Privacy Policy
Effective date: 2026-08-07 Version: 2.2
ResumeCallBack is operated by Shannon Kelley, an Arkansas sole proprietor doing business as ResumeCallBack, referred to as "ResumeCallBack," "we," "us," or "our."
ResumeCallBack is an AI-powered career toolkit. This Privacy Policy describes what we collect, how we use it, who we share it with, and the controls you have.
Who is responsible for your data
- Operator: Shannon Kelley, Arkansas sole proprietor
- Trade name: ResumeCallBack
- Privacy requests: privacy@resumecallback.com
- Support: support@resumecallback.com
- Legal notices: legal@resumecallback.com
The Service is offered in the United States only. See §4.
The Service does not currently authenticate to, publish to, or schedule content on LinkedIn. Any LinkedIn-related draft or review is based on information you choose to upload and is for your manual review and use.
1. What we collect
We collect only what's needed to operate the Service.
Account information
- Email address
- Name (if you provide one)
- Encrypted password (we never see your plaintext password)
- The plan you're on and Stripe customer ID (for billing)
Career data you upload or enter
- Resume content (text, PDF, or DOCX you upload — parsed to structured fields and stored on our servers)
- Job descriptions you save
- LinkedIn profile PDF (if you upload one to the LinkedIn Profile Enhancer — stored in private cloud storage scoped to your user ID; parsed to structured fields)
- Target roles you enter
- Gap-question answers you write
- Tailored resumes and other AI outputs we generate for you
LinkedIn post drafts (Full Access)
- Post drafts you generate, edit, or approve
We do not connect to your LinkedIn account. We hold no LinkedIn login, authorization, or credential of any kind, and we do not publish or schedule anything on LinkedIn. Drafts are text on your screen; you copy them out and publish yourself if you choose to.
Product analytics
- Events tied to your account identifier — for example signing up, saving your Vault, adding a job, running an AI action, starting checkout, or reaching a credit limit
- Page views, referrer, device and browser type, approximate location from your IP
We use this to understand how the product is used. It does not include your resume content, job descriptions, gap answers, or AI outputs. See §3.
Usage data
- Which AI actions you've run, when, and the number of credits consumed
- Estimated AI cost per call (for our internal accounting)
- Application status of jobs you track
Technical data
- Standard server logs (IP address, browser user-agent, request path) — used for security and debugging, retained for a limited window
- Vercel deployment logs
- Supabase database logs (for incident response)
We do not collect: payment card numbers (Stripe handles these directly), biometric data, precise device location, or content from any service other than what you explicitly upload.
2. How we use it
- To deliver the Service — store and process your resume, jobs, LinkedIn snapshot, target roles, etc. so the AI features can act on them.
- To bill you — Stripe processes payments; we record your plan and subscription status.
- To improve reliability — server logs, error monitoring, and debugging.
- To communicate with you — transactional emails about your account, password resets, payment receipts.
We do not sell your data, share it with advertisers, or use your resume, LinkedIn or job content to train AI models.
Automated assessments are for you, and go only to you. The Service produces match scores, estimated screening risk, Hard Stops and misalignment assessments about your own materials. These are model estimates based on the job description you supplied, the resume information you supplied, and our own methodology — they are not derived from any employer's applicant-tracking system or hiring outcomes, and they are not measurements of what an employer will do.
We do not make employment decisions. We do not act for any employer, recruiter, staffing agency, job board or background-screening company, and we do not furnish any score, assessment or report about you to any of them. Nothing we generate is sent to a prospective employer unless you choose to send it yourself.
We transmit portions of the content you submit, such as resumes, job descriptions, and related instructions, to our AI service provider to generate the requested analysis or draft. The provider processes this information on our behalf under its commercial terms and data-handling settings. We do not authorize the provider to use our API inputs and outputs to train general-purpose models unless we separately disclose and obtain any consent required for a change. See §3 for the provider and its published retention practices.
