Legal
Privacy Policy
Last updated
/ Contents
Who we are
Rezifi is operated by Rezifi AI LLP (LLPIN ACX-0634), a limited liability partnership registered in India with the Registrar of Companies, Haryana. In this policy, Rezifi AI LLP is the data fiduciary under India's Digital Personal Data Protection Act, 2023, and the data controller under the EU and UK GDPR.
Our Grievance Officer, as required under the DPDP Act, is Rishab Lamba (rishab@rezifi.com).
We have not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR. Rezifi is operated from India, and our processing of EU and UK personal data is occasional — we will appoint a local representative if that changes. If you are in the EU or the UK, you can exercise every right in this policy by writing to us directly, and nothing about the missing representative narrows those rights.
For anything in this policy, or to make a request about your data, write to support@rezifi.com.
What this policy covers
This policy covers the Rezifi website at rezifi.com, the Rezifi app at app.rezifi.com, the Rezifi Chrome extension, and the emails we send you about your account.
It does not cover the job boards, employers, and applicant tracking systems you apply through — and that limit matters more here than it does for most products. When you use auto-apply, you are asking us to type your information into someone else's website and, if you approve it, to press submit. From the moment that happens, the employer and their applicant tracking system hold your data, and their privacy policy applies to it, not ours. We have no ability to retrieve or delete what they hold.
The same applies to job listings you view through our extension, and to Google Drive and Google Docs when you choose to import or export a resume.
Our Terms of Service, at rezifi.com/terms, cover the rest of the relationship — what Rezifi is, what you can do with it, and who is responsible for what. The two documents are written to agree with each other.
What we collect
Account and sign-in
When you create an account we store your name, your email address, whether that address has been verified, your profile image if your sign-in provider supplies one, and internal flags describing your account type and role.
Sign-in options are the ones shown on our sign-in page. Depending on which we have enabled, these include a social provider such as Google, a magic link sent to your email, or an email address and a password. If you sign in with a social provider, we store the access and refresh tokens it issues us so we can keep you signed in and, where you have asked for it, export a resume to your Google Docs. If you set a password, we store it hashed — we never hold it in readable form and we cannot recover it for you.
For each active session we store the IP address and browser user-agent that created it. We use these to keep your account secure and to let you recognise a session you do not think is yours.
Billing
If you subscribe, we store the mobile number you give us for the payment mandate, the identifiers Cashfree assigns to your subscription and to each payment, the subscription's status, and the date and amount of each payment. We never see or store your card number or UPI details: you enter those on Cashfree's own page, and Cashfree returns the status of the mandate and of each payment.
Resumes and documents
When you upload a resume we keep the original file as raw bytes, not just the text we extract from it, because rebuilding your exact formatting on export depends on the original document. Alongside it we store the parsed structure of your resume, which typically contains your name, email address, phone number, location, and any LinkedIn, GitHub, or portfolio links you have on it.
We keep every version you save, so you can go back to an earlier one. We also store the files we generate for you — PDFs, Word documents, thumbnails — and a set of derived artefacts we compute so the product does not have to redo expensive work: resume analyses, extracted skills, job-fit scores, a written profile summary, cached grammar and rewrite suggestions, and a numerical embedding of your resume used for matching.
If you upload a PDF, the text extraction happens on our own servers. If you import from Google Drive, the file is selected in your browser through Google's own picker under a scope that only grants access to the specific file you choose.
Job search preferences and application answers
If you use the job feed, we store the preferences you set: the roles and locations you want, whether you need remote or hybrid work, a salary floor, employment types and company stages, companies and keywords to exclude, whether you need visa sponsorship, and any named filter sets you save.
If you use auto-apply, we store the details it needs to fill in forms: your preferred name and postal address, your work authorisation and whether you need visa sponsorship — recorded per country, because the answer differs by country — notice period, willingness to relocate, languages, years of experience, highest education, your current compensation and the salary you would accept, and your portfolio, LinkedIn, GitHub, Twitter and website links.
