ResumeForAI. Version 2026-10-08

Privacy Policy

Effective date: 12 August 2026 · Version: 1 · Previous versions: none


Read this part first

resume4.ai can make your professional profile findable and readable — by people, by search engines, and by AI systems. How far it goes is controlled by separate settings.

When you publish, your page goes live at a public web address, and by default search engines are invited to index it. That is the default state. You can change it.

Search engine indexing — on by default. We list your page in our sitemap and search engines can index it, including for searches on your name. It also governs whether AI systems are invited to read your profile in order to answer questions about you. It does not govern AI training, which we refuse on every page regardless — see below.

resume4.ai directory listing — off by default. Your page appears in our public directory at resume4.ai/discover.

Employer search — off by default, and not yet operating. This one is an advance authorisation for a feature we are building. Nothing reads it today. Section 9 explains exactly what it will and will not do, and what we will tell you before it starts.

These settings are independent. Switching off one does not affect the others. Each does only what it says.

"Not indexed" is not the same as "private." A published page is served to anyone who has its web address, whatever these settings say. Instructions to crawlers are requests, not walls. If someone shares your link, it is out there. The only genuinely private state is unpublished.

Nothing can be un-published from the rest of the internet. If you unpublish or delete your page, we remove it from our systems. We cannot remove copies that search engines, AI systems, archives, or other people have already made.

Put nothing on a published page you would not put on a public billboard. Home address, personal phone number, identity numbers, date of birth, salary, health information, and details about other people belong in the private parts of your account, or nowhere.

The rest of this policy is the detail.


1\. Who we are

This service is not yet operated by a company. It is run by an individual, and we would rather say so plainly than imply otherwise.

resume4.ai is operated by XU ZHIHAO, an individual based in Singapore. For the purposes of data protection law, that individual — not a company — is the data controller for the personal data described in this policy.

For privacy questions, requests, or complaints: privacy@resume4.ai. Postal enquiries: 118 Upper Bukit Timah Road \#17-08, Singapore.

If and when we incorporate, we will update this policy, tell every registered user before the change takes effect, and name the company here.

2\. Who this policy covers

3\. What we collect

What you give us. Your account details come from signing up: your email address, your name as Google provides it, and the identifiers Google returns so we can recognise you next time. Your résumé and its contents come from the file you upload — work history, education, skills, and anything else you chose to put in it. Your structured profile is that same material after we parse it and after you edit it. Optional depth fields are extra context you choose to add. Support correspondence is whatever you write to us.

Job advertisements you paste. When you check your page against a job, you paste the advertisement's text. We send it to a model to extract the job's requirements, and we keep the text afterwards. We keep it separately from your account: the advertisement is stored with no link back to you, and the record that you checked against it lives with your account and is deleted when your account is. Before storing an advertisement we remove email addresses and phone numbers from it — advertisements often name a recruiter, and that is a person's data rather than the employer's.

We do not open web pages. If you paste a link instead of the text, nothing is fetched, from that address or any other. This product has no crawler.

We do not store passwords, because there are none. Signing in goes through Google. We never see, set, or hold a password for your account.

We do not keep the file you uploaded. The PDF or Word document is read once, parsed into structured data, and discarded in the same request. It is never written to disk or to object storage. What we keep is the parsed profile, which you can see and edit.

What is sent to you through us. When someone uses the Contact button on your page, we receive their name, email address, and message, and pass it on to you.

What we collect automatically. When a message is sent through a published page we record a one-way hash of the sender's IP address and their browser's user-agent string, so that we can recognise a source flooding the service. We keep the hash rather than the address on purpose: it is enough to stop abuse, and it is not a location log of everyone who looked at somebody's page. We also set an essential session cookie to keep you signed in.

We do not run analytics on visitors. There is no third-party tracking script anywhere on the site, no advertising pixel, and no table recording who viewed which page. We do not collect page-view histories or referring URLs. Our own product numbers are counts of accounts, drafts, and published pages, computed from the data described above.

We do count AI systems reading your page. When a named AI assistant or AI search crawler — such as ChatGPT, Claude or Perplexity — fetches a published page from an address its operator publishes, we add one to a daily count for that page. Only the page's owner sees those counts. They describe machines, not visitors: we keep no IP address, no user-agent string and no time of day, and nothing in them says who asked an AI system about you or what was asked.

