Back to ResuLune

Privacy

Privacy Policy

How the apps keep resume content local, and how the website and update service use limited first-party analytics.

Last Updated: August 19, 2026

This Privacy Policy explains how ResuLune handles information in the desktop application, Web edition, website, downloads, and update service. The data controller is the operator and publisher of ResuLune (referred to as “ResuLune”, “we”, or “us”). Privacy questions and requests can be sent to info@resulune.com.

1. Resume content stays under your control

ResuLune processes the information you enter to create a resume, which may include your name, contact details, work and education history, skills, languages, references, and a photograph. ResuLune does not provide accounts, cloud resume storage, or a server-side resume-upload channel.

Desktop application

The desktop application stores profiles, settings, and gallery images locally in its application-data folder on your device. Imports, exports, and PDF creation are local file operations that you initiate.

Web edition

The Web edition runs the resume editor in your browser. Imports, exports, previews, and printing are handled locally and resume content is not sent to ResuLune's server.

If you explicitly use the Web edition's Save action, the current profile is stored in your browser's localStorage. It expires seven days after the last save and is removed when the Web edition next loads; you can clear it earlier from the application or your browser settings. A selected photo is session-only and is not included in this saved browser record. Interface preferences such as theme, template, and language may remain in localStorage until you clear them.

2. Information processed by ResuLune's servers

When you visit the website or Web edition, download ResuLune, or request an application update, your IP address must be processed in memory to establish the network connection, serve the request, apply abuse-rate limits, and derive the limited analytics described below.

For selected website-document, Web-edition, download, and update requests, the server stores:

  • a secret-keyed, pseudonymous HMAC-SHA256 identifier derived from the IP address;
  • an approximate country, first-level region, and city when available from a locally installed GeoLite2 database;
  • the time, request method and path, event and route type, response status, and response duration; and
  • the selected site language, platform category, or requested release filename when relevant.

The raw IP address is not written to the ResuLune analytics database. The pseudonymous identifier is not an anonymous value: it can distinguish requests derived from the same address while the secret remains unchanged. ResuLune does not store raw query strings, referrer headers, or full user-agent strings in that database.

Approximate location is inferred from the network address. It is not GPS data, a street address, or a precise statement of where a person is located. The GeoLite2 lookup occurs on ResuLune's server; the live visitor address is not sent to MaxMind for this lookup.

Ordinary nginx access logging is disabled in the supplied production configuration. Operational or security error logs may temporarily contain network information when necessary to diagnose a failure or protect the service. Those logs are restricted and retained according to the server's short operational rotation and backup cycle.

3. Why this information is used

ResuLune uses the limited server information to:

  • deliver the website, Web edition, downloads, and updates;
  • protect the service, investigate errors, and limit abusive traffic;
  • measure aggregate visits, downloads, and update activity; and
  • make aggregate decisions about platform support, language and regional priorities, releases, and infrastructure capacity.

ResuLune does not use this information for advertising, cross-site tracking, selling personal data, or making automated decisions about you that produce legal or similarly significant effects.

The legal basis for service delivery and security is the legitimate interest in providing a reliable and secure service. The legal basis for the limited first-party analytics is the legitimate interest in understanding aggregate use and planning the product while minimizing the retained information. You may object to processing based on legitimate interests by contacting us.

4. Retention

  • Server analytics events: retained for no more than 90 days. The server automatically deletes expired rows from both the current table and quarterly archive tables.
  • Aggregate statistics: may be retained longer when they no longer identify or single out a visitor.
  • Operational and security logs: retained only for the period reasonably required for troubleshooting, security, and the server's rotation and backup cycle.
  • Web saved profile: expires seven days after the last explicit save and is removed the next time the Web edition loads. Browser preference data remains until cleared by you.
  • Desktop data and exported files: remain on your device until you remove them.

5. Recipients and service providers

Access to server data is limited to the ResuLune operator and service providers needed to host, secure, back up, and maintain the service. ResuLune may also disclose information when required by law or when reasonably necessary to establish, exercise, or defend legal claims. ResuLune does not sell this information.

Third-party software components used by the applications remain subject to their own terms. The desktop update workflow communicates with ResuLune's update infrastructure. The current applications do not include advertising SDKs, third-party analytics beacons, cloud resume synchronization, or crash-reporting services.

6. Your choices and rights

You can delete desktop profiles and gallery images, clear Web-edition saved data and browser preferences, and delete exported JSON or PDF files from your device.

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal data, and to complain to your local data-protection authority. Contact info@resulune.com to exercise a right.

ResuLune has no user accounts and the analytics identifier is pseudonymous. We may be unable to connect a request to a specific person without sufficient information, and we will not collect additional identity data solely to identify an analytics record.

7. Security

ResuLune uses data minimization, a secret-keyed identifier, restricted configuration files, transport encryption, database access controls, and limited retention to reduce risk. No system can guarantee absolute security.

8. Changes to this policy

We may update this policy when ResuLune or its data practices change. The current version and its update date will be published on the ResuLune website. Materially different collection or use should be described before or when it takes effect.