reflekt.me

Privacy Policy

Last updated: August 12, 2026

reflekt.me (the "Service") is operated by KUECH-DEV LLC, a Washington limited liability company ("we", "us", "our"). We are the controller of the information described here. This policy covers the reflekt.me web app, the API behind it, and the reflekt.me website.

The most important thing to know up front: generating a resume or cover letter means sending the text of your record and the job description you supplied to a third-party AI provider for processing. Section 4 sets out exactly what that involves. You can export everything we hold, or delete all of it, from the Account page at any time.

1. What you give us

  • Account details. Your email address. If you sign in with Google or GitHub, that provider also gives us your name, profile picture, and their account identifier for you.
  • Your record. The documents you upload (PDF, DOCX, Markdown, or plain text), the text extracted from them, and any edits you make to that text; your mailing address, qualifications, achievements, and free-form notes; and your generation defaults.
  • Job material. The company, role title, and job description for each role you pursue, any instructions you add, and optionally a hiring manager's name and company address.
  • Feedback. What you write in the in-app feedback widget, plus — unless you untick the box before sending — an automatically captured screenshot of the page you were looking at, and your browser's reported app version, viewport, user agent, and current URL.

2. What we generate or record about you

  • Generated documents and their measurements. The resume and cover letter PDFs, page counts and page-fill measurements, the model's own relevance score and rationale, keyword lists, and fact-check results.
  • Generation transcripts. The full conversation with the AI model for each run, which contains your record text and the job description verbatim. We keep it to debug failures and to give a later revision the context of the run it is revising.
  • Billing records. Your credit balance and a permanent log of every movement in it — signup grant, purchase, generation charge, refund. For a purchase, Stripe tells us the checkout session identifier, the amount, the currency, and the pack size. Your card number never reaches us.
  • Sign-in and session records. A hash of each emailed sign-in code (never the code itself), a hash of each session's refresh token, and the IP address and browser user agent recorded when a session is created.
  • Job search activity. The search terms and filters you use; search suggestions generated from your record; and, if you turn a listing into a job, a stored snapshot of that listing.
  • Technical logs. Request and error logs, each tagged with a trace identifier, kept by our hosting provider on a short rolling window.
  • Website analytics. Cloudflare Web Analytics runs on the reflekt.me marketing pages only, using a cookieless page-view beacon with no persistent visitor identifier. The app itself carries no analytics, advertising, or session-recording trackers.

3. Why we use it

  • To run the Service — store your record, generate and store your documents, and show you your jobs and balance. Legal basis: performance of our contract with you.
  • To take payment and keep credit accounting correct. Legal basis: performance of our contract.
  • To sign you in and keep accounts secure — including using the IP address and user agent on a session to spot abuse. Legal basis: contract, and our legitimate interest in securing the Service.
  • To screen submitted job descriptions and other input for abusive content and prompt-injection attempts before an expensive run starts. Legal basis: legitimate interests.
  • To answer support requests and act on feedback. Legal basis: contract and legitimate interests.
  • To debug failures and improve reliability, using transcripts and logs. Legal basis: legitimate interests.
  • To meet legal, tax, and accounting obligations and respond to lawful requests. Legal basis: legal obligation.

We do not use your record, your generated documents, or your transcripts to train AI models. We do not sell your personal information, and we do not share it for cross-context behavioural advertising — under any definition of "sell" or "share" in US state privacy law, and we have not done either in the past twelve months.

4. AI processing

Generation is the point of the Service, and it is not something we can do locally. Here is exactly what happens:

  • The text of your record (the extracted or edited text of your uploads, plus your qualifications, achievements, notes, and mailing address), the job description, and your instructions are sent to a third-party AI provider. The uploaded files themselves are not sent — only the text taken from them.
  • The same provider is used for the moderation pass that screens input before a run, the drafting loop, the optional fact-check pass, and the generation of job-search suggestions from your record.
  • The provider today is Moonshot AI, whose Kimi models the Service currently runs on. The Service is built to be provider-neutral; if we change providers we will update this policy.
  • What that provider does with the content it receives, and how long it keeps it, is governed by its own terms and is not under our control.

Sensitive information. A resume or a set of career notes can contain information that counts as sensitive — health or disability details, union membership, religious or political affiliation, ethnicity, sexual orientation, or veteran status. We never ask for it, and we use whatever is in your record for one purpose only: generating the documents you asked for. Where that information is special category data under the GDPR, we process it on the basis of your explicit consent, which you give by uploading the material and asking us to generate from it, and which you can withdraw at any time by removing the material or deleting your account. If you would rather it were not processed by an AI provider at all, remove it from your record before generating.

5. Who else sees your information

We use the following providers to run the Service. They act on our instructions, and each receives only what it needs:

  • Cloudflare, Inc. (United States) — hosting for the app and API, object storage for your uploads and generated PDFs, the containers that render them, and request logging.
  • Neon, Inc. (United States) — the managed Postgres database holding your account, record text, jobs, generations, and billing ledger.
  • Moonshot AI — AI generation, moderation, and fact-checking, as described in section 4.
  • Stripe, Inc. (United States) — payment processing. Stripe receives your payment details directly and acts as its own controller for them.
  • Resend (United States) — sending sign-in codes to your email address, and notifying us when you submit feedback.
  • Google LLC and GitHub, Inc. — only if you choose to sign in with, or link, one of those accounts.
  • Adzuna, Jobicy, and USAJOBS — the job boards behind job search. They receive the search terms and filters used for a query, which may have been suggested from your record. They do not receive your record, your documents, or your identity.
  • Cloudflare Web Analytics — usage measurement on the marketing website only, in addition to Cloudflare's hosting role above.

