Privacy Policy

Last updated: September 6, 2026

1. Who we are

ResumeWave ("we", "us") is a career-tools service. The controller is Maracuya Labs UG (haftungsbeschränkt), Dreschstrasse 5, 80805 Munich, Germany. For any privacy request, write to support@resumewave.app (see the contact page).

2. Data we collect

  • Account data: your email address and a salted hash of your password. If you sign in with Google, we store your Google account identifier and email instead of a password.
  • Resume content: the text you type, paste, upload, or send to the builder, including files you import (PDF, DOCX, TXT). This is the product's purpose; we store it so you can edit and export your resumes.
  • Career-tool data: your master profile, saved and hidden jobs, applications, saved searches, cover letters, interview answers and scores, and LinkedIn-review content you choose to save.
  • Application autofill: when you start an Apply Queue, the core answers needed for applications are stored with your account so they work across devices. Voluntary demographic answers stay only in your browser and extension. Each application opening gets a signed, one-use PDF token that expires after ten minutes and stops working if that saved resume changes. The extension sends it from its background worker in an authorization header, not in the request URL, and starting a queue does not enable the resume's public share link.
  • Prefill sessions: when a third-party integration sends resume text to pre-fill the builder, that text is stored temporarily and expires after 7 days. If you sign in from that report, we save one account resume from the session so you can continue editing it without uploading the content again.
  • Technical logs: standard server logs (IP address, request path, timestamps) kept for security and abuse prevention.
  • Product analytics: when you import, save, export, search, open a job, track an application, start a checkout or use an AI action, we record the event name, its outcome, how long it took and a pseudonymous key derived from your account (never the email). These rows are kept for 90 days and deleted with the account. They are used to see where the product fails or is slow, not to profile you.

We do not collect payment card details ourselves; payments are processed by our payment provider.

3. How we use your data

  • To provide the service and the career tools you request.
  • To authenticate you and keep your account secure.
  • To measure which integration sent a prefill session (the "source" tag), so we can evaluate partnerships. This tag contains no personal data.

We do not sell your data. We do not use your resume content for advertising, and we do not share it with third parties except the infrastructure processors below.

4. Where your data lives

Data is stored on Railway (application hosting and PostgreSQL in the United States). Payments, when enabled, are processed by Stripe. Transactional email, when enabled, is delivered through Resend. When you use a generative feature, the resume, job, profile, letter, or interview text needed for that request is sent to Google's Gemini API. These providers process data only to deliver the requested service.

5. Retention

  • Prefill sessions: deleted after 7 days. A resume you keep by signing in is account data and remains until you delete it or the account.
  • Account and user-owned product data: kept until you delete the account or ask us to delete it.
  • Server logs: kept for a short rolling window for security.

6. Your rights

You can download every piece of data we hold on your account as one JSON file ("Download my data" in the dashboard) and delete the account and its user-owned product data directly from the dashboard. You can also request access, correction, or deletion by writing to support@resumewave.app from the address on your account. Payment processors and other providers may retain records they are independently required to keep.

7. Cookies

We use a single session cookie to keep you logged in, a short-lived cookie during Google sign-in, and a cookie to connect a prefill session to your new account. No advertising or cross-site tracking cookies.

8. Browser extension

The ResumeWave Autofill extension for Chrome fills job application forms on the applicant tracking systems listed in its manifest with the resume and application answers you choose to load into it. It fills only when you click its button or while an Apply Queue you started is running, it never submits a form, and it has no account of its own, no analytics, and no tracking.

  • What it stores: the resume fields it fills (name, headline, email, phone, location, links, summary, and your most recent experience and education entries) and your application answers (work authorization, visa sponsorship, years of experience, notice period, salary expectation, relocation, and the voluntary self-identification answers). This data is kept in the extension's local storage in your browser; the extension does not sync it or send it anywhere.
  • Where it comes from: your own ResumeWave page when you start an Apply Queue, or a public share link you paste into the extension popup. The extension exchanges data only with pages on the ResumeWave origin.
  • What it sends: two kinds of requests, both toResumeWave over HTTPS: the public resume behind a share link you pasted, and your resume PDF, fetched with the signed one-use token described above, sent in a request header. Nothing is sent to any other party.
  • What it reads on employer pages: form field labels and attributes, to decide which empty fields to fill, and, after you submit an application opened from an Apply Queue, the page address and visible confirmation text, to tell ResumeWave that the employer confirmed the submission. Only the confirmation page address (without query parameters) is kept, in the extension's local storage, and shown back to you on ResumeWave; page content is never stored or transmitted, and that address is not sent to our servers.
  • Deleting it: Clear saved data in the extension popup removes everything the extension stored. Uninstalling the extension does the same.

9. Changes

We will update this page when our practices change and revise the date above. Material changes will be announced in the product.