We do count shares of our research articles. When someone uses a share button on one of our research articles, we add one to a daily count for that article and that network (for example, "LinkedIn" or "copy link"). That is all we record: no IP address, no user-agent string, no time of day, and no cookie, so nothing in these counts says who shared an article or who read it. They tell us which research people find worth passing on. The share buttons are plain links to each network's own share page; we load no script from any of those networks.

Note on résumé contents. Résumés often contain more than career facts — nationality, marital status, date of birth, a photograph, referee names and phone numbers. We do not ask for any of this. If your résumé contains it, we will process it as part of your document, but we recommend removing it before uploading, and we will not display it on a published page unless you place it there yourself.

Note on other people's data. If your résumé names referees, managers, clients, or colleagues, you are giving us personal data about them. Please remove or anonymise it unless you have a proper basis for including it.

4\. What we use it for, and on what basis

Under the PDPA, and under the GDPR where it applies:

We do not sell your personal data. We do not sell or license your résumé or profile to third parties as a dataset. We do not send marketing email; if that ever changes it will be opt-in, and off until you opt in.

5\. Who else processes your data

We use a small number of service providers. They act on our instructions and are not permitted to use your data for their own purposes — with one exception, which is the AI processing described immediately below, and which is why it gets a section of its own.

About AI processing — please read this

Your résumé text is sent to Google's Gemini API so that it can be turned into structured data.

We currently use Google's unpaid service tier. Under the terms that apply to that tier:

We are stating this plainly because most services in this category do not. If you are not comfortable with your résumé being processed on these terms, please do not upload it.

What you can do:

This is separate from what happens after you publish — see section 6\.

6\. Published pages and your visibility settings

Publishing puts your page at a public web address. Separate settings then control how far it travels. Each does only what it says — switching one off does not switch the others off.

Search engine indexing — on by default

When on:

When off:

An important limit — please read this one. Switching indexing off asks search engines to stop. It does not remove a page they have already indexed, and we cannot promise it will disappear:

If you need a page out of search results promptly: unpublish it, then email us at privacy@resume4.ai. We will submit a removal request manually.

AI training — refused on every page

"Read by a machine" and "absorbed into a model" are not the same thing, and we treat them differently.

Every page we serve — yours and ours, whether indexing is on or off — carries a Content Signals declaration in its robots.txt (contentsignals.org) naming three separate purposes:

There is no setting for the last one because we do not think a résumé should be training data, and a setting would imply we thought it was a close call. It is refused whether you have found this page or not.

What this is worth, stated honestly. A signal is a declaration of permission, not a technical barrier. It is weaker than a lock and weaker than a paywall. Systems that respect the convention will see that permission for training was never given; systems that ignore it will take the content anyway, and we cannot stop them. What we can say is that consent was never given, and now it is written where an automated visitor reads it.

We do not currently issue instructions to individually named AI crawlers in addition to this. If you want that as well, tell us at privacy@resume4.ai.

resume4.ai directory listing — off by default

When on, your page appears in our public directory at resume4.ai/discover, which anyone can browse. This is separate from search engines: being in the directory does not make you indexed, and being indexed does not put you in the directory.

Employer search — off by default, and not yet operating

See section 9\. This setting is an advance authorisation, not a live feature.

True in every state

Never published, in any state

Unpublishing

You can unpublish at any time. We take the page and its machine-readable files offline immediately. Removal from our systems is immediate; removal from search indexes is subject to the limits described above; removal from third-party copies, caches, and archives is outside our control.

7\. Research use

We study, in aggregate, how résumés compare against real job requirements. We publish what we find — for example, "X% of job requirements had no supporting evidence in the résumés we examined."

What we publish is only ever aggregate. Before any analysis is published, we remove:

We publish distributions, percentages, and correlations. We do not publish profiles, excerpts, or anything from which an individual could reasonably be re-identified.

The advertisements themselves. The job advertisements people paste form the other half of that comparison — without them there is no "job requirements" to compare résumés against. They are held with no link to any account, which is why they are not personal data about you and why the setting below does not govern them. What that setting governs is your side of the comparison: your profile, and the record of which jobs you checked against.

