Privacy policy
Last updated: April 11, 2026
HubKit ("we," "us," or "our") operates the HubKit resume-builder platform available at hubkit.net (the "Service"). This Privacy Policy describes what personal data we collect, how we use and protect it, and what choices you have regarding your data.
1. Information we collect
1.1 Account information
When you register we collect your full name, email address, and password (hashed and never stored in plain text). If you sign in via Google OAuth we receive your Google profile name, email, and profile picture URL.
1.2 Resume and career content
You may provide detailed personal and professional information through the resume editor, including but not limited to:
- Contact details (email, phone number, location)
- Professional title, profile summary, and work experience
- Education history, skills, languages, certifications, and awards
- Projects, publications, courses, organisations, and references
- Profile photograph (uploaded image)
- Optional sensitive fields you choose to provide: date of birth, nationality, passport/ID number, marital status, military service, driving licence, gender/pronoun, disability information, visa information, and height
You control which fields you fill in. We do not require sensitive personal data; these fields exist because certain regional CV formats expect them.
1.3 Job application tracker data
If you use the career tracker feature we store company names, job titles, URLs, application statuses, interview and offer dates, salary details, notes, and other job-search metadata you enter.
1.4 Cover letters
When you generate a cover letter we store the letter text along with job details, tone preferences, and related metadata you provide.
1.5 AI interaction data
When you use AI-powered features (resume optimization, ATS checks, job-match analysis, text assistance, cover letter generation, resume translation, or PDF import) we transmit the relevant resume content and/or job description to our AI provider for processing. Chat messages and resume checkpoints created during AI sessions are stored to enable undo/redo and session history.
1.6 Uploaded files
You may upload PDF files (up to 10 MB) for resume import and profile photographs (up to 5 MB). PDFs are parsed for text content and are not stored as raw files after processing. Profile photos and resume screenshots are stored in our cloud object storage.
1.7 Payment and billing data
When you subscribe to a paid plan your payment is handled by a third-party payment processor. We store your subscription tier, status, billing period dates, and transaction history (amounts, currency, descriptions). We do not store credit card numbers or full payment instrument details—those are held by the payment processor.
1.8 Automatically collected data
- Session information: IP address, browser user-agent string, session token, and session expiry timestamp.
- AI usage metrics: prompt and completion token counts per billing period, used for enforcing plan limits.
1.9 Analytics
We use Google Analytics 4 on the public website and signed-in app to understand aggregate usage (page views and navigation patterns). When you are signed in, we may send Google Analytics an anonymous internal account identifier (not your email or name) so repeat visits from the same account are counted as one user in aggregate reports. Product actions (for example saving a resume or using AI features) are recorded as separate events and are not limited to one per visit. Google may set cookies or use similar technologies as described in Google's Privacy Policy. We do not use advertising pixels, sell your data, or rent your data.
2. How we use your information
We use personal data for the following purposes:
- Providing the Service: creating and managing your account, storing and rendering your resumes, generating PDFs, and powering AI-assisted editing and optimization features.
- Authentication and security: verifying your identity, managing sessions, enforcing rate limits, and protecting against unauthorized access.
- Email communications: sending email verification links and password reset emails. We do not send marketing emails.
- Billing: processing subscription payments, tracking usage against plan limits, and maintaining transaction records.
- AI processing: transmitting your resume content to AI models for optimization, translation, assessment, ATS compatibility checks, job-match analysis, cover letter generation, and text assistance.
- PDF export: rendering your resume in a headless browser to produce a downloadable PDF document.
- Support and troubleshooting: diagnosing errors and responding to support requests.
3. Legal basis for processing
We process your data primarily because it is necessary to provide the Service you signed up for. Where you voluntarily provide optional sensitive information (e.g., nationality or disability details in your resume), we treat your decision to enter that data as consent, which you can withdraw at any time by removing it. We also use basic security measures (such as session management and rate limiting) to protect the Service and its users.
4. Third-party service providers
To operate the Service we rely on a limited number of third-party providers. We only share the minimum data each provider needs to perform its function:
- AI processing provider: when you use AI features, relevant resume content and any job description you provide are sent to a third-party AI model for processing.
- Payment processor: when you subscribe to a paid plan, your email and subscription details are shared with our payment provider. We never store your credit card number or full payment details.
