Privacy policy
Last updated: July 30, 2026
Reqline ("the service", "we") helps you keep a verified base resume and build tailored, ATS scored PDF resumes from it. A resume is a concentrated record of your working life, and the jobs you are applying to say even more about you. This policy explains exactly what we hold, who touches it, how long it lasts, and how to get it back or destroy it.
The short version
- We collect your resume, the job descriptions you paste, the jobs you track, and a history of the builds you run.
- We use it to do the one job you asked for: tailor your own resume to your own applications.
- We have never sold or shared your personal information, and we never run advertising against it.
- Tailoring and resume parsing send your resume text and the job description to an AI provider. That section is spelled out below.
- You can export everything, correct anything, and delete your account yourself. Deletion is real and it is permanent.
Who we are
Reqline is an independently operated service, run from the United States by its sole developer, who is the data controller for the personal data described here. There is no company behind it, no sales team, and no investor with a claim on your data. You can reach the controller directly at privacy@reqline.app.
What we collect
- Account information. When you sign in with Google we receive your name, email address, and profile picture. We never receive your Google password, and we ask for no other Google data.
- Resume content. The resume PDF you upload, the structured content extracted from it, and every edit you make. Your account holds up to three resume documents; when you save a fourth, the oldest one that is not your active resume is removed to make room.
- Job descriptions. The job description text you paste when scoring or building a tailored resume, in the app or through the Claude connector.
- Job tracker entries. If you use the job tracker, we store what you put in it: company, role title, location, work mode, employment type, the job posting link, salary range, application status and dates, and your own free text notes.
- Tailoring rules. Short guidance sentences you save (or approve during a tailoring conversation) that shape how your bullets get reworded.
- Build and parse history. A record of each build and each resume upload: when it ran, the job title and company it targeted, the scores it produced, whether it succeeded, and the file it generated.
- Connector credential. If you enable the Claude connector, we store your personal connector token so the setup page can show you the full URL again later. You can rotate or revoke it at any time.
- Usage counters. Per day build and parse counts, to enforce fair use limits on a free service.
- Technical logs. Standard server logs from our hosting provider: request times, status codes, model latency, token counts, and error traces. We do not write your resume content or your prompts into our logs.
We do not collect payment information, because the service is free. We do not run analytics, tracking pixels, session recording, or fingerprinting. We do not buy personal information about you from data brokers, and we do not enrich your profile from third party sources.
Why we use it, and our legal basis
If you are in the UK, the EEA, or Switzerland, the GDPR requires us to name a lawful basis for each purpose. Here they are.
| What we do | Legal basis |
|---|---|
| Parse your uploaded resume into structured content you can review and edit | Performance of our contract with you (Art. 6(1)(b)) |
| Score your resume against a job description and build tailored PDFs at your request | Performance of our contract with you (Art. 6(1)(b)) |
| Store your job tracker entries and tailoring rules and show them back to you | Performance of our contract with you (Art. 6(1)(b)) |
| Show you your own build history and account information | Performance of our contract with you (Art. 6(1)(b)) |
| Keep the service running, debug failures, enforce usage limits, and prevent abuse | Our legitimate interest in a secure and available service (Art. 6(1)(f)) |
| Answer your emails and handle your privacy requests | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)) |
Your resume content is used only to serve you. It is never used to train models, never used for marketing, and never surfaced to another user.
AI processing
Two features send your content to an AI model: extracting a resume from an uploaded PDF, and tailoring a resume against a job description (in the app or through the Claude connector).
Those requests go to OpenRouter, an AI gateway that forwards the request to the model provider. The model in use by default is Anthropic's Claude, reached through OpenRouter rather than directly. What we send is the resume text, the job description, and your saved tailoring rules. We do not send your name, email, Google profile, or job tracker entries to the model beyond whatever contact details your resume itself contains.
OpenRouter does not retain prompt or completion content by default, and stores request metadata such as timestamps, model, token counts, and latency for billing and operations. Whether an upstream provider may retain or train on a prompt depends on that provider's own policy and on the routing settings on our OpenRouter account. This is the part of the pipeline furthest from our direct control, so we state it plainly rather than promising more than we can enforce.
If you use the Claude connector, you are also using Anthropic's Claude product directly, and your conversation there is governed by Anthropic's own privacy policy and your own Claude settings, not by this one.
Scores and automated decisions
The ATS score is an estimate of keyword coverage and formatting. It is feedback for you about a document you control. It is not a decision about you, it is not shared with any employer, and it is not used to rank, profile, or evaluate you as a person. We do not carry out automated decision making that produces legal or similarly significant effects, and we do not use automated decision making technology to make decisions about you.
Cookies
We set only the cookies needed to keep you signed in. These are the session and refresh token cookies issued by our authentication provider, and they are strictly necessary, so we do not show a cookie banner asking permission for them. We set no advertising cookies, no analytics cookies, and no third party tracking cookies. Signing out clears them.
Who else processes your data
These are every processor that touches your personal data, and the only thing each one does with it:
| Provider | Role | Location |
|---|---|---|
| Google Cloud (Cloud Run) | Hosts the web app and the resume build service | us-central1 |
| Supabase | Database, authentication, and private file storage | us-east-2 |
| Sign in with your Google account | United States | |
| OpenRouter | AI gateway for resume parsing and tailoring | United States |
| Anthropic | Model provider reached through OpenRouter, and the Claude connector if you enable it | United States |
| Cloudflare | DNS for reqline.app. Records are DNS only, so traffic and content do not pass through it | Global |
Each provider processes only what its role needs. We do not disclose your personal information to anyone else, and we have no other recipients to name.
