded, along with when the account was created.
Your resumes: every section you fill in, which is to say your contact details, work history, education, skills, projects, publications, certifications, references, awards, languages, volunteering, memberships, courses and interests. A profile photograph if you add one.
Version history: up to twenty previous states of each resume, so an edit can be undone. Older ones are discarded as new ones arrive.
Billing: your plan, its status, when access ends, how many AI credits remain, and a record of each payment. Card numbers are never received or stored.
Interview answers: if you answer the guided questions before creating an account, those answers are held so they are not lost while you sign up. They are deleted automatically thirty days after you last touched them.
What reaches an AI model
AI features are the one place your resume text leaves this service, and they only run when you ask for them. Nothing is sent to a model in the background.
When you ask for a rewrite or a set of changes, the sections your request concerns are sent to the configured AI provider, along with a one-line count of the sections it does not need to see. A request about your summary does not carry your employment history with it.
Your profile photograph is never sent. It is removed before the request is built.
If you attach a screenshot of a paper, that image is read once, at the moment you attach it, and what is kept from it is the citation text. Re-running the same edit does not send the image again.
The provider processes the request to generate the reply and is not given your account details or your email address. Which provider is in use depends on how this installation is configured.
As with any AI feature anywhere, do not type information into your CV that you would not want processed by a third party.
Who else receives anything
Stripe handles payment. You enter card details on Stripe's own pages and Resume X receives only the result: which plan, whether it succeeded, and when access runs out.
The AI provider receives what the section above describes, and only when you ask for it.
An email provider sends account email such as verification links.
Object storage holds uploaded images where that is configured, and files there are reachable only through short-lived links this service signs.
Google is involved only if you choose to sign in with Google.
Nothing is sold, and nothing is shared with advertisers.
What other people can see
By default, nothing. Your resumes are private to your account.
Publishing is an explicit action and is reversible. When you publish a resume, the public page shows only the fields on an allowlist: references are excluded by default because they are somebody else's contact details, and your own email, phone and location are individually switchable.
Revoking a share link stops the page working immediately. The link itself is deliberately kept, so republishing restores the same address and any QR code you have already printed keeps working.
Share links are long and random rather than guessable, and published resume pages are excluded from search engine indexing.
How long things are kept
Your account and its content are kept while the account exists.
Resume version history keeps the last twenty states of each resume.
Interview answers given before signing up are deleted automatically after thirty days.
Email verification links expire, and are stored only as a one-way hash, so a copy of the database does not contain a working link. The record of the link is removed after it expires.
Payment records are kept as long as they are needed for accounting and dispute handling.
Security
Passwords are stored as bcrypt hashes and are never recoverable in readable form.
Email verification links are stored as SHA-256 hashes; the usable link exists only in the email that was sent.
Access to a paid feature is decided on the server on every request. A client cannot grant itself access by changing something in the browser.
No system is perfectly secure, and this one is no exception. If you believe you have found a weakness, report it through the support channel rather than testing it against other people's accounts.
Your choices
You can edit or delete any resume from inside the app, and deleting a resume removes its stored versions with it.
You can unpublish anything you have published, at any time.
You can ask for a copy of what is held about you, or ask for your account and its contents to be deleted, through the support channel. Deletion removes your account, resumes and versions. Payment records may be retained where accounting rules require it.
Your browser's site-data controls clear what is stored locally. The Cookie Policy lists exactly what that is.
Children
Resume X is intended for people old enough to be looking for work and is not directed at children. Accounts are not knowingly created for them.
Changes and contact
If what is stored or who receives it changes, this page changes with it, and the date below records the last revision.
For a copy of your data, a deletion request, or any question about this page, contact the team through the support channel shown in the app.