Privacy Policy
Last updated: May 27, 2026
Resume Prune is operated by Jen Built It LLC, a US limited liability company organized in Illinois. Throughout this policy, "we," "us," and "our" refer to Jen Built It LLC. "Resume Prune," "the Service," or "the app" refer to the website at resumeprune.com and its subdomains.
This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and the rights you have. We've tried to keep it plain English. If anything is unclear, email privacy@jenbuiltit.com and we'll explain.
What's in this policy
- Who we are
- What we collect
- Why we collect it (purposes and legal basis)
- Who else handles your data
- International data transfers
- How long we keep it
- Your rights
- How to exercise your rights
- Cookies and tracking
- Children
- How we protect your data
- California residents (CCPA / CPRA)
- Changes to this policy
- Contact
1. Who we are
Resume Prune is owned and operated by:
Jen Built It LLC
10800 S Lloyd Drive
Worth, IL 60482
United States
privacy@jenbuiltit.com
Jen Built It LLC is the "data controller" under EU and UK GDPR. The same entity is the "business" under California law.
2. What we collect
2.1 Free sample (no account required)
- Email address you submit on the homepage form so we can email you the rendered sample.
- Resume text you paste or upload, and the job description you paste, for the duration of one request.
- Rendered output (the pruned resume + cover letter we generated), stored for 30 days behind a private unguessable URL so you can revisit it; then automatically deleted.
- Hashed IP address (we hash it; we never store the raw IP), used only for rate-limiting and abuse prevention. Kept 30 days.
- Newsletter consent timestamp if you opted in.
2.2 Pro / Sprint account
- Email address and a password hash (we use PBKDF2 with 100,000 iterations; the plaintext password never touches our database).
- Resume text you upload, and the structured version our system generates from it.
- Tweak history: each job description you've worked on plus the tailored resume + cover letter we produced.
- Usage counters: how many tweaks you've made this billing period.
- Subscription metadata: your Stripe customer ID, subscription ID, status, and billing-event log. We do not store your card number, Stripe does that.
- Profile fields you choose to set: target role, target industry.
- Email-verification status and account-creation date.
2.3 Automatically collected
- Cloudflare edge logs: request URL, timestamp, your IP, user agent, and response status. Held by Cloudflare per their retention policy (typically 30 days). We do not store these ourselves; they are operational.
- Auth session cookie: one cookie named
rp_session(HttpOnly, Secure, SameSite=Lax). Holds a signed JWT. Used only to keep you logged in. - Feedback widget: if you submit feedback via the in-app widget, we store your message, the page URL you sent it from, your user-agent string, and your user ID if you were logged in.
3. Why we collect it (purposes and legal basis)
For visitors in the EU, UK, or anywhere else with GDPR-style law: each thing we collect maps to a specific legal basis.
| What | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email + resume text (free sample) | Deliver the requested sample to you | Performance of a contract you initiated |
| Account email + password hash | Authenticate you across sessions | Performance of contract |
| Stored resume + tweak history | Provide the paid product you signed up for | Performance of contract |
| Subscription metadata | Bill you correctly and let you cancel | Performance of contract |
| Hashed IP + rate-limit rows | Prevent abuse and protect the service | Legitimate interest (security and fraud prevention) |
| Newsletter consent + email | Send you occasional product-update emails | Consent (the checkbox you ticked) |
| Cloudflare access logs | Operate and troubleshoot the service | Legitimate interest |
We do not use your data for any automated decision-making that produces legal or similarly significant effects (GDPR Article 22). The AI helps you write; it does not judge you, score you, or decide anything about you.
4. Who else handles your data
We use a small number of well-known service providers to run Resume Prune. Each one signs a data processing agreement (DPA) that binds them to handle your data only for our purposes, and to protect it as we do.
| Provider | What we send them | Why | Their privacy policy |
|---|---|---|---|
| Anthropic (Claude API) | Your resume text + job description, during one request | To generate the tailored resume + cover letter | Privacy |
| Cloudflare | All requests (it's our infrastructure) | Hosting, security, DDoS protection, analytics | Privacy |
| Resend | Email address + email contents | Sending transactional emails (verify, reset, sample delivery) | Privacy |
| Stripe | Email + payment method + subscription info | Processing subscription payments | Privacy |
| Kit (formerly ConvertKit) (only if you opt into the newsletter) | Email + first name if provided | Sending the email newsletter | Privacy |
Anthropic does not train its models on your resume. Our use of the Claude API is governed by the Anthropic Commercial Terms of Service, which prohibit training on customer inputs.
We do not sell your personal information to anyone. We do not share it with advertisers. We do not allow third parties to use your data for their own purposes.
5. International data transfers
All of the providers listed above are US-based companies. If you are in the EU, UK, or Switzerland, your data is transferred to the United States for processing.
We rely on the EU Standard Contractual Clauses (and the UK / Swiss equivalents) included in each provider's DPA as the safeguard for those transfers. Some providers (Cloudflare, Anthropic) are also certified under the EU-US Data Privacy Framework.
6. How long we keep it
- Free-sample rendered output: 30 days, then automatically deleted.
- Free-sample rate-limit rows (hashed email + hashed IP): 30 days.
- Account email, password hash, profile, stored resume, tweak history: until you delete your account. Most rows are removed within minutes of deletion; some derived caches purge within 24 hours.
