Your data
Plain answers, because you're handing over a resume. Last updated 12 August 2026.
The short version
Your resume is stored in a private database in California, read by Anthropic's API so it can be parsed and tailored, and visible to the person running this app. It is not sold, not used for advertising, and not fed to any analytics service. Deleting your account really deletes it.
Where it physically lives
- Database, files, sign-in
- Supabase (on AWS), us-west-1 — Northern California
- The website itself
- Vercel, United States
- The daily job scan
- GitHub Actions, United States
- Resume analysis
- Anthropic API
- Email delivery
- Resend
Everything is served over HTTPS, and the two storage buckets — your uploaded file and any generated documents — are private, so nothing is reachable by guessing a URL.
What’s stored
- The resume file you upload, exactly as you sent it.
- Everything parsed out of it: jobs, bullet points, education, skills, and your contact details.
- What you told us you're looking for, and the job matches scored for you.
- Any tailored resumes and cover letters you generate.
- Anything you add yourself under Extra materials, or send through Help & feedback.
Only your three most recent resume uploads are kept — older ones are deleted automatically, unless a document you generated cites them.
Who can see it
Other users cannot. Every table is locked to the signed-in account at the database level, and every link between tables carries the account id, so one person's data cannot reference another's even by mistake. Your files live under a folder that the database pins to your account.
The person running this app can. This is a personal project run by a friend, and they hold the administrative keys to the database. Your resume is encrypted on disk and in transit, but not in a way that hides it from them. If you wouldn't want them reading your resume, don't upload it — that's a straight answer rather than a comfortable one.
What leaves the app
- Anthropic
- Your resume text — it is what parses, scores and tailors. Nothing works without it.
- Resend
- Your email address and the job titles in your digest. Never your resume.
- Job boards
- Outbound only: we read public listings. They receive a search like “mechanical engineer, Los Angeles”, never your name or resume. One of them (Careerjet) has no HTTPS endpoint, so that search text travels unencrypted — which is why nothing identifying is ever put in it.
- Only if you use Google sign-in, and only that you signed in. The email-link option avoids this.
There is no advertising, no session recording, and no selling of anything — no Google Analytics, no advertising pixels, no cross-site tracking.
What we do count, so we know whether the app is working: page views (via Vercel, the host — which page was opened, roughly where the visit came from, and the kind of device; no cookies, no name, no email, nothing about your resume), and the date you last opened the app, stored on your own row so we can see whether people come back. Neither can see your resume, and neither is shared with anyone.
Applications
This app never submits an application on your behalf, and no part of it is built to. Every “apply” is a link out to the employer's own site. When a job shows as Applied, it's because you pressed the button to say so.
Generated resumes are assembled only from lines already in your own resume or materials. The one place text is written for you is the rewrite suggestions, which you approve line by line and can undo. If a number would make a line stronger, you are asked for it — nothing is invented.
Deleting your account
Delete from your profile page and the rows and the stored files go with it — not a hidden flag. One exception: the record of what each AI call cost is kept with your account id removed, so the shared monthly budget stays accurate after you leave. Those rows contain token counts and dollar amounts only — never any part of your resume.
What this isn’t
A company. There is no security certification, no data-processing agreement, and no formal breach process. It is a carefully built personal project running on free infrastructure, open to anyone who finds it but run by one person. Judge it on that basis.
Questions, or want your data removed by hand? Use Help & feedback inside the app — it goes straight to a real person.