Privacy Policy
Last updated: December 26, 2025
Data We Collect
DE Resume Scanner collects minimal data to provide our service:
- IP addresses for rate limiting
- Email addresses (when you create an account via Google/GitHub OAuth)
- Resume text (first 10,000 characters) and job descriptions (first 5,000 characters)
- Scan results, scores, and analysis data
- User ID and authentication tokens (managed by NextAuth.js)
How We Use Your Data
Your data is used to provide and improve our service:
- Resume and job description text is sent to OpenRouter API for AI analysis
- Scan results are stored in your account for history and dashboard access
- Data is used to enforce rate limits and prevent abuse
- Analytics help us improve the service (no personal data shared)
- Your data is never sold or shared with third parties
Rate Limiting
We use Upstash Redis to store IP addresses temporarily for rate limiting. This data is automatically deleted after 24 hours.
Data Retention
We retain data for the following periods:
- Scan results: Stored indefinitely until you delete them
- Account data: Until you delete your account
- IP addresses: 24 hours (for rate limiting)
- Authentication tokens: Until you sign out
Data Security
We implement industry-standard security measures:
- All data transmitted over HTTPS (TLS 1.3)
- Database encryption at rest (Supabase)
- Row Level Security (RLS) - only you can access your scans
- OAuth authentication (Google, GitHub) - no passwords stored
- Rate limiting to prevent abuse
- Input validation and XSS protection
Third-Party Services
We use the following third-party services:
- OpenRouter: AI analysis provider - your resume text is sent to their API (via OpenAI GPT-4o-mini) for keyword extraction and scoring
- Supabase: Database and authentication - stores your scans and account data securely
- Upstash Redis: Rate limiting storage - stores hashed IP addresses for 24 hours
- Vercel: Hosting and edge functions
- Google/GitHub: OAuth authentication providers
Your Rights
You have the following rights regarding your data:
- Access: View all your scans in the dashboard
- Delete: Delete individual scans or your entire account
- Export: Export your scan results as PDF
- Portability: Request a copy of your data in JSON format
- Withdraw Consent: Delete your account at any time
To exercise these rights, visit your dashboard or contact us.
Contact
For privacy questions or concerns, please contact us through our website.