Privacy & Security
Last updated: 23 September 2026
Introduction
StackShift AI is a career workspace that helps you analyse, write and tailor job application documents. This page explains, in plain language, what information StackShift handles, how our AI features use it, which outside services are involved, and what you can control. It describes how the product actually works today and is not legal advice.
Information we collect
- Account information — the email address you sign in with, and basic profile details you choose to add.
- Content you create or upload — resume text, career profile details, job descriptions, target roles, company or recipient names, and any instructions or notes you type into a tool.
- Results we save for you — ATS analyses, tailored resumes, cover letters, outreach messages and your activity history.
- Usage information — pages visited and actions taken in the product, collected through analytics (see below).
Resume and career information
When you upload a resume, the PDF or Word file is read inside your own browser. The original file is not uploaded to or stored on our servers. What we save is the text and structured details taken from it, so you can reuse your resume across tools. You can delete saved resumes, analyses and generated documents at any time from inside the app.
How we use your information
- To run the tools you ask for, such as scoring a resume or writing a cover letter.
- To save your work so it is there when you come back.
- To show you your history, progress and recommendations.
- To understand which features are used, so we can improve the product.
- To respond to you when you contact us.
AI-powered features
These parts of StackShift use AI to produce their output:
- ATS Resume Checker
- Resume Tailoring
- Resume Review
- Cover Letter Generator
- Recruiter Email Generator
- LinkedIn Outreach
- Career Profile extraction from a resume
The Resume Builder, My Resumes, History and your dashboard do not send anything to an AI model — they only work with what you have already saved.
How AI processing works
When you run one of the AI features above, the relevant information is sent from our servers to an AI model through Lovable's AI gateway, which currently routes these requests to Google's Gemini models. Depending on the tool, what is sent can include your resume text, career profile details, the job description you paste, your current and target role, a company or recipient name, and any instructions you add.
AI requests are only made for a signed-in account, and the credentials used to reach the AI service are held on our servers and never exposed in your browser.
AI output is generated automatically and can be wrong or incomplete. Please review anything you plan to send to an employer. For how the AI provider itself handles data, including retention and whether data may be used to improve their models, please refer to the current policies of Lovable and Google — we do not make claims on their behalf.
Data storage
Your account and saved content are stored in a managed PostgreSQL database provided through Lovable Cloud (built on Supabase). Access is restricted to your own signed-in account: every stored record is tied to your account, and database access rules prevent one account from reading another account's data.
Security
Signing in is required for every tool that reads, writes or analyses your data. AI features run on the server side, after checking your session. Service credentials stay on the server. Uploaded documents are parsed in your browser rather than stored as files. Locally cached data in your browser is tied to your account and cleared when you sign out or switch accounts.
No service can promise perfect security. We do not claim any formal security certification, and we recommend you avoid entering information you would not want processed by an AI service.
Third-party services
- Lovable Cloud / Supabase — hosting, sign in and database storage for your account and saved content.
- Lovable AI Gateway and Google Gemini — processing AI requests for the features listed above.
- PostHog — product analytics, to see which features are used.
- Google Analytics 4 — website analytics on our public pages.
Each of these providers handles data under its own terms and privacy policy, which we encourage you to read.
Analytics
We use PostHog to record product events, such as which tools are opened and completed. Signed-in activity is linked to an internal account identifier rather than your email address. Google Analytics 4 records page views on our public marketing pages. Both use cookies or similar browser storage. Analytics is used to improve the product, not to sell your data.
Data retention
We keep what you save for as long as your account exists, so your resumes, analyses and documents remain available to you. When you delete an item, it is removed from your account. Analytics providers keep usage data according to their own retention settings.
Your controls
Inside the app you can delete, at any time:
- Saved resumes
- ATS analysis history entries
- Tailored resumes
- Cover letters and outreach messages
- Career profile entries
Full account deletion is not yet available as a self-service button. If you would like your account and all of its data removed, email us at stackshift.support@gmail.com from the address you signed up with and we will handle it.
Changes to this page
As StackShift changes, we will update this page and the “last updated” date above. Significant changes to how we handle your data will be reflected here.
Contact us
Questions about privacy or your data? Email stackshift.support@gmail.com or use our contact page.