Privacy Policy (summary)
This policy provides a general overview of how user data is handled. A full GDPR/CCPA compliance review by legal counsel is recommended.
- Session cookie: An HTTP-only cookie is used to maintain login state.
- Stored data: email, name (optional), password hash, resume JSON, JD analysis history, snapshots, internal analytics events (name + timestamp).
- Third party: Resume fragments are sent to the OpenAI API for AI features (OPENAI_API_KEY is on your account).
- Export and deletion: JSON export and account deletion with password confirmation are available from the dashboard.
Questions: support email (NEXT_PUBLIC_SUPPORT_EMAIL).