We also store, verbatim, the answers you give to job application questions, so that the next application does not ask you again: the short answers you type or approve in the extension's check step — including a date of birth, if a form asks for one — and, when you press submit, the values you typed or changed on the page after that check. We never store a password, a one-time code, a government or tax identity number, a passport number, or a card or bank detail, whatever the form calls the field. Because these are free text, they contain whatever you chose to write. We keep a snapshot of the form fields on applications you submit, for the same reason.
Demographic information
Separately from everything above, you can optionally save answers to the voluntary equal-opportunity questions that many application forms ask: gender, ethnicity, veteran status, disability status, and pronouns. Every one of these is optional and every one is blank unless you fill it in. If you answer one of these questions yourself while the extension is filling a form, that answer is saved too, so you are not asked again — you can see and delete it under Your profile at any time. A question you declined to answer is never saved.
We use them for exactly one thing: pre-filling those voluntary questions when auto-apply fills a form for you. We do not use them to rank you, to match you to jobs, or to make any decision about you or your account.
You should know one thing before you fill them in: when auto-apply runs, these answers are sent to a third-party AI provider along with the rest of the form-filling request, so that it can work out which answer belongs in which box. We treat this information as sensitive personal data, and we know that sending it to a third party is the part of this policy a reasonable person would most want to be told about. You can withdraw it at any time by clearing the fields, which deletes the stored values.
What the browser extension collects
On the job sites and hiring platforms the extension recognises — the six job portals listed in the extension section below, and the common applicant-tracking systems such as Greenhouse, Lever, Workday, and Ashby — the extension reads the job listing you are viewing — its title, company, description, and the tiles on a search results page — so we can show it to you and tailor against it. A listing captured on a site we recognise may also be added to the job feed, where other users can see it: it is the employer's public posting. We keep a record of which account captured it, for abuse control, and never show that to anyone.
On every other page you open, a very small check runs inside your browser to see whether the page looks like a job listing: it looks for the standard job-posting markup that career sites embed, or for words like "careers" or "jobs" in both the page's address and its title. Almost every page fails that check, and for those pages nothing else happens and nothing is sent. When a page passes it, the extension reads the listing so the side panel can offer to tailor your resume to it, and sends us the site's domain name — for example careers.example.com — from your signed-in session, so that we can limit abuse; we store the domain without your account, and nothing else: not the page's address, not the listing, not anything you typed. We keep the company's domain (example.com) on a list of employer career sites to add to the job feed. That list holds no personal data; it is a list of company websites.
While the side panel is open, the extension also reads the page in the tab you switch to, so it can tell you whether there is a posting there to work from. If there is not, nothing from that page is sent to us — not its address, not its domain, not its content.
When you open one of the six job portals, the extension tells us which portal it is, so we can tell you in advance whether an inline apply will work there rather than letting you start and fail. It does not read whether you are signed in there, or anything about your account on that portal.
When you use auto-apply on an application page, the extension reads that page's form — the field labels, their choices, and any values already on the page — and the text of the page, and after it fills the form, what landed in each field, so it can check its own work. It reads a form before you have asked it to fill anything in two cases: when you start tailoring while the application form is already open in that tab, so that your answers are ready by the time the plan is; and when you queue jobs from the panel, in which case it opens each application in a background tab and reads its form. Nothing is typed into a page until you start the fill or approve the queue. The value of a password field is never read.
Technical and diagnostic data
We record errors, the cost and token usage of the AI calls we make on your behalf, which jobs were shown to you and whether you clicked, saved, applied to, or hid them, which tailoring suggestions you accepted or dismissed, and the outcome of apply attempts. Some of this is linked to your account, because a report that cannot be traced back to a specific run is not much use for fixing your specific problem.
