Tailor

Last updated 5 October 2026

Privacy Policy

Tailor turns a job description and your own profile into a tailored resume. This page explains what it stores, what it sends elsewhere, and how to delete it. It’s written to match how the app actually works.

Who runs Tailor

Tailor is run by Muhammad Ilham, an individual based in Indonesia, who decides how your data is used (the data controller). Contact: [email protected].

What Tailor stores

  • Your Google account basics: name, email address, profile picture link and Google account ID, plus the sign-in tokens Google returns. Used only to sign you in.
  • Session details: a session ID, its expiry, and the IP address and browser information of the device that signed in.
  • What you enter: your profile (work history, skills, projects, contact details you include), the job descriptions you paste, your answers to the questions, and revision requests.
  • What Tailor creates for you: the fit analysis, the tailored resume content, its Typst source, the PDF, any cover letter you generate, and the stage and dates you set for each application.

What Tailor does not store

  • Your Gemini API key. It stays in your browser, and Tailor’s server never receives it. Your browser sends it directly to Google’s Gemini API, and only the results (your job analysis, resume and cover letter) are sent to Tailor to be saved.
  • No analytics, no advertising, no tracking pixels, no data sold or shared for marketing.
  • Tailor does not use your data to train AI models.

How your data is used

Only to provide Tailor: signing you in, analyzing a job description against your profile, writing and revising your resume, producing the PDF, and showing your applications and their progress.

Who else handles it

  • Google (sign-in). When you sign in with Google, Google’s Privacy Policy applies to that step.
  • Google (Gemini API). To write your resume, your browser sends your profile, the job description and your answers directly to Google’s Gemini API using your own key. Google processes this under its Gemini API terms. On Google’s free tier, Google may use that content to improve its products; a paid key turns that off. Google may process it outside Indonesia.
  • Tencent Cloud (Jakarta, Indonesia) hosts the server and database where your data is stored.

Nothing else is shared, unless the law requires it.

Cookies and local storage

Tailor uses only the cookies needed to sign you in. There are no analytics, advertising or tracking cookies, so there is no cookie banner.

CookieWhyHow long
better-auth.stateProtects the Google sign-in step against forged requests.5 minutes, only while signing in
better-auth.session_tokenKeeps you signed in.7 days after you last use Tailor, or until you sign out

Both are HttpOnly, so scripts on the page can’t read them. On the live site their names start with __Secure-. Your Gemini key is kept in your browser: in local storage if you choose “Remember on this device” in Settings, otherwise in session storage, which the browser clears when the tab closes. Signing out removes it either way.

How long it is kept

  • PDFs are deleted from the server 24 hours after they’re made. You can still download an older resume: Tailor rebuilds it from the saved Typst source without storing it again.
  • Everything else stays until you delete it. Delete a single application from its page, or your whole account from Settings, which removes your sign-in, profile and all applications. Deletion is permanent.
  • If server backups exist, deleted data may remain in them until those backups are replaced.

Your rights

Under Indonesia’s Personal Data Protection Law (UU PDP) and similar laws, you can ask to see the data Tailor holds about you, correct it, get a copy, withdraw consent, or have it deleted. Most of this you can do yourself: edit your profile, download your resumes, delete applications or your account. For anything else, email [email protected] and you’ll get an answer within the time the law requires.

Age

Tailor is for people aged 18 and over. It is not meant for children and does not knowingly collect data from anyone under 18. If you believe someone under 18 has an account, email [email protected] and their data will be deleted.

Security

Connections use HTTPS, sign-in goes through Google, every request checks that you only reach your own data, and your Gemini key never reaches the server: your browser sends it only to Google, and the page is only allowed to connect to Tailor and Google’s Gemini API. No system is perfectly secure; if a breach affects your data, you’ll be told as the law requires.

Changes

If this policy changes, the date at the top changes too. Significant changes will be announced in the app before they take effect.