Recari Privacy Policy

Effective April 28, 2026 · Last updated September 1, 2026

This Privacy Policy explains how Recari, LLC (“Recari,” “we,” “us,” or “our”) collects, uses, and shares personal information when you use the Recari website at getrecari.com, the application at app.getrecari.com, and any related services (collectively, the “Service”). Capitalized terms not defined here have the meanings given in our Terms of Service.

If you have questions or want to exercise your privacy rights, contact us at support@getrecari.com.

1. Quick summary

Plain-English version of what’s below:

  • What we do: we run an AI-powered resume analysis tool. You upload a resume, paste a job description, and get an informational analysis.
  • What we do with your resume: we extract the text and send it to our AI provider (Anthropic) to generate the analysis. We keep one active copy of that text in your private storage area so you don’t have to upload it again every time you run an analysis. It is replaced when you upload a new resume, it remains available after you sign out, and a scheduled cleanup process ordinarily deletes it about 30 days after upload. The generated analysis itself is saved to your account history (see below).
  • Copies attached to a saved analysis: the resume and job-description text used for a particular analysis are also held briefly with that saved read. A scheduled cleanup process ordinarily removes those copies from our active systems within 24–48 hours (operational delays can occasionally extend this); the analysis itself stays in your history.
  • Your history: your most recent analyses (up to 50 “reads,” including the job title/company and a star rating if you leave one) are saved to your account until you delete them or delete your account.
  • Trying Recari before signing up: you can run your first analysis from our homepage before creating an account. The result is held server-side, linked to a temporary claim token; it becomes part of your account if you sign up. Unclaimed results are scheduled for deletion 24 hours after creation and are ordinarily removed by the next daily cleanup run.
  • Your rights: you can access, correct, or delete your information by emailing us, and you can delete your account yourself from the Service.
  • Where Recari is available: the Service is currently offered only in the 50 United States and the District of Columbia, and we use IP-based location to determine availability.

What Recari doesn’t do

  • We don’t sell or “share” your personal information.
  • We don’t use your resume or job-description content to train AI models. Under our API arrangement with our AI provider, your inputs and outputs aren’t used to train its models either.
  • We don’t run third-party analytics, advertising cookies, tracking pixels, or affiliate tracking. No Google Analytics, Meta Pixel, TikTok Pixel, or LinkedIn Insight tag.
  • We don’t buy personal information from data brokers or enrich your account from outside sources.

The full policy below has the legal detail.

2. Information we collect

2.1 Information you provide

Account information. If you sign up with email and password, we collect your email address; the password is hashed and stored by our authentication provider, and we never see your plaintext password. If you sign in with Google, we receive your email address, name, and basic Google profile metadata in place of a password.

Resume content. When you upload a resume, we extract the plain text from the file and store only that text in your private storage area; the file name is kept for display in your history. The original binary file is notretained. We replace any prior resume text on re-upload. We keep this active copy so you can run further analyses without uploading your resume again — it remains available after you sign out, and a scheduled cleanup process deletes it about 30 days after upload, measured from when you uploaded it rather than from when you last used it (see the retention table in §6). You can replace it at any time by uploading a new resume, and it is deleted when you delete your account. A copy of the resume text is briefly associated with each saved read and is ordinarily removed from it within 24–48 hours.

Job description content.When you paste a job description, we use it for that analysis. The job-description text is briefly associated with the saved read and ordinarily removed from it within 24–48 hours; a short job title and company name extracted from it are kept with the read for display in your history.

Analysis output (your history). The AI-generated analysis (a structured set of sections plus category metadata and an internal analysis identifier) is saved to your account history. Your account is designed to retain your 50 most recent reads; older reads are removed automatically as new ones are added. You can rename or delete individual reads from your History at any time, and all reads are deleted with your account.

Payment information. When you subscribe, our payment processor (Stripe) collects your payment method directly. Recari never receives or stores your full card number, CVV, or full payment credentials. From Stripe we receive your subscription status, customer ID, billing email, invoice and subscription event metadata, and other billing information Stripe makes available to us for account administration.

Feedback and communications. If you rate an analysis (1–5 stars), the rating is stored with that read. If you contact us by email, we receive your message and email address.

Cancellation feedback. If you cancel a subscription, we may collect a structured reason code and an optional free-text comment.

