Privacy Policy

Last updated: July 14, 2026

This is a plain-language starting template describing the Service's actual current data practices. It is not legal advice, and should be reviewed by a qualified lawyer before a real public launch.

This Privacy Policy explains what data Resume Builder (the "Service") collects and how it's used.

1. Data we collect

Account data (from GitHub OAuth): your GitHub username, display name, avatar URL, and public email if available — we never see or store your GitHub password. Resume content: whatever you enter into your dashboard forms, shown publicly only if and when you publish your page. Uploaded files: custom avatars and resume files (PDF/DOCX) are stored in our cloud storage (Amazon S3) — avatars are public, resume files are private and only released as short-lived, one-time download links after a visitor requests one. Visitor analytics: we count page views per day, in aggregate, with no IP addresses, cookies, or per-visitor tracking, and no third-party analytics scripts. Resume-download leads: a visitor requesting a download link submits their name and email, which we store and show only to you and site administrators, along with a best-effort location derived from their IP address (via a third-party IP-geolocation lookup) and a device/browser summary derived from their browser's own User-Agent header — we do not store the visitor's raw IP address itself. Session data: a signed, HTTP-only cookie identifying your logged-in session, containing no personal data beyond an internal identifier. Billing data: if you subscribe to a paid plan, payment details are handled entirely by Stripe — we never see or store your card number, and only keep a Stripe customer/subscription identifier.

2. Third parties we share data with

Amazon Web Services (S3) stores uploaded avatars and resume files. MongoDB stores account, resume, analytics, and lead data. A third-party IP-geolocation API receives a download-requesting visitor's IP address (not stored by us) to resolve a coarse city/region/country for the leads table. GitHub is used solely for OAuth sign-in. Stripe processes payments for paid plans, if you choose one. We don't sell your data or any visitor's data to anyone, and we don't run third-party advertising or tracking scripts on any page.

3. Your choices

You can edit or delete your resume content, avatar, and resume file at any time from your dashboard. You can delete resume-download leads for your own page at any time from your dashboard. You can unpublish your page, which hides it from the public (though a copy may still exist with someone who downloaded it before you unpublished). To delete your account entirely, contact [your-contact-email].

4. Data retention

We keep your data for as long as your account exists. Visitor analytics counts and download leads are kept indefinitely unless you delete them, since they're tied to your account rather than to any identifiable visitor record beyond the lead itself.

5. Security

Sessions use signed cookies; passwords are never stored (GitHub OAuth only); resume files are private by default and only exposed via short-lived, signed download links. No system is perfectly secure, and we can't guarantee absolute security.

6. Children's privacy

The Service isn't directed at children under 13, and we don't knowingly collect data from them.

7. Changes to this policy

We may update this policy from time to time; continued use of the Service after a change means you accept the updated policy.

8. Contact

Questions about this policy or your data: [your-contact-email].