Privacy policy

Last updated September 23, 2026

The short version

Your resumes live in your own browser. ResumePoint has no analytics or advertising trackers. Your text leaves your device only when you use an AI feature, or if you choose to sign in and sync. This page explains exactly when and where it goes.

What stays on your device

  • All resumes, cover letters and job descriptions you enter are saved in your browser’s storage (IndexedDB and localStorage).
  • The resume score, job match, keyword analysis, PDF, Word and text exports, and importing PDF, Word or text files all run locally in your browser. Nothing is uploaded for them.
  • Clearing your browser data, or using “Erase everything” in Settings, deletes it. Download a backup first if you need one.

AI features

When you click an AI button (rewrite, summary, tailoring, cover letter, interview questions, written review, or “read again with AI” when importing), the relevant text is sent to this app’s server, which forwards it to the configured AI service (Google’s Gemini API, or OpenRouter, which relays it to the model provider) to produce the result.

  • You are asked for permission the first time, and you can withdraw it in Settings.
  • For most features we send the resume text without your email address, phone number, links or photo. “Read again with AI” in the importer sends the text of the file you imported, which may contain contact details.
  • The ResumePoint server does not store your text or the AI’s reply, and does not use it to train any model. The AI service (and, for OpenRouter, the model provider behind it) handles data under its own terms; free models in particular may log requests, so check their terms.
  • If the app is running in “Demo AI” mode, no AI service is used at all: suggestions are produced by fixed rules on the server and nothing is sent to a third party.

AI can be wrong. It is instructed not to invent facts and to leave bracketed placeholders for numbers it cannot know, but you are responsible for everything on the resume you send to an employer.

Optional account and cloud sync

If you sign in (Google or email and password), your resumes are copied to a private area of Google Firebase (Cloud Firestore) tied to your account, so you can open them on another device. Security rules allow only the signed-in owner to read or change them. Google encrypts data in transit and at rest by default. You can delete your cloud copies at any time from the account dialog, and you can use the whole app without an account.

Logs and errors

The server keeps ordinary request logs (for example time, page and status). If something in the app crashes, a short error message (never your resume text) may be reported to the server log so we can fix it. There are no cookies for tracking; the app stores only your preferences and resume data in your browser.

Your choices

  • Use ResumePoint without AI or an account. The core features work without either.
  • Download a backup of everything (Settings, then “Download backup”), or erase it.
  • Delete your cloud copies and sign out from the account dialog.

Questions? Email hello@devnexa.dev.