Effective July 21, 2026
Privacy policy
This policy explains what ResFlow processes, why it is needed, where it is stored, and how you can export or delete it.
1. Current product scope
ResFlow is an account-based resume builder and ATS-style job-alignment service. It stores the resume content, job targets, analyses, and settings needed to provide the workspace you request.
Do not submit sensitive personal information, confidential employer information, government identifiers, health information, or information you do not have permission to process.
2. Information processed
- Your account identifier and authentication records, including basic Google profile information when you choose Google sign-in.
- Resume files you submit, structured resume content, edits, versions, and template choices.
- Job titles, job descriptions, matching criteria, scores, and approved suggestions.
- Technical request data such as IP address, browser type, request timing, and error metadata used for hosting, security, and abuse prevention.
- Files generated when you request PDF or DOCX export.
3. Where data is stored
Account and workspace records are stored in the connected Supabase project. Row-level security restricts candidate records to the authenticated account that owns them. The browser may keep a local draft cache so an interrupted edit can be recovered.
Uploaded files are parsed in request memory; ResFlow stores the resulting structured resume rather than the original upload. Saved job descriptions and derived analysis receive an additional versioned AES-256-GCM application-encryption envelope. Generated exports are returned directly and are not intentionally retained after the request completes.
4. AI processing
When you upload a resume for AI-assisted field extraction or request semantic job matching or a generated suggestion, ResFlow sends the extracted resume text or structured resume content, and when relevant the target role and job description, to OpenRouter. The original upload file is not sent. OpenRouter routes the request to the selected model provider so the service can return evidence-linked resume fields, qualification matching, or suggested edits. ResFlow does not send this content to OpenRouter for advertising or intentionally include it in analytics events.
ResFlow requires OpenRouter to use a zero-data-retention endpoint and disallows routing to model providers that may store request content. OpenRouter and the selected model provider still process the submitted content during the request and may retain non-content request metadata. Their practices and legal obligations are governed by their applicable policies. If external AI is unavailable, ResFlow may return a local, deterministic analysis instead.
5. Service providers and subprocessors
- Vercel hosts the application and may process hosting and request metadata under its Privacy Policy.
- Supabase provides authentication, database, and private storage infrastructure under its Privacy Policy.
- Google provides the optional sign-in interface and shares the account identifier, name, email address, and profile image you approve under its Privacy Policy.
- OpenRouter provides AI request routing and sends extracted resume text, structured resume content, and relevant job information to a selected model provider for AI-assisted features. Review OpenRouter's Privacy Policy, Terms of Service, and the applicable model provider terms identified by OpenRouter.
- PostHog receives allowlisted product events and error metadata. ResFlow does not intentionally place resume or job-description contents in analytics events, and sensitive form inputs are masked.
6. Retention and deletion
Saved job analyses expire after 30 days by default. In-memory abuse-control records expire automatically. Account records remain until you delete them or a stated retention rule applies.
The Settings page can download a readable candidate-data export or permanently delete saved resumes, derived analysis, events, and private files. Deletion requires an explicit typed confirmation. Browser-local ResFlow data is cleared at the same time.
Infrastructure providers may retain limited backups or security records under their own policies and legal obligations.
7. Security and product launch
ResFlow uses authenticated user sessions, row-level authorization, payload and rate limits, authenticated encryption for sensitive derived data, no-store download responses, and privacy-filtered observability. These measures reduce risk but cannot guarantee absolute security.
8. Changes
This policy will be updated when material processing changes, including changes to external AI providers, payments, or new categories of data. The effective date above identifies the current version.