TechResume ← Back to home

Legal

Privacy Policy

Last updated: September 25, 2026 · Effective date: September 25, 2026

TechResume ("we", "us", "our") is a native Android resume studio. This policy explains exactly what information the TechResume app collects, why we collect it, how it is protected, and the rights you have over it. We design the app to collect the minimum data necessary and to keep your resume data on your device wherever possible.

01 Data We Collect

We collect only the information necessary to provide our services:

We do not collect contacts, photos, precise location, call logs, SMS, or device identifiers for advertising. We do not sell your personal data and never share it with advertising or data-broker networks.

02 Data Security

Your data is protected with standard encryption: on-device storage uses SQLCipher (AES-256), optional cloud backups are encrypted client-side with AES-256-GCM, and all network traffic uses TLS 1.3. Your resume data is stored locally on your device in that encrypted SQLCipher vault, and is only backed up to your own cloud storage (e.g., Google Drive AppData folder) when you choose to enable sync. API keys for AI processing never ship inside the app; all AI requests pass through our signed proxy.

Cloud backups are AES-256-GCM encrypted before upload and stored in your own Google Drive AppData folder (invisible to other apps). When you use Export, files are written unencrypted so other apps can open them: PDF exports and HTML portfolios go to the app's external files folder (Android/data/com.techresume.app/files/ — readable by file managers granted all-files access), and a translation you choose to save to Downloads/ becomes readable by any app with storage access. CSV exports are written to a private cache and only leave via the share sheet you control. Delete exported files when you no longer need them; they are not protected by the app passcode. Our AI proxy does not store your resume content on our backend, does not attach your account identifiers to AI requests, and we do not use your resume data to train any model. To reduce cost and latency, an identical AI request may be served from a short-lived response cache (up to 2 hours for most features, up to 24 hours for interview-guidance prompts); cache entries store only the generated reply, keyed by a one-way SHA-256 hash of the request — your submitted text is never stored in plaintext, and cached replies are not associated with your account.

03 Third-Party Services

We rely on a small number of processors to deliver the app. Each processes data only to provide its service to us:

We do not share your personal data with third parties for their own marketing purposes, and never with advertising networks or data brokers.

04 Data Retention

Your data is retained as long as your account is active, and local resume data remains under your control on your device. When you delete your account, the local encrypted vault is removed immediately and server-side account data is permanently removed within 30 days — or within 45 days for California (CCPA) requests, as described on our Data Deletion page. Three narrow exceptions, isolated from product systems, may outlast those windows: anti-fraud and security audit logs are kept for a maximum of 90 days and then deleted or fully anonymized; a device-level record of free-trial claims — containing only a device identifier and a claim timestamp, with no resume content — is kept for up to 365 days to prevent repeated abuse of free trials, is not deleted when you delete your account, and does not restore a new free trial once it expires; and tax or accounting records we are legally required to keep may be retained for up to 7 years. Deleting your account also removes the feedback and AI-content reports attached to it. Anonymous usage statistics may be retained indefinitely in aggregated form. Backup copies held in your connected cloud storage are removed according to that provider's retention.

05 Your Rights

You have the right to access, correct, export, delete, restrict processing of, and object to processing of your personal data, including the right to data portability (CCPA §1798.100 et seq. for California residents):

To exercise any right, contact us at numbtibag@gmail.com, or in-app via Profile → Danger Zone → Delete account or Profile → Cloud Sync. We acknowledge within 72 hours and respond substantively within 30 days, or 45 days for CCPA requests, extendable once for complex requests with written notice.

06 AI-Generated Content

TechResume includes AI writing features. Content you send for AI processing is transmitted to our AI provider solely to generate your requested result. AI output may contain errors and should be reviewed before use. You can report offensive or inaccurate AI output directly within the chat using the report option, and we review submitted reports.

07 Children

TechResume is intended for professionals and job seekers and is not directed to children. You must be at least 16 years old to use the app. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us data, contact us at numbtibag@gmail.com and we will delete it within 7 days.

08 International Users

The app is served through regional infrastructure: Cloudflare Workers for international users (primary data path) and Tencent Cloud SCF for users in mainland China. Each region routes to its own AI proxy that signs requests and forwards only the minimum data needed to the DeepSeek API (China); our proxy does not persist your resume content, and DeepSeek's own log-retention practices are governed by its Open Platform terms.

Because DeepSeek and Tencent Cloud are located in China, the technical safeguards described above apply to all transfers: each AI request is forwarded individually, no account identifiers are attached, and no resume content is stored on our backend. For users in mainland China, any cross-border transfer is conducted under PIPL Articles 38-39 and we obtain separate consent where required. Data is encrypted in transit (TLS 1.3); account and subscription records held on rented serverless infrastructure are encrypted at rest by the hosting platform's storage layer, and we do not add a separate application-layer encryption. If you are in a region with local data-residency rules, switching to your local app channel keeps your data inside that region.

09 Data Breach Notification

In the event of a personal data breach likely to result in a risk to users' rights, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and will communicate high-risk breaches to affected users without undue delay.

10 EU, EEA and UK Availability

We do not currently offer this app or its paid plans to data subjects in the European Union, the EEA or the United Kingdom, and we geo-restrict sign-up, checkout and trial activation for those regions. Because we are not “offering goods or services to data subjects in the Union” within the meaning of GDPR Art. 3(2), the Art. 27 representative requirement is not currently triggered. Should we decide to serve these markets in the future, we will appoint and publish an EU and UK representative in this section before making the app available there. Until then, direct any privacy enquiry from these regions to numbtibag@gmail.com.

11 Changes to This Policy

We may update this policy. Material changes will be reflected by the "Last updated" date and, where appropriate, notified in-app. Continued use after an update constitutes acceptance of the revised policy.

12 Contact

For any privacy question, access request, data deletion request, or to exercise the rights listed in Section 05, contact us. We acknowledge requests within 72 hours and respond substantively within 30 days, or 45 days for CCPA requests; complex requests may be extended once with written notice.

numbtibag@gmail.com Data deletion requests → In-app: Profile → Danger Zone → Delete account

You may also lodge a complaint with your local data protection authority. California residents may contact the California Attorney General. We will cooperate fully with any such inquiry.