Skip to main content
ATSEyeATSEye

Privacy Policy

Last updated: 28 July 2026 · Effective: [EFFECTIVE DATE]

Draft pending legal review. This document describes ATSEye's actual data handling as implemented, but it has not yet been reviewed by a lawyer and the operator details below are unfilled.

ATSEye is a resume analysis tool. You give us a resume — and optionally a job description — and we score it, explain the score, and can generate an improved version. Doing that necessarily means processing the contents of your resume, which usually includes your name, contact details, and employment history.

This policy explains exactly what we collect, why, how long we keep it, and how you can get it back or delete it. It covers ATSEye, operated by KXN Technologies Pvt Ltd, Bengaluru, India — [REGISTERED ADDRESS].

1. What we collect

Resume and job description content

When you scan a resume we extract its text and process it. If you are signed in we also store the original uploaded file, unless you turn that off (see Your controls). If you are not signed in, the original file is never stored — only the extracted text needed to produce and re-display your score.

Resume text routinely contains personal data you chose to put in it: name, email, phone number, postal location, employers, dates, and education. We process it to score and improve the resume, not to build a profile of you.

Account details

  • Username, email address, and display name.
  • A one-way bcrypt hash of your password. We never store, log, or have any way to read your actual password.
  • If you use “Continue with Google”, the email and verified-email flag Google returns. We do not receive your Google password.

Usage and technical data

  • Scores, optimization history, saved resumes, cover letters, and job-tracker entries you create.
  • An activity log of actions on your account (for example “resume uploaded”), which records IP address and browser user-agent for security and abuse investigation.
  • Counts of AI operations performed, used for billing, quotas, and cost control.
  • Standard request logs containing method, path, status, and duration. We do not log resume text, job descriptions, contact details, tokens, or secrets.

Identifiers used to enforce usage limits

Free accounts may run one AI optimization per 24 hours. To make that limit meaningful we check three things, and we want to be specific about the third because it is derived from your resume:

  • Your account — your username, when signed in.
  • Your device and network — a random identifier your browser stores (aura.device.v1), and your IP address. Both are stored only as a keyed hash.
  • The email address and phone number printed on the resume. We extract them, normalise them, and store a SHA-256 hash keyed with a server-side secret. We do not store the address or number itself, we cannot reverse the hash back into it, and it is never logged or shown to anyone. Its only purpose is to recognise that the same resume has already been optimized today — from any device or account — so the free limit cannot be bypassed by opening a new browser. These hashes are automatically deleted about two days after the limit window ends.

2. How we use it

  • To score your resume and explain the score.
  • To generate optimized resumes and cover letters when you ask us to.
  • To keep your history so you can revisit past scans and versions.
  • To operate accounts, authentication, and password resets.
  • To enforce free-tier limits and prevent abuse.
  • To take payment for paid plans.
  • To keep the service secure and debug faults.

We do not sell your personal data, and we do not use your resume to train AI models.

3. AI processing

Resume scoring itself is deterministic — it runs on our own servers with no AI involved, which is why the same resume always returns the same score.

Three features do use a third-party AI model (Claude, provided by Anthropic): written insights about your resume, AI resume optimization, and cover-letter generation. For those, the relevant resume and job-description text is sent to Anthropic for processing. Before it is sent, we redact detected contact details from the text where the feature allows it. Anthropic processes the request and returns a result; we do not permit your content to be used to train their models.

4. Who we share data with

We share data only with service providers who help us run ATSEye, and only what each one needs:

  • Anthropic — AI processing for insights, optimization, and cover letters (resume and job-description text).
  • Google Cloud — hosting and infrastructure. Our servers and database run in the United States (us-central1).
  • MongoDB — the database storing your account and resume data.
  • Razorpay — payment processing for paid plans. Card details go directly to Razorpay; we never see or store them.
  • Google— only if you choose “Continue with Google”.
  • Our transactional email provider — to send verification codes, password-reset links, and service notices.
  • Adzuna — job listings shown as recommendations. This is a feed we read; your resume is not sent to them.

We may also disclose data where legally required, or to protect the rights and safety of our users.

International transfer: if you use ATSEye from outside the United States, your data is transferred to and processed there.

5. How long we keep it

  • Scans and scores — automatically deleted 90 days after they are created.
  • Optimized resumes — you choose: delete immediately after download, or keep for 1, 7, 30, 90, 180, or 365 days. The default is 30 days.
  • Original uploaded files — kept while your account is active if you have that setting on. Turning it off also deletes originals we already hold.
  • Usage-limit identifiers (device, network, contact-derived) — about two days, then automatically deleted.
  • Account details — until you delete your account.
  • Payment records — retained as long as tax and accounting law requires, even after account deletion.

6. Your controls

In Account settings you can turn off storage of original resume files and choose how long optimized resumes are kept.

7. Your rights

  • Access and portability — export everything we hold for your account as a single JSON file, from your account page.
  • Correction — update your profile details at any time.
  • Deletion — delete your account. This immediately ends your sessions and removes your profile details; your resumes, scores, and stored files are then purged.
  • Individual records — delete any single scan and its version history.

Depending on where you live you may also have rights to object to or restrict processing, or to complain to a data-protection regulator. To exercise anything not available in-product, contact us at [CONTACT EMAIL].

If you used ATSEye without an account, we have no way to identify which records are yours, so we cannot action an access or deletion request for them. Anonymous scans expire on the retention schedule above.

8. Security

  • All traffic is encrypted in transit over HTTPS.
  • Passwords are stored only as bcrypt hashes.
  • Credentials and API keys are held in a managed secrets store.
  • Resume text, contact details, and authentication tokens are excluded from our logs by design.
  • Access to your records is scoped to your account and enforced server-side.

No system is perfectly secure, and we cannot guarantee absolute security — but we do not keep what we do not need, and we expire what we do keep.

9. Cookies and browser storage

We do not use advertising or cross-site tracking cookies. We use browser storage for two things:

  • aura.session.v1 — your sign-in token, held in sessionStorage and cleared when you close the tab.
  • aura.device.v1 — a random device identifier used for the free-tier limit. Clearing site data removes it.

10. Children

ATSEye is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

11. Changes

If we make a material change to how we handle your data we will update this page and revise the date above. Significant changes will be notified in-product or by email.

12. Contact

Questions, requests, or complaints: [CONTACT EMAIL].

For users in India: our Grievance Officer under the Digital Personal Data Protection Act is [GRIEVANCE OFFICER NAME], reachable at the same address.