Back to Resmo
· Resmo · Privacy notice

We send. We don't sell.

Effective date: February 1, 2026 · Last updated: June 4, 2026 · See the Terms →

Working draft — pending counsel review. The substantive clauses below are drafted to align with GDPR (EU/UK), CCPA/CPRA (California), and general US consumer privacy expectations, but they have not yet been reviewed by a licensed attorney in our jurisdiction. They are published in good faith to give beta users a transparent understanding of how we handle data. Material changes will be emailed to subscribers before they take effect.

· The plain-English version
  • · Your resume, job descriptions, and tailored outputs are yours. We never sell them.
  • · We never market your resume to recruiters without your explicit opt-in to the Talent Cloud, and even after that you double-opt-in on each intro.
  • · We send your text to AI models (Anthropic, Google, OpenAI) to generate tailored content — those API calls are configured for zero-retention / no-training.
  • · You can delete your account and every byte of your data at any time from /account → Delete account.
  • · We use Stripe for payments. We never see your card.

1. Who we are (the data controller)

Resmo ("Resmo", "we", "us", "our") is the data controller for the personal data processed through the Resmo service. We are a US-based company operating under the laws of the State of Delaware, with our principal place of business at the address available on request from privacy@resmo.app. For EU/UK users, we will appoint an Article 27 representative prior to public launch; the appointment will be published here.

2. The categories of personal data we collect

  • Identifiers: name, email address, hashed password, IP address, browser/device fingerprint, account ID.
  • Resume content: the base resume you upload + every tailored resume we generate on your behalf. Treated as the most sensitive category in our system; encrypted at rest.
  • Job descriptions you submit: stored alongside your analyses for re-use and to power the Strategy Brief and Playbook features.
  • Outcomes you log: applied / interview / offer / rejection / no-response status per analysis.
  • Talent Cloud opt-in metadata: whether you opted in, your eligibility tier (Bronze/Silver/Gold), the recruiter intros you've sent, accepted, or declined.
  • Communications: emails you send us, support tickets, feedback you submit through the feedback widget.
  • Usage telemetry: pseudonymized page views, feature clicks, billing events (via PostHog, with IP truncation enabled).
  • Billing data: Stripe handles full card data; we only retain the Stripe customer ID, the subscription/credit grant history, and the last four digits of the card for receipt display.
  • Inferred data: skill normalization, role recency, fit scores, and integrity flags derived from the above.

We do not intentionally collect special-category data (race, religion, health, sexual orientation, biometric data) and we ask that you do not include it in your resume content. If you do, you authorize us to process it solely for the purposes set out below.

3. Why we process it (legal bases)

Under GDPR Article 6, we rely on the following legal bases:

  • Contract (Art. 6(1)(b)): to run the toolkit you paid us to run — tailoring, scoring, briefs, playbooks, interviewer research, audio briefings, etc.
  • Legitimate interests (Art. 6(1)(f)): product analytics, fraud prevention, abuse rate-limiting, security logs. We've balanced this against your interests and concluded the impact on you is minimal because telemetry is pseudonymized.
  • Consent (Art. 6(1)(a)): marketing emails outside transactional triggers, the Talent Cloud opt-in, sensitive cross-border transfers, optional cookies. You can withdraw at any time.
  • Legal obligation (Art. 6(1)(c)): tax records, accounting records (we retain payment receipts for 7 years as required by US tax law).

4. AI processors (sub-processors)

Tailoring, scoring, Honesty Check, Strategy Brief, and Interview Mode require sending your resume and job-description text to large language models. Each call is configured with the vendor's no-training / zero-retention flag where the API supports it. Current sub-processors:

  • Anthropic (Claude Sonnet 4.5) — text generation. No-training enabled.
  • Google (Gemini 3 / Nano Banana for image generation) — image + multimodal. No-training enabled.
  • OpenAI (GPT-4o, Whisper, GPT-Image-1) via the Emergent LLM router — text + audio + image. No-training enabled.
  • Perplexity — Interviewer Research feature.
  • ElevenLabs — interview audio briefings.
  • Resend — transactional email delivery.
  • Stripe — payment processing. PCI-DSS Level 1 certified.
  • PostHog — product analytics. IP truncation + cookieless mode where possible.
  • MongoDB Atlas — primary data store. AES-256 at-rest encryption.
  • AWS S3 — file storage for resume uploads (encrypted at rest, server-side encryption with AWS-managed keys).
  • Adzuna — job search aggregation (no personal data sent).

The current sub-processor list as of the date above is comprehensive. We will publish updates here at least 30 days before introducing a new sub-processor that touches resume content. If you object to a new sub-processor, you can delete your account before they go live.

5. How long we keep it

We hold your personal data for as long as your account is active. When you delete your account (from /account → Delete), the deletion runs as a single transaction across all our collections (users, analyses, integrity_checks, interview_playbooks, strategy_briefs, outcomes, talent_cloud_optin, matchmaker_intros, audit_events, and 20+ others) and completes within minutes. We retain billing/tax records for 7 years per US tax law, but they are decoupled from your account data and contain no resume content.

