DeckdOut ("we", "us", "our") is an AI-powered web app and Chrome extension that analyses your resume against job descriptions and helps you tailor and track applications. This Privacy Policy explains what data we collect across the website, web app and extension, how we use it, and your rights.
badgeDeckdOut is operated by
[Operator legal name] (ABN
[ABN — to be inserted]), based in Australia. For any privacy question or request, contact
support@deckdout.net.
verifiedBy creating an account or using DeckdOut, you agree to the practices described in this policy.
Depending on which features you use, we collect:
emailEmail address — provided at sign-up; used for authentication and account/service emails.
personFull name — provided at sign-up; used to personalise the app and emails.
descriptionResume, job description & LinkedIn profile text — submitted or scraped for analysis. Processed in-memory only and discarded after the AI responds, unless you explicitly save a version.
layersSaved resume versions — structured snapshots of rewritten/built resumes — stored only when you click 'Save version'. Opt-in, fully deletable.
workJob applications — if you use the tracker: job title, company, listing URL, platform, status, your notes, and match score.
folderSaved documents — generated cover letters, ATS resumes, interview packs, etc. — stored only when you choose to save them.
notificationsReminders & timezone — reminder type and schedule, and your timezone, used to send follow-up/interview reminders.
tunePreferences — email preferences and product settings.
bar_chartUsage counters & history — daily feature-usage counts (to enforce plan limits) and, if you save them, analysis summaries.
dnsTechnical & diagnostic data — IP address, device/browser info, and error reports (via Sentry); plus anonymous, non-identifying telemetry/crash beacons used to keep the service reliable.
03
How Your Data Is Processed
When you run an analysis, rewrite, LinkedIn review, cover letter, or similar, the relevant text (resume, job description and/or LinkedIn profile content) is sent to our backend server, which forwards it to Anthropic's Claude AI API for processing. The AI generates your match score, missing keywords, cover letter, and other outputs, which are returned to you.
lockResume, job description and LinkedIn profile text is processed in-memory only and is not stored on our servers. Once the AI response is returned, the input text is discarded — we do not retain, log, or archive it. Generated outputs are discarded too, unless you choose to save them as a resume version or document.
Anthropic processes data under their own privacy terms. We use their API in a configuration where input data is not used to train models. We also collect anonymous, non-identifying telemetry to detect errors and measure feature reliability.
Our database (hosted on Supabase / PostgreSQL) stores:
check_circleWhat we store
Email & account profile (name, plan)
Subscription / Stripe customer ID
Daily usage counters
Saved analysis summaries (opt-in)
Saved resume versions (opt-in)
Job applications you add to the tracker
Documents you save (cover letters, etc.)
Reminders, timezone & email preferences
cancelWhat we don't store
Resume / JD / LinkedIn text (unless you save it)
Generated outputs you don’t save
Payment card numbers or CVC (Stripe only)
Raw AI request/response logs
layersSaved items are opt-in. Resume versions, documents, analysis history and tracked jobs are only stored when you explicitly choose to save or add them. You can view, edit and permanently delete any of them from your account at any time.
All payment processing is handled by Stripe. DeckdOut never sees, processes, or stores your card number, CVC, or billing details. Stripe manages all payment data under its own PCI-DSS-compliant standards.
credit_cardWe receive only the minimum needed to manage your subscription: a Stripe customer ID and subscription status.
We use a small number of cookies and similar technologies:
keyEssential — authentication/session storage (via Supabase) so you can stay logged in. These are required for the service to work and are not used for tracking.
analyticsAnalytics (Google Analytics 4) — aggregate, privacy-conscious usage measurement. Loaded only after you accept analytics in our cookie banner — Google Consent Mode v2 keeps analytics storage denied by default until you opt in. You can decline or change this at any time.
videocamProduct session insights (Microsoft Clarity) — aggregate heatmaps and session-replay of interface interactions to diagnose usability issues. Loaded only after you accept analytics in the cookie banner; Clarity masks text and form inputs by default. You can decline.
speedProduct analytics (privacy-friendly) — aggregate page/performance metrics from our hosting provider (Vercel), which are anonymous and do not use advertising cookies.
blockWe use no advertising or cross-site tracking cookies, and we never sell your data.
07
Third Parties (Sub-processors)
blockWe do not sell your personal data, and we do not share it with third parties for their own advertising. We use the providers below strictly to operate DeckdOut.
The services we rely on:
databaseSupabase
Database & authentication
smart_toyAnthropic
AI analysis (not used for training)
mailResend
Transactional & opt-in emails
cloudVercel
Website hosting & privacy-friendly analytics
dnsRailway
Backend server hosting
analyticsGoogle
Analytics & optional 'Sign in with Google'
videocamMicrosoft Clarity
Opt-in session insights & heatmaps
08
International Data Transfers
Some of the providers above process data outside Australia (for example, in the United States or the European Union). By using DeckdOut you acknowledge that your data may be processed overseas. We only use reputable providers that maintain their own security and cross-border-transfer safeguards (such as standard contractual clauses where applicable).
boltTransient text — resume / job-description / LinkedIn text is held only in memory during processing and is discarded immediately after — never persisted.
inventory_2Saved data — account profile and anything you save (versions, documents, history, tracked jobs, reminders) is kept until you delete it or close your account.
delete_foreverAccount deletion — when you delete your account, your stored personal data is permanently removed within 30 days, including from routine backups on a rolling basis.
analyticsAnalytics — aggregate analytics is retained per the analytics provider's standard retention settings and is not tied to your saved content.
You may at any time:
check_circleAccess and export a copy of your stored data (from your account, or by request)
check_circleCorrect your account details, or delete your account and all associated data
check_circleCancel your subscription at any time from your account settings
check_circleAccept or decline analytics cookies, and change that choice later
check_circleLodge a complaint with a privacy regulator — in Australia, the Office of the Australian Information Commissioner (OAIC); in the EU/UK, your local data-protection authority