Resume Rerun

Privacy Policy

Effective August 5, 2026

What we collect

When you use Resume Rerun, you paste in your resume text and a job description. If you upload your resume or the job description as a file instead (PDF, Word, or plain text), it is read in your browser and only the extracted text is used - the file itself never leaves your device. If you request access, you give us your email, and optionally your role or industry. We keep that address - see How long data is retained, below. If you leave feedback on a result, you can add a comment and tap a reason chip; that message also carries the run's fit verdict and the company and role names read from the job description, so we can tell which kind of run the feedback describes.

Your resume itself often contains personal details - your name, phone number, email, and home city or address. We treat all of it the same way as the rest of your resume text: it goes to Anthropic to generate your result, and is not stored by us afterward.

If your resume is written in another language, it is translated into English as part of generating your result, and that translated text is handled exactly like the rest of your resume text - used to produce your result, and not stored afterward.

When you use Resume Rerun, some non-identifying technical data is collected to help us fix bugs: whether a page-repair pass fired, the fit verdict your run produced, your device/browser type, how long the run took, and rough input/output sizes (character and item counts - never the content itself). None of this telemetry includes your name, email, or IP address.

We do use your IP address to rate-limit requests and block abuse. We also use your IP address to determine your country, since Resume Rerun is currently limited to users in the United States - requests from outside the US are rejected before anything runs. It is checked at request time and is not stored or logged with your run.

To enforce usage limits we store a one-way HMAC of your access token, together with a count of generations, in a third-party cache (Upstash) for up to one hour from your first generation in that window. We do not store your access token itself, your IP address, or anything from your resume or the job description in that cache.

If you use a free preview run without an access code, we issue your browser an anonymous pass. To enforce the preview limits we store a one-way HMAC of that pass in the same cache, with a separate count for each tool you use, for up to 24 hours, and a daily total of free preview runs across all visitors for up to 48 hours. The pass is not linked to you, and we do not store your IP address or anything from your resume or the job description alongside either.

If something goes wrong while Resume Rerun is handling your request, we record what kind of failure it was - an error type and a status code - so we can find and fix it. Those records describe the failure itself: they do not contain your resume, the job description, or anything else you typed.

Before your resume and job description are used to generate a result, we automatically check for Social Security numbers and reject the submission if one is found. This check is scoped specifically to SSN-formatted numbers - it does not detect other categories of sensitive information.

Some things do not belong on a resume and we do not need them. Please leave out financial account numbers, government ID numbers, health information, and passwords or login details. We screen for Social Security numbers specifically, as described above; we do not detect these other categories.

What we don't do

Where your data goes

A short list of services touch your data to make the product work, and each is used only for that purpose:

How long data is retained

Your resume and job description are used to generate your result and are not written to any database. Your generated results and the run tracker (company, role, fit, and the tailored output) are kept only in your own browser's storage on your device - that copy is never sent to us - so your session survives a page reload or closing the tab. The stored run tracker clears automatically after about a day, when a different access code signs in on the device, or when you clear your browsing data. Your access token is stored the same way and expires after 24 hours. Emails we send ourselves (access requests, feedback) live in our inbox until we act on or delete them. The access-request list has no fixed expiry - we keep it until you ask us to remove your entry, or until we no longer need it.

The internal diagnostics named above are counts and are kept on their own schedules. Counts of how often each kind of error occurs, including which part of the app produced it, are kept for up to 24 hours from the first time that kind of error occurs. Daily totals of requests and runs are kept for up to 90 days. The count of how many times each access code has been redeemed has no fixed expiry, so a code that was shared more widely than intended stays visible to us. All three are counts only: no names, no email addresses, no IP addresses, and nothing from your resume or the job description.

The model itself runs on Anthropic's API. Anthropic's published policy for API content is that prompts and responses are not retained by default, and we use no feature that requires retention. It may hold them longer only where its own safety systems flag a request or the law requires it. We have not arranged any extended retention. That side is governed by Anthropic's terms, which they can change - see their privacy policy for the current position.

Your choices

If you asked for access, email us and we will delete your entry from that list. If you sent feedback, we will delete that email too. Nothing else about you is stored - your resume and job description were never kept.

Children

Resume Rerun is a job-search tool intended for job seekers of working age. It is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child under 13 has used the service, contact us and we will remove anything they sent us.

Changes to this policy

If what we collect or how we use it changes in a way that matters, we'll update this page and the date above.

Contact

Questions about this policy? Get in touch.