Privacy Policy
This policy explains how Premsan Inc (“Premsan”, “we”, “us”) handles personal data in Resumical — this website, the console, the API, and the Resumical apps for iPhone, iPad and Android. Premsan is the controller of that data. A resume is about a person, so this page is written to be read, not skimmed: it says what we hold, why, who else touches it, and how to make us stop.
1. What we collect
- Your account. Your name, your email address, and either a password — stored only as a hash — or, when you sign in with Apple, GitHub or Google, your identifier there and the sign-in tokens the provider hands us. Each session records the IP address and the browser or device it was opened from, and when it expires. We also record the date on which you accepted the Terms, and which version.
- What you tell it. The facts you give it, the messages you exchange with it, the documents it writes and every version of them, the pictures and PDFs you attach, and the PDFs it renders. What goes in is your choice, and some markets’ forms ask for things others never would — a date of birth, a nationality or visa status, a photo. Resumical holds them exactly as you gave them, for the document you want, and you can edit or delete any fact or document at any time.
- Links you paste. If you paste a link to a posting, our server fetches that page on your instruction and brings its text into your conversation. The site you linked sees a request from our server, not from you.
- Purchases. On the web, payment is taken by Stripe: it receives your email address and your account id, and your card details go to Stripe and never reach us. We keep the checkout’s id and the number of documents it bought. In the app, payment is taken by the App Store or Google Play; we receive the transaction’s id, confirm it with Apple or Google, and record it against your account.
- Usage. Counts of runs, renders and model tokens per month, kept inside your own account’s storage for our books. Server logs hold request metadata, your IP address among it, and error reports for a short time, for security and debugging.
- The bot check. Cloudflare Turnstile runs on our sign-in and sign-up pages, and in the app’s sign-in screen, to tell a person from a script.
- Nothing else. There is no advertising, no analytics, no tracking across sites or apps, no advertising identifier, and no data broker.
2. What we do with it
We use personal data to run Resumical: to write, render and check your documents, to sign you in, to send you the emails the account needs — a verification link and a password reset — to take payment and credit the documents you bought, to keep the service up and abuse out, to answer you when you write to us, and to meet legal obligations. We do not use your facts, conversations or documents to train models, we do not sell personal data, and we do not share it for advertising.
3. Why we are allowed to
Where the GDPR or a law like it applies, we rely on these bases:
- Performing our contract with you — your account, your facts, your conversations and documents, and the payments. Without them there is no service to give you.
- Our legitimate interests — keeping Resumical up, finding failures, and stopping abuse and automated sign-ups. We hold this to what running the product needs: the usage counts, the logs and the bot check, not profiling and not advertising.
- A legal obligation — payment records and anything else the law requires us to keep.
- Your consent — for anything the law treats as special, such as a photo, a nationality, or a health or family detail you choose to put in a document. You give it by putting the fact in, and you withdraw it by deleting the fact, the document or the account.
4. Who else processes it
Resumical runs on Cloudflare: the servers, the storage that holds your account, the model that writes for you, the browser that prints the PDF, the email that leaves, and the bot check are all Cloudflare services on our own account. No prompt of yours goes to any other AI provider. Email may instead be sent through Resend where we route it there. Stripe takes payment on the web; card details go to Stripe directly. Apple and Google take payment in the app, and each confirms a purchase to us when you make one. These providers process data only on our instruction, and we give notice here before a new one starts.
Signing in with Apple, GitHub or Google sends us your identifier and email from that provider. They act on their own behalf there, not as our processors, and their handling of your account with them is governed by their own privacy policies. The App Store and Google Play are the sellers of what you buy inside the app, and their handling of your payment is governed by theirs.
5. Where it is
Your data is processed on Cloudflare’s network, which spans the world, and stored on it under Cloudflare’s own commitments for international transfers. Premsan is in Japan, a country the European Commission recognises as protecting personal data adequately.
6. On the phone
The app keeps on your device a sign-in token, the language and appearance you picked, and, when you share a PDF, a copy of that PDF in the app’s own cache for the share sheet. It reads your camera, your photos or your files only when you tap the paperclip and pick something, and the OS asks your permission for the camera at that moment; nothing is read in the background. Purchases go through the store’s own sheet. The app carries no advertising or analytics library, and the one review prompt it may ever show is the operating system’s own, asked for once after you have shared your first PDF.
7. Cookies
On the web we set the cookies the product cannot work without: the one that keeps you signed in, and the ones Cloudflare Turnstile sets to tell a person from a bot on the sign-in and sign-up pages. The site and the console keep your theme and language in your browser’s own storage. That is the whole list: no advertising cookies, no cross-site trackers, and no analytics that follows you between sites, which is why nothing asks you to accept anything on arrival. Clearing them signs you out.
8. How long we keep it, and deleting it
We keep your account and everything in it for as long as the account exists. Deleting a fact removes it. Deleting a document removes it, its conversation, its versions, its attachments and its renders. Verification and reset links expire on their own.
You can delete your account at any time, from the console’s Account page or from Account in the app. Everything we hold for you is erased at once — documents, facts, conversations, versions, attachments, renders, usage and balance — and then the account itself. There is no recovery window and no undo.
Three things outlive that, and we would rather name them than let you find out. A purchase made in the app leaves a record of the store’s transaction id, the number of documents it bought, the date, and the id of the account it was credited to, so that the store replaying the receipt cannot credit it twice and because payment records must be kept by law; the account it names no longer exists. Stripe, Apple and Google keep their own records of a payment under their own obligations. Server logs age out on their own after a short time.
9. Your rights
You can read, correct and delete every fact and document yourself, download any document as a PDF, plain text or Markdown, and delete your account, without asking us. Depending on where you live, you may also have the right to a copy of the rest of what we hold about you, to restrict how we process it, to object to processing we base on legitimate interests, to withdraw consent where we relied on it, and to move your data elsewhere. Write to support@resumical.com and we will answer within one month.
If you live in California or another U.S. state with a law like its, you have the right to know what personal data we hold about you, to delete it, and to correct it; the controls above do that. We do not sell or share personal data as those laws define the words, so there is no opt-out to offer, and exercising a right gets you the same service on the same terms.
If you think we have handled your personal data wrongly, you can complain to a data protection authority — in the EEA or the United Kingdom, the one where you live or work or where the problem happened; in Japan, the Personal Information Protection Commission. We would rather you told us first, but you do not have to.
10. Security
Every connection is encrypted in transit. Passwords are stored as hashes. Each person’s data lives in its own isolated storage object, and every byte of it is deleted with the account. The app keeps its sign-in token in the operating system’s secure store, never a cookie. Credentials never enter our logs. If you find a weakness, write to security@resumical.com and give us a chance to fix it before you tell anyone else.
11. Children
Resumical is not for anyone under 16, and we do not knowingly hold a child’s data. If you think a child has an account, tell us and we will delete it.
12. Changes
We may update this policy. When a change matters we will say so in the console or the app, or by email. The date at the top is the version that stands.
13. Contact
Premsan Inc — 530-0001, 12-12, Osaka Ekimae Dai-2 Bldg., 1-2-2 Umeda, Kita-ku, Osaka-shi, Osaka, Japan. support@resumical.com.