Skip to content

Swiffit believes in transparency, privacy, and your right to control your data.

Our mission is to help job seekers present their best selves. We built Swiffit so your data works for you — never against you.

We make it simple to enhance your resume with AI, and equally simple to understand exactly how your data is handled every step of the way.

Effective date: April 23, 2026

This Privacy Policy describes how Swiffit, a brand of Vuego, (“we,” “us,” or “our”) collects, uses, and protects your personal information when you use our website and services at swiff.it (the “Service”).

1. What We Collect

We collect only the information necessary to provide and improve the Service:

  • Account information: Email address, name, and avatar (from Google OAuth if used).
  • Resume data: The files you upload and the text we extract from them. This data is used solely to provide the enhancement service.
  • Job descriptions: URLs and text you provide for matching and tailoring.
  • Usage data: Enhancement counts, feature usage, and product analytics to improve the product. Analytics are anonymous while you're signed out; once you log in or sign up, events are tied to your account ID (pseudonymous, not anonymous — see §2 for the full breakdown).
  • Payment information: Processed entirely by Stripe. We never see or store your full card number, CVC, or billing address.
  • Device data: Browser type, operating system, and IP address collected automatically for security and abuse prevention.

2. How We Use Your Data

  • To parse, analyze, and enhance your resume against job descriptions.
  • To generate ATS compatibility scores and recruiter heatmaps.
  • To generate downloadable PDF and DOCX documents.
  • To manage your account and subscription.
  • To send transactional emails (password resets, receipts, subscription updates).
  • To detect and prevent fraud, abuse, and security incidents.
  • To improve the Service through usage analytics — anonymous while you're signed out, tied to your account once you log in (see Legal basis below for the full breakdown).

Legal basis (GDPR Article 6)

For EU and EEA users, we process your personal data under the following legal bases under Article 6 of the GDPR:

  • Contract (Art. 6(1)(b)): Processing necessary to deliver the Service you signed up for — account management, resume parsing and enhancement, subscription billing, transactional email.
  • Legitimate interest (Art. 6(1)(f)): Fraud and abuse prevention and security monitoring. Where we rely on legitimate interest, we have balanced our interest against your rights. (Product analytics' legal bases and exactly what data each flow carries are covered in the two bullets below, not here.)
  • Consent (Art. 6(1)(a)): Non-essential, client-side (browser) analytics (PostHog) and error reporting (Sentry). One cookie-banner choice governs both — there is no separate category for each. Client-side analytics use a randomly generated anonymous ID while you're signed out; once you log in or sign up, events are tied to your account ID (pseudonymous, not anonymous). You can accept or decline and change your preference at any time.
  • Legitimate interest (Art. 6(1)(f)), server-side: Server-side product analytics (PostHog) and server- and edge-side error monitoring (Sentry) run independently of the cookie banner, because they happen on our servers, not in your browser. Server-side analytics events are tied to your account ID so we can debug and improve the specific feature you used; they are not linked to your email or name in the event itself. Error monitoring strips email and IP before an event leaves our servers.
  • Legal obligation (Art. 6(1)(c)): Retention of billing records and responses to lawful requests from public authorities where required.

3. AI Processing

We use Anthropic's Claude API to process your resume and job descriptions. Key facts about our AI processing:

  • No Swiffit-owned model training: Swiffit does not use resume or job-search data to train Swiffit-owned models.
  • Third-party processing terms: Anthropic's processing follows our configured commercial API terms; commercial API inputs and outputs are not used for model training by default, and retention depends on the API features and account configuration in use.
  • Designed never to fabricate: Our AI is designed to enhance the presentation of your existing experience, not invent it — anything it can't trace to your resume or job description is flagged for your review rather than presented as fact.
  • Confidence flagging: Changes the AI is less certain about are flagged with a “Verify” label so you can review them.

See Anthropic's Privacy Policy for more details on their data handling practices.

4. Data Storage & Security

Your data is stored securely using industry-standard protections:

  • Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.3).
  • Infrastructure: Hosted on Supabase (AWS) with row-level security (RLS) ensuring only you can access your own data.
  • File storage: Uploaded files are stored in encrypted cloud storage with per-user isolation.
  • Access control: Internal access to user data is restricted, logged, and requires multi-factor authentication.

