Legal

Privacy Policy

How we collect, use, and protect your personal data. We keep this short and specific.

Last updated: 21 April 2026

1. Who controls your data

Data controller: ResumeSync AB (org. nr to be registered), Sweden.
Contact: privacy@resumesync.io

The supervisory authority for data protection in Sweden is Integritetsskyddsmyndigheten (IMY) at imy.se. You have the right to lodge a complaint with IMY if you believe we have mishandled your data.

2. What data we collect and why

One-off resume generation (no account)

When you use the Service without an account, we process:

  • Your LinkedIn PDF export — to extract your professional background. Processed in-session, deleted within 24 hours.
  • The job description you paste — used solely to generate the resume. Deleted within 24 hours.
  • Your interview answers — used to verify experience. Deleted within 24 hours.
  • Payment transaction data — processed by Stripe. We receive only a transaction ID and status, not your card details.
  • Standard server logs — IP address, browser type, request timestamps. Retained for up to 30 days for security and error diagnosis.

Legal basis: Article 6(1)(b) GDPR — performance of a contract.

Account holders

If you create an account, we additionally process:

  • Name and email address — for authentication and account management.
  • OAuth profile data (if you sign in with Google or LinkedIn) — name, email, and profile photo from those providers.
  • Saved resumes — stored in our database at your request.
  • Job application data — company names, roles, statuses, contacts, and notes you add to your job tracker.

Legal basis: Article 6(1)(b) GDPR — performance of a contract (account services).

Communication

If you contact us by email, we retain that correspondence to respond and for quality purposes. Legal basis: Article 6(1)(f) GDPR — legitimate interest.

3. Data processors (sub-processors)

We share data with the following processors under data processing agreements:

ProcessorPurposeLocation
Anthropic PBCAI resume generation (Claude API)USA (SCCs applied)
Stripe, Inc.Payment processingUSA (SCCs applied)
Neon Inc.PostgreSQL database hostingEU (Frankfurt)
Vercel Inc.Web hosting and edge functionsEU + USA (SCCs applied)
Sanity ASCMS for blog and resource contentUSA (SCCs applied)

Standard Contractual Clauses (SCCs) are in place for all transfers outside the EU/EEA, in compliance with GDPR Chapter V.

4. Data retention

  • Session documents (LinkedIn PDF, job description, interview answers): deleted within 24 hours.
  • Account data: retained until you delete your account. You can request deletion at any time.
  • Saved resumes and job tracker data: retained until you delete them or close your account.
  • Payment records: retained for 7 years for accounting and legal compliance under Bokföringslagen (SFS 1999:1078).
  • Server logs: up to 30 days.

5. Cookies and tracking

We use only strictly necessary cookies required for authentication sessions. We do not use advertising cookies or third-party tracking pixels. No consent banner is shown because no non-essential cookies are set.

6. Your rights under GDPR

You have the right to:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion ("right to be forgotten").
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction — ask us to limit how we process your data in certain circumstances.
  • Objection — object to processing based on legitimate interest.

To exercise any of these rights, email privacy@resumesync.io. We will respond within 30 days. If you are unsatisfied with our response, you may complain to IMY at imy.se.

7. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Database access is restricted by role-based access control. We apply the principle of minimum necessary data collection.

8. Changes to this policy

We will notify account holders by email of material changes at least 14 days before they take effect. The current version is always available at this URL.