Privacy
How your data is handled.
Plainly, without marketing language: what stays on your device, what reaches our servers, what is sent to an AI provider, and what you can delete.
1. Working signed out
When you use Coral Resume without an account, document text extraction, ATS scoring, requirement extraction, and evidence matching run locally in your browser. Records you save are kept in your browser'slocalStorageand are not uploaded to our servers.
Browser storage is not encrypted. Anyone with access to your device and browser profile can read it. Clearing your browser data removes these records permanently, and we cannot recover them.
2. Signing in
Authentication is handled by Auth0. If you create an account, your identity is verified server-side and your records — resume versions, saved jobs, career evidence, applications, and Copilot conversations — are stored in Convex, our backend provider, scoped to your account and encrypted at rest by Convex.
Original resume files you upload while signed in are stored in Convex file storage so you can download them later.
Records created while signed out stay in your browser. They are never uploaded automatically when you sign in.
3. When AI is involved
Some features — the Career Copilot, AI-assisted resume parsing, and AI-reviewed analysis — send the text you submitted to a third-party AI provider for processing. Depending on configuration this may be Google Gemini, OpenAI, OpenRouter, Mistral, or a compatible gateway.
This only happens when you take an action that requests it. Uploading a document to Copilot does not send it anywhere on its own; it waits for your question. Provider API keys are held server-side and never reach your browser.
We do not use your content to train models. We cannot make that guarantee on behalf of the AI provider — their retention and training policies are their own, and you should read them if this matters to you. Deterministic analysis that does not involve a provider remains available regardless.
4. Analytics
We use Google Analytics on our public marketing pages to understand how many people visit and which pages they read. This sets cookies and shares your IP address with Google. IP anonymisation is enabled.
Analytics page views are not collected inside the private workspace at/app. Your resumes, job descriptions, and career evidence are never sent to Google.
Browser-level ad and tracker blocking prevents analytics from loading, and the product works normally without it.
5. Deleting your data
- Signed out: clear your browser data, or use the in-app controls to remove saved records.
- Signed in: deleted records are soft-deleted and removed from your workspace.
- For full account deletion, contact us via thecontact pageand we will remove your records.
6. Third parties we rely on
Auth0 for authentication, Convex for database and file storage, Cloudflare for hosting, Google Analytics for public-page measurement, and a configured AI provider for the features described in section 3. Each processes data under its own privacy policy.
7. Contact
Questions about any of the above can go through thecontact page.