The extension also sends a diagnostic report at the end of every fill — finished, cancelled or failed — and again when you press submit, so we can work out why fills go wrong. These reports are linked to your account and include the web address of the application page, the platform, timings, the form's field labels and types, counts of what was filled and what was left blank, and the name of the resume file that was attached, which is built from your name. They do not include the values that were filled in.
How we use it
We use the information above to:
- Run your account, keep you signed in, and send you the emails your account requires — sign-in links and codes, and notices about your subscription, such as a payment that failed or a cancellation.
- Set up, charge and manage your subscription, if you take one out.
- Store, parse, render, and export your resumes while preserving their formatting.
- Tailor your resume to a job description, suggest rewrites, check grammar, and produce insights about your resume.
- Rank the job feed against your skills and preferences.
- Find employers' career sites to add to the job feed.
- Fill in application forms, and submit them when you have reviewed and approved the filled form.
- Debug problems, keep the service reliable, and control what our AI usage costs us.
- Detect and prevent abuse, and keep accounts secure.
We do not use your information for advertising, we do not build advertising profiles, and we do not sell it.
Our legal bases
Where the EU or UK GDPR applies to you, we rely on the following legal bases. Where India's DPDP Act applies, we process your personal data on the basis of the consent you give when you create an account and when you choose to use each feature.
| What we do | Legal basis |
|---|---|
| Run your account, store and edit your resumes, tailor them, and export them | Performance of our contract with you |
| Fill in and submit application forms on your instruction | Performance of our contract with you |
| Store and use your demographic answers | Your explicit consent, which you can withdraw at any time |
| Rank and personalise the job feed | Performance of our contract with you |
| Note the domain names of employer career sites the extension sees, stored without your account | Our legitimate interest in building a complete job feed |
| Debug, monitor reliability, and control AI costs | Our legitimate interest in running a working, affordable service |
| Detect and prevent abuse, and keep accounts secure | Our legitimate interest in protecting our users and our service |
| Send you account and transactional email | Performance of our contract with you |
| Set up, charge and manage your subscription, and keep the records of it | Performance of our contract with you; and, for the records, our legal obligation to keep accounts |
AI providers
This is the section most people will want, so it is near the front and written plainly.
To tailor your resume, generate insights, and fill in application forms, we send your information to third-party AI providers we work with. Tailoring sends the text of your resume and the job description. Auto-apply sends the most: your name, email address, phone number, location, your LinkedIn, GitHub and portfolio links, your work history and education — including your GPA, if it is on your resume — plus the text of the page you are applying on, any answers you have saved for reuse, and any demographic answers you have chosen to save.
We use several providers, and which one handles a given request can change as we tune the product for quality, speed, and cost. We do not publish which ones — that is commercially sensitive, and a printed list would go stale quietly. What we will do is tell you directly: if you want to know who currently receives your data, write to us and ask.
On training: we choose providers whose terms say they will not train their models on data sent through their APIs, and we have never given any provider permission to train on your data. We last checked each provider's published terms on 26 July 2026, and we repeat that check before adding a provider or changing which one handles your data. What we will not tell you is that we can independently verify what a provider does with your data once it reaches their servers, because we cannot, and no one in this market honestly can.
We do not use your data to train any model of our own.
The Rezifi browser extension
The extension requests access to all websites. We would rather explain that than bury it.
The reason is that job application forms live on domains nobody can list in advance — Workday, Greenhouse, Lever, Ashby, and thousands of company-specific career subdomains, each with its own address. Chrome has no permission for "the site the user is applying on", so an extension that fills in application forms has to ask for the broad permission or not work.
What that permission does and does not mean in practice:
- On six job sites — LinkedIn, Indeed, Naukri, Foundit, Wellfound, and Glassdoor — and on the common hiring platforms we recognise, such as Greenhouse, Lever, Workday, and Ashby, a script runs automatically when you open a job page, and reads the listing.
- On every other website you visit, only the small local check described under "What the browser extension collects" runs when a page loads. If the page does not look like a job listing, nothing else happens and nothing is sent. If it does, the extension reads the listing and sends us the site's domain name from your signed-in session, storing it without your account — nothing else about the page.
