Resume & CV Builder ("the app", "we", "us") is developed and published by QubitSofTech, a software development company based in India. The app is distributed worldwide through Google Play, and this policy applies to every user of the app wherever they live.
For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for the (very limited) processing described here. Google acts as an independent controller for the advertising data it collects through its own SDK — see section 5.1.
This policy is written to be accurate about this specific app, not a generic template. The same policy is shown, word for word, inside the app under Settings → Privacy Policy. If you disagree with anything here, please stop using the app and uninstall it.
Your resumes, CVs and cover letters stay on your device. Writing, editing, templates, previews, ATS guidance, job matching, importing, text recognition and exporting all run on your phone. There is no account, no sign-in and no server of ours, and nothing you write is sent to us.
The app connects to the internet for advertising (Google AdMob), for Premium purchases (Google Play), and — only if you switch it on yourself — for an optional cloud AI provider that you choose. None of these ever sends your documents to us.
Where the law requires it — in the European Economic Area, the United Kingdom, Switzerland and regulated US states — the app asks for your advertising consent before any ad is requested, and lets you change your mind at any time.
We collect nothing on servers of our own. The app has no sign-up, no login, no user profile, and no analytics or crash-reporting SDK of any kind. We do not operate a server that receives your data, and we have no way to see what you write or what you do with it.
Specifically, we do not collect, transmit to ourselves or store on any server:
Everything you create in the app — resumes, CVs, cover letters, saved versions, your Master Profile, the job application tracker and any photo you add — is stored only in the app's private storage on your device. The app reads and changes it only to show it to you and to make the changes you ask for.
Your content leaves the app only when you ask it to:
The following is written to the app's private storage on your device and stays there:
| What | Where it is stored | Why |
|---|---|---|
| Your documents, saved versions, Master Profile, cover letters and job applications | The app's private database | To provide the app's features |
| Photos you add to a document or your Master Profile | The app's private files directory | To show them in your document |
| Your settings — theme, page size, on-device AI and cloud AI choices, cloud AI endpoint and model | Local key-value storage | To remember how you like the app configured |
| Your points balance, remaining rewarded-ad slots and editing time | Local key-value storage | So points you earned are not lost when the app restarts |
| Your Premium status and when it was last confirmed by Google Play | Local key-value storage | So Premium keeps working for a short time without a connection |
| A cloud AI API key, only if you enter one | Encrypted storage protected by the Android Keystore | So you do not have to enter it every time. It is never included in backups |
| Your advertising consent choice, where one was asked for | Stored by Google's User Messaging Platform SDK on your device | So the question is not asked again on every launch |
| Temporary copies of files you export or share | The app's private cache directory | So the receiving app can read them. Cleared by the system, or when the app's cache is cleared |
Android's automatic cloud backup and device-to-device transfer are switched off for this app, so none of the data above is copied to your Google account by Android. Everything above is removed when you uninstall the app or clear its data.
The free version of the app is funded by advertising served by Google AdMob using the Google Mobile Ads SDK. Premium users see no ads. Ads appear in these forms:
To request, serve, measure and (where permitted) personalise ads, Google's SDK may collect and process information such as your device's advertising identifier, IP address, device and operating-system characteristics, approximate location derived from IP, and ad interaction data. This processing is carried out by Google as an independent third-party controller — the data goes to Google, not to us. We never receive your identifiers, and we receive only anonymous, aggregate revenue reporting from AdMob. The advertising SDK has no access to your documents.
Google's handling of this data is governed by:
Where your local law requires consent for advertising — currently the EEA, the UK, Switzerland and regulated US states — the app shows you Google's consent form before any ad is requested, using Google's User Messaging Platform. Until you have made a choice, no ad request is sent. Declining does not restrict any feature.
You can change or withdraw your choice at any time from Settings → Ad privacy choices. That entry appears in the app wherever a consent choice applies to you. Withdrawing consent takes effect immediately.
Device-level controls, available to everyone: you can reset or delete your advertising ID, or opt out of ad personalisation, in Android Settings → Privacy → Ads (the exact path varies by manufacturer and Android version). You can also review your ad settings at myadcenter.google.com. Opting out does not remove ads; it makes them non-personalised. Premium removes ads entirely.
Premium subscriptions are sold and processed by Google Play. We receive only the information needed to unlock Premium — the purchase status and its signed confirmation from Google Play, which the app checks on your device. We never see your name, email address or payment details. Google's privacy policy applies to payment processing. You can manage or cancel your subscription from Settings → Manage Google Play subscription.
