Skip to main content

Privacy Policy

Last updated: September 2026•4 min read
Parsing happens in your browser

Your PDF or DOCX file is read locally. Only the extracted text is sent to our server when you use an AI feature, the file itself never leaves your device.

Your own API keys stay local

If you supply your own AI provider key (BYOK), it's kept in your browser's local storage and sent only as a per-request header, we never store it on our servers.

1. What we process, and where

  • Resume files (PDF/DOCX): parsed entirely client-side (pdfjs-dist/mammoth). The file is not uploaded; only the extracted plain text is sent to our server, and only when you use an AI feature (parsing, ATS analysis, or optimization).
  • Job descriptions: the text you paste is sent to our server solely to extract keywords or tailor your resume against it.
  • Saved resumes: if you're signed in, resumes you explicitly save are stored server-side in Supabase (PostgreSQL), scoped to your account. If you're using the local demo/guest mode, resumes are kept only in your browser's local storage and never reach our server.
  • Feedback you submit: your message, and any name/email/rating you choose to include, is emailed to the project maintainer and best-effort logged for follow-up. This isn't rate-limited or authenticated, don't include anything you wouldn't want in an email.
  • Aggregate usage counts: we track platform-wide totals (resumes compiled, bullets tailored, user count), not tied to your individual activity, shown on the homepage.
  • Page-view analytics: we use Vercel Analytics for aggregate, privacy-respecting traffic metrics (no cross-site tracking, no ad identifiers).

2. Account & cloud storage

Signing in uses Supabase Authentication (email/password, or OAuth if enabled). Resumes you save while signed in are stored in our Supabase database, associated with your account, and our API only ever queries resumes matching your own user ID. A local-only demo mode is also available that skips account creation entirely and keeps everything in your browser.

Deleting your data: there is currently no self-service "delete my account" control in the product. To request deletion of your account and associated resumes, email connect@sahilbansal.net and we'll process it manually. You can export your locally-saved resumes at any time from Profile → Data.

3. Third-party AI providers

When you use an AI feature, the relevant text (resume content and/or job description) is sent to whichever provider is configured, currently Google Gemini, Groq, Mistral AI, OpenRouter, OpenAI, GitHub Models, or (if you supply your own key) Anthropic. Each provider has its own data-handling and retention policy, and OpenRouter in particular can route to different underlying model vendors depending on availability. We don't independently verify or guarantee each provider's training-data practices, if that's a concern for you, use the BYOK option with a provider whose terms you've reviewed, or the local Standalone Editor, which performs no AI processing at all.

4. Questions & data requests

To ask about your data, request a copy, or request deletion, email connect@sahilbansal.net. Depending on where you live, you may have specific legal rights (e.g. under GDPR or CCPA) regarding your personal data, this page describes what LumaCV actually does technically, and isn't a substitute for legal advice about your rights in your jurisdiction.