Legal acceptance records. When you accept our Terms and Privacy Policy, we record the document versions accepted, the acceptance method, a timestamp, your account ID, and the IP address of the request. We keep these records as evidence of assent.

Trying Recari before creating an account. If you run your first analysis from our homepage before signing up, we process the uploaded resume text and pasted job description as described above and hold the resulting analysis server-side, associated with a temporary claim token (not with any account) and a keyed hash of your IP address used for abuse prevention. The claim token is also stored in your browser’s local storage so we can connect the pending result to you when you sign up. The analysis content is not shown or transmitted until an account exists. If you create an account (or sign in) and claim it, the read becomes part of your account history subject to the free-analysis eligibility rules in our Terms; otherwise the record is scheduled for deletion 24 hours after creation and is ordinarily removed by the next daily cleanup run.

2.2 Information collected automatically

Cookies and browser storage set by Recari. We use strictly necessary cookies and similar browser storage to authenticate you, keep you signed in, maintain account and session state, preserve temporary claim state for a pre-signup analysis, and protect the Service. Authentication cookies may persist so you remain signed in until you log out or the cookie expires; some operational storage is shorter-lived.

We do not set advertising cookies, analytics cookies, or third-party tracking cookies. We do not embed Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight, or any similar tracker in the Service.

Third-party cookies. When you interact with third-party services through Recari — for example, signing in with Google or completing checkout via Stripe — those providers may set their own cookies and collect information under their own privacy policies. We do not control those cookies.

Server logs. Our application creates operational and security logs — for example request identifiers, account identifiers, timestamps, event names, and error data — in connection with significant events and errors. We do not log the contents of your resume, your job description, or your AI-generated analysis.

Hosting-level logs. Our hosting and infrastructure providers may collect and retain technical request data, including IP addresses, user-agent strings, and timestamps, for their own security and operational purposes. We do not control the retention windows of those provider logs.

Rate-limiting and abuse-prevention counters. To apply rate limits, monitor for abuse, and measure Service usage, we maintain short-lived counters with our rate-limiting provider (Upstash). For signed-in usage the counters are keyed to your account identifier; for the anonymous homepage flow and free-analysis abuse prevention they are keyed to a keyed (HMAC) hash of your IP address, and the raw IP address is not stored with those counters. Counters expire automatically, typically within 24 hours. Our provider also records aggregate counter statistics for us.

Approximate region. We infer an approximate geographic region from request metadata to support security, fraud prevention, and applicable legal compliance, and to determine whether Recari is available in your region.

2.3 Information from third parties

Google (if you use Sign in with Google). We receive the data described in §2.1 from Google’s OAuth response.

Stripe. We receive subscription, customer, and billing event data described in §2.1 from Stripe’s webhooks.

We do not buy personal information from data brokers or enrich your account with information sourced from third parties.

3. How we use your information

We use the categories of information described above to:

  • Provide the Service — authenticate you, parse and analyze your resume, generate output, deliver and export results, and operate your account.
  • Process payments — through Stripe, manage subscriptions, handle renewals, and respond to billing events.
  • Communicate with you — send or facilitate transactional messages, including account confirmations, password resets, billing notifications, security alerts, and responses to support requests. Some authentication-related messages are sent through our authentication provider on our behalf.
  • Maintain the security and integrity of the Service — detect and prevent fraud and abuse, enforce rate limits, prevent duplicate use of the free analysis, defend against attacks, and investigate violations of our Terms.
  • Improve the Service — analyze usage records (for example, what role categories are commonly analyzed and which sections of output receive positive or negative feedback) to improve quality. These records contain category-level metadata and an analysis identifier rather than your name or contact details; because the same identifier exists on the corresponding read in your history, they are pseudonymous — capable of being linked back to an analysis while that read exists — rather than fully de-identified. This work uses metadata only — never your resume or job-description text.
  • Comply with legal obligations — meet tax, accounting, audit, and other legal requirements; respond to lawful requests from authorities.
  • Enforce our Terms — investigate and act on suspected violations.

