Skip to content

Privacy Policy

Last Updated: September 30, 2025

1. Introduction

Latexy ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered resume optimization service.

2. Information We Collect

2.1 Personal Information

  • Account Information: Name, email address, profile picture
  • Authentication Data: Login credentials, social media profile information (if using social login)
  • Billing Information: Payment details processed securely through Razorpay
  • Communication Data: Support tickets, feedback, and correspondence

2.2 Resume and Content Data

  • Resume Content: LaTeX code, text content, and formatting
  • Job Descriptions: Text provided for optimization purposes
  • Optimization History: AI-generated suggestions and changes
  • Usage Patterns: Feature usage, compilation frequency, optimization preferences

2.3 Technical Information

  • Device Information: Browser type, operating system, device identifiers
  • Usage Analytics: Page views, session duration, feature interactions
  • Performance Data: Compilation times, error logs, system performance metrics
  • Security Logs: Login attempts, security events, access patterns

2.4 Anonymous Trial Data

  • Device Fingerprinting: Browser-based identification for trial limits
  • IP Address: For abuse prevention and geographic analytics
  • Session Data: Temporary identifiers for trial usage tracking

3. How We Use Your Information

3.1 Service Provision

  • Process and compile LaTeX resumes to PDF format
  • Provide AI-powered resume optimization using LLM providers
  • Calculate ATS compatibility scores and recommendations
  • Manage user accounts and subscription billing
  • Provide customer support and technical assistance

3.2 Service Improvement

  • Analyze usage patterns to improve features and performance
  • Conduct A/B testing for user experience optimization
  • Monitor system performance and reliability
  • Develop new features based on user feedback

3.3 Communication

  • Send service-related notifications and updates
  • Provide customer support and respond to inquiries
  • Share important policy changes and security alerts
  • Send marketing communications (with consent)

3.4 Legal and Security

  • Comply with legal obligations and regulatory requirements
  • Protect against fraud, abuse, and security threats
  • Enforce our Terms of Service and policies
  • Respond to legal requests and court orders

4. Information Sharing and Disclosure

4.1 Third-Party Service Providers

  • LLM Providers: OpenAI, Anthropic, Google (for AI optimization)
  • Payment Processing: Razorpay (for subscription billing)
  • Cloud Infrastructure: AWS/GCP/Azure (for hosting and storage)
  • Analytics: Google Analytics, Mixpanel (for usage analytics)
  • Monitoring: Sentry, DataDog (for error tracking and performance)

4.2 BYOK (Bring Your Own Key) Data

  • User-provided API keys are encrypted and stored securely
  • API keys are only used to access LLM services on your behalf
  • We do not share or access the content of your API communications
  • Users retain full control over their API key usage and costs

4.3 Legal Requirements

  • We may disclose information when required by law
  • Compliance with court orders, subpoenas, and regulatory requests
  • Protection of our rights, property, and safety
  • Investigation of fraud, security incidents, or policy violations

4.4 Business Transfers

  • Information may be transferred in case of merger, acquisition, or sale
  • Users will be notified of any ownership changes
  • Privacy protections will continue under new ownership

5. Data Security and Protection

5.1 Security Measures

  • Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Role-based access with multi-factor authentication
  • Network Security: Firewalls, VPNs, and intrusion detection systems
  • Regular Audits: Security assessments and vulnerability testing

5.2 API Key Security (BYOK)

  • API keys encrypted using industry-standard encryption (AES-256)
  • Separate encryption keys for each user's API keys
  • No plain-text storage of sensitive API credentials
  • Secure key management and rotation procedures

5.3 Data Backup and Recovery

  • Regular automated backups with encryption
  • Geographic redundancy for disaster recovery
  • Backup retention policies and secure deletion
  • Tested recovery procedures and business continuity plans

6. Data Retention and Deletion

6.1 Retention Periods

  • Account Data: Retained while account is active plus 30 days after deletion
  • Resume Content: Stored for subscription period plus 90 days for recovery
  • Usage Analytics: Aggregated data retained for 2 years
  • Security Logs: Retained for 1 year for security monitoring

6.2 Data Deletion

  • Users can delete their accounts and associated data at any time
  • Automatic deletion of trial data after 24 hours of inactivity
  • Secure deletion procedures that make data unrecoverable
  • Compliance with "right to be forgotten" requests

7. Your Privacy Rights

7.1 Access and Control

  • Access: Request copies of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal data
  • Portability: Export your data in a machine-readable format

7.2 Communication Preferences

  • Marketing Opt-out: Unsubscribe from promotional communications
  • Notification Settings: Control service-related notifications
  • Cookie Preferences: Manage cookie and tracking preferences

7.3 GDPR Rights (EU Users)

  • Right to access personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Rights related to automated decision-making

7.4 CCPA Rights (California Users)

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising privacy rights

8. Cookies and Tracking Technologies

8.1 Types of Cookies

  • Essential Cookies: Required for service functionality
  • Analytics Cookies: Used to understand usage patterns
  • Preference Cookies: Remember user settings and preferences
  • Marketing Cookies: Used for targeted advertising (with consent)

8.2 Cookie Management

  • Users can control cookie preferences through browser settings
  • Essential cookies cannot be disabled without affecting functionality
  • Third-party cookies are subject to their respective privacy policies

9. International Data Transfers

9.1 Cross-Border Processing

  • Data may be processed in countries outside your residence
  • We ensure adequate protection through appropriate safeguards
  • Compliance with applicable data transfer regulations
  • Standard contractual clauses for international transfers

9.2 Data Localization

  • Primary data storage in secure data centers
  • Compliance with local data residency requirements
  • Transparent disclosure of data processing locations

10. Children's Privacy

10.1 Age Restrictions

  • Our service is not intended for children under 16
  • We do not knowingly collect information from children under 16
  • Parents can request deletion of their child's information
  • Additional protections for users under 18

11. Privacy Policy Updates

11.1 Change Notifications

  • Users will be notified of material changes via email
  • Continued use constitutes acceptance of updated policy
  • Previous versions available upon request
  • Effective date clearly indicated for all changes

11.2 Review Schedule

  • Regular review and updates to maintain compliance
  • Updates based on regulatory changes and business needs
  • User feedback incorporated into policy improvements

12. Contact Information

12.1 Privacy Inquiries

Data Protection Officer

  • Email: privacy@latexy.com
  • Response Time: 5-7 business days
  • Mailing Address: [Company Address]

12.2 Rights Requests

To exercise your privacy rights, contact us at:

  • Email: privacy@latexy.com
  • Subject Line: "Privacy Rights Request"
  • Include: Full name, email address, and specific request details

12.3 Complaints and Concerns

  • Internal: privacy@latexy.com
  • EU Users: Local Data Protection Authority
  • California Users: California Attorney General's Office

13. Compliance and Certifications

13.1 Regulatory Compliance

  • GDPR: General Data Protection Regulation (EU)
  • CCPA: California Consumer Privacy Act (US)
  • SOC 2: Security and availability controls
  • ISO 27001: Information security management

13.2 Industry Standards

  • Payment Card Industry Data Security Standard (PCI DSS)
  • Cloud Security Alliance (CSA) guidelines
  • NIST Cybersecurity Framework
  • Regular third-party security assessments

---

Effective Date: September 30, 2025 Version: 1.0

For questions about this Privacy Policy, please contact us at privacy@latexy.com.

Latexy Team Website: https://latexy.com Email: privacy@latexy.com