This Privacy Policy describes how ResumeFlex handles information when you use the resume builder and the public website. Resume documents, photos, and optional API keys stay in this browser unless you export them, back them up, or turn on optional AI generation. When you ask to open the tools, we email a confirmation link. Your name and email are kept as the access record only after you confirm. Contact messages and newsletter signups, if you submit them, are stored so we can reply or send the confirmation email you requested. Campaign newsletters are not sent until a separate marketing sender is configured. If you accept the cookie banner, Google Analytics counts visits to public pages. It does not load in the builder. Not all website data stays in the browser.
1. Information We Collect
Builder documents (local)
Resumes, cover letters, emails, LinkedIn drafts, profiles, jobs, and settings are stored as JSON in your browser. ResumeFlex does not receive that library when you open the builder. Clearing site data deletes it. A workspace backup is a file you download; API keys are not included in that backup.
Tool registration
Before opening the tools, we ask for your name and email and send one confirmation message through Zoho ZeptoMail. You must agree to the Terms of Service and this Privacy Policy. The address is written to the access record in Cloudflare D1 only after you use the link. Until then it is held with the confirmation request and deleted when the 24-hour link expires. On confirmation we record the date, form source, notice version, that agreement, and your separate optional marketing choice. A random access cookie remembers this browser for 30 days; the server stores a hash of its token. Confirmation shows that the address received the link. It is not a password account, and it does not upload or sync your documents. A marketing choice records interest in product and career email. It is optional, it is not required to use the tools, and selecting it does not by itself subscribe you to a campaign.
Optional AI
If you generate text, career content is sent through the ResumeFlex proxy to the provider you chose, using a key you supply. Structured contact fields are omitted. Extra redaction can strip emails and similar patterns from free text; it is not anonymity. Your API key is forwarded for that request and is not stored on our server.
Forms you submit
- Contact form: name, email, subject, and message, so we can reply.
- Newsletter signup: email address, consent text version, and form source. New signups start pending until you confirm.
Technical information
- A hashed network identifier used only to limit form abuse, then discarded on a short schedule.
- Cloudflare Turnstile tokens when that widget is configured, to reduce automated submissions.
- Public page views in Google Analytics, only after you accept.
Google Analytics loads on public pages only after you accept analytics. It does not load in the resume builder, on confirmation links, or on unsubscribe pages. We do not collect payment card details or create user accounts, and we do not turn on Google advertising storage.
2. How We Use Your Information
- Send one confirmation email so you can open the tools, then remember that access without uploading your local documents.
- Send product or marketing email only when you have opted in separately.
- Reply to contact messages.
- Send a confirmation email for a newsletter signup you requested.
- Keep confirmed subscribers until they unsubscribe, and honor suppressions.
- Limit automated abuse of public forms.
- Count public page views with Google Analytics after you accept analytics cookies.
- Forward optional AI requests to the provider you configured.
We do not use resume content to train models. We do not receive local drafts unless you paste them into a contact message or send them through optional AI.
3. Where Information Is Stored
Builder documents: this browser. They are not uploaded to ResumeFlex by default.
Registration and forms: Cloudflare D1 in the account that hosts this site. Transactional email is sent through Zoho ZeptoMail. Campaign mail, if it ever runs, will use a separate permitted sender — not ZeptoMail.
Public site: hosted on Cloudflare. Google Analytics is optional. The script loads on public pages only after you accept, and it is not loaded in the builder.
4. Sharing
- You: local documents stay in your browser until you export or back them up.
- AI providers you configure: career text you send through Generate, using your key.
- Email and hosting vendors: Cloudflare and ZeptoMail, only for the forms and mail you trigger.
- Google: if you accept analytics, Google receives the public page path and ordinary browser data. Resume documents are not included. Query strings are removed before a page view is sent. Advertising storage stays off.
- Legal process: when required by law.
We do not sell, rent, or trade personal information.
5. Your Choices
- Local drafts: export or delete them in the builder, or clear this site's data in your browser.
- Registration: use Settings → Privacy to forget registration on this browser. Email support to request deletion of your server-side name, email, and registration records. We may ask you to verify ownership before acting.
- Contact records: email support@resumeflex.com to ask for access, correction, or deletion of a message you sent.
- Newsletter: use the unsubscribe link, or email support@resumeflex.com.
- Analytics cookies: use Cookie settings in the footer, or Reject on the banner. The site works either way. The choice lasts 180 days, then we ask again.
6. Retention
- Local documents: until you delete them or clear site data.
- Unconfirmed tool requests: deleted when the 24-hour confirmation link expires. These addresses are not kept as access records.
- Confirmed registration: scheduled cleanup removes leads after 180 days without a new registration and registration events after 180 days. Access sessions expire after 30 days. Tool-access abuse counters are retained for up to two hours plus the cleanup interval.
- Contact messages: long enough to reply and keep a support record.
- Pending newsletter signups: until the confirmation link expires or you confirm.
- Confirmed subscribers: until you unsubscribe.
- Hashed abuse records: about 48 hours.
- Analytics choice: 180 days in this browser.
7. Cookies and similar tools
Necessary tools stay on because the site needs them. An HttpOnly access cookie remembers registration for 30 days. The builder stores your documents in this browser. A first-party cookie named rf_consent stores your analytics choice for 180 days. Cloudflare Turnstile may set a widget cookie when a form asks you to complete verification.
Analytics is optional. If you accept, the public site loads Google Analytics 4 to count page views. The tag is not added to the resume builder, confirmation links, or unsubscribe pages. If you open the builder after accepting, measurement pauses for that page. Page addresses sent to Google omit query strings, so a search or a confirmation token is not included. Rejecting analytics does not block the builder, forms, or articles.
There is no advertising cookie program. Google ad storage, ad personalization, and ad user data stay denied.
8. Age
The service is intended for people 18 or older. We do not knowingly collect personal information from children.
9. Updates
We may update this page when the product or vendors change. The date at the top is the latest revision. Continued use after a posted change means you are using the updated policy.
10. Contact
For privacy questions or to exercise rights over form data, email support@resumeflex.com.