Roy-Gulyamov Digital Inc.

01 / Privacy

Privacy policy

This policy explains what Resumify collects, why we collect it, who receives it, how long we keep it, and how you can access or delete it.

Effective October 3, 2026 · Roy-Gulyamov Digital Inc. · Ontario, Canada

Who we are

Resumify is an iOS app operated by Roy-Gulyamov Digital Inc., a company based in Ontario, Canada. In this policy, “we,” “us,” and “our” mean Roy-Gulyamov Digital Inc. “Resumify” means the iOS app and the account services behind it.

We are the organization responsible for personal information collected through the app. You can reach us at [email protected].

What this policy covers

This policy covers the Resumify iOS app, the accounts and files we store for it, and the pages on resumifyapp.org. It covers resume scoring, editing, tailoring, generation, cover letters, job tracking, subscriptions, the optional intake questions, and the product-usage records described below.

Apple processes your App Store payment, your Apple ID, and any App Store review you choose to submit under Apple’s own privacy policy. If you sign in with Google, Google processes that sign-in under Google’s privacy policy. This policy covers what we receive back from those services and what we do with it. We do not receive an App Store rating or review.

Information you give us

Account

When you create an account we collect your first name, last name, and email address. If you use an email and password, our authentication provider stores the password as a protected hash. We do not see or store the password itself.

If you use Sign in with Apple, Apple shares the name and email address you authorize. That email may be a private relay address. We store an Apple refresh token for that sign-in so we can revoke Resumify’s access to it when you delete the account. If you use Sign in with Google, Google shares the name and email address on the Google account you choose.

Optional intake

The first time a new account signs in, we show four optional questions, one at a time. You can skip every question. If you skip a question, we store that answer as empty. The answers are stored with your account so we can understand who the product is for. They are:

Accounts created before September 30, 2026 at 00:00 UTC are not shown this form. These answers are profile information. They are not part of your resume, and they are not sent to the scoring, editing, generation, tailoring, cover-letter, or extraction features.

Resumes, jobs, and files

When you use the app, you may give us:

A resume or job posting can contain contact details, work history, education, and other information about you or other people. We treat the whole document as personal information.

Information collected as you use the app

We keep product-usage records in our own database, tied to your account, so we can see which parts of the app people start, finish, leave, or export, and so we can see when an AI request fails. We do not send these records to an advertising network or a third-party analytics product.

Workflow and export records

When you run score, resume generation, deep-dive edits, improve, or a new cover letter, we store a row for the start of that run. If the run finishes, we store a completion row. If you leave before it finishes or fails, we store an abandonment row. If the run fails, we store a failure row. Opening a cover letter that was already saved does not create one of these rows. Closing the app in the middle of a run may leave only the start row.

When a resume PDF, a resume Word file, or a cover letter Word file is shared from the app, we store an export row with the format, either PDF or Word.

Each of these rows contains:

AI request measurements

Each time the app sends an authenticated AI request, our server stores a separate measurement. That row contains your account id, whether the request was a metered feature or an extraction, the feature or operation name, the model name, the duration on our server until the response, an error code, the app version sent with the request, and the same subscription snapshot. A successful request is coded “ok.” A refused or failed request is coded with a short reason such as premium required, rate limited, or the upstream status.

That measurement does not include the resume, the job description, the screenshot, the prompt, or the model’s reply. Those materials are still sent to the AI providers named below so the feature you started can run. They are not copied into the measurement.

Subscription metering

We store whether Resumify Premium is active, the plan length, and the purchase date, so the app can turn paid features on or off. We also store a count, for the current plan cycle, of how many times the account has used score, improve, tailor, cover letter, generate, and upload, so we can apply the plan limits. Those counts are numbers. They are not the text of your resume. Apple charges your payment method. We do not receive your card number, full payment card details, or Apple ID password.

The app keeps a sign-in session on your device, and it keeps temporary working copies of a resume task on the device while you are using that task. Signing out clears those working copies from the device. It does not delete the account or the files stored for that account.