Google account data
Reqline's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only your basic profile and email address, we use them only to create and identify your account, we do not transfer them to third parties except as needed to run the service, we never use them for advertising, and no human reads them except as required for support you asked for, security, or the law.
Where your data is stored
All of it is stored and processed in the United States. If you use the service from the UK, the EEA, or Switzerland, your personal data is transferred to the United States and handled there. For those transfers we rely on the safeguards our providers put in place, which include standard contractual clauses and, where a provider is certified, the EU-US Data Privacy Framework. You can ask us for details on any specific provider.
How long we keep it
| Data | Retention |
|---|---|
| Account profile (name, email, picture) | Until you delete your account |
| Resume documents | Until you delete them or your account. Capped at three per account; saving a new one evicts the oldest that is not your active resume |
| Uploaded resume PDFs | The two most recent uploads are kept, and older ones are removed the next time you upload. All are deleted with your account |
| Generated PDFs | The 20 most recent builds. Older files are deleted automatically after each new build |
| Build and parse history rows | Kept as a record after the file itself is gone, and deleted with your account |
| Job tracker entries and tailoring rules | Until you delete them or your account |
| Job descriptions you paste | Kept only for the session that uses them, except the job title and company recorded on a build |
| Connector token | Until you rotate or revoke it, or delete your account |
| Server logs | Short operational retention at our hosting provider, typically 30 days |
One point deserves emphasis, because it is easy to assume otherwise: your uploaded source PDF is not deleted the moment extraction finishes. Two uploads stay in storage so the review step keeps working, and they clear out on your next upload or when you delete your account. If you want one gone sooner, upload again or delete your account.
When you delete your account, the deletion runs immediately: your connector token is revoked, both storage buckets are emptied, and your login is destroyed, which cascades every row listed above. Residual copies can persist in encrypted provider backups for a short period before rotating out, and in no case longer than 30 days.
Your rights
Most of these you can exercise yourself, immediately, without asking us:
- Access and portability. Your resume content is visible and editable in the app, and every tailored resume downloads as a PDF. Email us for a machine readable copy of everything we hold.
- Correction. Edit any resume field, job tracker entry, or tailoring rule in the app at any time.
- Deletion. Delete individual items in the app, or delete your whole account from account settings. Account deletion is immediate and unrecoverable.
- Revocation. Rotate or revoke your Claude connector token whenever you want, which cuts off connector access without touching the rest of your account.
Depending on where you live, you also have the right to restrict or object to processing, to withdraw consent where we rely on it, to know the categories of personal information we collect and why, to limit the use of sensitive personal information, and to be free from discrimination for exercising any of these rights. We charge nothing for a request and we do not degrade the service for anyone who makes one. You may use an authorized agent, in which case we will need proof of their authority.
To exercise anything on this list, email privacy@reqline.app from the address on your account. We respond within 30 days, and within 45 days for requests under US state privacy laws.
If you are in the UK, the EEA, or Switzerland and you think we have handled your data badly, we would like the chance to fix it, but you have the right to complain to your local data protection authority without going through us first.
Selling, sharing, and advertising
We do not sell your personal information, and we never have. We do not share it for cross context behavioral advertising. We do not disclose it to third parties for their own purposes. Because none of that happens, there is no opt out to offer you, and a Global Privacy Control signal from your browser changes nothing about how we treat you: you already have the outcome it asks for.
Sensitive information
A resume does not need your government identification number, date of birth, photograph, health information, religion, race, union membership, or sexual orientation, and we ask that you keep those out of the content you upload. We do not request sensitive personal information, we do not use or disclose it to infer characteristics about you, and if it reaches us inside a document you uploaded, it is treated like the rest of that document and deleted with it.
Security
- Every table is protected by row level security enforced in the database, so your account can read and write only its own rows. Storage buckets are private, and file paths are scoped to your user ID.
- Traffic is encrypted in transit with TLS, and data is encrypted at rest by our database and storage provider.
- To be straight with you about administrator access: the service administrator can read account records, build and parse history, and resume documents, in order to operate and support the service. Your job tracker entries are not readable by the administrator. Your data is never visible to another user.
- Connector access is scoped to your own account and gates resume tailoring only. You can rotate or revoke it at any moment, and removing the connector in Claude ends its access there and then.
- Reqline is a free service built by one developer. It has not been through SOC 2, ISO 27001, or any third party audit, and we would rather tell you that than imply a certification we do not hold.
If something goes wrong
If a breach affects your personal data, we will notify you by email without undue delay, and we will notify the relevant supervisory authority within 72 hours where the law requires it. We will tell you what happened and what data was involved, rather than issuing a statement that avoids saying.
Legal and government requests
We will not hand your data to anyone, including law enforcement, unless we are compelled by valid legal process such as a warrant, subpoena, or court order. If we receive one, we will notify you before disclosing anything, unless we are legally prohibited from telling you.
Children
The service is not directed to children under 16, we do not knowingly collect their data, and we delete any account we discover belongs to one.
Changes to this policy
If this policy changes in a meaningful way, we will update this page and the date above, and we will notify signed-in users by email or in the app before the change takes effect. We will not quietly broaden what we do with data you already gave us.
Contact
Privacy questions, data requests, and complaints all go to the same person: privacy@reqline.app