Back
Privacy Policy for MagicResume
Last Updated: January 15, 2025
Thank you for using MagicResume ("we," "us," or "our"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our AI-powered resume building platform at https://magicresume.top (the "Service").
By accessing or using MagicResume, you agree to the terms of this Privacy Policy. If you do not agree with these practices, please do not use the Service.
1. Information We Collect
1.1 Personal Information
We collect the following personal information:
- Name and Email: For account creation, authentication, and communication
- Payment Information: Processed securely through Stripe. We do not store your credit card details on our servers
- Profile Photo: If you sign in via Google, GitHub, or LinkedIn, we may collect your profile picture
- LinkedIn Profile Data: If you choose to import from LinkedIn, we collect your work experience, education, skills, and other public profile information
1.2 Resume and Career Data
To provide our AI-powered services, we collect and store:
- Resume Content: Personal information, work experience, education, skills, projects, certifications, and languages you enter
- Cover Letters: Content you create or generate using our AI tools
- Job Descriptions: URLs and text of job postings you analyze
- Interview Responses: Your answers during practice interview sessions (text, and in the future, audio/video recordings)
- Resume Versions: Multiple branches of your resume and their performance metrics (views, applications, interviews)
- Analytics Data: How recruiters interact with your shared resume links
1.3 AI-Generated Content
We store AI-generated suggestions, edits, and content created by our system based on your input. This helps improve our services and provides caching for faster performance.
1.4 Non-Personal Data
We automatically collect:
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages visited, features used, time spent, click patterns
- Cookies: We use essential cookies for authentication and functional cookies to remember your preferences
- Analytics: Aggregated usage statistics to improve our product
2. How We Use Your Information
We use your data to:
- Provide AI-powered resume optimization, cover letter generation, and interview preparation
- Process payments and manage subscriptions via Stripe
- Authenticate your account via NextAuth (Google, GitHub, LinkedIn, or email)
- Generate personalized suggestions based on your resume and target jobs
- Track resume performance metrics (views, applications, interview success rates)
- Send transactional emails (password resets, subscription updates, important notifications)
- Provide customer support via our chat system
- Improve our AI models and service quality
- Comply with legal obligations
2.1 AI Processing
Your resume data is processed by OpenAI's GPT-4 API to provide:
- Resume analysis and PowerEdit suggestions
- Cover letter generation
- Interview question generation and feedback
- Job-fit analysis and keyword optimization
- ATS score calculation
We cache AI responses for 24 hours to improve performance and reduce costs.
3. Data Sharing and Third Parties
We share your data with the following trusted third-party services:
- OpenAI: For AI-powered features (resume analysis, cover letters, interviews)
- Stripe: For payment processing and subscription management
- MongoDB Atlas: For secure database hosting (encrypted at rest)
- Resend: For transactional email delivery
- Vercel: For hosting and serverless functions
- NextAuth: For OAuth authentication (Google, GitHub, LinkedIn)
We do NOT:
- Sell your personal data to advertisers or data brokers
- Share your resume content with recruiters without your explicit consent (public sharing)
- Use your data to train third-party AI models without anonymization
- Share your interview responses or performance metrics with third parties
3.1 Public Resume Sharing
If you choose to make a resume branch public:
- Anyone with the link can view your resume
- We track view counts and analytics
- You can password-protect, set expiration dates, or disable downloads
- You can revoke public access at any time
4. Data Storage and Security
- Data Location: Your data is stored in secure MongoDB Atlas databases with encryption at rest
- Encryption: All data transmitted to and from our servers uses HTTPS/TLS encryption
- Access Control: Only authorized personnel have access to user data, and only when necessary for support or service improvement
- AI Cache: AI-generated responses are cached for 24 hours and then automatically deleted
- Retention: We retain your data as long as your account is active. After account deletion, data is removed within 30 days
5. Your Rights and Choices
You have the right to:
- Access Your Data: Request a copy of all personal data we hold about you
- Correct Your Data: Update or correct inaccurate information in your account settings
- Delete Your Data: Request account deletion. We will remove your data within 30 days
- Export Your Data: Download your resumes, cover letters, and interview history
- Opt-Out of Emails: Unsubscribe from marketing emails (transactional emails cannot be disabled)
- Revoke Third-Party Access: Disconnect LinkedIn, Google, or GitHub at any time
- Control Public Sharing: Make your resume private, password-protected, or time-limited
To exercise these rights, contact us at bartzalewskidev@gmail.com.
6. Children's Privacy
MagicResume is intended for job seekers aged 16 and older. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, please contact us immediately, and we will delete it.
7. Cookies and Tracking
We use the following types of cookies:
- Essential Cookies: Required for authentication and core functionality (cannot be disabled)
- Functional Cookies: Remember your preferences (resume editor settings, UI preferences)
- Analytics Cookies: Understand how users interact with our service (aggregated, anonymized)
You can control cookies through your browser settings, but disabling essential cookies will prevent you from using MagicResume.
8. Data Breach Notification
In the unlikely event of a data breach affecting your personal information, we will:
- Notify affected users via email within 72 hours
- Provide details about what data was compromised
- Explain steps we're taking to resolve the issue
- Offer guidance on protecting your account
9. International Users
MagicResume is operated in the United States. If you access our Service from outside the U.S., your data will be transferred to and processed in the United States. By using MagicResume, you consent to this transfer.
10. Updates to This Privacy Policy
We may update this Privacy Policy to reflect:
- New features or services
- Changes in legal requirements
- Improvements to our privacy practices
When we make significant changes:
- We'll update the "Last Updated" date
- We'll notify you via email
- Continued use of the Service constitutes acceptance of the updated policy
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to know what personal data we collect and how it's used
- Right to request deletion of your personal data
- Right to opt-out of the "sale" of personal data (note: we do not sell personal data)
- Right to non-discrimination for exercising your privacy rights
12. European Privacy Rights (GDPR)
If you are in the European Union, you have rights under the General Data Protection Regulation:
- Right to access, rectify, and erase your personal data
- Right to restrict or object to data processing
- Right to data portability
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority
13. Contact Information
For privacy-related questions, data requests, or concerns:
Email: bartzalewskidev@gmail.com
Website: https://magicresume.top
For security issues, please use the subject line "SECURITY" in your email.
By using MagicResume, you acknowledge that you have read and understood this Privacy Policy.