Our authentication provider keeps the IP address and user-agent string for a sign-in so it can operate and secure the account. The user-agent string is a short label sent with the request, such as the app and system version. It is not an advertising identifier.

What we do not collect

We do not ask how long you have been job searching. We do not collect a satisfaction rating. We do not ask for a cancellation reason. If you cancel in Apple’s subscription settings, Apple does not send us a reason.

After you finish Improve and return to Home or My Resumes, the app may invite you once to leave an App Store review. You can dismiss it. If you choose to rate the app, you submit that review to Apple, not to us. We do not receive the star rating or the review text, and we do not add a usage record for the invitation or for your choice. The device remembers that the invitation was shown so it is not shown again. That memory stays on the device. It is not sent to us, and it is not tied to your account.

We do not ask you to create an advertising profile. We do not collect contacts, precise location, health information, advertising identifiers, or government identity numbers as separate fields. We do not use a third-party advertising or cross-app tracking SDK. If a resume you upload contains a phone number, address, or similar detail, that detail is there because it is inside the document you chose to store.

How we use information

We use account information, resumes, job information, files, subscription status, and feature-use counts to provide the service you asked for: to host your library, run a score, edit, tailor, generate, extract a job posting, track an application, keep you signed in, apply plan limits, and turn Premium features on or off.

We use intake answers to understand who the product is for. We use workflow, export, and AI-request records to see whether features finish and to find failures. Those purposes are separate from producing a score or a rewrite.

We use the IP address and user-agent string from a sign-in to protect accounts, prevent abuse, and meet legal duties that actually apply to us.

We do not use personal information to train a Resumify model. We do not use it for advertising. We do not sell it.

Where Canadian privacy law applies, we rely on your consent. Creating an account and sending a resume for scoring, editing, generation, or extraction is consent to use that content to provide those features. Choosing an intake answer is consent for that optional item. You may skip every intake question and still use the app. Where the GDPR or UK GDPR applies, we rely on contract for the resume service and the subscription, on consent for the optional intake answers, and on legitimate interests for security and for the usage records that are kept out of the resume tools. You can object to those usage records as described under Your choices and rights.

Intake answers and usage records do not change the product. Target industry, role category, experience band, age band, feature usage, workflow completion, abandonment, processing time, export records, app version, and error codes are not inputs to scoring, editing, generation, tailoring, cover letters, or job extraction.

They do not change your results or your credits. Subscription status is the check that unlocks paid features, and the feature-use counts apply the plan limits. The intake answers and the workflow, export, and AI-measurement rows are not part of that decision.

Intake answers and usage records stay out of the resume tools

We store intake answers and product-usage records apart from the content that is sent for an AI request. A scoring, editing, generation, tailoring, cover-letter, or extraction request contains the resume, job text, or screenshot needed for that request, plus the instructions for that feature and the app version. It does not contain your age band, industry answer, role answer, experience band, your history of workflow and export records, or the IP address and user-agent string from your sign-in.

AI providers

Resumify uses artificial intelligence to score, edit, tailor, and generate resume text, to draft cover letters, and to read job-posting screenshots. The result is a draft for you to review. It is not a prediction that you will be hired, and it is not legal, career, or employment advice.

When you run one of those features, the relevant text and any screenshot you selected are sent to our server and then to OpenRouter, Inc., which routes the request to a model provider. The providers the app is allowed to use are OpenAI, Google, and Meta. We send that content so the provider can return the result you asked for.

We do not use your content to train a Resumify model. OpenRouter’s published policy states that OpenRouter does not use prompts or outputs to train its own models, and that it does not store prompt content unless the OpenRouter account turns on logging. We do not enable that logging for Resumify requests.

The model provider still processes the content to produce the response. Paid OpenAI and Google API services generally do not use API content to train their public models, and they may keep a request for a limited time to detect abuse. Resumify can also fall back to free Meta Llama endpoints. A free endpoint can follow different rules, and the provider may retain or use inputs under its own terms, including to improve its models. We name that fallback here so this policy matches the app.

