Privacy Policy
Last updated: August 2026
greenlit.cv (“greenlit,” “we,” “us,” or “our”) is a resume scanning, building, and coaching service. This policy explains what information we collect, how we use it, and what choices you have.
We built greenlit to help people improve their resumes. We take the trust you place in us seriously — especially because resumes contain personal and professional information. This policy is written to be clear, not to bury things in legal language.
What We Collect
Resume content you upload. When you use our free scan, builder, or paid coaching features, you may upload a resume file (PDF, DOC, or DOCX). We extract the text content from your file to perform the analysis. We do not permanently store your original resume file or full extracted resume text after your scan is complete. Resume data is processed in memory, used to generate your results, and then discarded. A short-lived report snapshot containing scores, findings, generated coaching, and the weakest bullet may be held for up to 24 hours so you can unlock that exact report.
Email address. If you join our waitlist or create an account, we collect the email address you provide. We use this solely to communicate with you about greenlit — waitlist updates, account information, and product announcements. We do not sell, rent, or share your email address with third parties for their marketing purposes.
Purchase and credit records. If you buy a full report, we store your checkout email, payment session identifier, purchase status, and a report snapshot so you can access the paid result after checkout. If you later buy a Launch Pack, we also store credits purchased and remaining. We use these records to unlock paid features and prevent duplicate access grants.
Basic usage data. We collect standard analytics information to understand how people use the site — page views, feature usage, browser type, and general location (country/region level, not precise). This data is aggregated and not tied to your resume content.
How We Process Your Resume
When you upload a resume for scanning, here is exactly what happens:
- Your file is uploaded to our server (hosted on Vercel).
- We extract the text content from the file.
- The text is sent to a third-party AI model for analysis:
- Free tier: Google Gemini (provided by Google). Google's API terms apply to this processing. Google may process your resume text on their servers to generate the analysis.
- Paid tier: Anthropic Claude (provided by Anthropic). Anthropic's API terms apply to this processing.
- The AI model returns scores and suggestions.
- We display the results to you.
- The resume text and file are discarded from our systems. We do not retain a copy of the uploaded resume.
We do not use your resume content to train AI models. We do not share your resume content with anyone other than the AI service provider processing your scan. We do not build a database of resumes.
Third-Party Services
We use the following third-party services to operate greenlit:
- Vercel — hosting and deployment. Vercel's privacy policy applies to infrastructure-level data (server logs, IP addresses).
- Vercel Postgres — stores waitlist, purchase, and credit records.
- Stripe — processes full report and future Launch Pack payments. We do not store your card number.
- PostHog — privacy-conscious product analytics for page views and funnel events.
- Google AI (Gemini) — processes resume text for free-tier ATS scans. Google's AI API terms of service and privacy policy govern their handling of data sent through their API.
- Anthropic (Claude) — processes resume text for paid-tier coaching. Anthropic's API terms and privacy policy govern their handling of data sent through their API.
We choose AI providers whose API terms do not permit using customer input data for model training. However, we encourage you to review their terms directly if this is a concern.
Cookies
We use essential cookies for site functionality, including session management and a signed 30-day counter that enforces the anonymous scan allowance. We also use privacy-conscious analytics to measure product usage (for example, page views and scan funnel events). We do not use advertising cookies or third-party ad tracking cookies, and analytics events are not tied to your resume content.
Data Retention
- Original resume file and full text: Not retained. Processed in memory and discarded after your scan completes.
- Unpurchased report snapshots: Expire after 24 hours.
- Email addresses: Retained for as long as you remain on our waitlist or maintain an account. You can request removal at any time by contacting us.
- Purchase and credit records: Retained as needed to provide access, support refunds, and prevent duplicate credit grants.
- Usage analytics: Retained in aggregated, non-identifying form for up to 24 months.
Your Rights
Depending on where you are located, you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct inaccurate information.
- Deletion: Request that we delete your personal information (for email/account data — resume content is already not retained).
- Withdrawal of consent: If you provided consent for email communications, you can withdraw it at any time by unsubscribing or contacting us.
For EU/EEA residents (GDPR): Our legal basis for processing your email address is your consent, provided when you submit the waitlist form. Our legal basis for processing resume content is the performance of the service you requested (the scan). You have the right to lodge a complaint with your local data protection authority.
For California residents (CCPA): We do not sell your personal information. You have the right to know what personal information we collect and to request its deletion.
To exercise any of these rights, contact us at ben@sproutflow-studio.com.
Security
We use HTTPS encryption for all data transmission. Resume files are processed over encrypted API connections to our AI providers. We do not store resume content at rest. We also apply API abuse protections (including rate limits) on scan and waitlist endpoints to reduce automated misuse. Access to our infrastructure is restricted to authorized personnel.
No system is perfectly secure. If you have concerns about uploading sensitive information, we recommend removing personal contact details (phone number, home address) from your resume before uploading.
Children's Privacy
greenlit is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
Changes to This Policy
We may update this privacy policy from time to time. If we make significant changes, we will notify you by email (if we have your address) or by posting a notice on the site. The “Last updated” date at the top reflects the most recent revision.
Contact
For privacy-related questions, data requests, or concerns:
Email: ben@sproutflow-studio.com