Legal
Privacy Policy
MB Resume Builder is a browser-first, local-first résumé product with an optional MB HR Documents workspace for HR teams. This policy describes exactly what each part of the product does with your data — including where it falls short of “nothing ever leaves your browser,” since parts of it genuinely don’t.
Résumé editing: anonymous/local mode vs. account mode
Anonymous mode (no account). Everything you type into the builder — every section, every edit — is written only to this browser’s local storage. Nothing about your résumé’s content is sent to our servers merely by editing it.
Account mode. Signing in does not change where your résumé drafts live — they stay in this browser’s local storage exactly as before. We do not silently upload an existing local résumé to your account when you sign in, and there is no background sync of résumé content to our servers today. An account exists for premium ownership, purchase history, and (where you use them) the HR workspace and shared-link features below — not for storing your résumé.
If cloud sync of résumé drafts is ever introduced, it will be off by default and require your explicit, separate opt-in — never turned on silently for existing local drafts.
Two features are explicit exceptions, because you take a deliberate action to trigger them:
- Sharing a résumé (the Share button) creates a server-side snapshot at a public link, so a recruiter can view it without an account. You choose whether to include your contact details in that snapshot, and you can revoke the link at any time.
- Importing a résumé file is parsed locally first; if the automatic parse has low confidence, or you click “Improve with AI parsing,” the extracted text (which can include your name, email, and phone) is sent to our AI provider for that one request — see the AI section below.
AI & data processing — what runs where
Six things can happen when you use this product, and only one of them ever sends your data to an outside AI provider:
- Local editing. Typing into the builder, formatting, and template switching happen entirely in your browser. Nothing is sent anywhere.
- ATS deterministic checks. The ATS Simulator’s score, keyword coverage, and formatting checks run as plain code in your browser against rules we ship — no AI model, no network request, for the deterministic parts of that score.
- Local autosave. Your draft is written to this browser’s local storage on every change (debounced), so a refresh or crash doesn’t lose your work. This never leaves the browser.
- AI-assisted processing. “Improve this bullet,” rewrite/summary suggestions, AI-suggested tailoring edits, the job-description semantic match, and the AI-enhanced resume import path all send the specific text involved (a bullet, a summary, a job description, or — for import parsing only — your full extracted résumé text) to Google’s Gemini API, our one AI provider, for that single request. It is not used to train Google’s models on our configuration, and we do not send it anywhere besides Gemini. The job-description matcher builds a name/email/phone/location-stripped digest before sending anything, and shows you an explicit disclosure you must acknowledge before it runs. You can turn AI-assisted processing off entirely for your account from AI preferences — every one of these routes refuses to call Gemini once you do, checked on our server, not just hidden in the interface.
- Cloud sync. There is no résumé cloud sync today (see the section above). Nothing to disclose beyond: if that changes, it will be opt-in.
- Account metadata. Your name, email, password hash, premium/subscription status, and (if you use MB HR Documents) your company and employee records are stored on our servers — described fully in the next section. This is separate from, and does not by itself involve, any AI provider.
Accounts, premium access, and the HR company workspace
Account data includes your name, email address, password (stored as a one-way hash, never recoverable by us), email verification status, sign-in provider information, and purchase or subscription status. Resume templates, editing, and export are free for all users and are never watermarked; premium currently unlocks the HR document generators.
MB HR Documents is different from résumé editing: it is server-side by nature. If you set up a company workspace, everything you enter — company details, employee records (including annual CTC/salary), signatories, custom document templates, bulk-generated documents, approval workflows, and their audit trails — is stored on our servers under your account, because generating and tracking real HR documents requires it. Nothing in a company workspace is ever visible to, or shared with, another account.
Your own résumé and a company workspace are never combined. These are two different kinds of data about two different people, and we do not join them. Your résumé is not read into any employer’s employee records, an employer’s records are not read into anyone’s résumé, and there is no shared identifier linking the two. That holds even when the same account does both — an HR manager who also builds their own résumé here has one of each, not a merged profile. This is enforced in the code itself: the two halves of the product cannot read each other, and an automated check fails our build if that ever changes.
