← Back

Privacy Policy

Last updated: February 27, 2026

1. What We Collect

We collect the following information to provide the Service:

  • Account data: email address and hashed password (managed by Supabase Auth)
  • Profile data: resume content, work history, bullet points, and skills you enter
  • Job posting data: job descriptions you paste or upload for matching
  • Usage data: feature interactions, match results, and export history
  • Payment data: transaction ID and billing country (processed by Stripe — we do not store card numbers)

2. How We Use Your Data

We use your data to:

  • Provide and improve the Service
  • Process AI requests (your resume content is sent to Anthropic or OpenAI APIs)
  • Send transactional emails (purchase confirmations, expiry warnings)
  • Respond to support requests
  • Detect and prevent abuse

3. AI Processing

When you use AI features, portions of your resume content and job postings are sent to third-party AI providers (Anthropic and/or OpenAI) to generate responses. These providers have their own privacy policies. We do not permit them to use your data for model training under our API agreements.

4. Third-Party Services

We use the following third-party services:

  • Supabase — database and authentication
  • Stripe — payment processing
  • Anthropic / OpenAI — AI features
  • Resend — transactional email
  • Vercel — hosting and deployment

5. Data Retention

We retain your data for as long as your account is active. If you delete your account, all personal data is permanently removed within 30 days, except where retention is required by law (e.g., payment records may be retained for 7 years for tax purposes).

6. Your Rights (GDPR / CCPA)

You have the right to:

  • Access: request a copy of your data
  • Deletion: delete your account and all associated data from Settings
  • Portability: export your resume data (available from the export page)
  • Correction: edit your data at any time from your profile
  • Opt-out: unsubscribe from emails via the link in any email

To exercise any right, contact us at privacy@butterflyresume.com.

7. Cookies

We use a single authentication cookie (managed by Supabase) to keep you logged in. We do not use advertising or tracking cookies. No cookie banner is needed.

8. Data Security

All data is encrypted in transit (TLS) and at rest. Access to production data is restricted to essential team members. Row-level security (RLS) ensures users can only access their own data.

9. Children

The Service is not directed at children under 13. We do not knowingly collect data from children under 13.

10. Contact

Privacy questions? Contact us at privacy@butterflyresume.com.