- While the side panel is open, the extension reads the page in the tab you switch to, so it can tell you whether there is a posting to work from; if there is not, nothing from that page is sent. It also reads an application form that is already open when you start tailoring, or that you have queued, so your answers are ready — nothing is typed until you start the fill.
- Beyond that, the extension acts on a page only when you start something on it yourself — a manual capture, a fill.
- Nothing from a page that is not a job posting or an application form is sent to us.
The extension stores a sign-in token in your browser's extension storage. That token is what lets the side panel talk to your Rezifi account, and it is removed when you sign out.
When auto-apply runs, it reads the application form, sends the form's structure and the page's text to an AI provider to work out which of your answers goes where, fills the form in, and attaches your resume. It then shows you every field to check, marking on the page what it left blank or is unsure about. On a form that runs over several steps, it may press the employer's own Next or Continue for you when every answer on that step came from answers you had already approved — you can pause that at any time — and it never presses Submit: submitting is always your own press.
Where your data is stored
Our API, database, and caches run in India, in Amazon Web Services' Mumbai region. Your resume files are stored on Cloudflare's network and served from it. Our AI providers may process your data in the United States or elsewhere, depending on the provider.
Your subscription mandate and payments are processed by Cashfree in India.
If you are in the European Union, the United Kingdom, or India, this means your personal data is transferred outside your country. Where the GDPR applies, we rely on standard contractual clauses approved by the European Commission, incorporated into our agreements with the service providers that store or process this data, for those transfers.
How long we keep things
We would rather show you the real schedule, including the parts we are not proud of, than write that we keep data "only as long as necessary" and leave you to guess.
| What | How long |
|---|---|
| Resumes, saved versions, and generated files | Until you delete them or delete your account. No automatic expiry. |
| Applications, saved answers, and preferences | Until you delete them or delete your account. No automatic expiry. |
| Demographic answers | Until you clear them or delete your account. |
| Sign-in sessions | Until the session expires or you sign out. |
| Cached generated documents | 30 minutes. |
| Error records | 30 days. |
| AI cost records | 60 days, then kept indefinitely as daily totals containing no personal data. |
| Uploads still being processed | 7 days after the upload finishes or fails. |
| Extension and auto-apply diagnostics | Deleted manually. There is no fixed schedule for this today. |
| Job listings collected by our crawler | 90 days for the raw page snapshots. |
| Domains of employer career sites reported by the extension | Kept indefinitely as a list of company websites. Nothing personal is stored with them. |
| Subscription and payment records | 8 years from the date of the payment — kept after account deletion where tax and accounting law requires it. |
The first three rows are the honest answer to the question most people are actually asking: we do not delete your resume on a timer. It stays until you remove it or close your account.
Your choices and your rights
What you can do yourself, right now
- Delete any individual resume. This removes the file, every saved version, and everything we derived from it.
- Delete any individual application.
- Clear your preferences, including every demographic field.
- Cancel your subscription from the billing page. Your access runs to the end of the week you have paid for.
- Download a copy of your data from the account page — every resume with its original file, your applications, saved answers, preferences and billing records, as one zip file, straight away.
- Delete your whole account from the account page. It cancels any live subscription first, then removes your resumes, applications, saved answers, preferences and account record immediately.
- Sign out, which ends that session, or sign out of every other device from the account page.
Email from us
We send only the email your account needs — sign-in links and codes, and notices about your subscription: a payment that failed or went through on a retry, a mandate that started or ended, and access that paused — and no marketing. Every one comes from an @rezifi.com address, and a subscription notice carries a reply address that reaches support@rezifi.com. There is nothing to unsubscribe from: while the account is open we cannot stop sending the notices it depends on; close the account and they stop.
