Privacy Policy
Last updated 11 August 2026
Luminary AI operates BuildMyResume. This policy explains what personal information we collect, why we collect it, who we disclose it to, and how long we keep it. It is written to meet our obligations under the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).
What we collect
We collect only what the service needs to produce your report:
- Your CV. The file you upload, and the text extracted from it. A CV commonly contains your name, contact details, employment history, education, and whatever else you have chosen to put in it.
- The job description you paste in.
- Your email address. Used to sign you in, to deliver your report, and to count your free reports. You sign in with a single-use link sent to that address, or with Google — we never ask for or store a password.
- The role details you tick on the upload form, which select the analysis track.
- Technical and usage data: your IP address (for rate limiting), and non-content metrics such as report score, band, job description length, processing duration and errors.
- Payment records if you purchase premium materials — see “Payments” below.
Please do not include information you do not want analysed. If your CV contains sensitive information — health, disability, racial or ethnic origin, religious beliefs, criminal record, union membership, or visa and nationality details — it will be processed along with the rest of the document. By uploading it you consent to that processing. If you would rather it were not processed, remove it from the file first.
How we use it
- To generate the report you asked for.
- To email that report to you.
- To count and enforce your free-report allowance.
- To rate limit abuse and keep the service available.
- To understand aggregate service quality using the non-content metrics above.
We do not sell your personal information. We do not use your CV to train AI models, and we do not send your CV to employers or recruiters. Reports are produced for you alone.
Disclosure to overseas recipients (APP 8)
The text of your CV and the job description is sent outside Australia. This is essential to how the service works and you should read this section before uploading anything.
To produce your report we send your CV text and the job description to OpenRouter, Inc. (United States), which routes the request to a large language model. The model is Claude, made by Anthropic, PBC, but it is run for us by Amazon Web Services (United States) on their Bedrock service. Amazon, not Anthropic, is the party that receives and processes the text.
We require this request to be handled under a zero data retention arrangement, which means the provider does not store your CV or the job description after the response is returned. We also refuse any provider that would keep the text to train models on it. If no provider meeting those conditions is available, the analysis fails rather than falling back to one that does not.
Because these recipients are outside Australia, their handling of your information is governed by the laws of the country they operate in, which are not the same as the Privacy Act 1988 (Cth). We take reasonable steps to ensure they handle it appropriately, but we cannot guarantee that overseas recipients will comply with the Australian Privacy Principles, and you may not be able to seek redress under the Privacy Act for anything they do. By uploading a CV you consent to this cross-border disclosure.
Our other service providers, and where they sit:
- Vercel(United States) — application hosting. Compute for this app runs in Vercel’s Sydney region.
- Upstash — Redis, holds your CV text and finished report for the short retention windows described below.
- Supabase — the database holding your email address and non-content metrics. It never holds CV or job description text.
- Resend (United States) — sends your report email.
- Stripe — payment processing, if you buy premium materials.
- Sentry (United States) — error monitoring. We send it technical details of application errors (for example, a stack trace and which operation failed) so we can find and fix bugs. We configure Sentry not to collect your IP address, and request bodies, query strings and cookies are stripped before an event is sent — an uploaded CV or job description is never sent to Sentry via those. On top of that, every event is checked for fields named like personal data (an email address, phone number, token) and for values that look like an email address, wherever they appear, including nested inside other data; anything that matches is redacted before the event leaves the server or your browser.
How long we keep it
CV and job description content is never written to our database. It exists only in short-lived cache storage with an automatic expiry:
- Your uploaded CV and job description: deleted automatically about 1 hour after upload, or as soon as the analysis completes.
- Your finished report: deleted automatically about 24 hours after it is generated. After that the report link stops working. Download the PDF if you want to keep it.
- Your email address and report metrics: retained while we need them to enforce the free-report limit and to keep business records.
- Payment records: retained for as long as Australian tax and financial record-keeping law requires.
Security (APP 11)
- Report links are protected by a 256-bit random access token; the link is the credential, so treat it like a password.
- All database tables deny direct client access; only our server can read them.
- Traffic is encrypted in transit.
- CV content is never persisted to the database, which limits what a database compromise could expose.
No system is perfectly secure. If we suffer a data breach likely to cause you serious harm, we will assess and notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
Payments
Payments are processed by Stripe. We never see or store your card number — Stripe handles it directly. We keep a record that a payment was made, the amount, the currency, and the email address you gave Stripe, so that we can release what you paid for and handle refunds.
Access, correction and complaints (APP 12 and 13)
You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Email buildmyresume@luminaryai.com.au. We will respond within a reasonable period, normally 30 days. There is no charge for making a request.
Because CV content is deleted automatically within hours, a deletion request will usually concern your email address and report metrics.
To stop marketing email, use the unsubscribe link in any email we send you. Report delivery emails are transactional and are sent regardless.
If you are unhappy with how we have handled your personal information, email us first so we can try to fix it. If you are still unsatisfied you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Cookies and tracking
We do not use advertising or analytics cookies, and we do not track you across other sites. The site uses only what is technically necessary to serve pages and, during private beta, an access-gate credential your browser supplies.
The site does run Sentry’s error-monitoring script in your browser so that a crash on our end is reported to us. It does not set tracking cookies, does not build an advertising profile of you, and is configured to redact fields and values that look like personal data before anything is sent — see “Disclosure to overseas recipients” above.
Children
BuildMyResume is not intended for anyone under 16. We do not knowingly collect their personal information.
Changes to this policy
If we change this policy we will update the date at the top of this page. Material changes to how we disclose your information will be reflected here before they take effect.
Contact
Luminary AI — privacy enquiries: buildmyresume@luminaryai.com.au. Postal address: Luminary AI, Australia.
See also our Terms of Service.