GitResume GitResume
Features Docs Blog Pricing Login
Features Docs Blog Pricing Login

Privacy Policy

Last updated: July 28, 2026

1. Introduction

GitResume ("we", "us", "our") operates the gitresume.co platform. This Privacy Policy explains how we collect, use, and protect your personal information when you use our services.

2. Information We Collect

We collect information in the following ways:

  • Account Information: When you sign up via GitHub or Google OAuth, we receive your username, email address, display name, and avatar URL.
  • Repository Data: When you connect a GitHub repository, we access your resume YAML files via the GitHub App integration to build your resume. We do not store your repository contents beyond what is necessary for rendering.
  • Payment Information: When you subscribe to a paid plan, payments are processed by Polar (Polar Software Inc.) as our Merchant of Record. We do not directly collect or store credit card numbers or payment details. We store subscription status, plan type, and billing cycle information.
  • Cookies: We use httpOnly cookies for authentication (JWT access and refresh tokens). See our Cookie Policy for details.
  • AI Assistant Authorization Records: When you authorize an AI assistant to access your account (see section 9), we store the name and return URL the assistant registered, the permissions you approved, when the authorization was created and last used, and a record of the tokens issued. These are credentials and operational state; they do not include your conversations with the assistant.

3. How We Use Your Information

  • To provide and maintain the GitResume service
  • To authenticate you and manage your account
  • To build and deploy your resume from YAML files
  • To host your public resume page at gitresume.co/@username/slug
  • To process payments and manage subscriptions
  • To send service-related emails (such as welcome emails and build status notifications)
  • To send product updates and marketing communications (every email includes an unsubscribe link, and you can opt out at any time)
  • To let an AI assistant access your account data on your behalf, as you authorized (see section 9)
  • To improve and optimize our platform

4. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: Processing account information, repository data, and build artifacts to provide the service you signed up for.
  • Legitimate Interests: Improving and optimizing the platform, preventing abuse, and ensuring service security.
  • Legal Obligations: Retaining or disclosing information when required by law.
  • Consent: Where applicable, we obtain your explicit consent before processing your data (for example, authorizing an AI assistant to access your account).

5. Third-Party Service Providers

We use third-party service providers to operate our platform, including:

  • Payment Processor (Polar): Processes all payment transactions, tax calculations, and compliance as our Merchant of Record. Payment information is collected and processed directly by Polar and does not pass through GitResume servers. See Polar's Privacy Policy.
  • Hosting and Infrastructure Providers: Provide CDN, DNS, DDoS protection, and file storage services.
  • Email Service Provider: Sends transactional and product communication emails on our behalf, and stores recipient contact details (name, email) and unsubscribe status.

These providers process your data only to the extent necessary to deliver their services and are bound by their respective privacy policies.

6. Data Sharing

We do not sell, trade, or rent your personal information to third parties. We may share data only in the following circumstances:

  • With your consent
  • To comply with legal obligations
  • To protect our rights, privacy, safety, or property
  • With the service providers listed above, bound by confidentiality obligations
  • With an AI assistant you explicitly authorized, limited to the permissions you approved (see section 9)

7. Public Resume Pages

When you deploy a resume, the content you include in your YAML file becomes publicly accessible at your chosen URL (gitresume.co/@username/slug). You control what information appears in your resume. You can delete your resume at any time — once deleted, the page will no longer be accessible and search engines will remove it from their indexes.

8. Resume Analytics

We collect anonymous viewing statistics for public resume pages, such as view counts, referrer sources, visitor countries, and device types. This data is visible only to the resume owner. We do not use cookies or third-party tracking tools for this purpose.

9. AI Assistant Authorization

You can authorize an AI assistant (for example Claude) to access GitResume on your behalf. You start that authorization, you choose its scope, and you can revoke it at any time.

You choose what to grant. The authorization screen lists the permissions the assistant asks for, and granting read access alone is a valid choice:

  • Read: your projects, resume content, build history, resume PDFs, and analytics
  • Build: trigger a resume rebuild
  • Publish: publish or unpublish your resume

A permission you withhold does not exist for that assistant: it can neither see nor call the corresponding feature.

This authorization never gives GitResume write access to your GitHub repository. After an assistant helps you revise your resume, you commit the change to your repository yourself.

How to revoke. Revoke under Profile → Connected Agents. Revoking ends the authorization at once, so the assistant can no longer obtain new access tokens. An access token already issued is stateless and remains usable for up to 15 minutes, so a revoked connection stops working within 15 minutes at the latest. If you believe an assistant behaved unexpectedly, review your builds and publication status for that period in addition to revoking it.

What the assistant's provider does with your data is not governed by this policy. Once an assistant you authorized receives data, its provider's own privacy policy applies. We recommend confirming you trust the service before authorizing it.

We do not collect your conversations with AI assistants. We store the authorization record itself (see section 2) and the ordinary server logs produced when the assistant calls our service.

10. Data Storage

  • All data transmission is encrypted using HTTPS
  • Built artifacts (PDFs, HTML) are stored in encrypted cloud object storage

11. Data Retention

We retain your account data for as long as your account is active. When you delete your account, your data will be permanently removed within 30 days. Built artifacts (PDFs, HTML) are deleted immediately upon project or account deletion. Payment records are retained by Polar as required by law.

12. Data Security

We implement industry-standard security measures including encrypted connections (HTTPS), httpOnly cookies with SameSite=Lax, webhook signature verification (HMAC-SHA256), secure token handling, and DDoS protection and traffic filtering. However, no method of transmission over the Internet is 100% secure.

13. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and associated data
  • Export your data (your resume YAML is always in your GitHub repo)
  • Opt out of marketing communications (via the unsubscribe link in any email, or by contacting us)
  • Withdraw consent for optional data processing
  • Revoke an authorization you gave an AI assistant (see section 9)

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice on our website. Your continued use of the service after changes constitutes acceptance.

15. Contact

If you have questions about this Privacy Policy, contact us at [email protected].

GitResume GitResume

Resume as Code

[email protected]

Resources

  • Documentation
  • Blog
  • Pricing

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy
© 2026 GitResume. All rights reserved.