Privacy Policy
Last updated: September 7, 2026
A resume is the most personal document most people ever write, and you are handing us yours. So here is the short version: we take what the product needs to work, we tell you plainly who else touches it, and we make it easy to take back. ResumeClerk is a web app with a companion Chrome extension. It scores your resume against a job posting, rewrites it to match, and keeps track of where every application stands.
Your account, and the extension session
ResumeClerk needs an account, on the web and in the Chrome extension. The extension holds no identity of its own: on first run it shows a single screen asking you to sign in, and signing in happens on our website, in your browser, exactly as it does anywhere else. Once you are signed in there we create an extension session for that install and hand it a pair of short-lived tokens. From that point the extension is simply your account, with the same history and the same free weekly quotas, including 3 tailors per week.
The session is one row we keep: an identifier, the account it belongs to, a label guessed once from your browser and operating system (something like Chrome on macOS) so you can tell one install from another, when it was last used, and when it was revoked. It is not a device fingerprint, it is not used to recognise you on other websites, and it grants nothing your account does not already have. Settings lists every connected extension and lets you disconnect one, which stops its tokens working and asks that install for a fresh sign-in.
How you sign in
You can sign up with an email address and a password, or with Google or LinkedIn. Sign in through Google or LinkedIn and we receive three things: your name, your email address, and whether they have confirmed that address. We never see your password with them, and we cannot post anything as you. A password you set here is stored only as a one-way hash, so we cannot read it either. The extension uses the same sign-in and never asks for a password of its own.
Information we collect
- Account details. Your email address, the sign-in methods linked to your account, and a one-way hash of your password if you set one.
- Resume content. The resume you add in the extension (uploaded as a PDF and parsed into structured fields: name, contact details, experience, education, skills, and any photo you add). This is personal information and is treated as such.
- Job posting data. When you score or tailor against a LinkedIn job you have open, the extension reads that posting (title, company, location, and description text) using your active LinkedIn session and sends it to our service. No LinkedIn credentials are forwarded to our server.
- Extension session & tokens. The session row described above, and the short-lived access and refresh tokens issued with it, which are stored locally in your browser (
chrome.storage.local). - Optional email. Only if you choose to submit it for product updates. It is never required and never gates any feature.
- Technical data. Standard request metadata such as IP address and timestamps. Your IP is kept in hashed form only, as an abuse-prevention cap on free usage. We do not store it in the clear.
How we use your data
- To compute your ATS match score and the matched/missing keywords.
- To generate a tailored resume and a clean PDF you can download.
- To enforce the free weekly tailoring quota and prevent abuse.
- To send product updates only if you opted in with an email.
We do not sell your data, and we do not build advertising profiles from it. The website measurement described above is counted in aggregate and read to decide what to improve. That is the whole of it.
Cookies and analytics
- Strictly necessary. A session cookie keeps you signed in, and a CSRF token stops another site submitting forms as you. Turn these off and the site stops working, which is why there is no switch for them.
- Google Analytics. We use it to see how the site is used as a whole: which pages people open, how they found us, and where they give up. It sets its own cookies so a returning browser is recognised as the same visitor. We read it to decide what to fix next. We do not use it to work out who you are, and we never use it for advertising.
Your browser settings can block or clear cookies whenever you like, and Google publishes an add-on that opts you out of Analytics on every site that uses it. Nothing in the product breaks if you do. The measurement exists for our benefit, not yours, and we would rather say so than pretend otherwise.
Third-party processing (Google Gemini)
Scoring and tailoring are performed by an AI model. To do this, your resume content and the job posting text are sent to Google Gemini (Google) through our server for processing. Your API key never lives in the extension. All AI calls go through our backend. We rely on Google's API terms for this processing; the content is sent to generate your results and is not used by us to train models. Review Google's Gemini API terms for how Google handles API data.
Service providers
A short list, and short on purpose. Each of these sees only the part it needs to do its job, and none of them receives your resume except the AI provider named above.
- Google Analytics, for the aggregate website measurement described above.
- Google and LinkedIn, if you choose to sign in with one of them.
- Cloudflare Turnstile, a bot check used on sign-up. It reports whether a request looks automated and is not used to track you across sites.
- Resend, which delivers account email such as address verification and password resets.
Google and Cloudflare are established outside the European Union and may process this data elsewhere, including in the United States, under the safeguards those providers publish.
Browser permissions we request
- storage: to keep your session tokens, scoring cache, and saved resumes on your device.
- scripting: to load our content script into LinkedIn tabs you already had open when the extension was installed or updated. Without it, those tabs stay inert until you reload them.
- alarms: tailoring runs on our server and takes minutes, while Chrome shuts a dormant extension down after about 30 seconds. This wakes it back up to check whether your result is ready.
- sidePanel: to open ResumeClerk beside the job posting instead of on top of it, so it stays put while you read.
- Host access to LinkedIn: a content script runs on
linkedin.comand reads a job posting (title, company, location, and description) using your active session. The access covers the site rather than the job URLs alone because LinkedIn is a single-page app: it swaps a posting in without a page load, so a script restricted to/jobs/*would often never start. We read a posting only when you ask for a score or a tailor, and nothing from your LinkedIn session is sent to our servers. - No access to our own API, and none to any other site. The extension reaches our server as an ordinary cross-origin request, which needs no permission over your browser, and our server accepts those requests only from this extension.
We request the minimum permissions needed and do not request access to your browsing history, your Chrome profile, or unrelated sites.
Where data is stored and how long we keep it
- On our server. Your account, your structured resume, the jobs you scored, the applications you track, and your tailoring history are stored in our database so the product works across sessions and devices. Resume content, email addresses, and tokens are redacted from our server logs.
- On your device. Session tokens, a short-lived scoring cache, and your generated resumes are stored locally. Generated resumes are automatically deleted after 24 hours, and you can delete any of them sooner from the extension.
- Legacy extension accounts. Until September 2026 the extension could be used without an account, under a random identifier it generated on your device. Those accounts still exist and are not deleted automatically. Sign in from an extension that still holds one and its resumes, jobs, and tailoring history are merged into the account you signed in to, once, on your action. We never merge on the email address read out of an uploaded resume, because that address is not one we have verified. If you would rather have such an account merged or deleted, write to us.
Your choices and deletion
- Delete a saved resume from the extension at any time, or let it expire after 24 hours.
- Resetting the extension's local storage clears your local data and its tokens, which signs that install out.
- Disconnect a connected extension from Settings. Its tokens stop working straight away and it asks for a sign-in the next time you open it.
- Request deletion of everything held under your account (resumes, jobs, tailoring history, and any newsletter email) by emailing hey@resumeclerk.com.
- Download a copy of your data from the account section of Settings.
- Delete your account from Settings. That removes your resumes, saved jobs, applications, and tailoring history.
- Unsubscribe from product updates using the link in any email, or by contacting us.
Security
Everything travels over HTTPS. Resume content, email addresses and tokens are stripped from our logs before they are written, and every AI request is proxied through our server so no key ever reaches your browser. No system is perfectly secure. The honest mitigation is to hold less of your data in the first place, which is what we do.
Children
ResumeClerk is not directed to children under 16 and we do not knowingly collect data from them.
Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date above.
Contact
Questions or data requests? Email hey@resumeclerk.com.