Privacy
Effective 15 September 2026
Who handles your data
Resume Liberator is operated by Filip Vrlak in the Netherlands. For privacy questions or requests, email support@resumeliberator.com. Resume Liberator is the product name, not a separate legal entity.
What the service processes and why
- Account details, such as your email and authentication identifier, to sign you in and keep your workspace separate from other accounts.
- Resumes, uploaded files, experience, roles, saved job descriptions and URLs, notes, preferences and generated documents to provide the features you use.
- Selected resume and job content, prompts and AI results to parse, clean up or tailor content when you request an AI operation.
- Credit balances, payment references, transaction states, AI usage and provider costs to operate billing, resolve failures and handle payment questions.
- Technical request information, rate-limit signals and workflow events to protect accounts, limit abuse, diagnose problems and understand onboarding completion.
- Messages you send support to answer questions and handle requests.
We rely on performance of the service contract for account and requested features, legitimate interests for proportionate security and service reliability, legal obligations where applicable to financial records, and consent where required for optional processing. You can contact us about the basis for processing your information or to object to processing based on legitimate interests.
Service providers and AI processing
- WorkOS provides authentication and account management.
- Vercel currently hosts the web app; Convex provides backend processing, database and file storage.
- Stripe processes payments. The app records payment references and status; enter card details through Stripe checkout.
- OpenRouter routes AI requests to the model provider used for the operation. The relevant resume or job content is sent with that request. Routing can use different providers; there is no special retention-based provider filter.
- Exa processes search terms when job suggestions are enabled.
- When error monitoring is enabled, Sentry receives filtered technical error reports and private application source maps to help diagnose failures. Reports omit resume and job content, prompts, cookies, account details and request bodies. Session replay is disabled.
These providers may process information outside your country, including outside the European Economic Area. Their handling of logs, retention and AI training depends on the provider and the applicable service settings and terms. We do not guarantee zero retention or EU-only processing. OpenRouter publishes data collection information and provider retention information. Contact us for information about the providers and transfer arrangements relevant to your account. Avoid submitting unnecessary sensitive information about yourself or others.
Chrome extension
When you explicitly save a job, the extension reads the current page URL, title and up to 20,000 characters of job text and sends them to your Resume Liberator account. It supports choosing a role, checking for duplicates, saving and opening the job in the app. It does not collect your browsing history in the background. Page access is used when you invoke the save action, including through the right-click menu.
The extension keeps connection state and save results in browser session storage and loads role information from your account. The connected app session authenticates requests; the extension does not ask for or store your password. Disconnect clears its session data; sign out in the web app to end the app login. Any later AI processing of the saved posting follows the AI processing described above.
Limited use of extension data
We use information obtained through the extension to provide and improve its job-saving and application features, protect the service, and support your requests. We do not sell extension user data, use it for advertising or creditworthiness decisions, or transfer it for unrelated purposes. We share information with the service providers described above as needed to operate those features, or when required by law.
Our use of information received through the extension follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
Cookies and local storage
The app uses authentication cookies and local preferences to maintain sessions and interface settings. The extension uses browser storage for its connection and role state. Payment and authentication providers also handle technical data during their flows. Blocking these cookies or clearing browser storage may sign you out or reset preferences. You can manage cookies in your browser and disconnect or remove the extension at any time.
Retention, backups and deletion
Workspace content is stored until you remove it or close your account. Account deletion removes app-owned workspace records and uploaded files through a retryable cleanup before deleting the authentication identity. Accounts may retain up to 20 PDF files or pending uploads, each up to 10 MB. Unused uploads have a 24-hour grace period before bounded cleanup; deletion timing depends on the cleanup backlog.
For accounts with purchased credit or payment history, minimum accounting records remain internally: amounts, funding and usage records, payment/provider references, timestamps and the account reference needed to handle claims. Free-text billing descriptions, AI errors and operation references are removed. For accounts without purchased credit or payment history, the minimal account-deletion guard expires after 30 days. For financial records, our retention baseline is seven complete calendar years after the year of closure or the latest later payment event; applicable tax rules or unresolved claims can require longer. Expiry requires an obligations review. Outstanding purchased credit does not expire on closure.
Stripe and its backend payment component retain payment/customer records separately, which can include name, email and account references. Provider-spend controls remain to reconcile costs. Deleting workspace data does not immediately erase historical backups or records held separately by service providers. Support correspondence is kept while needed to resolve your request and related disputes. Backup and provider-log retention varies by service; contact us to request information or deletion of provider-held records.
Your choices and requests
Contact Support to request access, correction, an account data export, deletion, or information about restricting or objecting to processing. Where applicable, you may withdraw consent and request data portability. Settings → Advanced provides an account-wide JSON Lines export of stored workspace, settings, usage and billing data, with links to original PDFs to download separately. Avoid editing while it runs: it is a live paginated export. Contact support for larger exports, provider-held records or account recovery. A single resume download is not an account-wide export.
We may need to verify account ownership before releasing or changing data. You may also complain to your local data protection authority; in the Netherlands, this is the Autoriteit Persoonsgegevens.
Age and policy updates
The service is not directed to children under 16. Users aged 16–17 need parent or guardian permission where local law requires it. Contact support if you believe a child has provided data.
The effective date above identifies this version. We will update this notice when our processing changes and explain material changes through the service where appropriate.