Privacy Policy
Last updated: September 10, 2026 · Deutsche Fassung
Controller
Elizaveta Akimova, Berlin, Germany. Contact: exportmyresume@gmail.com.
What we process
- Website visits — hosted on Vercel; standard server logs (e.g. IP address, browser, timestamp) are processed to deliver and secure the site.
- Analytics — Vercel Web Analytics (cookieless) and Microsoft Clarity (aggregated session insights and heatmaps), to understand how the site is used and improve it.
- The browser extension & editor — used to import your LinkedIn profile and build and export a designed résumé.
- LinkedIn import — the extension reads the rendered pages of your own signed-in LinkedIn profile in your browser and hands the extracted résumé to the editor locally. It does not use LinkedIn’s “Save to PDF” feature or read your password or session tokens. The extracted résumé content is not uploaded during this handoff. Import diagnostics can include your profile identifier when an import fails, as described below.
- Extension usage statistics — production builds of the browser extension generate a random installation identifier and report basic lifecycle events to us: installed, first opened, uninstalled, and whether an import started and how it ended, together with browser, operating system, interface language and extension version. These events contain no résumé content; when an import fails — entirely, or in one of its sections — the address of your own LinkedIn profile (the page the import ran on) is included so we can investigate and fix the failure. If you sign in, the identifier may be linked to your account so we can understand which installations lead to purchases. Uninstalling the extension ends this collection.
- Résumé export — generating your résumé as a PDF, DOCX, PNG or TXT file. Some of this runs in your browser and some on our server. Where our server is involved, the résumé content is sent only to produce the file you asked for and is not kept afterwards.
- AI improvement (“Improve with AI”) — when you run this optional feature, your résumé text, editing instructions, any pasted job posting and your answers to our experience questions are sent to our server and the selected model provider (OpenAI/GPT, xAI/Grok or Anthropic/Claude) to generate improvements and suggestions. Requests may be routed through OpenRouter. Retention and use for model training by AI services depend on OpenRouter account settings and provider policies. We do not use this text to train models or store the text of AI requests or responses in our AI logs; these logs contain operational metadata such as model, token counts, cost and timing. If you do not run this feature, this content is not sent to the AI services.
- Saved AI prompts — instructions you explicitly save, their names and your default AI settings are stored with your account in Supabase for reuse across devices. A one-off edit does not change a saved prompt unless you save it. You can delete individual prompts; deleting your account also deletes your saved prompts and settings.
- Accounts & sign-in — you can create an account identified by your email address. Sign-in is passwordless: either “Sign in with Google” (we receive your email address and basic profile from Google) or a one-time link we email you via Resend. Your email identifies your account and your Pro subscription.
- Cloud sync — while you are signed in, your résumés are stored on our servers (hosted on Supabase) so you can access them across devices. You can request deletion of your account and stored résumés — see “Your rights” below.
- Payments — subscription payments are handled by Stripe.
Data types
Depending on the feature used, the résumé data we process can include your name, contact details (email, phone, location), professional headline, work experience, education, skills, languages, certifications and similar résumé details. The résumé you edit is stored locally in your browser. If you are signed in, a copy is also stored on our servers so it syncs across your devices; you can have it and your account deleted at any time, on request. If you are not signed in, it is only sent to our server for the features described above.
How we protect your data
- We do not sell personal data to third parties.
- We do not use the data processed through the extension or the website for advertising profiling.
- Payment card details are handled by Stripe and are not stored by us.
- Data is retained only as long as necessary for the purposes described or as required by law.
Legal bases
We process personal data on the basis of your consent (Art. 6(1)(a) GDPR), the performance of a contract (Art. 6(1)(b) GDPR), and our legitimate interests in operating and securing the service (Art. 6(1)(f) GDPR).
Processors
We rely on the following service providers: Vercel (website & app hosting and the backend API), Supabase (accounts and résumé cloud storage), Google (“Sign in with Google”), Resend (sign-in emails), Microsoft (Clarity analytics), Stripe (payments), OpenRouter (AI request routing), OpenAI (GPT), xAI (Grok) and Anthropic (Claude). Each AI request goes to the provider of the model used for that request.
Your rights
You have the right to access, rectification, erasure, restriction, objection and data portability. That includes requesting deletion of your account and stored résumés: email us and we handle the request without undue delay, at the latest within 30 days. Account deletion removes the account, stored résumés, and sessions. Installation and purchase records can remain with their account link removed; records required by law are retained for the applicable period. To exercise any of these rights, contact exportmyresume@gmail.com.