We keep the text you save in Resumify, such as an extracted resume, a saved job description, an edit, or a cover letter, until you delete it or delete your account. We do not keep the screenshot file in our file storage after the extraction request is finished.

Who receives information

We share personal information with the service providers below so they can perform a specific job for us. They are not authorized to use it for their own advertising.

RecipientWhat they receiveWhy
Supabase, Inc. Account records, the Apple refresh token when you use Sign in with Apple, resume and job records, original PDF and Word files, subscription status, feature-use counts, intake answers, workflow and export records, AI-request measurements, and the IP address and user-agent string for a sign-in. Host the database, authentication, private file storage, and the server functions that call the AI provider and delete accounts.
OpenRouter, Inc. The resume text, job text, screenshot, and instructions for the feature you run, and the model’s response. The usage-record tables are not sent. Route that request to a model provider.
OpenAI, Google, and Meta The content OpenRouter forwards for that request. Produce the score, edit, draft, or extraction.
RevenueCat, Inc. Your Resumify user id, subscription status, product identifier, and related purchase events from Apple. RevenueCat also receives device and connection information, including an IP address and Apple’s identifier for the vendor. RevenueCat does not receive your name, email, or an advertising identifier. Tell the app whether Resumify Premium is active, and provide the subscription. When you delete your account, we ask RevenueCat to delete the subscriber record tied to that user id.
Apple What you authorize for Sign in with Apple, the full payment and subscription record for an in-app purchase, and an App Store review if you choose to submit one. When you delete an account that used Sign in with Apple, we send Apple a revocation request for that app credential. We do not receive the rating or the review text. Sign-in, App Store billing, and an App Store review you choose to submit. Apple is the seller of the subscription.
Google The sign-in you start, if you choose Sign in with Google. Google also receives the AI content described above when a request is routed to a Google model. Sign-in, and, separately, model processing.
Cloudflare, Inc. Connection data for visits to resumifyapp.org, such as IP address, browser, and the page requested. Host and protect this website, and measure visits to it in aggregate.

These pages also load fonts from Google Fonts. When your browser requests those fonts, Google receives your IP address and ordinary browser information. Google’s privacy policy describes that processing.

We may also disclose information if the law requires it, or if it is reasonably necessary to investigate abuse, protect the security of the service, or establish or defend a legal claim. If we sell the company or the Resumify business, the buyer would receive the information needed to continue the service, and we would tell you about that change.

Original resume files are stored in a private storage area. They are not published on a public URL. A signed-in user can read only that user’s own rows. The app downloads an original file through a short-lived link.

Selling and advertising

We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not allow advertising networks to track you across other companies’ apps or websites through Resumify. Because we do not sell or share personal information in that way, we do not operate a “Do Not Sell or Share” list.

How long we keep information

InformationHow long
Account, intake answers, resumes, cover letters, job tracker entries, stored PDF or Word files, workflow and export records, AI-request measurements, feature-use counts, the subscription status we store, and the IP address and user-agent string stored with the sign-in session Until you delete the item, where the app lets you delete that item, or until you delete the account. Deleting the account removes these records from our active systems when the deletion succeeds. Apple keeps Apple’s own transaction record under Apple’s policies.
Screenshot files sent for extraction For the extraction request. We do not store those image files in our file storage.
Server logs For the period our hosting provider keeps logs. We write those logs so they do not include resume text, job text, or screenshots.
Backup copies Removed on the backup cycle, and in any case within 90 days after the active copy is deleted, unless we must keep a specific record longer for a legal duty, a dispute, or security, and then only for that purpose.

Where information is processed

We are based in Ontario, Canada. Our service providers operate in Canada, the United States, and other countries. When you use Resumify, your information will be processed in those locations. Those providers remain responsible to us by contract for the work they do, and we remain responsible for personal information we control.