- Payment events log: kept for 7 years for tax and accounting purposes (US IRS retention rules apply).
- Newsletter subscriber list: until you unsubscribe. Unsubscribe is honored instantly.
- Email-opt-out records: kept indefinitely (in hashed form) so we honor your opt-out even if you sign up again later.
- Cloudflare edge logs: held by Cloudflare per their retention policy (currently ~30 days); we don't store our own copy.
- Backups: any deleted data may persist in encrypted backups for up to 90 days before they roll over.
7. Your rights
Depending on where you live, you have some or all of these rights:
- Access, request a copy of everything we hold about you (GDPR Article 15; CCPA/CPRA "right to know"). Available right now: log in and click "Download my data" on your Account page.
- Rectification / correction, fix anything that's wrong. Available now: edit your profile fields, re-upload your resume.
- Deletion / erasure, have us delete your account and everything tied to it (GDPR Article 17; CCPA "right to delete"). Available now: the Delete Account button on the Account page.
- Portability, receive your data in a machine-readable format (GDPR Article 20). The same JSON export covers this.
- Object / restrict, tell us to stop using your data for a specific purpose (e.g. unsubscribe from product updates while keeping your account active). Available now: any marketing email has a one-click unsubscribe link.
- Withdraw consent, at any time, with no effect on the lawfulness of processing done before withdrawal.
- Lodge a complaint, you can complain to your local data protection authority (in the EU/UK) or your state attorney general (in the US). We'd appreciate the chance to fix the issue first, email privacy@jenbuiltit.com.
8. How to exercise your rights
The fastest path for most rights is the self-serve tools in your Account page. If you can't access those (e.g. you used the free sample but didn't create an account), email privacy@jenbuiltit.com from the email address you used.
We will respond within 30 days for GDPR requests and within 45 days for CCPA requests, in line with the legal deadlines. We may ask one or two questions to verify the request is really from you (so someone else can't request your data).
We won't charge you, retaliate, or change the price of the service because you exercised these rights.
9. Cookies and tracking
Resume Prune sets one cookie: rp_session. It holds your signed login JWT. It's HttpOnly, Secure, and SameSite=Lax. It's strictly necessary to keep you logged in, so under EU ePrivacy rules it does not require consent.
We do not set marketing cookies. We do not use Google Analytics or third-party tracking pixels. We use Cloudflare Web Analytics, which is cookieless. There is no consent banner because there are no non-essential cookies to consent to.
10. Children
Resume Prune is not intended for users under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us their data, email privacy@jenbuiltit.com and we will delete it.
11. How we protect your data
We follow standard security practices for a small SaaS:
- All traffic is encrypted in transit (HTTPS with HSTS).
- All data is encrypted at rest by Cloudflare (D1) and Stripe (payment data).
- Passwords are hashed with PBKDF2 (100,000 iterations, per-user salt). The plaintext is never stored or logged.
- Sessions can be globally invalidated on demand (every JWT carries a token version we can bump).
- We rate-limit all public endpoints and have automated rules for abusive traffic.
- We run a security regression scanner on every deploy that blocks common vulnerabilities from shipping.
- Access to production secrets is limited to the LLC owner; secrets are stored in Cloudflare's secret store, never in source code.
No system is perfectly secure. If we discover a personal-data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware (as GDPR Article 33 requires) and notify affected users without undue delay if the breach is likely to cause significant harm.
12. California residents (CCPA / CPRA)
If you live in California, you have additional rights:
- Right to know what personal information we've collected about you in the previous 12 months, same as our GDPR access right, fulfilled by the "Download my data" export.
- Right to delete, same as our deletion process.
- Right to correct inaccurate information, edit your profile or contact us.
- Right to opt out of "sale" or "sharing" of personal information, Do Not Sell or Share My Personal Information. (We do not sell or share personal information for cross-context behavioral advertising. This link is provided because California law requires us to provide it.)
- Right to non-discrimination, we won't charge you a different price or deny service for exercising any of these rights.
Categories of personal information we collect (CCPA labels)
- Identifiers: name (from resume), email, account ID, hashed IP.
- Customer records: payment metadata, email address.
- Commercial information: subscription history.
- Internet activity: pages visited within the app, feedback widget submissions.
- Professional or employment information: the resume content you upload.
- Inferences: none, we do not build profiles of you for ad targeting or any other purpose.
We do not collect: geolocation (beyond country-level from your IP), biometrics, genetic data, health information, sensitive demographic information, government IDs, or precise location.
Sources of personal information
Directly from you (the resume + email you submit), and from automated logging by Cloudflare when you visit the site.
Categories of third parties data is shared with
Service providers only, see Section 4. We do not share data with advertisers, data brokers, or analytics partners.
13. Changes to this policy
We update this policy when we change the way we handle data. The "Last updated" date at the top reflects the most recent revision. For material changes (new processor, new data category, new purpose), we will notify account holders by email at least 14 days before the change takes effect, and post a banner on the site.
For non-material changes (typo fixes, clarifications), we will just update the document and revise the date.
14. Contact
Questions about this policy, requests for your data, or anything privacy-related:
Jen Built It LLC
Attn: Privacy
10800 S Lloyd Drive
Worth, IL 60482
United States
privacy@jenbuiltit.com
We aim to reply within five business days for general questions and within the legal deadline for formal rights requests (30 days GDPR / 45 days CCPA).