This policy explains what Tailored (“Tailored”, “we”, “us”) collects when you use our product at https://tailoredapply.com, why we collect it, who we share it with, and the rights you have over it. We've tried to keep it readable. If anything here is unclear, please email gor.mikaelyan.eworld@gmail.com.
1. The short version
- We don't sell your data. Ever. To anyone.
- Your resume content stays yours.We process it to make the product work; we don't train any model on it.
- We use sub-processors(hosting, payments, analytics, AI) — they're listed below in plain English.
- You can delete your account and all your data at any time from the dashboard.
2. What we collect
Account information
When you sign in with Google we receive your email address, display name, and profile image from Google. We don't see or store your Google password.
Content you create
Resumes you upload or generate, job descriptions you paste, cover letters, application notes, and your profile photo (if you upload one). We store this so you can access it across sessions and so our AI features can work. We do not train AI models on this content.
Usage analytics
We capture product usage events (page views, button clicks, AI generation counts) via PostHog. These events carry no resume or job-description text — only counts, durations, file types, and anonymous identifiers.
Only if you say yes. PostHog is not loaded at all until you accept on the banner — not loaded and held back, but never started: no script, no request, no identifier. Declining is a complete answer and nothing else about the product changes. If Do Not Track is set in your browser we treat that as a no and never ask.
Page-view counts and loading-speed measurements from Vercel run without asking, because they set no cookie, create no identifier you carry between sites, and record no individual — only totals.
The help assistant
When you ask the in-product assistant a question, we store the question — on its own. Not your name, not your account, not your IP, not the answer, and not the rest of the conversation. It is kept for 30 days and then deleted. We do it so we can see which parts of the product people cannot work out, and it is stored with nothing attached so that it cannot later be connected to you.
The assistant is not given your account or your CV, so it cannot discuss them even if asked.
Billing data
When you buy credits or subscribe to Pro, Stripe processes your card. We never see or store your card number, CVC, or expiry — Stripe handles all of that on PCI-compliant infrastructure. We store a Stripe customer ID and your subscription state (tier, renewal date, cancellation flag).
Technical data
Standard server logs (IP address, user agent, request timestamps) for security and abuse prevention. Logs are retained for 30 days.
3. How we use it
- To provide the product — render your resumes, run AI tailoring, deliver PDF and DOCX downloads, track applications on your Kanban board.
- To process payments — manage your subscription, charge credits, issue refunds.
- To improve the product — aggregated analytics tell us which features work and which fall flat. No individually-identifying analysis is performed.
- To send transactional emails— receipts, payment failures, security notices, subscription expiry reminders. We don't send marketing email without explicit opt-in.
- To meet legal obligations — tax records, dispute response, abuse investigations.
4. Sub-processors
We rely on these services to run the product:
- Google — authentication (OAuth). Receives: sign-in attempts.
- Vercel — application hosting + edge network. Receives: all traffic.
- Neon — managed PostgreSQL. Stores: your account, resumes, applications, version history, Kanban cards, Pro subscription state.
- Stripe — payments + subscription billing. Receives: name, email, card details (which we never see), billing address.
- Resend — sending email (account notices, confirmation that credits arrived, and one message if your free credits run out). Receives: your email address and the contents of that message. Never your CV, and there is no tracking pixel — we do not record whether you opened anything. Every non-essential message carries a one-click unsubscribe.
- Google Gemini API — AI generation, scoring, and tailoring. Receives: the resume + job description for the specific request. Google processes this under their Gemini API terms and does not use API inputs to train their consumer models.
- PostHog — product analytics. Receives: anonymous event names, durations, counts, status codes. Never receives resume content.
- Upstash — rate-limit tracking. Receives: hashed user identifier + request route only.
5. Retention
We keep your account data while your account is active. When you delete your account, we delete your resumes, applications, version history, notes, and uploaded photos within 30 days. Stripe transaction records and tax documents are retained for seven years under applicable tax law. Server logs are retained for 30 days.
6. Your rights
Regardless of where you live, you can:
- Access — view and download all your stored data from the dashboard.
- Correct — edit your resumes, applications, and account details at any time.
- Delete — delete your account and all associated data from the dashboard.
- Export — download your CVs as PDF or DOCX; export application notes from the Kanban board.
If you are in the European Economic Area, UK, or Switzerland you also have rights under the GDPR including the right to object to processing, the right to portability, and the right to lodge a complaint with your supervisory authority. Our lawful basis for processing is contract performance (running the product you signed up for) and legitimate interest (security, abuse prevention).
If you are in Californiayou have rights under CCPA/CPRA including the right to know what we collect, the right to delete, the right to opt out of “sale” or “sharing” of personal information (which we do not do), and the right to non-discrimination for exercising these rights.
To exercise any right, email gor.mikaelyan.eworld@gmail.com. We'll respond within 30 days.
7. Cookies and local storage
We use a small number of cookies and a localStorage entry:
- Authentication session cookie — required to keep you signed in. Set by NextAuth.
- PostHog analytics cookie — anonymous device identifier. Disabled when
Do Not Trackis set. - Guest draft (localStorage) — stores your generated resume in your browser when you use the product without signing in. Never leaves your device unless you sign in and claim the draft.
8. International transfers
Our infrastructure runs in the United States. If you use the product from outside the US, your data is transferred to and processed in the US. We rely on Standard Contractual Clauses for EU/EEA transfers where applicable.
9. Children
The product is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
10. Security
All traffic is encrypted in transit (TLS 1.2+). Data is encrypted at rest in our database. We use industry-standard access controls. No system is perfectly secure — if we ever experience a breach affecting your data, we will notify you without undue delay.
11. Changes to this policy
We'll update this page when we change how we handle data. Material changes will be announced by email (for account holders) at least 30 days before they take effect. The “Last updated” date at the top always reflects the current version.
12. Contact
For any privacy question, email gor.mikaelyan.eworld@gmail.com. For billing-specific questions, our Refund Policy may answer faster.