If the GDPR applies to you, those transfers are made using an available lawful transfer tool, such as the European Commission’s standard contractual clauses, where that tool is required. You can contact us for a description of the safeguard that applies to a particular transfer.

How we protect information

The app talks to our servers over encrypted connections. Account data is stored so that one signed-in user cannot read another user’s rows. Original resume files sit in a private bucket with the same limit, and download links expire quickly. AI-request measurements can be written by our server only. Access to production systems is limited to the people who operate the service.

No method of storage or transmission is perfectly secure. If we learn of a breach that creates a real risk of significant harm, we will notify the people and authorities the law requires us to notify.

Your choices and rights

You can skip every intake question. You can ask us to correct or delete an intake answer by emailing [email protected]. You can delete an individual resume in the app, which also deletes the stored file for that resume.

The app does not have a switch that turns usage records off while the account stays open. Deleting the account deletes the workflow, export, and AI-measurement records we can tie to you, and it ends further collection for that account. You can also email us for a copy of the personal information we hold, or to ask us to delete intake answers and usage records we can tie to you. We may need to confirm that the request comes from you. You can export resume files from the app.

If the GDPR or UK GDPR applies to you, you also have the right to restrict or object to certain processing, to receive certain information in a portable format, and to withdraw consent for optional processing without affecting processing that already happened. Withdrawing consent for an optional intake answer means we delete that answer. It does not turn off the resume tools. Objecting to usage records is handled by deleting those records and, if you want collection to stop, by deleting the account.

If the California Consumer Privacy Act applies, you may ask us to know, delete, and correct personal information. We do not sell or share it for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics for advertising. We will not discriminate against you for making a request.

We respond to privacy requests within 30 days, or sooner when the law that applies to the request sets a shorter time. If we need longer, we will tell you why.

Deleting your account

You can delete your account in the app under Account & Security. You can also ask us to delete it by emailing [email protected]. Before you confirm deletion in the app, we tell you that an Apple subscription keeps billing until you cancel it with Apple, and the screen includes a control that opens Apple’s subscription management.

When in-app deletion succeeds, we remove the active account and the records tied to it: sign-in, including the IP address and user-agent string stored with that session, intake answers, resumes, cover letters, job tracker, stored resume files, feature-use counts, subscription status we store, workflow and export records, and AI-request measurements. If you used Sign in with Apple, we revoke that app credential. We also ask RevenueCat to delete the subscriber record for that user id, including the device and connection information RevenueCat holds for it. Email requests are completed within 30 days.

Deleting the account does not cancel an Apple subscription. Apple keeps billing until you cancel. You can cancel from the deletion screen, in the iOS Settings app under your Apple ID subscriptions, or at apps.apple.com/account/subscriptions.

Backup copies follow the schedule in How long we keep information. We may refuse deletion of a specific record only when the law allows us to keep it, and we will tell you if we do.

Age

Resumify is for people who are 18 or older. We do not knowingly collect personal information from anyone under 18. The age question, when it is shown, starts at 18. If you believe a person under 18 has created an account, email [email protected] and we will delete it.

This website

resumifyapp.org describes the studio and Resumify, and it hosts this policy and the Terms of Use. If you email us, we use that message to reply and to handle the request. The site is served through Cloudflare, which processes connection data to deliver and protect the site and may measure visits in aggregate. The site does not ask you to create an advertising profile, and it does not collect the intake answers or usage records described above.

Changes

If we change this policy, we will post the new version on this page and change the effective date. If a change materially expands how we use personal information we already hold, we will notify you in the app or by email and, where the law requires it, ask for your consent before that new use applies. Continuing to use Resumify after a non-material update means the updated policy applies to later use.

Contact and complaints

Roy-Gulyamov Digital Inc.
Ontario, Canada
[email protected]

If you are in Canada, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca. If you are in the EEA or the United Kingdom, you may also contact your local data protection authority. We ask that you write to us first so we can address the concern.