We never reproduce an advertisement's text. The same promise we make about your writing applies to the employer's: what we publish is distributions and percentages, never the wording of a posting.

Your control. There is a setting in your account — Allow my profile to be used in aggregate research. It is on by default. You can change it at any time, and switching it off removes you from all future analyses.

An honest limit. Aggregate findings that have already been published cannot be recalled — a percentage in a published report cannot be un-computed. Switching the setting off stops future use; it does not retract past publications. If you want your data excluded from a specific study before it is published, email us and we will remove it.

Separate consent for anything identifiable. If we ever want to publish something about a specific profile — a case study, a before-and-after, a named example — we will ask you directly and get your explicit agreement first. A setting in your account is not enough for that, and we will not treat it as such.

8\. Contact messages

When someone writes to you through your page, we receive their name, email address, and message, and forward it to your account.

9\. Employer and API access

Nothing described in this section is operating yet. We are writing it now, and asking for the setting now, because we would rather you decide with the whole picture in front of you than be asked for a quick yes on the day we switch it on.

We intend to offer employer features, including search over published profiles and API access to published profile data. When we build them:

Before it starts operating, we will email everyone who has the setting switched on, describe what is going live, and give you the chance to switch it off first. If what we build differs from what is described here in any way that matters, we will ask again rather than rely on this.

What exists today is narrower: we issue keys to employers so that automated senders can use the Contact relay on a published page under a rate limit. That is a way of sending you a message. It does not read, search, or return your profile.

This setting is independent of search engine indexing. Switching employer search off will not remove you from Google, and switching search engine indexing off will not remove you from employer search.

10\. How long we keep things

We do not currently charge for anything, so there are no billing records. If that changes, we will keep them for as long as tax and company law requires and will say so here.

11\. Where your data is held

Your account details, profile, and published page are stored in Singapore. The application runs on Fly.io in the Singapore region; the database runs on Neon, on AWS infrastructure in the AWS Singapore region.

Some processing happens elsewhere:

Where personal data is transferred out of Singapore, we take steps to ensure a comparable standard of protection as required under the PDPA.

If you are in the EEA, Switzerland, or the UK: we are established in Singapore, and the AI processing described in section 5 takes place under Google's unpaid-tier terms. Please read section 5 before uploading, and consider whether you are comfortable with it. You retain your rights under section 12, including the right to erasure and the right to complain to your local supervisory authority.

12\. Your rights

Whatever your location, you can:

If you are in the EEA or UK, you additionally have the rights to restrict processing, to data portability, to object to processing based on legitimate interests, and to lodge a complaint with your local supervisory authority.

If you are in Singapore, you have rights of access and correction under the PDPA, and may withdraw consent. You may also complain to the Personal Data Protection Commission.

To exercise any of these: privacy@resume4.ai. We aim to respond within 30 days. We do not charge for reasonable requests.

13\. Security

Traffic is encrypted in transit. Access to the production systems is limited to the operator. Every change runs through an automated test suite before it can be deployed. Error reports are configured to exclude request bodies and local variables, so a crash report does not carry your profile with it.

There are no passwords to protect, because there are none — signing in goes through Google, and your session is held in a signed cookie.

We are a small operation. We do not hold a formal security certification. We tell you this plainly rather than implying more than we have. No system is completely secure. If a breach affects your data, we will notify you and the relevant authority as required by law.

14\. Children

resume4.ai is not for anyone under 16\. We do not knowingly collect data from anyone under 16\. If we discover that we have, we will delete it. If you believe a child has an account, contact us.

15\. Changes to this policy

We will post any new version here with a new effective date, and keep the previous versions available.

For material changes — anything that expands how we use your data — we will email you at least 30 days before it takes effect, and describe the change in plain language rather than only pointing at the new document.

16\. Contact

privacy@resume4.ai

XU ZHIHAO, operating resume4.ai as an individual 118 Upper Bukit Timah Road \#17-08, Singapore

We have not appointed a Data Protection Officer. At our current size we are not required to, and we would rather not name a role that nobody actually holds. Privacy requests go to the address above and are handled by the operator personally.