Skip to content
Resfolio

Privacy Policy

Updated 16 August 202611 min read17 sections
In short

We collect what Resfolio needs to work and nothing else: your name and email from Google or GitHub, the career content you write, and basic technical logs. We do not sell your data, do not use it to train AI models, and run no advertising or third-party tracking. AI features send the relevant part of your profile to our model provider. Your portfolio is public only when you publish it; your resume link is never indexed. You can export or delete everything, at any time.

A plain-language summary, not a substitute for what follows.

This policy explains what Resfolio collects, why, who it is shared with, and what you can do about it. It applies to resfolio.in, app.resfolio.in and s.resfolio.in. If anything here is unclear, write to us — the address is at the bottom.

Who we are

Resfolio is an AI career workspace operated from India. For the purposes of data-protection law we are the controller of the personal data described here, which means we decide what is collected and why.

For anything about your data — a question, an export, a deletion — write to hi@resfolio.in.

What we collect

From your sign-in provider

You sign in with Google or GitHub. We receive your name, email address, profile picture URL and the provider's account identifier — nothing more. We never receive your password, and we never ask you to create one for Resfolio.

What you put into Resfolio

  • Your profile — roles, projects, education, skills, links, summary, and any contact details you choose to include, in both its draft and its published versions.
  • Documents and sites — resumes, their layout settings and visibility, your portfolio's template and configuration, your public handle.
  • Writing — blog posts, drafts included, and the images inside them.
  • Applications — job postings you paste in, the match analysis produced from them, the status of each application and its history, and any cover letter generated for it.
  • Assistant conversations — saved so you can reopen them. A stored transcript is a record; it is never fed back to a model as context.
  • Uploaded files — avatars, cover images, favicons, and the résumé PDF you may import from.
  • Imports — items fetched from public sources you connect, held for review until you import or skip them.

Technical data

Our hosting and monitoring providers record standard request data — IP address, timestamp, browser and operating system, the page requested, and errors. We use it to keep the service running, diagnose faults, and enforce rate limits. We also count AI usage per account against your plan's allowance.

When you visit a page from outside India, our host tells us the country your request came from so we can quote prices in the right currency. We do not store it.

What we don't collect

  • No card details. Payments are handled entirely by Dodo Payments; card numbers never reach our servers.
  • No passwords, because there are none to store.
  • No advertising or analytics trackers. There are no third-party pixels, no ad networks, and no cross-site profiling on any Resfolio page.
  • No special-category data. Do not put health information, government identifiers, or similar into your profile — Resfolio has no field that needs it.
  • No contacts, calendar, or email access. We never ask a sign-in provider for more than your basic profile.

How your data is used

Everything is used for one of five purposes, and nothing else:

  • To run the service — store your profile, render your resume and portfolio, generate PDFs, publish what you publish.
  • To provide AI features you have asked for — matching a posting, tailoring a resume, drafting a letter, translating an export, reading a résumé you uploaded.
  • To keep it working and safe — error monitoring, abuse investigation, rate limiting, backups.
  • To bill correctly, once billing starts — counting usage against your plan's allowance.
  • To contact you about your account and about material changes to the service. These are service messages; we do not send marketing email you have not asked for.

We do not sell your data, and we do not use your content to train AI models. We instruct our AI provider not to train on it either.

AI processing

When you use a feature that calls a model, the input for that feature is sent to our AI provider over an encrypted connection. What is sent depends on the feature and is deliberately limited:

FeatureWhat leaves Resfolio
Job matchThe posting you pasted, and a structured view of your profile
Resume tailoringThe posting, and the profile content the resume renders
Cover letterThe posting, and the profile content it draws evidence from
AssistantYour message, the conversation, and a structured view of your profile
Translated exportOnly the prose of the resume — never dates, links, or company names
Résumé importThe PDF file you uploaded, which is read and then discarded

Two things we do not do. The placeholder content a new profile ships with is stripped before anything is sent, so a model never discusses example data as if it were your career. And an uploaded résumé is never stored — it is read to build your profile and the file itself is not kept.

If you would rather no content of yours reached a model provider at all, simply do not use the AI features. Your profile, resume PDFs, portfolio site and writing all work without them.

What is public, and what is not

This is the part most worth reading closely, because it is the part you control.

  • Private by default. A new profile, a draft, an unpublished post and an unpublished site are visible only to you.
  • Your portfolio is public once you publish it, at `s.resfolio.in/p/<your-handle>`, and search engines may index it while it is marked discoverable. Everything on it is content you put in your profile.
  • Your public resume is readable by anyone with the link but is never indexed — we send a no-index directive and disallow it in `robots.txt`, because a resume carries an email address and a phone number. Each resume also has its own public/private setting.
  • Your published posts appear on your portfolio and in its sitemap.
  • Nothing else is ever public. Drafts, tracked applications, match scores, assistant conversations and cover letters are visible only to you, and no employer sees any of them.

A page that has been public may have been copied, cached, or archived by parties we do not control. Unpublishing removes it from Resfolio; it cannot recall a copy somebody else already holds.

