Privacy Policy
We collect what Resfolio needs to work and nothing else: your name and email from Google or GitHub, the career content you write, and basic technical logs. We do not sell your data, do not use it to train AI models, and run no advertising or third-party tracking. AI features send the relevant part of your profile to our model provider. Your portfolio is public only when you publish it; your resume link is never indexed. You can export or delete everything, at any time.
A plain-language summary, not a substitute for what follows.
This policy explains what Resfolio collects, why, who it is shared with, and what you can do about it. It applies to resfolio.in, app.resfolio.in and s.resfolio.in. If anything here is unclear, write to us — the address is at the bottom.
Who we are
Resfolio is an AI career workspace operated from India. For the purposes of data-protection law we are the controller of the personal data described here, which means we decide what is collected and why.
For anything about your data — a question, an export, a deletion — write to hi@resfolio.in.
What we collect
From your sign-in provider
You sign in with Google or GitHub. We receive your name, email address, profile picture URL and the provider's account identifier — nothing more. We never receive your password, and we never ask you to create one for Resfolio.
What you put into Resfolio
- Your profile — roles, projects, education, skills, links, summary, and any contact details you choose to include, in both its draft and its published versions.
- Documents and sites — resumes, their layout settings and visibility, your portfolio's template and configuration, your public handle.
- Writing — blog posts, drafts included, and the images inside them.
- Applications — job postings you paste in, the match analysis produced from them, the status of each application and its history, and any cover letter generated for it.
- Assistant conversations — saved so you can reopen them. A stored transcript is a record; it is never fed back to a model as context.
- Uploaded files — avatars, cover images, favicons, and the résumé PDF you may import from.
- Imports — items fetched from public sources you connect, held for review until you import or skip them.
Technical data
Our hosting and monitoring providers record standard request data — IP address, timestamp, browser and operating system, the page requested, and errors. We use it to keep the service running, diagnose faults, and enforce rate limits. We also count AI usage per account against your plan's allowance.
When you visit a page from outside India, our host tells us the country your request came from so we can quote prices in the right currency. We do not store it.
What we don't collect
- No card details. Payments are handled entirely by Dodo Payments; card numbers never reach our servers.
- No passwords, because there are none to store.
- No advertising or analytics trackers. There are no third-party pixels, no ad networks, and no cross-site profiling on any Resfolio page.
- No special-category data. Do not put health information, government identifiers, or similar into your profile — Resfolio has no field that needs it.
- No contacts, calendar, or email access. We never ask a sign-in provider for more than your basic profile.
How your data is used
Everything is used for one of five purposes, and nothing else:
- To run the service — store your profile, render your resume and portfolio, generate PDFs, publish what you publish.
- To provide AI features you have asked for — matching a posting, tailoring a resume, drafting a letter, translating an export, reading a résumé you uploaded.
- To keep it working and safe — error monitoring, abuse investigation, rate limiting, backups.
- To bill correctly, once billing starts — counting usage against your plan's allowance.
- To contact you about your account and about material changes to the service. These are service messages; we do not send marketing email you have not asked for.
We do not sell your data, and we do not use your content to train AI models. We instruct our AI provider not to train on it either.
AI processing
When you use a feature that calls a model, the input for that feature is sent to our AI provider over an encrypted connection. What is sent depends on the feature and is deliberately limited:
| Feature | What leaves Resfolio |
|---|---|
| Job match | The posting you pasted, and a structured view of your profile |
| Resume tailoring | The posting, and the profile content the resume renders |
| Cover letter | The posting, and the profile content it draws evidence from |
| Assistant | Your message, the conversation, and a structured view of your profile |
| Translated export | Only the prose of the resume — never dates, links, or company names |
| Résumé import | The PDF file you uploaded, which is read and then discarded |
Two things we do not do. The placeholder content a new profile ships with is stripped before anything is sent, so a model never discusses example data as if it were your career. And an uploaded résumé is never stored — it is read to build your profile and the file itself is not kept.
If you would rather no content of yours reached a model provider at all, simply do not use the AI features. Your profile, resume PDFs, portfolio site and writing all work without them.
What is public, and what is not
This is the part most worth reading closely, because it is the part you control.
- Private by default. A new profile, a draft, an unpublished post and an unpublished site are visible only to you.
- Your portfolio is public once you publish it, at `s.resfolio.in/p/<your-handle>`, and search engines may index it while it is marked discoverable. Everything on it is content you put in your profile.
- Your public resume is readable by anyone with the link but is never indexed — we send a no-index directive and disallow it in `robots.txt`, because a resume carries an email address and a phone number. Each resume also has its own public/private setting.
- Your published posts appear on your portfolio and in its sitemap.
- Nothing else is ever public. Drafts, tracked applications, match scores, assistant conversations and cover letters are visible only to you, and no employer sees any of them.
