Last updated September 21, 2026
A resume is one of the more personal documents most people own. This page says exactly what we do with yours, who else sees it, how long we keep it, and how to make us delete it.
Four kinds of thing, and nothing else:
Payment details are handled entirely by Stripe. We never see or store a card number; what we hold is a customer reference and the state of your subscription.
A resume usually contains a great deal about you: where you have lived, where you studied, sometimes more. We treat all of it as yours, and none of it is used to train anyone's model.
This is worth its own section because it is unusual. When you record a practice answer, the video is captured and held in your own browser. It is not uploaded, not stored on our servers, and not sent anywhere else. It disappears when you leave the page.
Only the transcript (the words you said, produced by your own browser's speech recognition) is sent to us so the AI can give feedback on the answer. There is no recording of you on our side, on any server, ever.
We do not sell your information and we do not build a profile of you for anyone else's benefit. If you reached us by clicking one of our ads, we do tell Google Ads that the click led to a free account or a payment, and what the payment was. That is how we know which ads are worth running. It carries the click identifier and the amount, never your name, your email or anything from your resume.
Rewriting a resume means sending its text to a large language model. We use Anthropic's Claude for that. When you ask for a rebuild, a tailored version, a cover letter, a fit assessment or interview prep, the relevant text goes to Anthropic's API, Anthropic processes it and returns the result, and we store the result against your account.
Anthropic's commercial terms state that inputs and outputs sent through their API are not used to train their models. We do not train any model on your data either.
Interview preparation additionally runs a live web search about the company you named, so that company's name is part of that request. Nothing about you is included in the search itself.
The complete list of companies involved in running this service, and what each one holds:
All of these are United States companies, and your data is processed in the United States.
Your account and your documents stay until you delete them or delete your account. We do not expire a resume you have not opened for a while: losing someone's work to a retention timer would be a worse failure than keeping it.
Usage records (what ran and whether it worked) are kept for troubleshooting and to spot abuse. Abuse-prevention counters, which hold only hashed IPs, expire within hours.
When you delete your account we delete your resumes, jobs, applications, letters, guides and notes with it. Stripe keeps its own record of payments because tax law requires it to; that is out of our hands.
Whoever and wherever you are, you can ask us to:
Email support@resumefox.ai and we will action it within 30 days, usually far sooner. We will not ask you why.
If you are in California, the CCPA and CPRA give you these rights specifically, plus the right not to be discriminated against for exercising them. We do not sell or share personal information as those laws define it, so there is nothing for you to opt out of. If you are in the UK or EU, the equivalent GDPR rights apply and the same address reaches us.
This service is for adults looking for work and is not directed at children under 13. We do not knowingly collect anything from them. If you believe a child has created an account, tell us and we will remove it.
If we change something material (a new sub-processor, a new category of data, a different retention period), we will update the date at the top and email account holders. We will not quietly widen what we do with your data and rely on you re-reading this page.
Email support@resumefox.ai and a person will answer, usually within one business day. Or use the contact page.
ResumeFox is operated by TopStack Resume, a US career-services firm. This policy describes how the software actually behaves; where it names a practice, that practice is implemented in the product.