Privacy Policy
Version 2026-09-14
Published September 14, 2026.
Resumarsh hosts your résumé and lets you share it. This describes what we hold, where it goes, and how to get rid of it.
What we hold
What you give us. Your profile: name, headline, contact details you choose to add, your work history, projects, and any media you upload. You decide what goes in and you can edit or remove any of it.
Who you are. Sign-in is handled by WorkOS. We store the identifier they give us and your email address. We never see your password, and if you sign in with Apple, Google or GitHub we never see those credentials either.
Services you connect. You can connect accounts you hold elsewhere — GitHub today — to your resumarsh account. WorkOS holds the connection and its access tokens; we never store them. What we keep is only what the feature makes from the connection: repositories you choose to import become draft projects in your résumé (yours to edit or delete like anything else you wrote), and — only if you switch it on — a small synced summary of your public activity that the AI features may cite. That summary is off by default, you can see exactly what it contains before and after enabling it, and switching it off deletes it immediately.
What happens to what you share. When you create a share link we record that it was opened and when, and — if you named a recipient — who it was for. This is the point of the feature, and it is visible to you in your console.
Questions asked about you. If someone uses the Ask feature on your profile, we store the question, the answer, and which share link they came from.
Screening and billing. Recruiters can save screening questions, generated answers, source references, and scorecards. We record answer usage to apply free allowances and paid packs. For purchases, we retain the purchase reference, amounts and taxes, payment and refund status, allowance, activation and expiration dates, and whether Stripe is merchant of record for the purchase. Stripe hosts checkout and processes the payment and billing-location information needed for tax calculation. For transactions labeled Sold through Link, Stripe also acts as merchant of record, provides receipts and transaction support, and handles applicable tax compliance. It processes payment and billing information under its own privacy policy. If you contact Link about a payment, the information you provide is handled by Link; contacting Resumarsh support uses the mail process described below. We do not store payment-card details in the Resumarsh purchase ledger.
Support messages. Messages sent to our published contact addresses include the sender and reply address, message body, and any attachments. They are received through Resend and forwarded to a Gmail inbox monitored by the owner. Please do not send payment-card details in support messages.
Where it goes
Your résumé content is processed by large language models to answer questions and generate reviews. That happens on Amazon Bedrock, inside our own AWS account, in the United States. Bedrock does not use your content to train models.
Other services that necessarily see some of your data:
| Who | What for |
|---|---|
| Amazon Web Services | hosting, database backups, media storage and delivery, email |
| Neon | the database your profile lives in |
| Vercel | serving the website |
| WorkOS | sign-in, the accounts you connect and their access tokens, and the emails it sends about your account |
| Stripe / Link | checkout, payments, merchant-of-record services where identified at checkout, applicable tax compliance, receipts, transaction support, and refunds |
| Resend | receiving and forwarding contact mail, including its contents and attachments |
| Google Gmail | the owner's monitored support inbox |
We do not sell your data, and we do not share it with advertisers.
What is public
A profile is private by default. It is visible to others only if you publish it, or if you create a share link and give that link to someone. A private profile is not listed anywhere and returns "not found" to anyone without a link.
Disconnecting a service
Disconnecting removes the synced summary, the consent setting, and the link between the connection and anything it imported. Draft projects you accepted into your résumé stay — they are your content — and you can delete them like anything else. Disconnecting here does not revoke resumarsh's access at the other service; to do that, remove the grant where it lives (for GitHub: Settings → Applications → Authorized OAuth Apps).
How long we keep it
Your profile content stays until you delete it. Deleting a profile removes its profile-owned data. Recruiters' saved screening answers, candidate records, and scorecards have separate lifecycles and may remain after a profile is deleted. Contact support to request review or removal of retained material. Mail sent to our contact addresses is moved to Gmail Trash after 90 days. Gmail normally permanently deletes mail from Trash after another 30 days, so a forwarded support-inbox copy may remain for up to about 120 days. Mail providers may retain delivery logs and backups under their own policies.
Purchase records are separate from your public profile. Deleting a profile does not itself delete the purchase ledger, which supports payment reconciliation, refunds, and accounting. Contact support to request review of retained records.
Your choices
You can edit or delete anything in your profile at any time, revoke any share link, disconnect any connected service, and delete your account. To ask what we hold about you, or to have it removed, write to support@resumarsh.com.
Changes
If we change this policy we publish a new version and ask you to accept it the next time you sign in. Old versions stay on record, because they are what people agreed to at the time.
Questions: support@resumarsh.com.