Imports from other services

You can connect GitHub, an RSS feed, Dev.to or Stack Overflow to bring your own work into your profile. All four are public sources: we fetch what is already published at those addresses, and we do not ask for or store any credential for them.

Fetched items are staged for your review and go nowhere until you press Import. Once imported they are ordinary Resfolio content — yours to edit or delete. Disconnecting a source stops future fetches and leaves everything you already imported in place.

Files and images

Images you upload are re-encoded on our servers before storage. That strips embedded metadata — including the GPS coordinates many phone cameras write into a photo — and rejects files that are only pretending to be images.

Files are stored on Cloudflare R2 under a key derived from your profile, so deleting your profile removes them in one operation. Generated resume PDFs are cached the same way, and are streamed back through an authenticated route rather than exposed at a public address.

Images used on a published page are served from our CDN and are, by necessity, publicly readable at their URL for as long as that page is published.

Cookies and local storage

We use the minimum a signed-in application needs, and nothing for advertising.

WhatPurposeKind
Session cookieKeeps you signed inEssential
Session cache cookieAvoids a database read on every requestEssential
Sidebar stateRemembers whether your sidebar is collapsedPreference
ThemeRemembers light, dark, or system (stored in your browser)Preference

There is no consent banner because there is nothing to consent to: every one of these is either strictly necessary or a preference you set yourself, and none of them tracks you across sites. Clearing your browser storage signs you out and resets your preferences.

Who we share data with

We share data only with the providers that run the service. Each is bound by its own agreement, receives only what it needs, and never receives your content for its own purposes.

ProviderWhat it doesWhat it sees
VercelHosts and serves all three sitesRequests, IP addresses, logs
NeonOur managed Postgres databaseEverything you store in Resfolio
Cloudflare R2File and image storage, and our CDNUploaded files and generated PDFs
OpenAIThe models behind every AI featureOnly the inputs listed in the AI section
Dodo PaymentsPayments, as merchant of recordYour email and payment details — not your content
Fly.ioRenders resume PDFsThe resume being printed, transiently
UpstashRate limitingAn account identifier and a counter
SentryError monitoringError reports and technical context
GoogleCompany icons in the Job TrackerThe domain of a company you tracked

The last row is the one worth flagging explicitly: to show a company's icon beside a tracked application, your browser requests it from Google's favicon service, which means that company's domain is sent there. Nothing about you accompanies it.

Beyond these, we disclose data only where the law requires it, or where it is necessary to investigate abuse or protect someone's safety. If Resfolio were ever acquired, your data would transfer with it and we would tell you before that happened.

Where your data lives

Our database is hosted in Singapore. Application servers run in India and, for some requests, at edge locations worldwide. Files are stored on a globally distributed object store, and our AI and payment providers process data in the United States.

Using Resfolio therefore means your data is transferred across borders. Where the law requires a safeguard for such a transfer, we rely on our providers' standard contractual clauses and equivalent mechanisms.

How long we keep it

  • Your content is kept for as long as your account exists, because it is the thing the account is for.
  • Published versions of your profile are kept as snapshots so a live page cannot change under a visitor while you edit a draft.
  • Deleted content goes immediately and is purged from backups within 30 days.
  • Technical logs and error reports are kept for up to 90 days.
  • Billing records are kept for as long as tax and accounting law requires, typically several years. These are records of payments, not of your career content.

Deleting your account deletes your profile, documents, sites, posts, tracked applications, conversations and files, and takes every published page offline.

Your rights

Depending on where you live you may have rights under the DPDP Act in India, the GDPR in Europe, or comparable laws elsewhere. We extend all of the following to everyone regardless:

  • Access — ask for a copy of what we hold about you.
  • Correction — most of it you can edit yourself, at any time, in the workspace.
  • Deletion — delete your account from settings, or ask us to do it.
  • Export — take your content with you: resumes export as PDFs, and we will provide a machine-readable copy of your profile on request.
  • Objection and restriction — ask us to stop a particular use of your data.
  • Withdraw consent — stop using the AI features, unpublish a page, or disconnect a source, at any time and without losing anything else.

Write to hi@resfolio.in and we will respond within 30 days. There is no charge. If you are unhappy with our answer, you may complain to your local data-protection authority.

Security

Everything is served over HTTPS. Sessions are stored server-side and can be revoked. Content-security policies restrict what a page may load, uploads are re-encoded rather than trusted, and AI endpoints are rate-limited per account. Access to production data is limited to what running the service requires.

No system is perfectly secure. If a breach ever affected your data, we would tell you and the relevant authority without undue delay, and say plainly what happened.

Found a vulnerability? Report it to hi@resfolio.in rather than disclosing it publicly, and we will work with you on a fix.

Children

Resfolio is not intended for anyone under 16 and we do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.

Changes to this policy

We will update this page as the product changes — a new sub-processor, a new feature that processes data differently. The date at the top always reflects the current version, and material changes are announced in the workspace before they take effect.

Contact

Privacy questions, data requests, and anything else: hi@resfolio.in. Our Terms of Service sit alongside this policy.

Still have a question?

Write to hi@resfolio.in. A person reads it.

Start free