Privacy Policy

Effective date: July 6, 2026  ·  Applies to: RESUME.AI (operated by PRPL 7 Inc.)

1. Who we are

RESUME.AI is a job-search platform operated by PRPL 7 Inc., a corporation incorporated under Canadian federal law. We help job seekers optimize resumes, prepare for interviews, and manage their job search pipeline using artificial intelligence.

This Privacy Policy explains how we collect, use, disclose, and protect your personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles.

Questions or requests can be sent to support@launchresumeai.com.

2. Information we collect

We collect information you provide directly and information generated by your use of the service.

2a. Information you provide

  • Account information — email address and password when you register.
  • Resume content — the PDF or DOCX files you upload; parsed text extracted from those files.
  • Job descriptions — the text you paste or import when tailoring a resume or scoring an application.
  • Profile data — work history, skills, certifications, and other career details we extract from your resume and store to power future tailoring (your “diarized profile”).
  • Sensitive vault data — personal identifiers such as address, phone number, and social insurance number that you optionally store in our encrypted vault for auto-filling job applications. These fields are encrypted at rest with a key derived from your session and are never sent to third-party AI systems.
  • Google account information — when you choose to sign in with Google or connect your Google account, we may collect your Google account identifier, email address, basic profile information, and the authorization tokens necessary to provide the Google-integrated features you request (such as sending emails through Gmail).
  • Chrome extension data — if you install our optional browser extension, the page URL, job title, and job description text you clip from a job site, and the labels and types of the form fields on a job application page when you trigger autofill. See Section 7 for details.
  • Payment information — billing is handled by our payment processor; we do not store full card numbers on our servers.

2b. Information generated automatically

  • IP address and approximate location derived from IP.
  • Browser type, operating system, and device identifiers.
  • Pages visited, features used, and timestamps of activity.
  • Error logs and performance metrics.

3. Why we collect it — purposes

We collect and use your information only for the purposes for which you provide it or that are reasonably necessary to deliver the service:

  • Creating and authenticating your account.
  • Tailoring your resume to specific job descriptions using AI.
  • Generating cover letters, interview prep materials, and follow-up emails.
  • Sending emails through your connected Gmail account when you explicitly request it (such as job application, follow-up, or networking emails you create or approve).
  • Scoring your application fit before you apply.
  • Populating job application forms with your stored profile data.
  • Tracking your job search pipeline (boards, stages, analytics).
  • Analyzing rejection patterns to surface actionable improvements.
  • Processing payments for paid subscription tiers.
  • Sending transactional emails (receipts, password resets, account notices).
  • Improving the service — identifying bugs, monitoring performance, and refining AI outputs.
  • Complying with legal obligations.

We do not use your resume content or job application data to train general-purpose AI models, sell to advertisers, or share with prospective employers without your explicit action.

4. Consent

By creating an account and using RESUME.AI, you consent to the collection, use, and disclosure of your personal information as described in this policy. Where we collect sensitive information (such as vault data), we rely on your express consent at the point of collection.

You may withdraw consent at any time by closing your account (see Section 8). Withdrawal of consent may prevent us from providing the service to you.

5. How we share your information

We do not sell your personal information. We share it only in these circumstances:

5a. Service providers (sub-processors)

We use the following third-party services to operate the platform. Each is bound by data processing terms:

ProviderPurposeData shared
SupabaseAuthentication & database hostingAccount info, all stored user data
VercelApplication hosting & edge deliveryRequest logs, IP addresses
UpstashSession caching (Redis)Temporary session tokens
AnthropicAI resume tailoring & generationResume text, job descriptions — not vault data
DataFastPrivacy-friendly analyticsPage URL, referrer, anonymised IP, browser/device type
Payment processorSubscription billingPayment card data (not stored by us)

5b. Legal requirements

We may disclose personal information if required by law, court order, or government authority, or when necessary to protect the safety of our users or the public.

5c. Business transfers

If PRPL 7 Inc. is acquired, merged, or sells its assets, your personal information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.

6. Google account and Gmail access

If you choose to connect your Google account to RESUME.AI, we may request access to certain Google account information and permissions.

When you authorize Gmail access, we use the Gmail API solely to send emails on your behalf that you create, approve, or initiate through RESUME.AI, such as:

  • Job application emails
  • Follow-up emails
  • Networking outreach messages
  • Other job-search communications requested by you

We do not use Gmail access to:

  • Read your inbox contents
  • Monitor your email activity
  • Delete emails
  • Modify existing emails
  • Access email content unrelated to messages you choose to send through RESUME.AI

Any Gmail access tokens are used only to provide the requested functionality and are protected using industry-standard security measures.