Your copy, and deleting your account
Both are self-serve on the account page. A copy of your data downloads at once as one zip file: every resume with the original file you uploaded, the document as we hold it and the list of its saved versions, your applications, saved answers, preferences, the jobs you saved or hid, your free-trial usage, your signed-in devices and sign-in methods, and your subscription and payment records. It does not include rendered PDFs and thumbnails (made from the resume on demand), the document bytes of each saved version, internal document markup, the payment provider's own payloads, or the operational records described below.
Deleting your account is immediate. The page asks you to type a confirmation, cancels any live subscription first so nothing is charged afterwards, and then removes your resumes, applications, saved answers, preferences, and account record. There is no recovery window — download your copy first if you want one.
One thing we want to be straightforward about: a small amount of operational data that identifies you only by an internal account identifier — error records, AI cost records, and the technical record of each tailoring run — is not reached by that deletion today and ages out on the schedule in the previous section. We are closing that gap. Subscription and payment records are kept after deletion only where tax and accounting law requires it, for the period in the previous section.
If you cannot sign in to do either yourself, write from the email address on your account to support@rezifi.com.
and we will delete the account, or send the copy, within 30 days of confirming the request.
If you are in India
Under the Digital Personal Data Protection Act, 2023, you have the right to access a summary of the personal data we hold about you and how we process it, to have it corrected, completed, or updated, to have it erased, to nominate someone to exercise your rights if you die or become incapacitated, and to a grievance redressal process. Contact our Grievance Officer, named above, in the first instance. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
If you are in the European Union or the United Kingdom
Under the GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to how we process it, to receive it in a portable format, and to withdraw consent at any time where our processing is based on consent — including for your demographic answers. Withdrawing consent does not affect processing we carried out before you withdrew it.
You also have the right to complain to your local supervisory authority. We would appreciate the chance to put it right first, but you do not have to come to us before going to them.
If you are in California
Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect and how we use and disclose it, to request that we delete it, to request that we correct it, and not to be discriminated against for exercising any of those rights.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do collect sensitive personal information — your demographic answers, and the contents of your resume — and you have the right to limit its use. In our case the limit is already narrow: we use it only to fill in the forms you ask us to fill in, and never to infer characteristics about you.
Security
We describe here only what we actually do.
- All traffic between you and Rezifi is encrypted in transit with TLS.
- Your files and database records are encrypted at rest by our hosting and storage providers.
- If you set a password, it is stored hashed by our authentication library, never in readable form.
- Your resume files are served through short-lived signed links, so a link cannot be reused or shared to reach your documents later.
- Administrative access to our internal tools is limited to a small allowlist of named accounts.
No service can promise that a breach is impossible, and we are not going to. If one happens and it affects your personal data, we will tell you and the relevant regulators within the time limits the law sets.
Children
Rezifi is not directed at anyone under 18, and we do not knowingly collect their personal data. We word this as "not directed at" rather than "we prevent", because we do not currently verify age at sign-up and we are not going to imply a control we do not have.
If you believe someone under that age has given us their personal data, write to us at support@rezifi.com.
Changes to this policy
When we change this policy we update the date at the top of the page. If a change materially affects how we handle your personal data — a new category of information, a new purpose, or a new kind of recipient — we will tell you by email or in the app before it takes effect, and where the law requires your consent, we will ask for it rather than assume it.
Contact and complaints
For any question about this policy, or to exercise any of the rights above, write to support@rezifi.com.
If you need a postal address — for example, to serve a legal notice — write to us by email and we will provide it. Rezifi AI LLP's registered office is on public record with the Registrar of Companies, Haryana, under LLPIN ACX-0634.
If you are not satisfied with how we have handled a request, you can escalate: in India, to our Grievance Officer and then the Data Protection Board of India; in the EU or UK, to your local supervisory authority; in California, to the California Privacy Protection Agency or the Attorney General.
This policy is governed by the laws of India, and any dispute arising from it is subject to the exclusive jurisdiction of the courts at Gurugram, Haryana.