5. Data Sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. Period.

We share data only with the following service providers, solely to operate the Service (web app and desktop coach app):

  • Anthropic AI processing for resume enhancement, ATS scoring, and diagnostics on the web app.
  • OpenAI Real-time voice transcription and live chat coaching during active Swiffit Coach (desktop) sessions.
  • Voyage AI Text embeddings for the resume-to-job-description skills-match scorer on the web app. This is the primary production embedding backend; a lower-quality local model is used only when Voyage isn't configured.
  • Stripe Payment processing and subscription management.
  • Supabase Database hosting, authentication, and file storage for the web app; session-token verification for desktop/backend auth.
  • Google Cloud (Firestore) License, device-entitlement, and usage-metering store for the swiffit-api backend that powers the desktop coach app.
  • Vercel Hosting and edge delivery for the swiff.it web application.
  • Resend Transactional email delivery — account, billing, reminder, and onboarding emails.
  • Upstash Rate limiting and usage-metering counters for the web app's API routes, so one account or IP can't overwhelm the service.
  • Cloudflare (Turnstile) Bot and abuse protection (CAPTCHA alternative) on public forms — contact, newsletter signup, and coach waitlist.
  • PostHog Product analytics. Two distinct data flows with different consent status — not a single opt-in behavior: (1) client-side browser analytics, which only load if you accept analytics cookies in the cookie banner, and which start on a random anonymous ID but switch to your account ID once you log in or sign up (src/components/auth/login-form.tsx, signup-form.tsx call posthog.identify(user.id) via src/lib/analytics.ts); (2) server-side product events (e.g. resume enhancement, cover-letter, salary, diagnostic, and revert actions), which are always on in production regardless of the cookie-banner choice and are keyed to your account.
  • Sentry Application error and crash reporting. Two distinct data flows with different consent status: (1) client-side browser error capture, which only loads if you accept analytics cookies in the cookie banner (there is no separate error-reporting cookie category — one banner choice governs both PostHog and Sentry client SDKs); (2) server- and edge-side error capture, which is always on in production regardless of the cookie-banner choice.

We may also disclose data if required by law, court order, or to protect the safety and security of the Service or its users.

6. Cookies

We use essential cookies for authentication sessions and remembering your preferences (theme, dismissed banners). Optional analytics cookies are only set if you accept them in the cookie banner. We do not use advertising cookies, retargeting pixels, or social media trackers.

7. Your Rights

You have the following rights regarding your personal data:

  • Access: View all your data in the app at any time.
  • Portability: Export a structured JSON copy of your account data from Settings, and download your enhanced resumes in PDF or DOCX format.
  • Correction: Update your profile information at any time.
  • Deletion: Delete your account and all associated data from Settings. This is permanent and irreversible.
  • Objection: Object to specific data processing activities.
  • Restriction: Request that we limit how we use your data.

If you are in the EU/EEA, these rights include those granted under the General Data Protection Regulation (GDPR). If you are in California, you have additional rights under the CCPA. For any data requests, contact us at hello@swiff.it. We will respond within 30 days.

8. Children's Privacy

Swiffit is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly.

9. Data Retention

We retain your data for as long as your account is active. When you delete your account, we delete your personal data from our production systems immediately. This includes your profile, uploaded resumes, enhancement history, cover letters, application tracker, reminders, notifications, usage events, and tool history. Backups that contain your data are overwritten on our standard rolling 30-day backup rotation, after which no copy of your personal data remains. Anonymized, aggregated analytics that cannot be linked back to you may be retained indefinitely.

10. International Transfers

Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for any international data transfers, including standard contractual clauses where required by applicable law.

11. Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via email or in-app notification at least 30 days before they take effect. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Data Protection Officer

For data-protection inquiries, including GDPR data-subject requests (access, portability, erasure, rectification, objection, restriction), reach our Data Protection Officer at privacy@swiff.it. Please include the email address on your Swiffit account so we can verify your identity. We respond within 30 days as required by GDPR Article 12(3).

EU representative

Swiffit is based in the United States and does not currently maintain an establishment in the EU. We serve EU users directly and respond to data-protection inquiries through the DPO email above. If you are an EU data subject and prefer to contact a supervisory authority, you may contact the data protection authority in your EU member state; a directory is maintained by the European Data Protection Board.

Breach notification

If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay and, where feasible, within 72 hours of becoming aware, as required by GDPR Articles 33 and 34. Notifications will include the nature of the breach, the approximate categories and number of data subjects and records affected, likely consequences, and the measures we have taken or propose to take in response. Where the breach is unlikely to result in such risk, we will still log it internally for audit purposes and notify supervisory authorities as required by law.

Your data works for you — never against you

Encrypted, transparent, and under your control. Try Swiffit free.