Accounts inactive for 24 months are notified by email and archived 30 days later if no response is received. Archived accounts are fully deleted; you can re-sign-up with the same email.

6. Sharing & disclosure

We share your data only with:

  • The sub-processors listed in §4, each bound by a Data Processing Agreement.
  • Recruiters you've explicitly accepted intros from via the Matchmaker double-opt-in flow.
  • Recruiters you've explicitly linked your Resmo account to via the Resmo Pro Acting-on-behalf feature. You can revoke this link from /account at any time.
  • Recipients of public-share links you've personally created (Strategy Brief share, Playbook share, Resume share). You control whether these exist; you can revoke any of them from your dashboard.
  • Successor entities in the event of a merger, acquisition, or asset sale — but only under the same Privacy notice, and only with 30 days notice to you so you can delete your account first.
  • Legal authorities if compelled by valid legal process (subpoena, search warrant, court order). We will challenge overbroad requests and, where legally permitted, notify you before disclosure.

We do not sell your personal data, and we do not engage in cross-context behavioral advertising. We have no "Do Not Sell My Personal Information" link because there is nothing to sell. If California law eventually requires the link anyway, we will add it.

7. International transfers

Our primary servers are in the United States. If you access Resmo from the EU/UK, your data will be transferred to the US. We rely on the EU Commission's Standard Contractual Clauses (SCCs, 2021 module-1 controller-to-processor variant) with each sub-processor that handles your personal data outside the EU/EEA/UK, supplemented where appropriate by encryption-in-transit, encryption-at-rest, and contractual no-training commitments. A copy of the SCCs is available from privacy@resmo.app on request.

8. Cookies & similar technologies

Resmo uses a single first-party HTTP-only cookie (access_token) to keep you signed in. We do not use third-party tracking cookies, advertising cookies, or session replay tools. Our analytics (PostHog) runs in cookieless mode where supported by the browser.

9. Your rights

Subject to applicable law, you have the right to:

  • Access: ask what data we hold about you.
  • Rectify: correct inaccurate data.
  • Erase: delete your data ("right to be forgotten"). The /account Delete account button is the fastest way.
  • Restrict / object: pause or limit certain processing.
  • Data portability: receive a machine-readable copy of your data. Email privacy@resmo.app and we'll deliver a JSON export within 30 days.
  • Withdraw consent: where processing is based on consent.
  • Complain: to your local data protection authority (in the EU: your national DPA; in the UK: the ICO; in California: the CPPA).

We respond to verifiable requests within 30 days (45 if complex). To submit a request, email privacy@resmo.app from the address on your account.

10. Children

Resmo is not directed at, and we do not knowingly collect personal data from, anyone under the age of 16 (or the applicable minimum age of digital consent in your jurisdiction — in some EU states this is as high as 16, in the US under COPPA it is 13). If you believe a minor has created an account, email privacy@resmo.app and we will delete it within 7 days.

11. Security

We encrypt sensitive fields (base resumes) at the application layer using AES-256-GCM with keys held in the backend environment and rotated quarterly. All network traffic is over TLS 1.2+. Production access is limited to engineers under a written Information Security Policy. We will publish a SOC 2 Type II report by Q4 2026.

We will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to your rights and freedoms, as required by GDPR Art. 33.

12. Automated decision-making

The Resmo toolkit uses AI to generate suggestions, score fit, and flag honesty risks, but every output is delivered to you for review and approval. No decision with legal or similarly significant effects on you is made by the system alone. The Verified by Resmo seal is only issued once you have personally reviewed every flagged claim — there is no automated "approve" path.

13. Contact

Privacy questions, requests, or complaints: privacy@resmo.app. We respond to all inbound requests within 5 business days, and to verifiable rights requests within 30 days.

14. Changes to this notice

We will notify subscribers by email before any material change to this notice takes effect (at least 30 days in advance). Non-material updates (e.g., adding a vendor for translation services that doesn't touch resume content) will be reflected in the "Last updated" date at the top. Continued use after a material change counts as acceptance.

· For our reviewing attorney

Specific items we'd appreciate verification on:

  1. Confirm Article 27 EU representative arrangement before public launch.
  2. Confirm SCCs (2021 module 1) selection vs. UK IDTA preference.
  3. Confirm 24-month inactive archival window is reasonable for our retention category.
  4. Confirm the "no-sale" language survives CCPA's expanded "sharing" definition under CPRA.
  5. Confirm 7-year tax retention is correct for our jurisdiction; some require longer.
  6. Sub-processor list in §4 — confirm each is bound by a current DPA; flag any that need vendor-side updates.
  7. Confirm age threshold language (16 default vs. country-specific carve-outs).
  8. Decide whether to add an arbitration / class-action waiver in the Terms (currently absent).

© 2026 Resmo. Working draft pending counsel review. By using the service you accept this notice.