3. Third parties we share data with
We use a small number of trusted third-party services. Each receives only the data necessary for its function:
| Provider | What they get | Why |
|---|---|---|
| Supabase (database + auth + storage) | All account + career data | Our primary backend |
| Vercel (hosting) | Server logs, request metadata | Web hosting + analytics |
| Anthropic (Claude API) | The specific text content of an AI request (e.g. your resume + a job description, at the moment you run an AI action) | AI generation. See the note below. |
| Stripe (billing) | Email, name, payment details | Subscription billing. Stripe processes your full payment-card details directly; we never receive or store a full card number or CVC. |
| Resend / Supabase Mail (email) | Email address + email contents | Transactional email (password resets, receipts, billing acknowledgments, data-retention warnings) |
| Vercel Analytics & Speed Insights | Page views, referrer, approximate location, device and browser type, performance timings | Understanding which pages are used and whether the site is fast. Does not use cookies and does not identify you individually. |
| PostHog (product analytics) | Product events tied to your account identifier — for example that you saved your Vault, ran an AI action, started checkout, or hit a credit limit — plus page views and device type | Understanding how the product is used so we can improve it. This is linked to your account, so it does profile your use of the product. It does not receive your resume content, job descriptions, gap answers, or AI outputs. |
About our AI provider. We use the Anthropic API — Anthropic's commercial developer service, not a consumer Claude product. Anthropic's published terms for that service state that customer inputs and outputs are not used to train its models, and Anthropic's documentation for the API describes a standard retention period of 30 days for inputs and outputs, subject to exceptions Anthropic identifies (for example, longer retention where required by law, to investigate a suspected violation of its usage policy, or where a service with different retention is used).
We describe Anthropic's published practices for the service we use. We do not control them, they are Anthropic's to change, and we are not making a separate promise to you about how Anthropic operates. If we become aware of a material change we will update this policy. For the authoritative and current position, see Anthropic's own terms and privacy documentation.
About PostHog specifically. We think you should know this rather than find it in a vendor list. PostHog receives events tied to your account identifier — what you did in the app and when — but never the content you put in. It does not receive your resume, your job descriptions, your answers, or anything the AI generated for you.
We do not use advertising pixels, advertising SDKs, or any tool that shares your data with an advertising network. We do not sell your personal information and we do not use it for cross-context behavioural advertising.
4. Where data is stored
- Primary data store: Supabase (PostgreSQL) hosted in their managed cloud (currently US region).
- File uploads: Supabase Storage, in a private bucket scoped to your user ID.
- Hosting and execution: Vercel.
- AI inference: Anthropic.
The Service is offered in the United States only. Account creation and payment are restricted to users in the US, and we do not market or offer the Service to residents of the European Economic Area, the United Kingdom, or any other jurisdiction.
Our primary data stores are US-based. We select providers whose primary processing for our account is in the United States. However, our providers operate global infrastructure and may use subprocessors or edge locations outside the United States for functions such as content delivery, routing, caching, redundancy and abuse prevention. We do not control every location at which our providers process data, and we therefore do not claim that all processing occurs exclusively within the United States. Each provider's own documentation describes its infrastructure and subprocessors.
If we expand to other countries we will update this policy, bump the version, and put the appropriate safeguards in place before opening signups there.
5. How long we keep it
We publish only retention periods we actually enforce. Where something is policy rather than an automated job, we say so.
Deleted when you delete your account — removed from active systems within 30 days, and in practice immediately:
- Account settings and profile
- Raw resume files you uploaded
- Parsed career data — employment history, education, skills, certifications
- Job descriptions and your job pipeline
- Gap answers
- AI prompts, outputs, scores and assessments
- Master resume and tailored resumes
- Interview preparation
- Uploaded LinkedIn screenshots or exports
- LinkedIn post drafts
- AI usage history
Kept after account deletion, and why. These are deliberately narrow. None of them contains your resume, job descriptions, gap answers, AI assessments or employment history — that material is deleted on the schedule above and is not held for the periods below.
- Subscription consent and cancellation records — 6 years. Evidence that you authorized a recurring charge and that we told you how to cancel. The window is set past the period in which someone can bring a claim on a written agreement, because destroying the evidence while a claim is still possible would leave us unable to answer it. It holds the plan, the price, the timestamps and the identifiers — not your career data.
- Billing email records — 6 years. Evidence that the required subscription, annual-reminder and cancellation notices were sent.
- Eligibility attestation — 6 years. Your confirmation that you were 18 or older and located in the United States.
- Account review records where one exists.
- A minimal deletion record containing a one-way hash of your account identifier, the dates, what was retained, and why. We treat this as a pseudonymous compliance record: it does not contain your name, email or career data, and we do not use it to identify you — but a hash derived from an identifier is not the same as anonymous data, and we do not claim that it is. It exists so we can evidence that a deletion request was carried out.
- Your email address, so a deleted account cannot be silently re-created and so we can confirm the deletion if you contact us.
- Stripe transaction and tax records — held by Stripe, typically 7 years, as required by tax law. Not ours to delete.
Other periods:
- Server logs — 30 to 90 days, unless needed for a documented security or fraud matter.
- Support communications — 24 months after the conversation closes, unless a dispute or legal hold applies.
