Privacy Policy
Last updated 25 July 2026
We do not store résumés or job descriptions. Documents you send are processed and deleted immediately — we keep no copy, and neither we nor our model providers train on them.
What we do keep is the boring operational minimum: your account, hashed API keys, and a usage log of which endpoint was called and what it cost. Never the document contents.
This summary is for orientation only — the full text below is what governs.
Equirig, Inc. (“we”, “us”) operates Rezmatch.ai. This policy explains what we collect, why, and what you can do about it. Contact: support@rezmatch.ai.
1.Two kinds of data, two different roles
This distinction determines nearly everything else in this policy.
- Account data — information about you as our customer: your account, billing, and usage records. Here we are the controller and decide how it is handled.
- Document content — the résumés and job descriptions you submit through the API, which may contain personal data about candidates. Here you are the controller and we act solely as your processor, acting on your instructions (your API calls) and nothing else. We do not decide the purposes of that processing, do not use it for our own ends, and do not retain it.
If you are a candidate whose résumé was processed through Rezmatch.ai, we almost certainly hold no data about you — see Section 9.
2.Document content: what actually happens
When you call a parsing or matching endpoint, the document you send is held only for as long as the request takes to process:
- it is held in memory and, for uploaded files, staged in temporary object storage strictly for the duration of the call;
- the staged copy is deleted as soon as processing finishes, whether the call succeeded or failed;
- as a backstop against any deletion failure, that storage has an automatic expiry rule so nothing can persist beyond a day even if the delete does not run;
- document text is never written to our database and never written to our application logs.
To produce results, document content is transmitted to the model providers listed in Section 5. We do not use document content to train models, and our model providers are engaged under commercial terms that likewise do not permit training on API inputs.
What survives a call is a usage record containing only: a request identifier, which API key was used, which endpoint was called, how many credits it cost, and a timestamp. It contains no document text, no candidate name, and no derived candidate profile.
3.Account data we collect
| Data | Why | Retention |
|---|---|---|
| Email, name, authentication identifiers | Create and secure your account | Life of the account, then up to 30 days |
| API key hashes, labels, last-used time | Authenticate calls; let you audit and revoke keys | Until you revoke, then up to 90 days |
| Usage records (endpoint, credits, timestamp, request ID) | Meter credits, show your usage, detect abuse | Up to 24 months |
| Billing records (customer ID, plan, invoices) | Take payment; meet tax and accounting duties | As required by law, typically 7 years |
| Operational logs (IP, timestamp, status, error traces) | Security, debugging, abuse prevention | Up to 90 days |
| Support correspondence | Answer your questions | Up to 24 months |
We never see your full API keys — only SHA-256 hashes, which is why a lost key cannot be recovered. We never receive your card details; payment data goes directly to our payment processor.
4.Why we may process account data (GDPR)
- Contract — to provide the Service you signed up for: accounts, keys, metering, billing, support.
- Legitimate interests — securing the Service, preventing abuse and fraud, and improving reliability, balanced against your rights.
- Legal obligation — tax, accounting, and responding to lawful requests.
- Consent — where we ask for it, such as marketing email, which you can withdraw at any time.
For document content we process on your documented instructions as your processor; your own lawful basis governs that processing.
5.Subprocessors
We use a small number of providers. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
| Provider | Purpose | Sees document content? |
|---|---|---|
| Amazon Web Services | Hosting, compute, storage, logs (US) | Transiently, during processing |
| Anthropic | Language model for extraction and explanations | Yes, to produce results |
| Voyage AI | Embeddings for similarity scoring | Redacted feature text only |
| Clerk | Authentication and account management | No |
| Stripe | Payments, invoicing, tax | No |
| Vercel | Website and dashboard hosting | No |
We will give notice before adding a subprocessor that materially changes this picture. Email support@rezmatch.ai to be notified of changes, or to request a data processing agreement.
6.Where data is processed
Our infrastructure runs in the United States. If you or your candidates are in the European Economic Area, the United Kingdom, or Switzerland, using the Service involves transferring personal data to the US. Those transfers rely on Standard Contractual Clauses or another approved mechanism with the relevant provider. We can supply a data processing agreement incorporating the SCCs on request.
7.Security
Measures include encryption in transit and at rest, API keys stored only as hashes, credentials held in a managed secrets store rather than in code, least-privilege access controls, verified webhook signatures for billing events, and automatic expiry on the temporary storage used during processing. The single most effective control is architectural: we do not keep the sensitive data in the first place.
No system is perfectly secure. Report a suspected vulnerability to support@rezmatch.ai and we will not pursue good-faith researchers who follow responsible disclosure.
8.Your rights
Depending on where you live you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to receive it in a portable format, and to withdraw consent. California residents have rights to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising a right.
Email support@rezmatch.ai. We respond within 30 days and may need to verify your identity. You can also delete your account from the dashboard. If you are in the EEA or UK you may complain to your supervisory authority.
9.If you are a candidate
If an employer or platform used Rezmatch.ai to process your résumé, we do not hold it. It was deleted at the end of that request, and we keep no profile of you, no copy of your document, and nothing that identifies you.
That means we generally cannot locate, correct, or delete your data on request, because there is none to find — and we cannot tell you which employers processed your résumé, as we have no record linking you to them. Direct requests about how your application was evaluated to the employer or platform you applied through; they are the controller. If you contact us we will help you identify the right recipient where we can.
11.Children
The Service is for business use and is not directed to anyone under 18. We do not knowingly collect data from children. If you believe a child’s data reached us, contact us and we will delete it.
12.Changes to this policy
We may update this policy. Material changes take effect 30 days after we post them and notify your account email. The “last updated” date above always reflects the current version.