Skip to content
CheckResumeATS
Interactive exampleDecision methodPricing
PricingOpen workspace

Privacy Policy

Last updated: July 20, 2026 · pilot-privacy-2026-07-20

CheckResumeATS ("we", "our", or "us") operates www.checkresumeats.com and app.checkresumeats.com. This policy explains the different data rules for those surfaces and for the invitation-only paid pilot.

Public Site and Private Workspace

www.checkresumeats.com contains product information and interactive fictional examples and does not accept real resumes, job descriptions, or App sessions. Real career data is handled only at app.checkresumeats.com after sign-in. The App does not load Google Analytics, Microsoft Clarity, or marketing session recording on sensitive routes.

Information We Collect

In the App we collect account identifiers needed for sign-in, the resume facts and job descriptions you choose to save, target-job decisions, service consent and task decisions, and payment status. Public-site analytics, when enabled with consent, are limited to marketing interactions and must not contain resume text, job text, email, user IDs, report IDs, or App sessions.

How We Handle Resume Data

The structured base resume is the fact source for analysis and delivery. Saved source, confidence, confirmation state, and evidence IDs remain traceable so you can correct or reject facts. Raw uploaded resume files are processed for the request and are not retained unless you explicitly choose a feature that says otherwise. Saved App records remain private to your account under access controls.

AI Processing

External DeepSeek processing is currently disabled for the live US pilot. If enabled later, it will require separate just-in-time authorization. DeepSeek would receive only minimized, confirmed evidence and job requirements after direct contact identifiers are removed; that is not anonymization. DeepSeek is based in China and says personal data may be processed and stored in the People's Republic of China. Its current Privacy Policy says downstream developer-app end-user processing is not covered, and its public terms do not give us a fixed retention period or a binding no-training commitment for that content. Until a provider agreement, transfer basis, retention and deletion, training use, security, and end-user authorization are approved, fulfillment remains human-only. Any AI output is untrusted and cannot create new resume facts without your confirmation.

Human Review

The paid pilot includes human review only after an active, versioned opt-in for one target job. An authorized reviewer may then view that job's resume, job description, analysis, confirmed evidence, and working drafts for fulfillment. Each Reveal window is purpose-limited, audited, and no longer than 10 minutes. Reviewer policy prohibits download, screenshot, recording, and external copying, but technical controls cannot guarantee that screenshots are impossible. Withdrawing consent immediately blocks new access and starts the applicable cancellation or refund workflow.

Cookies & Tracking

The App uses host-only essential cookies for authentication and security. The public site may use consent-controlled analytics to understand marketing performance. App and Admin cookies are separate and are not parent-domain cookies.

Third-Party Services

Core providers include Supabase for authentication and database, Google for sign-in, and Vercel for hosting. DeepSeek is the disclosed but currently disabled external AI provider. If checkout opens, Creem will act as merchant of record and collect buyer identity, billing address, payment, invoice, and order information under its own Buyer Terms and Privacy Notice. Public marketing analytics may use Google Analytics, Microsoft Clarity, and Vercel analytics only on the public site and subject to the applicable consent choice.

Data Security

We use HTTPS, separate App and Admin authentication boundaries, row-level access controls, owner checks, bounded requests, short-lived reviewer access, and audit events. No Internet or human-operated system can be guaranteed completely secure.

Retention and Deletion

You can export workspace data. Deleting a job or account removes sensitive content unless an active service or pending refund must be resolved first. After resolution, we delete execution content and retain only de-identified payment and policy-version evidence where needed for accounting, refunds, disputes, security, or legal obligations. Failed AI-run records older than 30 days are deleted, and expired saved check text is cleared according to its record expiry. External AI remains disabled because no acceptable provider retention and deletion commitment has yet been verified.

Your Rights

The App provides data export, job deletion, account deletion, fact correction, and human-review consent withdrawal. Active service and refund obligations are shown instead of silently discarding records. Contact support@checkresumeats.com for access, correction, deletion, or privacy questions.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

Contact Us

If you have any questions about this Privacy Policy, please contact us at support@checkresumeats.com.

Current Provider Documents

  • DeepSeek Open Platform Terms
  • DeepSeek Privacy Policy
  • Creem Privacy Notice
CheckResumeATSEvidence-first job decisions
Decision methodPricingPrivacyTermsRefunds
© 2026 CheckResumeATSsupport@checkresumeats.com