ATS guidance, the Job Matcher, importing and reading resumes, the built-in writing tools and cover-letter drafts all run on your device, without sending your text anywhere.
Text recognition (OCR) — reading the text from a photo of a resume — uses a recognition model that ships inside the app (Google ML Kit's bundled model). The image is never sent anywhere.
On-device AI, where your phone supports it, uses Android's AICore system service (Gemini Nano) through Google's ML Kit GenAI APIs. Your text is processed on your phone and is not sent to Google or to us. If you tap Download on-device model, the model is downloaded and kept up to date by Android's AICore service, not by us.
Google's ML Kit may send Google limited technical information about how its features perform — such as device model, operating-system version, app package name and version, which feature was used, error codes and timings — to maintain and improve ML Kit. It never includes your text, images or documents. See ML Kit's data disclosure.
Cloud AI is off by default. If you switch it on, the app first asks for your consent, and then lets you configure any OpenAI-compatible provider you choose, with your own API key. Only after that, when you ask the writing assistant to improve a piece of text, that text (not your whole document unless you select it), the model name you entered and your API key are sent directly from your device to the provider's address you entered, over an encrypted HTTPS connection. The app accepts only https:// addresses.
We never receive any of this — it goes straight from your phone to your provider. The provider's own terms and privacy policy apply, including how long it keeps your text. Your API key is stored encrypted on your device only. You can switch cloud AI off at any time in Settings, and remove the saved key with Settings → Cloud AI provider → Remove saved key.
Reading, previewing and exporting your documents work offline. Creating, editing and importing documents need an internet connection. To know whether you are online, the app asks Android for the phone's network status; it does not send a request to us or to any other server for this.
If you are in the EEA or the UK, the GDPR requires us to tell you the legal basis for each processing activity:
| Processing | Legal basis |
|---|---|
| Storing your documents, settings and points on your own device | Not our processing — the data never reaches us. Storage on your device is necessary to provide the service you requested (Art. 6(1)(b)) |
| Personalised advertising, and storing/accessing information on your device for advertising | Your consent (Art. 6(1)(a)), collected through the form described in section 5.2 and withdrawable at any time |
| Non-personalised advertising, where you decline consent | Google's own legal basis as controller; we rely on our legitimate interest in funding a free app (Art. 6(1)(f)) |
| Processing a Premium purchase | Performance of a contract (Art. 6(1)(b)); Google Play processes the payment as an independent controller |
| Sending text to a cloud AI provider you configured | Your consent (Art. 6(1)(a)), given when you switch cloud AI on, and withdrawable by switching it off |
| Replying to a support email you send us | Performance of a request you initiated, and our legitimate interest in supporting our users (Art. 6(1)(b)/(f)) |
Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
Your documents and everything else the app stores stay on your device, wherever you are, and are never transferred anywhere by us.
Advertising and purchase data collected by Google may be processed on servers outside your country, including in the United States. Those transfers are made by Google under its own safeguards — including the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Details are in the Google Privacy Policy and Google Ads Data Processing Terms. If you use cloud AI, where your text is processed depends on the provider you chose.
Because we hold no personal data about you, most rights below have an unusual answer when directed at us: there is nothing for us to produce, correct or erase. We say so plainly rather than pretending to a process we do not have. For advertising and purchase data, the holder is Google, and for cloud AI it is the provider you chose — we will help you get to the right place.
You have the right to: access your data; have it rectified; have it erased; restrict or object to its processing; data portability; and to withdraw consent at any time (Settings → Ad privacy choices, or switching cloud AI off). You also have the right to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office; in the EEA, your country's data protection authority, listed by the European Data Protection Board.
We do not carry out automated decision-making or profiling. ATS guidance and job-match scores are calculated on your device for your own information only and are never shared with anyone.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We receive none to sell.
However, when personalised ads are enabled, Google's collection and use of your advertising identifier may constitute a "sale" or "share" under the CCPA/CPRA and similar state laws. You can opt out in the app via Settings → Ad privacy choices, where that entry is shown to you, and on your device via Android Settings → Privacy → Ads → Delete advertising ID, which applies across all apps.
Subject to those laws you may also have the right to know what personal information is collected, to delete it, to correct it, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights. We do not knowingly sell or share the personal information of anyone under 16.
Categories under the CCPA: the app itself collects no categories of personal information. Google's SDK may collect identifiers (advertising ID), internet or network activity (ad interactions), and coarse geolocation derived from IP address, for the business purpose of advertising.
