ATSPrep
Studio

Privacy

Your resume file is never uploaded.

ATSPrep is designed so you can import, edit, check, and export a resume without creating an account. Everything runs in your browser except one optional feature, named below, which you have to press a button to use.

Last updated August 2, 2026

Resume processing

  • Imported PDF, DOCX, TXT, and Markdown files are read by JavaScript in your browser.
  • The file itself is never uploaded to ATSPrep or to anyone else.
  • Resume fields and generated PDF bytes are processed locally on your device.
  • ATSPrep does not store, sell, or train models on your resume contents.
  • The X-Ray checks the generated PDF using a text extractor running in your browser.
  • The Proof Engine and job-description keyword matching also run entirely in your browser.

Semantic match — the one exception

Every feature above runs on your device. Semantic match is the single exception, and it only runs when you press its button. It is never automatic.

When you run it, two things are sent to our matching service: the requirement lines we extracted from the job description you pasted, and the content lines of your resume — your headline, summary, role and company names, bullet points, education, and skills.

Your name, email address, phone number, street address, and profile links are structurally excluded. They are held in a separate part of the draft that the request is not built from, and a check in the code rejects the request outright if any of them are detected in it.

The service turns each line into a vector — a list of numbers standing for its meaning — and sends those back. The comparison itself happens on your device, so the service never learns which requirement your resume answered, or how well. It writes nothing to a database and does not log the text you sent. If you never press the button, nothing is ever sent.

It runs as a Supabase edge function hosted in the EU (Ireland). The embedding model runs inside that function, so your text is not passed on to any third-party AI provider. See the Supabase Privacy Policy.

Storage on your device

Your current draft is stored in your browser's local storage so it remains available after a refresh or when you return on the same browser. You can remove it with the Studio's Clear action or by clearing site data in your browser.

ATSPrep does not provide cloud backup or cross-device sync. Anyone with access to your browser profile may be able to access locally stored data.

Optional email checklist and updates

ATSPrep can offer to email you a one-time application checklist after an export and in a few clearly labelled places on the site. It is optional, never blocks a result or download, and never sends your resume or job description with the request.

The form sends the address, the choices you ticked, the place where you submitted it, and limited campaign attribution such as UTM values, an advertising click ID, the landing path, and an external referrer hostname. Those values help us understand whether an ad produced a real, confirmed opt-in. They are not derived from resume content.

The first email asks you to confirm the address. Until you do, you are not added to a marketing list. If you requested only the checklist, ATSPrep deletes the subscriber record after sending it. If you separately selected product, job-search, or Job Hunt Pass updates, we retain the address, consent record, selected interests, and campaign attribution until you unsubscribe or ask us to delete them. Using the unsubscribe link deletes that subscriber record.

You can use “Continue with Google” instead of typing an address. It creates no ATSPrep account, no profile, and no login session, and it gives us no access to your Google account, contacts, or files. Google returns a signed token that ATSPrep verifies on its server to read one thing: your email address, and the fact that Google has confirmed you own it. Because that check replaces the confirmation email, no confirmation link is sent. Your consent to marketing updates is still the box you tick, not the sign-in.

Google’s sign-in code is not loaded when a page loads. It is fetched only once you move to that button, so browsing this site never contacts Google. From the moment you do, Google can see that a visit to ATSPrep came from your browser, and it knows you signed in here.

Email is delivered by Resend, subscriber records are stored in Supabase, and Google processes the optional sign-in. Every optional update includes a self-service unsubscribe link. You can also email support@atsprep.com for access, correction, or deletion.

Website analytics and infrastructure

ATSPrep uses DataFast in cookieless mode for aggregate product analytics. It may process page URLs, referrers, browser information, approximate location, and a short-lived pseudonymous identifier derived from request signals. It does not receive resume contents.

Alongside page views, ATSPrep records a handful of named product events so we can see which steps people use — for example opening the Studio, starting or finishing a resume import, picking a template, and exporting a PDF. These events carry only non-identifying labels we generate ourselves, such as the file type (PDF, DOCX, or text), a template name, or a small count. No resume content, file names, file data, pasted text, or anything you typed is ever attached to them.

Cloudflare hosts and protects the website and may process standard request, security, and performance data such as IP address, user agent, requested URL, and timing information.

Campaign parameters are also kept in session storage for the current tab so an export can be attributed to a broad channel. DataFast receives only coarse source and medium labels. Full campaign values and click IDs are sent to ATSPrep only when you explicitly submit an email form.

Learn more in the DataFast cookieless tracking documentation, the Cloudflare Privacy Policy, the Resend Privacy Policy, and the Google Privacy Policy.

Your choices and requests

You can block analytics scripts with browser privacy controls without losing the core resume tools. To ask about access, correction, or deletion of analytics or support data, email support@atsprep.com.

Children and changes

ATSPrep is not directed to children under 16. This notice may change as the product or its providers change; the updated date at the top will show the latest revision.