Privacy Policy

Last updated 22 September 2026

This policy explains what personal data Resura (“we”, “us”) collects when you use Resura, why, who it is shared with, and the choices you have. We've kept it specific to how the product actually works.

1. What we collect

  • Account details — your email address and a password. Your password is stored only as a one-way hash (bcrypt); we can't read it.
  • Your profile — what you enter or import: name, email, phone, location, links (LinkedIn, GitHub, LeetCode, website), education, work experience, projects, skills and achievements.
  • Resumes and emails you generate — the job description used, the tailored content, the LaTeX source and the PDF, kept so you can find, edit and download them later on the History page. The email you generate for a job (and any edits you make to it) is saved too, so it is still there when you come back.
  • Resume files you upload to import a profile — we read the text out of the file (using text extraction, and on-server OCR for scanned files) to fill in a draft profile for you to review. The file itself isn't stored.
  • Usage records — a timestamped count of each resume, email and suggestion scan you generate, so we can apply plan limits.
  • Payment records — for each purchase: the plan, amount, the UPI transaction ID you submit, status and dates. You pay through your own UPI app, so we never receive your card details, UPI PIN or bank login.
  • Payment screenshots — the screenshot you upload as proof of payment. It can show your name, UPI ID, bank and other transactions, so please crop or cover anything unrelated. Only our administrators can see it, only to verify the payment, and it is deleted as soon as the payment is approved or rejected.
  • Technical data — a sign-in cookie (see Cookies) and the routine request data (such as IP address and browser type) that our hosting providers log for security and reliability.

We don't collect sensitive categories on purpose. Please don't put things like government ID numbers, health details or caste in your profile — a resume doesn't need them.

2. How we use it

  • To provide the service: sign you in, build resumes and emails from your profile, and keep your history.
  • To apply plan limits, take payment, activate your plan and handle refunds and support.
  • To keep the service secure, prevent abuse and fix problems.
  • To meet legal, tax and accounting obligations.
  • To contact you about your account, payments or important changes. We don't send marketing email unless you ask us to.

4. Who we share it with

We do not sell your personal data, and we don't use advertising or analytics trackers. We share data only with the service providers who help us run the product:

  • OpenAI (AI processing). To do the AI work, we send it the relevant text: your profile and the job description to tailor a resume or check for gaps; your profile, tailored resume content and the job posting to draft a recruiter email; and the text of a resume you upload to build a draft profile. As of the date above, OpenAI's API terms say data sent through the API isn't used to train its models by default, and OpenAI may retain API data for a limited period for abuse monitoring under its own policies.
  • Your bank and UPI app (payments). You pay us directly through the UPI app and bank you choose, which handle the transfer under their own policies. We see only what appears in our own account and what you submit to us.
  • Database and hosting providers (currently Supabase for the database, plus the host that runs the application). They store and process data on our behalf under their security commitments.
  • Authorities — if the law, a court order or a valid government request requires it, or to protect our rights and the safety of users.

We don't send emails or applications on your behalf. The recruiter email we draft is shown to you to copy and send yourself; we never contact recruiters with your details.

Other users can't see your profile, resumes or emails. Jobs on the Jobs page are shared with everyone, but who generated a resume for a job is private to you.

5. Cookies

We use one cookie, called session, to keep you signed in. It is essential to the service, marked HttpOnly (so page scripts can't read it) and expires after 30 days or when you log out. We don't use analytics, advertising or tracking cookies.

6. How long we keep it

  • Your profile, generated resumes and saved email drafts are kept while your account is open. You can delete individual resumes from the History page at any time.
  • When you delete your account we delete your profile, resumes, email drafts, usage records and account details. Copies in routine backups are overwritten on the backup cycle.
  • Payment screenshots are deleted as soon as the payment is reviewed. Payment records (plan, amount, UPI transaction ID, dates) may be kept for as long as tax and accounting law requires, even after your account is deleted; they are held only for that purpose.

7. Your rights and choices

Under India's Digital Personal Data Protection Act, 2023 and similar laws you can:

  • Access the personal data we hold about you and how it's used.
  • Correct or update it — most of it you can edit yourself on the Profile page.
  • Erase it — delete resumes yourself on the History page, or email us to delete your whole account.
  • Withdraw consent or nominate another person to exercise these rights for you if you die or become unable to.
  • Complain to us (see below) and, if unresolved, to the Data Protection Board of India.

To use any of these, email yashchitale96@gmail.com from the address on your account. We may need to confirm it's you. We aim to reply within 7 days and to complete requests within 30 days.

8. Security

We protect your data with measures including hashed passwords, encrypted connections when the site is served over HTTPS, access controls so users can only reach their own data, and default-deny row-level security on our database tables. No system is perfectly secure, so we can't guarantee absolute security — please use a strong, unique password. If a breach affecting your personal data occurs we will notify you and the authorities as the law requires.

9. Where data is processed

Our providers (including OpenAI) may process data on servers outside India. By using the service you understand your data may be transferred there, to the extent permitted by Indian law, for the purposes described above.

10. Children

The service is for people aged 18 and over. We don't knowingly collect data from children; if you believe a child has given us data, contact us and we'll delete it.

11. Changes to this policy

We may update this policy as the service changes. The date at the top shows the latest version, and we'll tell you about significant changes in the service or by email. Our Terms of Service also apply to your use of Resura.

12. Contact and grievances

Resura
Email: yashchitale96@gmail.com

Send privacy questions, data requests and complaints to the email above and we'll respond as described under your rights.