Last updated: July 11, 2026
HiredByMorning ("we", "us", "the Service") is an AI-powered resume optimization and job application platform operated from India. This policy covers the website and dashboard at hiredbymorning.com, our Chrome extension (see also the dedicated Extension Privacy Policy), our in-app assistant, and our support channels.
Your resume is personal data. Resumes typically contain your name, contact details, employment history, education, skills, and sometimes photos or other identifying information. We treat the entire contents of every resume you upload or generate as personal data and protect it accordingly.
We collect and store:
We use your data solely to provide and improve the Service: scanning resumes for ATS compatibility, generating enhanced and tailored resume content, producing cover letters, tracking your applications, powering the autofill features of the Chrome extension, sending transactional emails, preventing abuse, and showing your own analytics on your dashboard. We use anonymized, aggregated data to improve our scoring and product.
We never sell your personal information or resume data, and we do not use your data for advertising.
Resume text and job descriptions are processed by the llama-3.3-70b-versatile model via the Groq API (United States) to generate ATS insights, enhanced resume content, tailored versions, and cover letters. Your content is sent to Groq only to generate a response for you. We do not train AI models on your data, and our AI pipeline is designed to preserve your real experience — it never invents numbers, achievements, employers, or dates that are not in your original resume.
We rely on the following service providers to run HiredByMorning. Each processes data only on our instructions and under its own security and privacy commitments:
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Website hosting and serverless infrastructure | United States |
| Neon | PostgreSQL database (account, resume, scan, and application data) | AWS Singapore (ap-southeast-1) |
| Cloudflare R2 | File storage (uploaded resume files, generated PDFs, profile photos) | Cloudflare global network |
| Groq | AI inference — resume text and job descriptions are processed to generate scores and enhanced content | United States |
| OAuth sign-in (name, email, profile photo) | United States | |
| Razorpay | Payment and subscription processing (customers in India) | India |
| Dodo Payments | Merchant of Record for international purchases — handles payment, sales tax/VAT, and billing outside India | Global |
| Resend | Transactional email (verification, receipts, support replies) | United States |
| Upstash | Redis caching and rate limiting | United States |
| RapidAPI job providers | Job listing search — receives only job-search queries (role, location), never your resume content | United States |
We use a session cookie containing a signed JWT (JSON Web Token) to keep you logged in — this is strictly necessary for the Service to work. We do not use advertising cookies or third-party tracking cookies. The Chrome extension stores an authentication token in your browser's local extension storage (chrome.storage.local), which is removed when you sign out or uninstall the extension.
Your database records are stored with Neon on AWS infrastructure in Singapore; uploaded files are stored encrypted in Cloudflare R2; the application runs on Vercel (United States); AI processing happens in the United States; and payments are processed in India. All data in transit is encrypted with TLS/HTTPS, passwords are hashed with bcrypt, and payment integrity is verified server-side with HMAC signatures.
We keep your data for as long as your account is active. When you delete your account, your database records — profile, resumes, scans, tailored documents, cover letters, applications, and assistant conversations — are deleted immediately, your uploaded files are removed from storage, and any active subscription is cancelled. Residual copies in encrypted backups and server logs expire within 30 days. Payment records may be retained longer where required by tax and accounting law.
You can access, correct, export, or delete your personal data at any time. You can delete your account — and with it all your data — directly from your profile settings in the dashboard; no email or approval needed. For anything else (data export, corrections, questions), email support@hiredbymorning.com or use the contact form. We respond to all requests within 30 days.
For users in India, we process your personal data under the Digital Personal Data Protection Act, 2023. By creating an account and accepting this policy you consent to the processing described here; you may withdraw consent at any time by deleting your account. You have the rights to access, correction, erasure, and grievance redressal. Our grievance contact is support@hiredbymorning.com — we acknowledge grievances promptly and resolve them within the timelines prescribed under the Act.
If you use the Service from the EEA or UK: our legal bases for processing are the performance of our contract with you (providing the Service you signed up for), your consent (given at signup and withdrawable at any time), and our legitimate interests (security, abuse prevention, service improvement). Your data is processed in the United States, Singapore, and India as described in sections 5 and 7. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority. To exercise any right, contact support@hiredbymorning.com.
The Service is intended for users aged 18 and over. We do not knowingly collect data from children. If you believe a minor has created an account, contact us and we will delete it.
Our Chrome extension reads job posting content on job sites you visit and application form fields on pages where you use its autofill — and sends only what is needed to our API to generate match scores, tailored resumes, and to fill forms with your saved profile data. It does not collect your browsing history, does not log keystrokes, and does not send data from pages unrelated to job applications. Full details are in the Extension Privacy Policy.
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice before they take effect. Your continued use of the Service after that constitutes acceptance of the updated policy.
For privacy questions or requests, email support@hiredbymorning.com or use the contact page.