Experiencer Pro
Privacy Policy
Effective August 10, 2026
Experiencer is designed to work without an account and to keep data collection small. Local resumes remain in your browser unless you choose to move them to Experiencer Pro. We do not sell personal information, use it for targeted advertising, or operate a general-purpose analytics service.
1. Who we are and what this policy covers
Experiencer is operated by Vincent La from Arizona, United States. Where privacy law uses terms such as “controller” or “business,” Vincent La is responsible for the processing described in this policy.
This policy covers the Experiencer website, the free browser-based editor, Experiencer Pro accounts and cloud features, temporary review links, and the Experiencer MCP service. It does not govern a third-party service or connected AI client, which applies its own privacy terms to information it receives.
2. Information we collect
Local editor data
You can create and edit resumes without an Experiencer account. Resume documents, document names, the active-document selection, migration state, theme, and interface preferences are stored in your browser's local storage. Experiencer does not receive a local resume merely because you edit, print, or export it in your browser.
Account information
If you sign in with Google, we receive the basic sign-in information needed to create and secure your account: your Google account's stable identifier, primary email address, and display name. We assign an internal account identifier and store account creation and update timestamps. We do not request access to Gmail, Google Drive, contacts, calendars, or your Google password, and we do not retain Google access or refresh tokens.
Cloud resume content
If you use Experiencer Pro cloud storage, we store the resume or template names, document data, styles, selected fonts, images embedded in the document, page settings, version history, ownership identifiers, and timestamps. A resume can contain personal information about you or other people, including contact, education, and employment information. Please do not place Social Security numbers, payment-card data, account passwords, medical records, or similarly sensitive information in a resume.
Billing information
Stripe collects payment and billing details through Stripe Checkout and the Stripe customer portal. Experiencer receives and stores Stripe customer, subscription, product, and price identifiers; subscription status and renewal or cancellation dates; and limited webhook event identifiers and timestamps. Experiencer does not receive or store your complete payment-card number or security code.
Feedback, support, and communications
If you send feedback or contact us, we receive the information you submit and your email address. In-app feedback includes the report type, summary, details, and submission time. If you leave “Include browser diagnostics” enabled, it also includes the current application path and browser user-agent string, but not resume content.
Technical and connected-service data
Our hosting and web servers receive ordinary request information such as IP address, request time, requested path, response status, referrer, browser or client type, and security or rate-limit events. MCP connections also involve client names and identifiers, registered redirect addresses, approved scopes, authorization records, token metadata, tool names, outcomes, duration, and request correlation identifiers. Tool logs do not intentionally include resume text, job descriptions, credentials, or tokens.
3. How we use information
We use personal information to:
- authenticate accounts and maintain secure sessions;
- store, synchronize, version, render, export, share, and delete content as directed;
- provide subscriptions, billing status, refunds, and account support;
- connect authorized MCP clients and perform the tools a user requests;
- respond to feedback and troubleshoot product issues;
- prevent abuse, enforce limits, protect users, and secure the service;
- comply with law and establish, exercise, or defend legal claims; and
- maintain and improve the service using feedback and operational evidence.
We do not use resume content to train a general-purpose artificial-intelligence model. We do not use personal information for automated decisions that produce legal or similarly significant effects.
4. Legal bases where applicable
Where a law requires a legal basis, we process information as needed to perform our contract with you, including providing the editor, cloud service, requested sharing, and billing. We rely on legitimate interests to secure, operate, support, and improve the service when those interests are not overridden by your rights. We process data to comply with legal obligations when required, and we rely on consent when a feature or applicable law specifically calls for it. You may withdraw consent at any time, without affecting earlier lawful processing.
5. When information is disclosed
We disclose information only as needed to operate a service, at your direction, or for legal and safety reasons. The principal recipients are:
- DigitalOcean hosts the web application, API, and database and may process stored cloud data and ordinary server traffic. See the DigitalOcean Privacy Policy (opens in a new tab).
- Google provides account authentication. If a document uses a Google Font, the viewing browser also requests the selected stylesheet and font files from Google. Those requests can include the requested font, IP address, browser headers, and similar request metadata; Google says the Fonts API is unauthenticated and does not set or log cookies. See the Google Privacy Policy (opens in a new tab) and Google Fonts privacy FAQ (opens in a new tab).
- Stripe processes checkout, payment, fraud-prevention, refund, and subscription information. See the Stripe Privacy Center (opens in a new tab).
- GitHub receives in-app feedback as a private issue, including the feedback, account email, and any diagnostics you elect to include. See the GitHub Privacy Statement (opens in a new tab).
- Cloudflare Browser Rendering processes resume content only when an MCP preview or saved-resume PDF operation requiring remote rendering is invoked. Experiencer disables render caching. Cloudflare states that Quick Action HTML and generated output are processed ephemerally and discarded after the response. See the Browser Run FAQ (opens in a new tab) and Cloudflare Privacy Policy (opens in a new tab).
