Privacy Policy
Last updated: 15 September 2026
InstaResume is operated by Tiraisoft ("we", "us"). This policy explains what personal data we collect when you use InstaResume, why we collect it, who we share it with, and the choices you have. We collect only what we need to run the service.
What we collect
- Your email address. Used for passwordless sign-in: we email you a one-time code to verify it's you. It identifies your account, your saved results, and your credit balance.
- The content you submit. The experience, skills, or draft text and the role you paste in are processed to generate your cover letter, résumé bullets, or summary. When you're signed in, each generation — your input and the produced result — is saved to your account so you can revisit it. The free tools on the site do not save your input to an account.
- Billing records. If you purchase credits or a subscription, we store your subscription status, payment records, and credit-ledger entries. Payments are handled by PayPal — we never see or store your card details.
- Basic technical data. Standard request information (such as IP address) is processed by our hosting provider to deliver the service and to protect against abuse and bots.
- Product usage measurements. We record which steps of the product are used — a page view, a free-tool run, a sign-up, a generation, a checkout — so we can see where people get stuck. This measurement is cookieless and does not follow you between visits. See the section below for exactly what it stores.
- Support chat conversations. If you use the "Ask us anything" chat, we store what you and the assistant write, together with your account id if you are signed in (or a random id kept in your browser if you are not) and the IP address the conversation came from, which we keep to investigate abuse of the chat. Each conversation is categorised — for example as a question, a bug report or a feature request — so our team can review it.
How we use it
- To authenticate you and keep you signed in.
- To generate the content you request and, if you're signed in, to store it for your later use.
- To process payments and track your credit balance.
- To secure the service — including bot protection and preventing abuse.
- To answer your support chat questions, and to find and fix the bugs and requests you report there.
We do not sell your personal data, and we do not use your submitted content to train our own models.
Who we share it with
We rely on a small number of service providers that process data on our behalf:
- A third-party large-language-model provider — generates your output. The text you submit is sent to that provider to produce your result, and the messages you send in the support chat are sent to it to answer you and to categorise the conversation.
- Cloudflare — hosting, our database, bot protection (Turnstile), and Cloudflare Web Analytics, which reports aggregate page views, referrers and country without cookies.
- PayPal, our third-party payment processor — subscriptions are paid for on PayPal's own site, so the card or account details you enter go to it and never reach us. It receives the plan you picked and an internal id that links the payment back to your account, and it sends back the subscription's status.
- An email delivery service — to send your sign-in codes.
Within Tiraisoft, when a support chat conversation is categorised as a bug report or a feature request, a short summary of it is emailed to our team's feedback inbox, which the team uses to review and follow up on it.
These providers act as processors under their own privacy terms and may store data outside your country.
How we measure product usage
This section describes what our own measurement actually stores, rather than a general statement of intent.
- No cookies, and no identifier that survives your visit. Each
visit is given a random id held in your browser's
sessionStorage. It is deleted when you close the tab, so two visits cannot be linked to each other or to you. - Signed in, we count returns against your account id and nothing else. To tell repeat use from one-off curiosity we keep a single row per account holding the first and the last day it was active — two dates, and no record of what was done on either. It uses the account id you already have with us, so it mints no new identifier and does not apply to signed-out visits. It is the one row about an individual that outlives the 30 days below, because a return after five weeks would otherwise read as a first visit. It is deleted when your account is.
- Device and system are kept as broad buckets, never as the browser's
own string. We record the kind of device (phone, tablet, desktop, or
an automated crawler) and the operating system with its major version only
—
iOS 17, neveriOS 17.4.1. The browser'sUser-Agentstring is read once to work that out and then discarded, because the full string is detailed enough to single somebody out. - Country and region come from Cloudflare, not from an address we keep. Cloudflare works the country out at its edge, so we get the answer without ever seeing or storing the address that produced it.
- Those are counted separately and never combined. We keep a daily total per device kind, and a separate daily total per country, and never a row that joins the two — so a total can never be narrowed down to “the one person on a tablet in Iceland”. It also means we cannot ask which system a particular country's visitors run, which is the trade we chose deliberately.
- We measure how long a page was visible. The clock stops whenever you switch away from the tab, so a page left open in the background is not counted as time spent reading.
- Your IP address is never stored in these measurements. To count how many distinct people used the product on a given day, we compute a one-way hash of your address together with that date and a secret unique to InstaResume, keep the first 8 bytes of it, and discard the address. Because the date is inside the hash, the result cannot be matched to any other day, and because the secret is unique to this product, it cannot be matched to any other Tiraisoft product.
- Only named steps are recorded. An event has to be on a fixed list we declare in the code — page views and the funnel steps named above. Anything else is discarded when it arrives. We do not record what you typed, and page addresses are stored without their query string.
- Referrers are reduced to the site name. If you arrive from a
search engine we store the host (for example
www.google.com) and never the search terms. - It stays in our own database. These measurements are stored in InstaResume's own database and are not sent to any analytics company. The individual rows are deleted after 30 days; what remains is a daily count per step, which cannot be traced back to a visit. The single exception is the per-account row described above, which is kept until the account is deleted.
How long we keep it
We keep your account data, saved results, and billing records for as long as your account is active. One-time sign-in codes are short-lived and expire automatically. Support chat conversations, including the IP address stored with each, are not deleted automatically: they are kept until your account is deleted, or until you ask us to delete them. When you ask us to delete your account, we remove your account data, your saved results, your support chat conversations, and the per-account measurement row described above; we may retain limited billing records where required for legal or accounting purposes. Daily totals are not adjusted — a past day's count is a number with nobody in it, and rewriting it would falsify history to remove a name it never carried.
Your choices
- You can request a copy of your data, or its correction or deletion, at any time.
- You can delete individual saved results from your workspace.
- You can ask us to close your account entirely.
Contact
For any privacy request or question, email support@tiraisoft.com. InstaResume is operated by Tiraisoft, Indonesia.
We may update this policy from time to time; the "last updated" date above reflects the current version.