You may revoke Google account access at any time through your Google Account permissions page or by disconnecting your Google account within RESUME.AI.

RESUME.AI's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Chrome extension

The RESUME.AI Chrome extension is an optional companion app. Its single purpose is to let you clip a job posting you are viewing into your RESUME.AI board, and to help you fill in a job application form using data already in your RESUME.AI account. It does not perform any function unrelated to that purpose.

7a. What it reads from a page

The extension only acts on the tab you are actively viewing, and only when you click its icon, its on-page button, or the right-click “Clip this job” menu item. When you do, it reads:

  • The current page's URL, job title, company name, and job description text (to create or match a job card).
  • On a job application page, the labels and types of the form fields present (for example, “Email” / text, “Resume” / file) — used to generate a fill plan. It never reads the contents of file inputs, since browsers do not expose those to scripts.

It does not run in the background across your browsing, and it does not read pages you have not activated it on.

7b. What it sends to our servers

  • The clipped job's URL, title, and description text, to create your job card.
  • The form field labels/types from an application page, to generate a fill plan for you to review.
  • Your account's authentication token (obtained when you connect the extension to your signed-in RESUME.AI session), so our API can identify you. This is “authentication information” under Chrome Web Store data-usage categories, stored locally in the browser and never sold or shared with third parties.

7c. What it does not do

  • It does not read or transmit your browsing history, other open tabs, or page content unrelated to a clip or autofill action.
  • It does not submit application forms on your behalf — every filled field is shown to you for review, and you always click the site's own Submit button.
  • It does not attach or upload files to forms; resume and cover-letter files must be attached by you, since browsers block scripted file uploads.

7d. Permissions and why we need them

  • storage — store your authentication token locally so you stay connected between visits.
  • scripting / activeTab — read the job posting and form fields on the tab you are actively viewing when you trigger a clip or autofill.
  • contextMenus — add the right-click “Clip this job to RESUME.AI” menu item.
  • Job-site host permissions (LinkedIn, Indeed, Greenhouse, Lever, Ashby, Workday, SmartRecruiters, Work at a Startup) — required to read job postings and forms on those specific domains only.
  • RESUME.AI host permission — required to receive your session when you connect the extension and to call our API.

Information read by the extension is used only for the purposes described above and in Section 3, transmitted over TLS, and protected under the same measures described in Section 9. We do not use extension data for advertising and do not sell it.

You can disconnect the extension at any time from its popup (“Disconnect extension”) or by removing it from Chrome, either of which deletes the locally stored token immediately.

8. Data retention

We retain your personal information for as long as your account is active or as needed to provide the service. Specifically:

  • Account data — retained until you close your account.
  • Resume and profile data — retained until you delete it or close your account.
  • Vault data — deleted immediately upon your request or account closure.
  • Payment records — retained for 7 years to comply with Canadian tax law.
  • Server logs — retained for up to 90 days for security and debugging.

After account closure, we delete or anonymize your personal information within 30 days, except where a longer retention period is required by law.

9. How we protect your information

  • All data is transmitted over TLS (HTTPS).
  • Databases are encrypted at rest.
  • Vault fields are encrypted with a session-derived key; we cannot read them without your authenticated session.
  • Access to production systems is restricted to authorized personnel.
  • We do not permanently store resume files — uploaded files are parsed and the binary is discarded after processing.

No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at support@launchresumeai.com.

10. Your rights

Under PIPEDA, you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — request that inaccurate or incomplete information be corrected.
  • Withdrawal of consent — stop our processing of your data, subject to legal or contractual restrictions.
  • Deletion — request deletion of your account and associated personal information.
  • Complaint — file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.

To exercise any of these rights, email support@launchresumeai.com with the subject line “Privacy Request”. We will respond within 30 days.

11. Cookies and tracking

We use session cookies set by Supabase to authenticate your session. We do not use third-party advertising cookies or cross-site tracking technologies. Analytics (if any) are collected in aggregate and not linked to identifiable individuals.

12. International data transfers

Some of our service providers (including Supabase and Anthropic) store or process data in the United States. By using RESUME.AI, you acknowledge that your personal information may be transferred to, stored in, and processed in the US, which may have different data protection laws than Canada. We ensure all sub-processors maintain appropriate contractual protections.

13. Children

RESUME.AI is not directed at individuals under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe a minor has provided us with their information, please contact us and we will delete it promptly.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top and notify you by email or in-app notice if the changes are material. Continued use of the service after the notice period constitutes acceptance of the revised policy.

15. Contact us

PRPL 7 Inc. is the organization responsible for the personal information under its control. For any privacy-related questions or requests:

PRPL 7 Inc.

Operating as RESUME.AI

support@launchresumeai.com