Sensitive and special-category data. Your resume or job description may contain information that is considered sensitive or special-category personal data under some laws (for example, references to health, religious or trade-union affiliations, ethnic origin, or veteran status). We process this user-submitted content only to provide the analysis you request, secure the Service, and comply with our legal obligations. We do not use it to infer protected characteristics about you, build advertising or third-party profiles, or make employment decisions about you. We keep this content only for as long as needed for those purposes: the active copy of your resume is retained for a limited period so you can run further analyses without uploading it again, is deleted on the schedule described in §6, and can be replaced or removed by you at any time by uploading a new resume or deleting your account.

4. How AI processing works

The Service relies on a third-party large language model operated by Anthropic (currently the Claude family of models). When you submit an analysis:

  1. We extract the text of your resume and combine it with the job description you provide.
  2. We send that text to Anthropic’s API for inference.
  3. Anthropic returns a structured analysis, which we store on your account and display to you.

What goes to Anthropic: the extracted resume text, the job-description text, and the instructions needed to produce the analysis. We do not intentionally append your Recari account ID, email address, IP address, or payment information to the prompt. However, the content you submit may itself contain personal information — resumes commonly include your name, contact details, employment history, education, and sometimes sensitive information — and that content is sent to Anthropic in full. Submit only information you are comfortable having processed this way.

No training on your content. Recari does not use your resume or job-description content to train any model. Under Anthropic’s current commercial API terms and our settings, API inputs and outputs are not used to train Anthropic’s generative models unless a customer affirmatively opts into a training program or submits content as feedback for that purpose — which Recari does not do.

Provider retention. Under Anthropic’s standard commercial API terms, Anthropic deletes API inputs and outputs from its systems within 30 days of receipt or generation. There are exceptions: where content is flagged by Anthropic’s automated trust-and-safety systems as violating its usage policy, Anthropic may retain inputs and outputs for up to 2 years and related classification scores for up to 7 years; and Anthropic may retain content longer where required by law. This window is Anthropic’s own and applies to the content we send it for inference; it is separate from how long Recari keeps the active copy of your resume in your private storage, which is described in §6.

Output is AI-generated and may be wrong. Output is generated statistically and may contain errors, omissions, or statements that are not accurate for your specific situation. Recari is not a recruiter or career counselor, and the output is not professional advice. See the Terms for the full disclaimer.

5. How we share your information

We share your information only with the categories of recipients below.

5.1 Service providers (subprocessors)

We share information with vendors who process it on our behalf, under contract, only to provide services to us. See Section 7 for where they may process that information. The current list:

  • Vercel — hosting and operational logging.
  • Supabase — authentication, database, and file storage.
  • Anthropic — AI inference.
  • Stripe — payment processing, subscription management, and tax calculation.
  • Upstash — rate limiting and operational caching.
  • Google — OAuth sign-in.
  • Resend — transactional email delivery, including authentication messages such as password resets and signup confirmations.

We may add or change subprocessors over time. We will update this list when we make material changes.

5.2 Legal and protective disclosures

We may disclose information when we have a good-faith belief it is necessary to (a) comply with applicable law, regulation, legal process, or governmental request, (b) enforce our Terms, (c) detect, prevent, or address fraud, security, or technical issues, or (d) protect the rights, property, or safety of Recari, our users, or the public.

5.3 Business transfers

If Recari is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you (for example, by email or in-app notice) if your information becomes subject to a materially different privacy policy.

5.4 With your direction

We will share information at your direction or with your consent (for example, if you ask us to do so in support of a request).

5.5 De-identified and aggregated data

We may create and use de-identified or aggregated information that does not identify you for any lawful purpose, including improving the Service. We commit not to attempt to re-identify de-identified data.

We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising.

6. Data retention

We retain personal information only as long as necessary for the purposes described in this Policy. Specifically:

