Effective date: February 1, 2026 · Last updated: June 4, 2026 · See the Terms →
Working draft — pending counsel review. The substantive clauses below are drafted to align with GDPR (EU/UK), CCPA/CPRA (California), and general US consumer privacy expectations, but they have not yet been reviewed by a licensed attorney in our jurisdiction. They are published in good faith to give beta users a transparent understanding of how we handle data. Material changes will be emailed to subscribers before they take effect.
Resmo ("Resmo", "we", "us", "our") is the data controller for the personal data processed through the Resmo service. We are a US-based company operating under the laws of the State of Delaware, with our principal place of business at the address available on request from privacy@resmo.app. For EU/UK users, we will appoint an Article 27 representative prior to public launch; the appointment will be published here.
We do not intentionally collect special-category data (race, religion, health, sexual orientation, biometric data) and we ask that you do not include it in your resume content. If you do, you authorize us to process it solely for the purposes set out below.
Under GDPR Article 6, we rely on the following legal bases:
Tailoring, scoring, Honesty Check, Strategy Brief, and Interview Mode require sending your resume and job-description text to large language models. Each call is configured with the vendor's no-training / zero-retention flag where the API supports it. Current sub-processors:
The current sub-processor list as of the date above is comprehensive. We will publish updates here at least 30 days before introducing a new sub-processor that touches resume content. If you object to a new sub-processor, you can delete your account before they go live.
We hold your personal data for as long as your account is active. When you delete your account (from /account → Delete), the deletion runs as a single transaction across all our collections (users, analyses, integrity_checks, interview_playbooks, strategy_briefs, outcomes, talent_cloud_optin, matchmaker_intros, audit_events, and 20+ others) and completes within minutes. We retain billing/tax records for 7 years per US tax law, but they are decoupled from your account data and contain no resume content.
Accounts inactive for 24 months are notified by email and archived 30 days later if no response is received. Archived accounts are fully deleted; you can re-sign-up with the same email.
We share your data only with:
We do not sell your personal data, and we do not engage in cross-context behavioral advertising. We have no "Do Not Sell My Personal Information" link because there is nothing to sell. If California law eventually requires the link anyway, we will add it.
Our primary servers are in the United States. If you access Resmo from the EU/UK, your data will be transferred to the US. We rely on the EU Commission's Standard Contractual Clauses (SCCs, 2021 module-1 controller-to-processor variant) with each sub-processor that handles your personal data outside the EU/EEA/UK, supplemented where appropriate by encryption-in-transit, encryption-at-rest, and contractual no-training commitments. A copy of the SCCs is available from privacy@resmo.app on request.
Resmo uses a single first-party HTTP-only cookie (access_token) to keep you signed in. We do not use third-party tracking cookies, advertising cookies, or session replay tools. Our analytics (PostHog) runs in cookieless mode where supported by the browser.
Subject to applicable law, you have the right to:
We respond to verifiable requests within 30 days (45 if complex). To submit a request, email privacy@resmo.app from the address on your account.
Resmo is not directed at, and we do not knowingly collect personal data from, anyone under the age of 16 (or the applicable minimum age of digital consent in your jurisdiction — in some EU states this is as high as 16, in the US under COPPA it is 13). If you believe a minor has created an account, email privacy@resmo.app and we will delete it within 7 days.
We encrypt sensitive fields (base resumes) at the application layer using AES-256-GCM with keys held in the backend environment and rotated quarterly. All network traffic is over TLS 1.2+. Production access is limited to engineers under a written Information Security Policy. We will publish a SOC 2 Type II report by Q4 2026.
We will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to your rights and freedoms, as required by GDPR Art. 33.
The Resmo toolkit uses AI to generate suggestions, score fit, and flag honesty risks, but every output is delivered to you for review and approval. No decision with legal or similarly significant effects on you is made by the system alone. The Verified by Resmo seal is only issued once you have personally reviewed every flagged claim — there is no automated "approve" path.
Privacy questions, requests, or complaints: privacy@resmo.app. We respond to all inbound requests within 5 business days, and to verifiable rights requests within 30 days.
We will notify subscribers by email before any material change to this notice takes effect (at least 30 days in advance). Non-material updates (e.g., adding a vendor for translation services that doesn't touch resume content) will be reflected in the "Last updated" date at the top. Continued use after a material change counts as acceptance.
Specific items we'd appreciate verification on:
© 2026 Resmo. Working draft pending counsel review. By using the service you accept this notice.