Lexa Resume Privacy Policy

Last Updated: April 4, 2026

This Privacy Policy explains how Lexa Resume collects, uses, and protects your information when you use our AI-powered resume building and career tracking application.

Quick Summary

  • We collect minimal data needed to provide our AI-powered features.
  • Your resumes and application data remain private and are processed securely.
  • We use encryption and strict security measures to protect your career data.
  • You have full control over your data and can delete it anytime.
  • We comply with GDPR, CCPA, and other major privacy regulations.

1. Information We Collect

Account Information:

  • Email address for account creation and communication
  • Name (optional) for personalization
  • Profile picture (optional)
  • Authentication credentials (encrypted)

Content You Create:

  • Resumes, cover letters, and professional summaries you generate
  • Job descriptions you input for ATS matching
  • Application tracking statuses and salary expectations
  • Files and documents you import (PDFs, Word docs, etc.)

Usage Information:

  • How you use the app (features accessed, time spent)
  • Device information (OS version, device type)
  • App performance data and crash reports
  • Preferences and settings you configure

Technical Data:

  • IP address (anonymized for analytics)
  • Session data and authentication tokens
  • App version and update information
  • Error logs and diagnostic data

2. How We Use Your Information

Core Service Delivery:

  • Process your content through AI to generate tailored resumes and cover letters
  • Sync your application data across your devices in real-time
  • Provide ATS capability matching against job descriptions
  • Generate tracking analytics and application funnels
  • Backup and restore your data seamlessly

AI Processing:

  • Send content to our partnered AI providers (OpenAI, Google) for processing
  • Analyze resumes to extract key professional skills and metrics
  • Generate summaries, experience bullets, and career insights

Product Improvement:

  • Analyze usage patterns to improve features
  • Fix bugs and enhance performance
  • Develop new AI capabilities to accelerate job hunting

Communication:

  • Send important service updates
  • Provide customer support
  • Notify about new features (with your consent)
  • Send security alerts when necessary

3. AI Processing & Third-Party Services

Lexa Resume utilizes state-of-the-art third-party AI services to power your job search. Here's how we strictly protect your career data during AI processing:

AI Service Providers:

  • OpenAI: Resume generation, summarization, and content optimization
  • Google AI: Document processing and natural language understanding for ATS scoring
  • Anthropic: Advanced chronological text processing and deep analysis

Data Protection During AI Processing:

  • Data is aggressively encrypted in transit to AI providers
  • We utilize enterprise-grade API access which enforces enhanced privacy protocols
  • Personal identifiers are removed before processing whenever technically feasible
  • AI providers are contractually bound to protect your data
  • Processed data is NEVER used to train third-party AI models.

4. Data Security & Protection

Encryption & Security Measures:

  • All data encrypted in transit using industry-standard TLS 1.3
  • Data encrypted at rest using AES-256
  • Database encryption with rotating security keys
  • End-to-end local-first architecture limits server exposure
  • Multi-factor authentication enforced for admin access

5. Data Sharing & Disclosure

We do not sell your personal data. We only share data in these limited circumstances:

Service Providers:

  • AI processing services (OpenAI, Google) for core functionality
  • Cloud hosting providers (with data processing agreements)
  • Analytics services (with data minimization)

Legal Requirements:

  • Court orders or legal process
  • Compliance with applicable laws
  • Protection of our legal rights

Business Transfers & Consent:

  • Mergers or acquisitions (with continued privacy protection)
  • Sharing with third-party integrations you explicitly enable

6. Data Retention

Account & Content Data:

  • Retained while your account is active
  • Deleted within 30 days of account deletion
  • Resumes and templates are immediately deleted when you delete specific content
  • Backups purged within 90 days of deletion

Analytics & Legal Data:

  • Aggregated usage data retained for 2 years (anonymized)
  • Security logs retained for 1 year
  • Legal compliance records as required by law

7. Your Privacy Rights

Access, Portability, & Correction:

  • View all data we have about you and export resumes
  • Download your data in portable formats (PDF, JSON) within 30 days
  • Edit your profile, settings, and career information at any time

Deletion & Control:

  • Delete specific application records or your entire account at any point
  • Opt out of data processing where legally required
  • Control email notifications and manage data sharing preferences

8. Regional Privacy Rights

GDPR Rights (EU/UK):

  • Right to be informed about data processing and right of access
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing and data portability
  • Right to object to processing and automated decision making

CCPA Rights (California):

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale (we never sell your data)
  • Right to non-discrimination for exercising privacy rights

9. Children's Privacy

Lexa Resume is designed for professionals and job seekers. It is not intended for children under 13 (or 16 in the EU). We do not knowingly collect personal information from children.

  • If we discover we have collected information from a child, we will delete the information immediately and terminate the account.
  • Parents and guardians can contact us to review any information or request deletion.

10. International Data Transfers

Lexa Resume operates globally and may transfer data internationally. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) for EU transfers
  • Adequacy decisions where available
  • Explicit consent where required
  • Strict technical safeguards (encryption, access controls) during transfer

11. Cookies & Tracking

Essential & Analytics Cookies:

  • Authentication, session management, and core app functionality (Cannot be disabled)
  • Security and fraud prevention
  • Usage statistics and performance monitoring (Anonymized - Can be opted out)
  • Error tracking and debugging

You can control cookies through browser settings. We respect Do Not Track signals where possible.

12. Privacy Policy Updates

We may update this Privacy Policy to reflect changes in our practices or legal requirements.

  • Material Changes: Email notification 30 days in advance
  • Minor Changes: Updated "Last Modified" date and Website Banner

13. Contact Us

We're committed to protecting your privacy. Your trust is important to us, and we're here to address any concerns. Please reach out:

  • Privacy-Related Inquiries: privacy@lexaresume.com (Response within 72 hours)
  • Data Protection Officer: dpo@lexaresume.com
  • General Support: support@lexaresume.com
  • In-App Help: Settings → Help & Privacy