DataRetention
Account profile (email, name)Until you delete your account
Subscription recordsUntil you delete your account, then as required by law for billing, tax, and accounting purposes (Stripe also retains transaction records under its own legal obligations)
Resume text (active copy in your private storage, reused for future analyses)Deleted about 30 days after you upload it, by a scheduled daily cleanup process — measured from upload, not from last use. Replaced when you upload a new resume; deleted with your account. This copy is kept so you can run analyses without uploading again, and it is not deleted when you sign out. This window is longer than the one in the next row, which covers a separate copy.
Resume and job-description text attached to a saved read (a separate, shorter-lived copy)Removed from the read by our scheduled daily cleanup process — ordinarily within 24–48 hours of the analysis; the analysis itself is retained (next row)
Saved reads (analysis output, job title/company, resume file name, rating)Designed to retain your 50 most recent reads, kept until you delete the read or your account; older reads are removed automatically as new ones are added
Pre-signup analysis (homepage free run, unclaimed)Scheduled for deletion 24 hours after creation if not claimed by an account, and ordinarily removed by the next daily cleanup run; if claimed, it becomes a saved read (row above)
Rate-limiting counters (keyed IP hash)Expire automatically, typically within 24 hours
Server logs (operational metadata only)90 days, extended only for an active security investigation
Free-analysis fraud-prevention recordLimited information needed to prevent duplicate free-analysis claims, retained for up to 365 days after account deletion, then hard-deleted.
Account deletion audit recordA limited record (internal account identifier, hashed email and billing identifiers, and non-identifying metadata) retained for fraud and abuse prevention for 24 months after deletion, then hard-deleted
Legal acceptance recordsThe document versions you accepted, the acceptance method, timestamp, account identifier, and the IP address of the request, retained as evidence of assent and to meet subscription consent recordkeeping requirements for as long as needed to establish or defend the agreement between us — ordinarily no longer than seven years — including after your account is deleted
Inactive accountsIf an account is inactive for about 23 months we send a warning email; after about 24 months of inactivity the account and its data are deleted as described in §11. Accounts with an active paid subscription are never treated as inactive.
Cancellation feedbackPseudonymized at account deletion (the link to your user ID and the related subscription identifier are removed); the reason code and any comment you typed are deleted 24 months after collection
Usage and improvement records (pseudonymous)Category-level metadata keyed to an analysis identifier; linkable to the corresponding read while that read exists, never linked to an account identifier, and deleted 24 months from creation
Content processed by our AI providerAnthropic deletes API inputs and outputs within 30 days under its standard commercial terms; where content is flagged as violating its usage policy, up to 2 years, and classification scores up to 7 years; longer where required by law (see §4)
Stripe customer recordAt account deletion we cancel any active subscription and request deletion of your Stripe customer record; Stripe retains transaction and compliance records under its own legal obligations
Support communications24 months after your request is resolved, unless needed for a legal claim
Hosting-provider logs (Vercel, Supabase, etc.)Per each provider’s retention policy; we do not control these windows

The timelines above describe our active systems, and scheduled cleanup can occasionally be delayed by operational failures or outages. Residual copies of deleted data may also persist for a limited time in encrypted backups maintained by our infrastructure providers until those backups age out. We may retain information longer if we are required to do so by law or where reasonably needed to defend against, investigate, or pursue legal claims.

7. Data processing locations

Recari is based in the United States. We and our service providers may store and process personal information in the United States and in other countries where our service providers or their subprocessors operate.

Those countries may have data-protection laws that differ from the laws of your state or jurisdiction. We enter into written data processing agreements with our service providers that include contractual and other safeguards designed to protect personal information processed on our behalf.

8. Your privacy rights

8.1 Rights available to everyone

Regardless of where you live, you can:

  • Access and review the personal information in your account by signing in.
  • Manage your subscription, reset your password, and request account deletion from your Settings page. To change your name or email address, contact us at support@getrecari.com.
  • Delete your account from your Settings page. Account deletion is described in §11. You can also delete individual saved reads from your History at any time.
  • Cancel your subscription at any time from your Settings page.
  • Contact us at support@getrecari.com with any privacy question or request.

8.2 California residents (CCPA/CPRA)

To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to Recari, California residents may have the following rights:

  • Right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it. The categories we collect map to the disclosures in §2 above and include: identifiers, internet or other electronic network activity, commercial information, professional or employment-related information (the contents of your resume and the job descriptions you submit), and customer records.
  • Right to delete the personal information we have collected about you, subject to exceptions.
  • Right to correct inaccurate personal information.
  • Right to portability — to receive your personal information.
  • Right to limit the use of sensitive personal information — your resume may contain sensitive personal information as defined under California law. We do not use sensitive personal information for purposes that would require offering a separate right to limit, such as inferring characteristics about you. You may still request access, deletion, or correction as described above.
  • Right to opt out of sale or sharing Recari does not sell personal information and does not share personal information for cross-context behavioral advertising. Because we do not engage in those activities, this Policy does not include an opt-out mechanism; if our practices ever change, we will update this Policy and provide any notice and choices required by law.
  • Right to non-discrimination — we will not discriminate against you for exercising your rights.

