Skip to content

Where your data goes.

Studio drafts stay in your browser by default. Optional AI, configured local or CRM sync, inquiries, and documents you send for human services have different data flows, explained below.

Last updated 30 September 2026

Who this is

Ahead on Paper is a résumé studio operated as an independent business, and is the controller of the data described here. For anything in this notice — questions, requests, complaints — write to support@aheadonpaper.com. A person reads that address.

What we store on our servers

An account exists so the studio can recognise you and remember what you bought. That is all it holds:

  • Your email address.
  • A salted password hash (PBKDF2-HMAC-SHA256, 600,000 iterations for new hashes). Slow hashing helps resist password guessing; it does not make a database compromise harmless. Use a strong, unique password.
  • The licence key you activated, if you bought Pro — so Pro follows you to a new browser.
  • SHA-256 hashes of active session and outstanding password-reset tokens. Storing hashes rather than usable tokens limits exposure from a database compromise; it is not a guarantee against every kind of breach.

What the hosted studio account does not store

The hosted studio account database does not hold the following editing data. This does not cover optional AI requests, configured local sync, or documents you deliberately send to us for human services:

  • Your résumé content.
  • Your career profile, cover letters, or job descriptions.
  • Your AI provider API key.

Drafts live in this browser. Folder backup requires browser support and your permission; server mirroring requires a separately configured local deployment. Clearing browser data can delete drafts permanently. Your licence follows your account, but documents do not automatically sync. Export a JSON backup first.

Optional AI features

This is the part most privacy pages leave out, so here it is plainly. When you run an AI feature — job match, rewrite, deep evaluation, cover letter, grammar — the text you are asking about is sent from your browser to our server, and on to the AI provider you chose. It has to be: a model cannot read a document it was never given.

What travels, for that one request:

  • The résumé text, job description, or career profile relevant to what you asked for.
  • Your API key for the provider, used to authenticate that single call.

The AI routes do not save request content or API keys to the account database. Requests pass through our server, and operational error logs may be retained by our hosting provider. The provider you picked — one of OpenAI, Anthropic, Google, DeepSeek, xAI, Mistral, Qwen or Kimi — receives it under their terms, not ours. Their retention policy is the one that governs what happens next, depending on your provider, account, and settings. AI usage is billed by that provider separately from your studio plan. If that is not acceptable for a particular document, don’t run an AI feature on it; every other part of the studio works without one.

Optional configured integrations

A local deployment can mirror drafts to its configured server folder. If CRM sync is configured and you choose to sync an application, job, company, status, contact details, notes, salary targets, and interview or next-action dates pass through our server to the configured Twenty CRM instance or CRM webhook. Those recipients can retain their own copies. Confirm the destination, access permissions, processing regions, and retention with the deployment operator before syncing confidential data. Local studio account deletion does not delete integration records.

Inquiries and human services

Contact forms send your name, email, message, selected package, and any practice details through our server to the configured intake service. Email inquiries and resumes you send for review or rewriting leave your device. They may be held in the support inbox, intake system, reviewer working copies, delivered files, and those services’ backups. They are used to respond, fulfill the agreed work, and resolve support or billing questions. Account deletion does not delete these separate records.

Before sending a service document, contact support@aheadonpaper.com to confirm who will review it, the inbox and intake providers, processing regions, and the retention and deletion arrangements for your order, including backup copies. Do not send documents until those arrangements are acceptable to you. Request access or deletion of service records at the same address; billing records may need to be retained to meet legal obligations. Do not send classified or government-sensitive information, identification numbers, or unnecessary personal data.

Who else touches your data

  • Vercel — hosting. Serves the site and keeps short-lived request logs (IP address, URL, timing) for operations.
  • Vercel Web Analytics — aggregate page views and funnel counts, such as sample views, registration, checkout clicks, exports, and licence activation. Event properties describe the action or plan; they must not include document content, contact details, or API keys. It sets no analytics cookies and does not follow you between sites.
  • Neon — the Postgres database holding the account fields listed above, hosted in AWS US East.
  • Resend — sends password-reset email. It records the recipient address and delivery outcome so we can tell whether a reset actually arrived.
  • Gumroad — takes payment as merchant of record and issues licence keys. Card details go to Gumroad, never to us; we never see or hold them.
  • Your chosen AI provider — as described above.

The hosted account infrastructure processes data in the United States. Your chosen AI, email, and intake providers may process data in other regions. We do not sell data, and there are no advertising trackers on this site.

Cookies

One: aop_session, set when you sign in. It is httpOnly, expires after thirty days, and exists only to keep you signed in. Signing out deletes the session on our side, so the cookie stops meaning anything even if a copy of it survives. There are no advertising or cross-site cookies.

How long we keep things

  • Sessions: thirty days, or until you sign out.
  • Password-reset tokens: one hour, and they are single-use.
  • Account record: until you delete it.

Your rights

Settings shows the account details used by the studio. These are the fields in What we store. Separate inquiry, service, billing, and operational records are described above.

Active account deletion is self-serve. Settings → Danger zone → Delete account removes your account row, and every session and reset token with it, in one transaction. There is no soft-delete and no recovery window for the active account. Infrastructure backups and separate service or billing records follow their own retention arrangements. Your local studio drafts are untouched, because they were never ours — they stay in your browser.

Depending on where you live you may also have rights to access, correct, or export your data, and to complain to a data protection authority. Write to support@aheadonpaper.com and we will handle it.

Children

The studio is not intended for anyone under 16, and we do not knowingly create accounts for them.

Changes

If this notice changes in a way that affects what we store or who receives it, the date at the top changes and account holders get an email. Wording fixes will not.