Privacy Notice
Last updated: 23 June 2026
This notice explains how Universal Resume collects and uses your personal data when you use the app.
Universal Resume lets you import or write a resume in Markdown and turn it into a website and PDF. It collects as little personal data as possible while still providing that service.
What it collects
- Account details. To save your work you sign in with your email address, using a one-time magic link or your Google or GitHub account. It stores your email address. It does not ask for or store a password. It also stores sign-in tokens to keep you signed in: a short-lived one-time link token, and, by default, a longer-lived token so you stay signed in across visits.
- Your resume content. This app stores the Markdown you write or import when you save or publish it, to persist your work so you can return to it, edit it, and access it across your devices.
- Files you upload to import. When you import a resume, the file you upload (a PDF or image, up to 10 MB) is stored only temporarily on the app's server and is deleted as soon as its contents have been extracted — whether the import succeeds or fails. It does not keep your original files.
- Usage analytics. It keeps privacy-friendly, cookieless analytics about page visits — the page path, an approximate country derived from your IP address, and a visitor count based on a one-way hash that is rotated daily and cannot be traced back to you. It does not store your raw IP address in its analytics.
- Technical data. Like any web service, it processes technical information such as your IP address momentarily to serve pages, keep the service secure, and limit abuse (for example, to rate-limit resume imports).
Why it uses your data, and its legal bases
- To provide the service — saving your resume, syncing it across devices, importing and converting uploads, and publishing — on the basis of its contract with you.
- To send you service emails, such as your sign-in link and a copy of your published Markdown, on the basis of its contract with you.
- To keep the service secure and prevent abuse, and to understand aggregate usage so the product can improve, on the basis of its legitimate interests.
Where it asks for your consent, it relies on that consent, which you can withdraw at any time.
Who it shares your data with
Universal Resume does not sell your personal data. It shares it only with the service providers used to run Universal Resume:
- Resend — delivers service emails (your sign-in link and your published-Markdown email).
- OpenAI and Anthropic — when you import a resume, the contents of the file you upload are sent to these AI providers to extract and convert it into Markdown. Universal Resume uses their business APIs, under which your content is processed only to perform the conversion and is not used to train their models.
- Hosting and database provider — runs the application and stores your data.
- Cloudflare — provides cookieless web analytics, used only when enabled.
- Let’s Encrypt — used only if you connect a custom domain to your published resume; the domain name is shared with this certificate authority so it can issue the domain’s HTTPS (TLS) certificate.
International transfers
Some of these providers — including the AI providers above — are based in the United States, so your data may be processed outside the European Economic Area. Where that happens, Universal Resume relies on appropriate safeguards, such as the providers’ standard data-protection terms, to protect it.
Cookies
It uses only essential cookies — to keep you signed in and to protect the app (for example, against cross-site request forgery). They are required for the app to work and are not used for advertising or cross-site tracking. Its analytics do not use cookies.
How long it keeps your data
- Your account, resume drafts, saved versions, and published resume are kept while your account is active, until you delete them or ask for your account to be deleted.
- Files you upload to import are deleted immediately after their contents are extracted.
- Sign-in tokens are short-lived and expire automatically.
- Analytics are kept only in aggregated form and contain nothing that identifies you.
When your resume is public
If you publish your resume or connect a custom domain, the published content is public by design — anyone with the link or domain can view it. To take it down, email hi@webpraktikos.com and it will be removed.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or object to this app's use of your personal data, to receive a copy of it in a portable format, and to withdraw consent where it relies on it. To exercise any of these rights, email hi@webpraktikos.com. You also have the right to lodge a complaint with your local data-protection supervisory authority.
Changes to this notice
This notice may be updated from time to time. When that happens, the “last updated” date at the top of this page will be revised.
Contact
Questions about your privacy or this notice? Email hi@webpraktikos.com.