Connected AI clients (MCP, e.g. a ChatGPT connector)
MB Resume Builder exposes an MCP (Model Context Protocol) server so an AI assistant you use elsewhere — for example a ChatGPT connector — can draft and render HR documents on your behalf.
Without connecting your account, such a client can only list supported HR document types, see what fields a document needs, draft one from details you type into it, and render that draft to a PDF or DOCX. None of this touches any account data, and nothing is saved on our servers.
Connecting your account requires an explicit OAuth authorization you approve, scoped to one company workspace you choose. Once connected, the client can read that company’s profile and employee records, and save a document it drafted into that company’s approval queue — always as a new draft only, never overwriting or sending anything, and only after a separate, explicit confirmation step for that save. This connector has no way to invent a fact about an employee: if information is missing, it reports exactly what’s missing instead.
Access tokens issued to a connected client expire automatically after one hour. Disconnecting the client from within that client (for example, removing the connector in ChatGPT’s own settings) revokes its ability to obtain new ones.
Cookies, analytics, and advertising
We use PostHog (EU-hosted) for privacy-first product analytics: which features are used, not what you typed into them. Session recording is off, typed input and page text are masked before capture even reaches PostHog, and nothing is collected until you accept the analytics banner — it starts opted out by default. Declining, or not responding, means nothing is sent.
Our own event catalog is structurally limited to counts, booleans, and short labels — it never includes résumé contents, job-description text, salary figures, employee names, or HR document body text, for any event, by design (not by a filter that could later be loosened).
We also use Google AdSense/Ads for advertising and conversion measurement, gated through Google’s own Consent Mode: ad-related tracking (including the automatic pixels Google’s tag would otherwise fire on every page load) defaults to denied and only turns on once you explicitly accept the banner. Declining stops both PostHog capture and every Google Ads signal. This does not remove the advertising script tags themselves from the page (loading a script is not the same as it sending data about you), and it does not affect Razorpay, which only runs during an actual checkout you initiate.
Payments and other third-party services
Trusted third parties that may process data on our behalf:
- Google Gemini — AI-assisted rewrite, tailoring, matching, and import-parsing requests (see the AI section above).
- PostHog — consent-gated product analytics (EU-hosted).
- Google AdSense/Ads — advertising and consent-gated conversion measurement.
- Razorpay — payment processing, transaction verification, and subscription handling.
- Google Sign-In — optional authentication.
Each processes data under its own privacy policy, only for the purpose listed.
Your data controls
Available directly from your account, no support request needed:
- Download my data — Account → Privacy & data → Download. Everything we hold about your account on our servers as one JSON file (résumé drafts and Career Vault aren’t included — see below for why).
- Delete a résumé — from Account → My Résumés, or directly in the builder. This is a real, immediate, permanent removal from this browser’s storage, because that’s the only place it ever lived.
- Delete Career Vault — Account → Privacy & data → Clear Career Vault data. Same reasoning: Career Vault is local-only, so clearing it locally is complete.
- Disconnect AI — AI preferences. Refuses every AI-assisted request for your account server-side.
- Delete an HR workspace — archive a company first (Company workspace → Archive), then Delete permanently once it’s archived. This two-step, type-the-name-to-confirm flow permanently deletes the company and every employee, document, batch, workflow, and verification record under it.
- Delete account — Account → Delete. Requires your password and a typed confirmation phrase. Permanently deletes your account and everything listed in the section above in one action — irreversible.
Retention and what "deleted" means
We try to be precise here rather than reassuring, since the two aren’t always the same thing:
- Résumé drafts, saved-résumé entries, and Career Vault data: exist only in your browser; deleting them there is complete and immediate.
- Archiving a company or HR document is a status change, not a deletion — the underlying data stays until you use the separate permanent-delete action, or delete your account.
- Revoking a shared résumé link makes it immediately inaccessible; the underlying snapshot is removed when you delete your account.
- Deleting your account is immediate and permanent for everything stored under it, with no recovery window — see the confirmation flow above before you use it.
We do not sell your résumé or HR document content as a product database, and we do not use it to train any AI model.
Policy updates and contact
We update this Privacy Policy as the product changes, and we only describe behavior the product actually has — not aspirational promises. For privacy questions, contact support@mbresumebuilder.com.