As a Data Principal you may seek access to, correction of, and erasure of personal data processed by a Data Fiduciary, nominate another person to exercise your rights, and raise a grievance. We process no personal data about you, so we hold nothing to disclose, correct or erase. You may contact us at the address in section 13 with any grievance, and we will respond within the period the Act requires.
Users in Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), South Korea, Japan, South Africa (POPIA) and elsewhere have broadly comparable rights of access, correction, deletion and complaint. The answer is the same: we hold nothing about you. Contact us and we will confirm that in writing and point you to Google, or to your cloud AI provider, where relevant.
Email admin@qubitsoftech.com from any address, telling us what you want. We do not require you to create an account or verify an identity we never recorded. We will respond within 30 days, or sooner where the law requires. Exercising your rights is always free.
The app asks for no runtime permissions — nothing produces a permission prompt. It reads a file only when you pick it in the system file dialog, and a photo only when you pick it in the system photo picker. It does not use the camera. Every permission the installed app declares is listed below, including those added automatically by Google's SDKs, so that this list matches what you can inspect on your device.
Requested by the app itself:
INTERNET — for advertising, Premium purchases, the on-device AI model download and, only if you switch it on, cloud AI.ACCESS_NETWORK_STATE — to know whether you are online (section 5.6), and used by the advertising SDK before requesting an ad.com.android.vending.BILLING — to offer Premium through Google Play.Added automatically by Google's SDKs, and used by Google, not by us:
com.google.android.gms.permission.AD_ID — allows access to your device's advertising ID. Deleting your advertising ID in Android settings stops it being usable.ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, ACCESS_ADSERVICES_TOPICS — Android Privacy Sandbox APIs, used by Google's advertising SDK for privacy-preserving ad measurement and topic selection.com.google.android.apps.aicore.service.BIND_SERVICE — lets ML Kit connect to Android's AICore system service for on-device AI (section 5.4).WAKE_LOCK, FOREGROUND_SERVICE — used internally by Google Play services components bundled with the SDKs.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION — an app-private permission Android generates so internal broadcast receivers are not exposed to other apps. It grants no access to anything of yours.The app requests no access to all your storage, camera, microphone, location, contacts, calendar, SMS, phone, body sensors or any other sensitive permission, and none of the permissions above lets us read anything from your device.
The app is a general-purpose productivity tool intended for a general audience aged 13 and over. It is not directed to children, and we do not knowingly collect personal information from children — we do not knowingly collect information from anyone, at any age.
In the EEA and UK, the age of consent for online services is between 13 and 16 depending on the country. If you are below that age where you live, a parent or guardian must make any advertising consent choice for you. If you are a parent or guardian and believe a child has provided personal information to us (for example, by emailing us), contact us at the address in section 13 and we will delete it.
Because nothing is stored on our servers, you are in complete control:
There is no account to delete, because there is no account. We hold nothing to erase on your behalf. To ask Google to delete advertising data, use myadcenter.google.com; for cloud AI, contact the provider you chose.
Data stored on your device is kept until you delete it, clear the app's data, or uninstall the app. We retain nothing, because we receive nothing. Data processed by Google is retained according to Google's own retention policies, and data sent to a cloud AI provider according to that provider's policies.
Your documents stay in Android's private per-app storage, protected by the operating system's app sandbox and by your device's own lock screen and encryption. A cloud AI key is additionally encrypted with a key held in the Android Keystore. All network traffic from the app uses encrypted (HTTPS) connections. Because we never transmit or hold your documents, there is no server of ours that could be breached. No method of electronic storage is perfectly secure, so please also keep your device itself protected and up to date, and keep your backup files somewhere safe.
Questions, concerns, privacy requests or grievances about the app:
Privacy requests, grievances and policy questions: admin@qubitsoftech.com
Help with the app: support@qubitsoftech.com
General and company correspondence: contact@qubitsoftech.com
Data controller: QubitSofTech, a software development company registered with the Government of India under Udyam Registration Number UDYAM-BR-11-0119074.
Registered office: 323, QubitSofTech, Pipra, Near Hanman Mandir, Areraj, East Champaran - 845419, Bihar, India.
We aim to respond within 30 days.
We may update this policy if the app changes — for example, if a future version adds a feature that uses the network. When we do, we will revise the "Last updated" date at the top and publish the new version at the same address, and the copy inside the app will be updated with the app release that changes it. Material changes will also be noted in the app's Google Play release notes. Continuing to use the app after an update means you accept the revised policy. Previous versions are superseded on publication.