- Email delivery service: your email address is shared with our email provider solely to send account verification and password reset emails.
- OAuth provider (Google): if you choose to sign in with Google, standard profile data (name, email, profile picture) is exchanged during the OAuth flow.
- Cloud storage provider: profile photos and resume screenshot images are stored with a cloud object storage provider.
We do not sell, rent, or trade your personal data. Data is shared with the providers above solely to deliver the Service.
5. AI-powered features
HubKit uses third-party AI language and image models to power resume optimization, ATS compatibility checks, job-match analysis, text assistance, cover letter generation, resume assessment, resume translation, PDF import parsing, and AI Professional Headshots.
- When you invoke an AI feature, the relevant portions of your resume content (and, where applicable, a job description you provide) are sent to the AI model for processing.
- AI-generated outputs (suggested edits, cover letters, assessments) are presented for your review. You decide whether to accept, modify, or discard them.
- Chat session history and resume checkpoints created during AI interactions are stored for 30 days to enable undo/redo, then automatically deleted.
- AI token usage (prompt and completion counts) is tracked per user per billing period for plan limit enforcement.
5.1 AI Professional Headshots
When you use the AI Headshots feature, the photo(s) you upload are sent to our third-party AI image provider solely to generate your headshot set. These source photos are used only to create your headshots and are deleted after generation completes. They are not used to train AI models, are not sold or shared for advertising, and are not used for facial recognition or identity verification. The generated headshots remain private to your account until you delete them or your account. Because each set runs a paid AI model that incurs real compute cost, headshot packs and credits are non-refundable; see our Terms of Service for details.
6. Cookies and browser storage
6.1 Essential cookies
We use strictly necessary session cookies to authenticate you and keep you signed in. These cookies are HTTP-only and secure (in production). They expire after 7 days of inactivity. Because these cookies are essential to operate the Service, they cannot be disabled.
6.2 Local storage
We store non-sensitive UI preferences in your browser's local storage, including theme preference (light/dark/system), table sorting and pagination settings, and resume list sort order. No personal data is stored in local storage.
6.3 Analytics cookies
Google Analytics may place first-party or third-party cookies (or use similar storage) to measure site traffic. For signed-in users we also use browser session storage once per tab session to avoid counting the same signed-in presence more than once. We do not use advertising cookies or third-party ad-tracking technologies.
7. Data retention
- Account and resume data: retained for as long as your account is active. When you delete your account all associated data is permanently removed.
- AI chat sessions and checkpoints: automatically deleted 30 days after creation.
- Session records: retained for the session lifetime (7 days) and removed when the session expires.
- Billing and transaction records: retained for the duration of your subscription and a reasonable period afterward for record-keeping purposes.
- Uploaded files: profile photos and resume screenshots are stored until you replace or delete them, or until account deletion.
- Headshot source photos: the photos you upload to generate AI headshots are used only for that generation and are deleted once your set is produced. The resulting headshots are kept until you delete them or your account.
- Imported PDFs: raw PDF files are processed in memory and are not persistently stored. Only the extracted structured resume data is saved.
8. Data security
We use reasonable measures to protect your data, including password hashing, encrypted token storage, secure session cookies, and rate limiting on authentication endpoints.
That said, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights
Depending on your jurisdiction, you may have some or all of the following rights:
9.1 All users
- Access and update: you can view and edit all your resume content, personal details, and career tracker data at any time through the Service.
- Delete your account: you can permanently delete your account and all associated data from the Settings page. This action is irreversible and removes all resumes, cover letters, versions, job applications, AI chat history, and billing records.
- Change your password: you can update your password at any time. All active sessions are revoked when you reset your password.
9.2 Additional rights by jurisdiction
Depending on where you live (e.g., EEA/UK under GDPR, California under CCPA/CPRA) you may also have the right to request access to, correction of, or deletion of your personal data, to restrict or object to processing, to receive your data in a portable format, or to withdraw consent where processing is based on consent. We do not sell your personal information. You may also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at [email protected]. We will do our best to respond promptly.
10. International data transfers
Your data may be processed in countries outside your own by the third-party providers described in Section 4. We choose providers that maintain reasonable data protection practices.
11. Children's privacy
The Service is not intended for children under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we intend to delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
13. Contact us
If you have questions about this Privacy Policy or your data, you can reach us at: