Comprehensive Data Collection & Storage Architecture
ResumeFormat.app is engineered from the ground up under a strict privacy-by-design framework. Traditional online resume builders require users to create cloud user accounts, storing employment histories, telephone numbers, home addresses, and educational credentials on central cloud databases. These cloud repositories expose job seekers to corporate data breaches, unauthorized recruiter indexing, and persistent tracking. ResumeFormat.app operates under a fundamentally different model: local-first client processing.
1.1 Client-Side Local Storage Architecture
When you input or edit information in our resume builder, all personal data—including full name, phone number, email address, physical location, work history, educational degrees, skill inventories, project summaries, and template layout preferences—is retained strictly inside your own device web browser using HTML5 LocalStorage and IndexedDB storage.
- Zero Central Database Repositories: We do not operate remote databases storing candidate draft resumes, user profiles, or career histories.
- Stateless Feature Micro-Services: Optional web utilities (such as automated ATS formatting verification, AI text polishing, or server vector rendering) process payload requests statelessly in ephemeral server RAM.
- Instant Processing Release: Once the payload output is computed and transmitted back to your web browser, memory allocations are immediately released by garbage collection. No residual files, server copies, or disk caches remain on our infrastructure.
1.2 Categories of Personal Data Handled
A. Candidate-Provided Resume Content (Local Only)
Full names, contact details, work experience, bullet points, education, skills, certifications, and target job titles. Stored 100% locally in browser memory.
B. Technical Edge Telemetry (Ephemeral)
Anonymized IP addresses (masked), browser user-agent strings, request timestamps, and system diagnostics for server stability and DDoS protection.
1.3 Information We Explicitly DO NOT Collect
We maintain strict technical guardrails preventing the collection of sensitive candidate items:
1.4 Sub-Processor Framework & AI Assistance Protection
To provide optional features such as AI bullet polishing, keyword matching, and PDF compilation, ResumeFormat.app utilizes carefully vetted edge infrastructure and sub-processors. All sub-processors adhere to strict enterprise data processing agreements (DPAs):
- Zero Retention Agreements: AI sub-processing requests are governed by commercial terms explicitly prohibiting long-term storage of prompt payloads.
- No Model Training on User Data: Candidate text, career accomplishments, and resume inputs are strictly excluded from public or private machine learning model training datasets.
- Encrypted API Transit: All sub-processor API communications occur over HTTPS endpoints protected by TLS 1.3 encryption.
1.5 Technical Infrastructure Logs
To maintain uptime, detect cyber threats, and enforce rate limits on public tools, our web application firewall (WAF) logs standard network access data. Access logs capture anonymized IP addresses (with the last octet truncated), HTTP method/endpoint, response status code, and timestamp. Logs are automatically purged after 30 rolling days and are never linked to individual candidate resume content.
Enterprise Encryption & Security Standards (SSL/TLS)
Data protection is embedded directly into our web architecture and edge network stack. We enforce modern cryptographic standards across all client-to-server communications and local state operations.
All web traffic is forced over HTTPS using Transport Layer Security version 1.3 (with TLS 1.2 fallback for older clients). Network channels employ perfect forward secrecy (PFS) ciphers including AES-256-GCM and ChaCha20-Poly1305.
We deploy HTTP Strict Transport Security (HSTS) with long max-age directives and preload flags, neutralizing SSL stripping, downgrade exploits, and man-in-the-middle (MITM) attacks.
Our HTTP response headers enforce strict Content Security Policies (CSP), blocking unauthorized script injection, cross-site scripting (XSS), framing, and unapproved external API data exfiltration.
Dynamic vector PDF generation tasks operate inside isolated, stateless container memory buffers. Memory sectors are zeroed out immediately post rendering to prevent data leaks.
2.1 Network & Infrastructure Security Controls
ResumeFormat.app is hosted on tier-1 edge global cloud infrastructure featuring automated threat protection, Web Application Firewalls (WAF), rate limiting, and real-time DDoS mitigation. Systems undergo continuous automated vulnerability checks to maintain compliance with modern security benchmarks.
Resume Data Ownership & Self-Service Auto-Deletion
Unlike cloud SaaS platforms that restrict candidate access behind paywalls or maintain perpetual database backups, ResumeFormat.app guarantees candidate 100% data ownership and immediate self-service control.
3.1 Candidate Intellectual Property & Copyright Guarantee
You retain complete, unencumbered ownership and copyright of all resume text, work experience bullet points, custom cover letters, and generated PDF/JSON files created using ResumeFormat.app. We claim zero intellectual property rights, licenses, or distribution permissions over your content.
3.2 Self-Service Immediate Data Purging
Because your data lives in your browser, you do not need to contact customer support or file formal tickets to delete your information. You can purge all active data instantly via three methods:
In-App "Clear Draft" Action
Inside the Resume Builder interface, select Settings > Clear Draft. This instantly wipes all active form fields and clears stored LocalStorage keys from your browser.
Browser Storage & Site Data Wipe
In Chrome, Firefox, Safari, or Edge, navigate to Browser Settings > Privacy & Security > Site Settings > ResumeFormat.app and click "Clear Data". This permanently erases all LocalStorage and IndexedDB items.
Offline JSON File Portability
You can export your resume structure as an encrypted JSON backup file directly to your personal hard drive. You can store your backup offline, wipe browser data, and re-import whenever needed.
3.3 Ephemeral Server Memory Purging
For server-side helper micro-requests (such as vector PDF compilation or ATS formatting checks), payload data exists in active server RAM only for the duration of execution (typically under 800ms). Post delivery, the memory sector is zeroed out by automated system garbage collection. No disk caches or database records are retained.
Global Data Protection Compliance (GDPR & CCPA/CPRA)
ResumeFormat.app maintains full alignment with international data privacy frameworks, including the European Union General Data Protection Regulation (EU GDPR / UK GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
European Union & UK GDPR Candidate Rights
If you reside in the European Economic Area (EEA) or the United Kingdom, Articles 15 through 22 of the GDPR grant you specific legal rights regarding your personal data:
Request confirmation of whether personal data is processed and receive a full copy of stored items.
Correct inaccurate or incomplete resume details directly inside the editor or request administrative updates.
Obtain immediate deletion of all personal data held locally or processed in transient server memory.
Export structured resume content in standard machine-readable JSON or PDF formats at any time.
California Consumer Privacy Rights (CCPA / CPRA)
For California residents, the CCPA and CPRA afford specific statutory privacy protections:
- Right to Know: Request disclosures detailing the categories of personal data collected, processing sources, and specific pieces of data held.
- Right to Delete: Request deletion of personal data collected from the consumer.
- Explicit "Do Not Sell or Share My Personal Info": ResumeFormat.app does NOT sell, rent, or share candidate personal information with third parties for commercial gain or cross-context behavioral advertising.
- Right to Non-Discrimination: We will never discriminate against any user (e.g. charging higher fees or degrading service) for exercising privacy rights.
Data Protection Officer (DPO) & Privacy Contact
If you have any questions, concerns, or formal Data Subject Access Requests (DSAR) regarding our privacy policies or data security practices, our dedicated Data Protection Officer is ready to assist you.
Data Protection Office
ResumeFormat.app Security & Compliance Team
Security Verification Protocol: To safeguard candidate privacy, DSAR requests submitted via email may require identity verification before disclosing or modifying records.
Postal Inquiries: ResumeFormat Data Protection Office, Attn: Privacy Compliance Officer, 100 Shoreline Highway, Suite 300, Mill Valley, CA 94941, USA.
Policy Updates & Amendments
We may update this Privacy Policy periodically to reflect improvements to our local storage architecture, security protocols, or legal requirements. Material revisions will be posted on this page with an updated "Effective Date". We encourage users to check this page periodically to remain informed about how we safeguard candidate data.