- Backups — rolling encrypted backups age out within 90 days. Deleted data can persist in a backup until it rolls off; we keep a marker so a restore does not return a deleted account to active use.
- After you cancel a subscription — your Resume Vault, saved jobs and generated documents are retained for 60 days, then permanently deleted. We email you about 7 days before. Resubscribing before then cancels the deletion.
- Subscription credits expire 60 days after they are issued. Trial credits expire 7 days after purchase.
6. Your controls
These are controls we build and honour because they are the right way to run this Service. We offer them to every customer regardless of where they live, and we are not claiming them under, or submitting ourselves to, any particular privacy statute.
You can, at any time:
- Access your data — everything you've entered is visible in the app. You can also email us for an export.
- Edit or delete content — Resume Vault edits, individual job deletes, individual gap-answer deletes, LinkedIn snapshot replace, and post-strategist deletes are all in-app.
- Delete your account — self-service from Settings → Danger Zone. Type your email to confirm, click Delete forever. This immediately cancels any active subscription, wipes all your career data + LinkedIn data + AI usage history, and disables the account. Your email address is retained as a historical record and you will not be able to sign back in.
- Cancel your subscription (without deleting your account) — Settings → Manage Subscription. Opens Stripe's billing portal. Your paid access continues until the end of the billing period you have already paid for, and you will not be charged again. Your account remains, and your career data is retained for 60 days after the subscription ends before it is deleted (see §5). Resubscribing within that window cancels the deletion.
- Object to processing / withdraw consent — use Delete your account, above. Deleting your account stops all processing.
- Download your data — self-service. Settings → Download my data returns a machine-readable JSON file containing your profile, Resume Vault, jobs, tailored resumes, interview prep, LinkedIn snapshot and post drafts, and a usage summary. If you would rather we sent it, email us and we will provide it within 30 days.
- Correct your data — every field of your profile and Resume Vault is editable in the app. If something is wrong that you cannot edit yourself, email us.
- Manage email preferences — transactional emails about your account and billing are required while you have an account, including an annual reminder that your subscription is active and advance notice of any price change. We do not send marketing email.
- Submit a privacy request — privacy@resumecallback.com. We aim to respond within 5 business days and will respond within 30 days.
- Cancel by email instead of signing in — if you cannot or would rather not use the billing portal, email support@resumecallback.com from the address on your account and ask us to cancel. We will not require you to authenticate in order to stop being charged.
To use any of these controls, contact us at the address in §10.
We do not sell your personal information, and we do not use it for cross-context behavioural advertising. We do not run advertising pixels or advertising SDKs.
7. Adults only
The Service is not directed to anyone under 18. You must be at least 18 to create an account, and we ask you to confirm that at signup.
If we learn that we have collected personal information from a person under 18, we will take reasonable steps to stop processing and delete the information, subject to legal, security, fraud-prevention, and transaction-record requirements.
We do not market the Service to high schools, school districts, teen employment programmes, minors, or parents purchasing for children.
We do not ask for your date of birth. A confirmation that you are 18 or older answers the question without us holding an identifier worth stealing.
8. Security
We use administrative, technical, and physical safeguards designed to protect personal information. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
What we do specifically:
- Traffic between your browser and our servers is encrypted in transit (HTTPS / TLS 1.2+).
- Database content is encrypted at rest by Supabase.
- Row-level security restricts every table so one customer cannot read or modify another's data. This is tested, not assumed.
- Uploaded files are stored in a private bucket scoped to your account, restricted to PDF and DOCX, and size-limited.
- Passwords are hashed and salted by Supabase Auth. We never see your password.
- We do not log resume content, gap answers, AI prompts, AI outputs, access tokens, or payment data.
- Credit operations run through database functions that are not reachable from the public API, so no user can grant themselves credits.
If we become aware of a breach affecting your personal information, we will notify the relevant authorities and affected individuals as and when required by applicable law.
9. Changes to this policy
We may update this policy from time to time. When changes are material we will bump the version number above and notify you by email or an in-app notice before the change takes effect.
This policy describes our practices; it is not a contract, and we do not treat your continued use of the Service as your agreement to a revised version. If a change would materially reduce the protection of information we already hold about you, we will tell you and give you the opportunity to delete your account before it takes effect.
Changes to the Terms of Use are handled separately and require your affirmative acceptance — see Terms of Use section 29.
10. Contact
Shannon Kelley d/b/a ResumeCallBack
- Privacy inquiries, data export and deletion requests: privacy@resumecallback.com
- General support: support@resumecallback.com
- Legal notices: legal@resumecallback.com
We aim to respond within 5 business days.
The practices described above reflect how the Service operates as of the effective date at the top of this policy.