Privacy Policy

How GetShortifyAI.com collects and protects your data.

Data Controller

The data controller responsible for your personal information is:

EntityGetShortifyAI.com
AddressAhmedabad, Gujarat, India
Privacy Contactprivacy@getshortifyai.com
Grievance Officergrievance@getshortifyai.com
JurisdictionIndia

We respond to all data requests within 30 days as required by the DPDP Act, 2026.

What We Collect

We collect only what is necessary to provide the service, across three categories:

1 · Resume & Job Data

  • Resume file content (text extracted from PDF or DOCX — the raw file is never permanently stored)
  • Job description text you paste for keyword matching
  • ATS scores, keyword gap reports, and AI suggestions produced during your session

2 · Account Information

  • Email address (used for login, receipts, and policy update notifications)
  • Name (optional, used for personalisation)
  • Authentication tokens (managed securely via Supabase Auth)

3 · Usage & Technical Data

  • IP address and approximate location (city-level only)
  • Browser type, device type, and operating system
  • Pages visited, features used, and session duration
  • Error logs captured by Sentry (anonymised where possible)

We never collect your Aadhaar, PAN, bank details, or any government-issued ID. Payment card data is handled exclusively by Razorpay and never touches our servers.

Why We Collect It

We process your data only for the following lawful purposes under the DPDP Act, 2023:

Resume AnalysisTo generate your ATS score, keyword gap report, and AI-powered rewrite suggestions.
Account ManagementTo authenticate your session, store scan history, and manage your subscription.
Payment ProcessingTo process payments via Razorpay and issue digital receipts.
Product ImprovementTo identify bugs and improve accuracy using anonymised, aggregated data only.
Legal ComplianceTo comply with Indian laws, court orders, or requests from competent authorities.
CommunicationsTransactional emails only (receipts, policy updates). No marketing without explicit opt-in.

We do not sell your data, profile you for unrelated purposes, or share it with recruiters or job boards.

Data Retention

We retain your data only as long as necessary to provide the service or meet legal obligations:

Raw Resume FileDeleted immediately after text extraction. We never store your PDF or DOCX.
Extracted Resume TextRetained for 90 days for score history and re-analysis. Auto-deleted after.
ATS Score ReportsRetained for the lifetime of your account, plus 30 days after deletion.
Account DataRetained while active. Deleted within 30 days of a verified deletion request.
Payment RecordsRetained for 7 years under the Income Tax Act, 1961 and GST regulations.
Error Logs (Sentry)Automatically purged after 30 days.
Usage & AnalyticsAnonymised and aggregated after 6 months. No individual data retained beyond this.

You may request early deletion of any data except payment records via the Your Rights section below.

Third Party Services

GO
Google Gemini
AI resume analysis (Gemini models)
View privacy policy →
AN
Anthropic
AI resume analysis (Claude models)
View privacy policy →
SU
Supabase
Database and authentication hosting
View privacy policy →
RA
Razorpay
Payment processing (PCI-DSS compliant)
View privacy policy →
SE
Sentry
Error monitoring (anonymised stack traces only)
View privacy policy →

Your Rights

You have the right to access, correct, or delete your personal data. Below are options to directly manage your information through our grievance and privacy team.

Cookies & Analytics

We use a minimal set of cookies strictly necessary for the service. We do not use advertising or cross-site tracking cookies.

auth-tokenStrictly necessary. Keeps you logged in securely. Expires with your session. Cannot be disabled.
themeFunctional. Remembers your light/dark mode preference. Expires after 1 year.
scan-sessionStrictly necessary. Tracks your current analysis session. Cleared when browser closes.

We do not use Google Analytics, Facebook Pixel, or any third-party tracking scripts. Any future analytics additions will be privacy-first and disclosed here before deployment.

Policy Changes

We may update this Privacy Policy to reflect changes in our practices or legal obligations. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send an email notification to all registered users at least 14 days before changes take effect
  • Display a notice on the platform dashboard for 30 days after the update

Continued use of the service after the effective date constitutes acceptance of the revised policy. If you disagree, you may delete your account before the changes take effect.