Your career data stays under your control.

LAST UPDATED JULY 19, 2026

Scope

This policy explains how Resume To Offer collects, uses, protects, and deletes information when you use the public website, private career workspace, optional provider connections, and related services.

Information we collect

  • Account information: your email address, display name, encrypted password credentials when you register with email, session records, and account preferences.
  • Connected identity information: when you choose Google or LinkedIn sign-in, the provider may supply an account identifier, name, email address, and profile image.
  • Career information: resumes, candidate-provided profile facts, target roles, career evidence, applications, companies, contacts, drafts, approvals, interviews, offers, and outcome records.
  • Service information: security events, source receipts, feature usage, device and browser details, and operational logs needed to protect and run the service.
  • Transaction information: purchase identifiers, plan status, amount, currency, and payment status. Payment card details are handled by the payment provider and are not stored by Resume To Offer.

Google and LinkedIn sign-in

Google sign-in requests only the basic openid, email, and profile scopes. Resume To Offer uses this information to create or match your account and establish a secure session. Google sign-in does not grant access to your Gmail inbox.

LinkedIn sign-in uses OpenID Connect and requests only openid, profile, and email. It may provide a lightweight member identity. LinkedIn does not verify the truth of career claims through this connection, and email may be absent. Resume To Offer does not use LinkedIn sign-in to retrieve work history, connections, messages, private analytics, or applications.

Provider access and ID tokens used for account sign-in are not retained after the sign-in exchange. Resume To Offer stores a one-way hash of the provider account identifier and encrypts retained connected-profile fields.

Optional mailbox connection

Mailbox authorization is separate from account sign-in. If you deliberately connect Gmail for approved message delivery, Resume To Offer requests the narrow Gmail send permission rather than inbox read or modify access. The refresh credential is encrypted and tenant-scoped. You can disconnect the mailbox and revoke access.

When you send approved outreach, Resume To Offer may rewrite links in your message to first-party redirect URLs so you can see whether a recipient clicked a portfolio, scheduling, or other link you included. This measures outbound link engagement only; it does not read your inbox, open messages, or add tracking pixels.

Google Limited Use & AI Training Compliance: The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Specifically, Workspace API data (including Gmail) is never used to develop, improve, or train generalized AI/ML models, nor is it transferred to third-party services that use that data to train AI/ML models.

How we use information

  • Provide authentication, onboarding, career planning, evidence review, document generation, opportunity organization, and user-approved workflows.
  • Maintain source, approval, and outcome records so generated work can be reviewed and corrected.
  • Protect accounts, prevent abuse, debug failures, and maintain service reliability.
  • Process purchases, provide support, and communicate material service or policy changes.
  • Produce aggregate measurements only where the user has consented and privacy thresholds are satisfied.

We do not sell personal information, use connected identity data for advertising, or automatically send applications, email, or LinkedIn messages without the user-controlled action and approval required by the product.

AI and service providers

Resume To Offer may send the minimum information needed to contracted infrastructure, model, email, payment, document-processing, and security providers to perform a feature you request. Provider access is limited by configuration and contract. Provider-independent source records and approvals remain in the Resume To Offer system.

Retention and deletion

Raw resume uploads are scheduled for deletion 24 hours after successful extraction by default. Structured career evidence remains until you delete it or your account. Sessions expire after 30 days unless renewed. Connected identity data remains until disconnection or account deletion, subject to short-lived security logs and legal retention duties.

Account deletion removes private workspace records from the active service. Backups may retain encrypted records for a limited recovery period before rotation.

Public portfolio information

Private career information is not automatically public. Portfolio fields are stored separately and require an explicit selection and publishing action. Contact details, raw uploads, private drafts, and unapproved claims stay private unless you intentionally publish them.

Security

Resume To Offer uses encrypted sensitive fields, one-way hashes for lookup identifiers, HTTP-only session cookies, tenant-scoped records, bounded provider permissions, and approval gates. No internet service can guarantee absolute security, so you should also protect your account and connected-provider credentials.

Your choices

  • Review and correct your candidate profile and generated materials.
  • Choose whether to connect Google, LinkedIn, or a mailbox.
  • Disconnect providers through account settings or the provider's security controls.
  • Select public portfolio fields separately.
  • Export or delete your account and private workspace records.
  • Withdraw optional aggregate-outcome consent.

International processing and legal requests

Service providers may process information in countries other than your own. Where required, Resume To Offer uses appropriate contractual and security safeguards. Information may be disclosed when required by law, to protect users and the service, or during a business transaction subject to confidentiality and applicable rights.

Changes and contact

Material changes will be posted here with a revised date and, when appropriate, communicated in the product. Privacy questions or requests can be sent to [email protected].