Overview
This Privacy Policy explains how Reactive Resume (the “Service”) collects, uses, stores, and shares information when you use it. Reactive Resume is open-source and can be operated in different ways (for example, by the official hosted service, or by an organization/self-hosted deployment). The specific data controller for your use depends on who operates the instance you are using.- Service Operator: Amruth Pillai
- Contact: [email protected]
- Service URL: https://rxresu.me
- Effective date: 2023-01-01
Note for self-hosted deployments: If you are using the official hosted service at
rxresu.me, the
project’s published support contact is [email protected]. Replace the placeholders above with the
correct operator details for your deployment if you are self-hosting.What the Service does
Reactive Resume is a resume builder that lets you:- Create and edit resumes and cover letters in a browser-based editor
- Store documents in an account, optionally make a resume public, and share it via a link
- Export resumes and cover letters (for example, to PDF, DOCX, Markdown, or JSON)
- Track job applications, including notes, contacts, interviews, and the documents you sent
- Upload files such as profile pictures (and other assets used in a resume)
- Optionally connect your own AI provider (e.g., OpenAI, Anthropic, Google Gemini, or another supported provider) to use AI features such as the assistant
Information we collect
Account information
When you create an account or sign in, the Service stores:- Identity and profile: name, email address, username/display username, optional profile image
- Authentication state: whether email is verified; whether two-factor authentication is enabled
Authentication and security data
To keep your account secure and keep you signed in, the Service stores:- Session data: session token, session expiry, and (if provided) IP address and user agent
- Verification data: values used for email verification, password reset, or email change flows
- Two-factor authentication: a 2FA secret and backup codes (if you enable 2FA)
- Passkeys (if you use them): public key, credential ID, device metadata, counters, and related fields
Resume and cover letter content
When you create or import a resume or cover letter, the Service stores the data you provide, which may include personal data such as:- Contact details, location, summary
- Employment, education, projects, links, and other resume sections
- Cover letter text and recipient details
- Any other content you add (including rich text and private notes)
Job applications
If you use the application tracker, the Service stores the application details you enter or import, such as company, role, job posting details, stages, interviews, notes, contacts, and which resume or cover letter you sent.Public resume access and statistics
If you publish a resume, other users may access it via its public link. The Service may also maintain simple statistics such as:- View count and download count, including daily totals
- Last viewed/downloaded timestamps
Uploaded files (e.g., profile pictures)
If you upload files, the Service stores them either:- On the local filesystem of the server (default: under a
data/directory), or - In S3-compatible object storage, if configured by the Service Operator, or
- In Vercel Blob storage, when the Service runs on Vercel
API keys created in the Service
If the Service Operator enables API key functionality, the Service can store:- API key metadata and rate limit counters
- A hashed form of the API key, used to verify it
Local-only preferences and settings
Some settings are stored on your device:- Cookies: UI preferences such as
themeandlocale - Local storage: some client-side state, such as view preferences and unsaved drafts
How we use information
We use the information above to:- Provide and operate the Service (account access, resume editing, storage, sharing)
- Authenticate users and prevent abuse/fraud (sessions, security logs/metadata)
- Generate PDFs, previews, and other exports you request
- Maintain basic functionality such as localization and theme preferences
- Provide support and respond to user requests (if you contact the Service Operator)
Cookies and similar technologies
The Service uses cookies primarily for functionality:- Authentication cookies: to keep you signed in
- Preference cookies: theme (
theme) and language (locale)
Sharing and third parties
We share information only as needed to provide the Service:PDF generation
When you download a PDF from the editor, the Service renders the document directly in your browser using the Forme PDF engine, which runs in your browser as WebAssembly. Resume content is processed locally on your device for this purpose. When a visitor downloads the PDF of a public resume, or when a PDF is requested through the API, the Service’s own server renders it with the same engine. No third-party “printer” or headless-browser service is involved in either case.Storage providers (optional)
If configured, uploaded files may be stored in an S3-compatible provider or in Vercel Blob. In that case, the storage provider processes and stores file data on behalf of the Service Operator.OAuth providers (optional)
If you sign in via OAuth (Google/GitHub/LinkedIn/custom), those providers receive authentication requests and return profile information (such as email/name) to the Service, as permitted by your provider settings.AI providers (optional, user-supplied)
If you enable AI features and provide your own API key, the Service stores your provider settings and stores the API key encrypted. When you use AI features, the Service sends prompts, the relevant document content, and any files you attach to your selected AI provider (for example, OpenAI, Anthropic, or Google Gemini), according to your use of those features and the provider’s policies. The Service stores your assistant conversations, attachments, and proposed changes in your account until you delete them or your account.Data retention
Retention depends on the Service Operator’s configuration and your actions. As a baseline:- Account data and resumes are retained until you delete them (or your account is deleted).
- Session and security data may be retained as needed for authentication and security.
- Uploaded files are retained until deleted (for example, when you remove a picture or delete a resume/account).
- Documents you move to the Trash are deleted permanently after 30 days, unless you restore or delete them sooner.
Security
We take reasonable measures to protect data (authentication, access controls, and storage separation). No method of transmission or storage is 100% secure; you should use strong passwords and enable 2FA/passkeys where available. If you are self-hosting, you are responsible for:- Securing your infrastructure, database, and storage buckets
- Using HTTPS and secure cookie settings
- Configuring access controls for object storage (and avoiding unintended public access)
International transfers
If the Service Operator (or its vendors) stores or processes data in other countries, your information may be transferred internationally. The Service Operator is responsible for providing appropriate safeguards where required by law.Your choices and rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data. You can often exercise these rights directly in the Service (for example, by editing or deleting resumes), or by contacting the Service Operator.Children’s privacy
The Service is not intended for children under the age of 13 (or the minimum age required in your jurisdiction). If you believe a child has provided personal data, contact the Service Operator.Changes to this Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.Contact
For privacy requests or questions, contact:- Service Operator: Amruth Pillai
- Email: [email protected]