A page that has been public may have been copied, cached, or archived by parties we do not control. Unpublishing removes it from Resfolio; it cannot recall a copy somebody else already holds.
Imports from other services
You can connect GitHub, an RSS feed, Dev.to or Stack Overflow to bring your own work into your profile. All four are public sources: we fetch what is already published at those addresses, and we do not ask for or store any credential for them.
Fetched items are staged for your review and go nowhere until you press Import. Once imported they are ordinary Resfolio content — yours to edit or delete. Disconnecting a source stops future fetches and leaves everything you already imported in place.
Files and images
Images you upload are re-encoded on our servers before storage. That strips embedded metadata — including the GPS coordinates many phone cameras write into a photo — and rejects files that are only pretending to be images.
Files are stored on Cloudflare R2 under a key derived from your profile, so deleting your profile removes them in one operation. Generated resume PDFs are cached the same way, and are streamed back through an authenticated route rather than exposed at a public address.
Images used on a published page are served from our CDN and are, by necessity, publicly readable at their URL for as long as that page is published.
Who we share data with
We share data only with the providers that run the service. Each is bound by its own agreement, receives only what it needs, and never receives your content for its own purposes.
| Provider | What it does | What it sees |
|---|---|---|
| Vercel | Hosts and serves all three sites | Requests, IP addresses, logs |
| Neon | Our managed Postgres database | Everything you store in Resfolio |
| Cloudflare R2 | File and image storage, and our CDN | Uploaded files and generated PDFs |
| OpenAI | The models behind every AI feature | Only the inputs listed in the AI section |
| Dodo Payments | Payments, as merchant of record | Your email and payment details — not your content |
| Fly.io | Renders resume PDFs | The resume being printed, transiently |
| Upstash | Rate limiting | An account identifier and a counter |
| Sentry | Error monitoring | Error reports and technical context |
| Company icons in the Job Tracker | The domain of a company you tracked |
The last row is the one worth flagging explicitly: to show a company's icon beside a tracked application, your browser requests it from Google's favicon service, which means that company's domain is sent there. Nothing about you accompanies it.
Beyond these, we disclose data only where the law requires it, or where it is necessary to investigate abuse or protect someone's safety. If Resfolio were ever acquired, your data would transfer with it and we would tell you before that happened.
Where your data lives
Our database is hosted in Singapore. Application servers run in India and, for some requests, at edge locations worldwide. Files are stored on a globally distributed object store, and our AI and payment providers process data in the United States.
Using Resfolio therefore means your data is transferred across borders. Where the law requires a safeguard for such a transfer, we rely on our providers' standard contractual clauses and equivalent mechanisms.
How long we keep it
- Your content is kept for as long as your account exists, because it is the thing the account is for.
- Published versions of your profile are kept as snapshots so a live page cannot change under a visitor while you edit a draft.
- Deleted content goes immediately and is purged from backups within 30 days.
- Technical logs and error reports are kept for up to 90 days.
- Billing records are kept for as long as tax and accounting law requires, typically several years. These are records of payments, not of your career content.
Deleting your account deletes your profile, documents, sites, posts, tracked applications, conversations and files, and takes every published page offline.
Your rights
Depending on where you live you may have rights under the DPDP Act in India, the GDPR in Europe, or comparable laws elsewhere. We extend all of the following to everyone regardless:
- Access — ask for a copy of what we hold about you.
- Correction — most of it you can edit yourself, at any time, in the workspace.
- Deletion — delete your account from settings, or ask us to do it.
- Export — take your content with you: resumes export as PDFs, and we will provide a machine-readable copy of your profile on request.
- Objection and restriction — ask us to stop a particular use of your data.
- Withdraw consent — stop using the AI features, unpublish a page, or disconnect a source, at any time and without losing anything else.
Write to hi@resfolio.in and we will respond within 30 days. There is no charge. If you are unhappy with our answer, you may complain to your local data-protection authority.
Security
Everything is served over HTTPS. Sessions are stored server-side and can be revoked. Content-security policies restrict what a page may load, uploads are re-encoded rather than trusted, and AI endpoints are rate-limited per account. Access to production data is limited to what running the service requires.
No system is perfectly secure. If a breach ever affected your data, we would tell you and the relevant authority without undue delay, and say plainly what happened.
Found a vulnerability? Report it to hi@resfolio.in rather than disclosing it publicly, and we will work with you on a fix.
Children
Resfolio is not intended for anyone under 16 and we do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
Changes to this policy
We will update this page as the product changes — a new sub-processor, a new feature that processes data differently. The date at the top always reflects the current version, and material changes are announced in the workspace before they take effect.
Contact
Privacy questions, data requests, and anything else: hi@resfolio.in. Our Terms of Service sit alongside this policy.
Still have a question?
Write to hi@resfolio.in. A person reads it.