You may also designate an authorized agent to make a request on your behalf; we will require verification of your identity and the agent’s authority.

California “Shine the Light” (Civil Code §1798.83): We do not share personal information with third parties for their direct-marketing purposes.

8.3 How to exercise your rights

To exercise any privacy right, email support@getrecari.com with the subject line “Privacy Request” and describe what you’d like to do. To protect your information, we will verify your identity (typically by confirming the request from the email address associated with your account; we may request additional information in some cases).

Where applicable law grants you these rights, we will respond within the period required by applicable law, generally within 45 days, subject to any extension permitted by law.

If we decline your request, you may appeal by replying to our response or by emailing us with the subject line “Privacy Appeal.” We will review the appeal and respond, generally within 45 days, and our response will tell you how to contact your state attorney general if you disagree with the outcome.

We will not discriminate or retaliate against you for exercising any of these rights.

9. Children

The Service is intended for adults; our Terms of Service require users to be at least 18. We do not knowingly collect personal information from anyone under 18. If we learn that a person under 18 has submitted personal information, we may close the associated account and will delete the information as required by law. If you believe a person under 18 has provided personal information to us, please contact support@getrecari.com and we will delete the information promptly.

10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect your information. These include encryption of data in transit, provider-managed encryption at rest, access controls that restrict privileged access to a need-to-know basis, user-level isolation so each user’s data is accessible only to that user in normal operation, rate limiting and abuse-prevention controls, identity re-verification on sensitive operations such as account deletion, and operational logging designed to exclude the contents of resumes, job descriptions, and analyses.

No security control is perfect, and we cannot guarantee that information will never be accessed without authorization. If we discover a security incident affecting your information, we will notify you and the appropriate authorities as required by law.

11. What happens when you delete your account

When you delete your account from the Settings page, we:

  • Cancel any active Stripe subscription.
  • Hard-delete your profile, your resume content, and all saved reads in your history (including the analyses, job titles/companies, file names, and ratings).
  • Hard-delete your subscription record from our database.
  • Pseudonymize your cancellation feedback (we overwrite the user-ID link and remove the related subscription identifier; the reason code and any comment text are retained).
  • Record a limited deletion audit entry to support fraud-prevention and abuse-investigation needs. It contains the internal account identifier of the deleted account, cryptographically hashed forms of your email address and billing customer ID, and non-identifying metadata (such as counts of deleted records) — not your email address, name, resume content, or analyses in readable form. It is kept for 24 months after deletion, then hard-deleted.
  • Retain your legal acceptance records as evidence of assent to the Terms and this Policy in force when you used the Service, as described in §6.
  • Retain a limited fraud-prevention record for up to 365 days after deletion to prevent duplicate free-analysis claims, then hard-delete it.
  • Delete your authentication record from our authentication provider.

If any step that removes your content fails, we do not report the deletion as complete — the request fails visibly and you can retry or contact support, rather than receiving a success message while data remains.

After deletion completes, your information is no longer recoverable by you. We also ask Stripe to delete your customer record; Stripe retains transaction records under its own legal obligations. Residual copies may persist for a limited time in encrypted provider backups until those backups age out, and our AI provider’s limited retention window is described in §4.

Support communications are not automatically deleted. Account deletion does not delete emails or other messages you previously sent to us. Those are retained as ordinary business records in our email system for the period described in §6 unless you separately request deletion (and deletion is permitted under applicable law).

If you’d like a copy of your information before you delete your account, request it by email under §8.3.

12. Changes to this Policy

We may update this Policy from time to time. If we make a material change, we will provide reasonable advance notice, by email to the address associated with your account or by in-app notice, before the change takes effect. The “Last Updated” date at the top of this Policy identifies the most recent revision. If you continue to use the Service after the effective date, the updated Policy applies to our processing of your personal information from that date forward.

13. Contact us

For privacy questions or to exercise your rights:

Email: support@getrecari.com (subject: “Privacy Request”)

Mail:
Recari, LLC — Privacy
124 W. Allegan St., Suite 1000
Lansing, MI 48933
United States