- Connected clients and review recipients receive information at your direction. An MCP client can receive authorized saved-resume data and tool results. Anyone who has an active temporary review link can view its saved snapshot. Review the connected client's privacy practices before authorizing it, and share bearer links only with intended recipients.
A remote image URL or another external resource you add to a resume may cause the viewer's browser to contact that resource's host and disclose ordinary request metadata. Experiencer may also disclose information to professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a merger, financing, acquisition, bankruptcy, or sale of the service, subject to applicable safeguards and notice.
6. No sale, advertising, or general analytics
Experiencer does not sell or rent personal information. We do not share personal information for cross-context behavioral advertising or targeted advertising. We do not place third-party advertising pixels or operate Google Analytics, PostHog, or a comparable general-purpose product analytics service. We do not send marketing email.
7. Cookies and browser storage
Experiencer uses an essential, HttpOnly authentication cookie for signed-in sessions and short-lived cookies needed to complete Google sign-in securely. The service does not set advertising or analytics cookies. Google and Stripe may use their own cookies when you visit their sign-in, checkout, or account-management pages.
The local editor uses browser local storage for local resumes and interface state. This data stays on that browser profile until you delete the local document or clear site data. Clearing local storage can permanently remove local-only resumes.
8. Retention and deletion
- Local data: remains in browser storage until you delete it or clear the site's local storage.
- Cloud resumes: remain until you delete them or the account is deleted. Deleting a cloud resume immediately removes its current document and revision history from the active database. Each retained resume is limited to its 100 most recent revisions.
- Temporary review links: expire after 30 minutes and can be revoked sooner. Expired and ineligible snapshots are deleted by automated cleanup.
- Remote rendering: render inputs are held in Experiencer's memory behind a one-time token for no more than two minutes. Returned preview images and PDFs are held in memory behind a bearer URL for up to 15 minutes. Cloudflare's Quick Action environment handles the content ephemerally as described above.
- MCP authorization: access tokens normally expire after 10 minutes and refresh tokens after 30 days. Grants can be revoked. Short-lived consent challenges expire after 10 minutes; expired challenge records are pruned after a limited cleanup period. Client registration metadata and security records may be retained while needed to operate and protect the protocol.
- Accounts, billing, feedback, and logs: are retained while needed to provide the service, handle support, maintain security, resolve disputes, and meet tax, accounting, payment, and legal obligations. Stripe, GitHub, Google, hosting providers, and connected clients apply their own retention policies to their copies.
You may request account deletion by contacting vincela9@gmail.com. We may verify your identity before acting. A deletion request does not require us or a service provider to erase information that must be retained for fraud prevention, payment records, legal compliance, disputes, or the establishment, exercise, or defense of legal claims.
9. Your choices and privacy rights
You can:
- use the local editor without creating an account;
- download current cloud resumes through the cloud-data export;
- delete local or cloud resumes and individual non-current cloud revisions;
- revoke temporary review links and connected MCP grants;
- manage or cancel a subscription through the Stripe customer portal; and
- omit optional feedback diagnostics or avoid optional remote fonts and resources.
Depending on where you live, you may have rights to know or access personal information, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, and appeal a denied request. You may also have the right to complain to your local privacy or data-protection authority. Contact vincela9@gmail.com to exercise a right. We may request information reasonably necessary to verify your identity and authority, and we will not discriminate against you for exercising an applicable privacy right.
10. Browser privacy signals
Because Experiencer does not sell personal information or use it for targeted advertising, there is no sale or targeted-advertising opt-out to apply when we receive Global Privacy Control or “Do Not Track” signals. Experiencer does not change its behavior in response to legacy Do Not Track signals. We do not knowingly permit advertising networks to track your activity over time through Experiencer.
11. Security
We use safeguards appropriate to a small service handling resume data, including HTTPS, HttpOnly and secure production cookies, account and ownership checks, paid-feature authorization, limited OAuth scopes, short-lived and hashed bearer credentials, request limits, restrictive browser policies, bounded storage, and suppressed access logging for sensitive bearer URLs. Access is limited to people and providers who need it to operate or support the service. No online system is completely secure, so we cannot guarantee absolute security.
12. Children
Experiencer Pro is intended only for people who are at least 18 years old. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact vincela9@gmail.com so we can investigate and delete it where appropriate.
13. International use
Experiencer is operated from the United States, and information may be processed in the United States or other countries where our service providers or a client you connect operates. Those countries may have privacy laws different from the laws where you live. Where applicable law requires a transfer mechanism or other safeguard, we will use one.
14. Changes to this policy
We may update this policy when the product, providers, or law changes. We will post the revised policy with a new effective date. If a change materially affects how we use information already collected, we will provide additional notice when reasonably required, such as an in-product notice or email.
15. Contact
For a privacy question, rights request, account-deletion request, or security concern, contact vincela9@gmail.com. Please do not email resume content, passwords, payment-card information, or other sensitive information unless it is necessary to resolve your request.