A small, fixed list of operators can see aggregate billing and generation data — account email addresses, credit movements, token usage, and the company name attached to a job — to run the Service, support it, and investigate billing problems. That view does not include your record content or your generated documents, and no operator account gets access to another user's record or documents through the ordinary app. As the people who run the database, we can technically reach stored content, and we access it only where genuinely necessary to operate, secure, or debug the Service, or where the law requires it.

We may also disclose information where we are legally required to, where it is necessary to protect our rights or someone's safety, or as part of a merger, acquisition, or sale of assets — in which case this policy continues to apply to the information transferred until it is replaced by a policy you are given notice of.

6. Where your information goes

We operate from the United States, and the providers above process information in the United States and — in the case of our AI provider — elsewhere, including China. If you are in the EEA, the UK, or Switzerland, this means your information is transferred outside your country to jurisdictions that may not provide an equivalent level of protection, and whose authorities may be able to access it. We rely on those transfers being necessary to perform our contract with you, and on your explicit consent to the transfer, given when you accept this policy and submit content for generation (GDPR Article 49(1)(a) and (b)). If you are not comfortable with that, do not upload content for generation.

7. How long we keep it

  • Your account, record, jobs, documents, and transcripts — until you delete them or delete your account.
  • A source document you remove from your record — the stored file and its extracted text are deleted once no existing job still refers to them, so past jobs keep showing what they were actually generated from.
  • Sign-in codes — stored only as a hash; single-use, valid for ten minutes, and locked after five wrong attempts.
  • Sessions (refresh token hash, IP address, user agent) — up to 30 days, or until you sign out, which revokes the session immediately.
  • Billing ledger and purchase receipts — for the life of your account. Stripe keeps its own record of payments under its own retention rules and legal obligations, which we cannot delete.
  • Feedback submissions and screenshots — kept while we work on what they report.
  • Server logs — a short rolling window set by our hosting provider.
  • Backups — database backups may still contain deleted content for a limited period before they roll off.

8. What you can do from your account

  • Correct or update anything in your record directly, including editing the text extracted from an uploaded document.
  • Remove a document from your record at any time.
  • Export everything from the Account page — a zip containing your record, every file you uploaded, and every PDF ever generated for you.
  • Delete your account from the Account page. This is immediate and irreversible: your account, record, uploads, jobs, generated documents, transcripts, sessions, and billing ledger are deleted, and the stored files are removed. Any unused credits are forfeited. Export first if you want a copy.

You can also unlink a connected Google or GitHub account, and change your theme, from the same page.

9. Your privacy rights

Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a portable copy, restrict or object to certain processing, or withdraw a consent you previously gave. Withdrawing consent does not affect processing that already happened.

If you are in California, you also have the right to know what categories of personal information we collect, use, and disclose, and for what purpose; to delete or correct it; to limit the use of sensitive personal information; and not to be discriminated against for exercising those rights. We do not sell or share personal information and do not offer financial incentives for it. The categories we collect are identifiers, commercial information, internet or network activity, professional and employment information, the contents of documents you upload, and sensitive personal information where your own uploads contain it — each disclosed only to the service providers listed in section 5, for the business purposes in section 3. An authorized agent may act for you with written proof of authority.

The quickest way to exercise these rights is the export and delete controls on the Account page. Otherwise, email privacy@reflekt.me from the address on your account. We reply within 30 days, or sooner where the law requires it, and will tell you if we need more time. If we turn a request down, you may appeal by replying to our decision, and you can complain to your local data protection authority — in the UK, the Information Commissioner's Office.

10. Cookies and local storage

  • Sign-in cookies — a short-lived access cookie (about 15 minutes) and a refresh cookie (up to 30 days), both signed, HTTP-only, secure, and same-site. Plus a brief state cookie while a Google or GitHub sign-in is in progress. These are strictly necessary; the app cannot keep you signed in without them.
  • Your theme choice is stored in your browser's local storage and never sent to us.

Cloudflare Web Analytics, which measures traffic on the marketing website, sets no cookies and stores no persistent identifier for your browser.

We do not use advertising or cross-site tracking cookies anywhere.

11. Security

  • Everything travels over encrypted connections.
  • Sign-in codes and refresh tokens are stored only as hashes, so reading the database does not yield a usable credential.
  • Access to your record, documents, and jobs is restricted to your own account, enforced both at the API boundary and in every database query rather than in one place that could be bypassed.
  • Signing out revokes the session on the server, not just in your browser.

No service is perfectly secure, and we cannot guarantee that yours will never be compromised. If a breach affects your information, we will notify you and the relevant regulators as the law requires.

12. Children

The Service is for adults: you must be at least 18 to use it. We do not knowingly collect information from anyone younger. If you believe a child has given us information, write to privacy@reflekt.me and we will delete the account.

13. Automated processing

The Service writes documents and scores their fit automatically — that is what it is for. It does not make any decision about you that produces legal or similarly significant effects: the relevance score is advisory, it never blocks you from generating anything, and no employment decision is made here. Content screening can stop a run, and if that happens to you in error, tell us at support@reflekt.me and a person will look at it.

14. Changes to this policy

We will update this policy as the Service changes — in particular if we change AI or infrastructure providers. The "last updated" date above always reflects the current version, and for changes that materially affect your rights we will give notice by email or ask you to review the new version in the app before you continue.

15. Contact

KUECH-DEV LLC, a Washington limited liability company. Privacy questions and rights requests: privacy@reflekt.me. Support: support@reflekt.me. Legal notices: legal@reflekt.me.

← Back