Last updated: 30 August 2026
Your resume is used to answer your own requests and nothing else. It is not shown to other users, not sent to employers, not sold, and not visible in the operator's own dashboard. There is no password to lose, because sign-in goes through Google.
Only you. The operator's admin view is built to show counts, revenue and error status — how many documents exist, whether a profile has been built, how many jobs were scored. It does not display your documents, your profile, or anything generated for you.
This is enforced in the code and covered by tests, not only stated in this policy. Every query for your data requires your account ID; there is no unscoped way to read it. That is a deliberate limit on what a compromised operator account could expose.
To run an AI action, the relevant part of your profile plus a job description is sent to our AI provider (OpenAI) over an encrypted connection, under an account belonging to this service — you do not need an AI account of your own. We do not send your data to any other third party, do not sell it, do not share it with recruiters, and do not use it to train any model.
Job postings are read from companies' own public careers feeds. Nothing about you is sent to those companies. When you apply, you do it yourself on their site.
Infrastructure: the application runs on a virtual machine in India, and the database is hosted in Singapore by Neon. Payments are processed in India by Razorpay.
Two things are shared across all accounts because they are identical for everyone and fetching them once keeps the service cheap: job postings and company briefings. Nothing derived from you is shared — your scores, resumes, messages, saved jobs and usage are visible only to your account.
One cookie holds your sign-in session, and a second short-lived one protects the Google sign-in handshake against cross-site request forgery. Both are strictly necessary for the service to function. There is no advertising, analytics or third-party tracking cookie on this site.
Your data is kept while your account exists. Sign-in sessions expire after 30 days and expired ones are purged automatically.
This is an early-stage product run by an individual, not a company with a security team. Tenant isolation is implemented and tested, traffic is encrypted, and payment details never touch our servers — but no independent security audit has been carried out. If that matters for your situation, it is a fair reason to wait.
Questions, corrections or a deletion request: hello@codeskate.com.