Legal

Cookies Policy

Which cookies and similar technologies ResumeCaliper uses, why, for how long, and how to change your choices at any time.

Last updated: 25 September 2026 (version 2026-09-25). This policy covers the ResumeCaliper marketing site and product app. It complements the Privacy Policy. Legal framework: Article 5(3) of the ePrivacy Directive as implemented by Article 22.2 of the Spanish LSSI-CE, the GDPR and the guidance of the Spanish data protection authority (AEPD).

1. What cookies and similar technologies are

Cookies are small files that a website stores in your browser. ResumeCaliper also uses browser storage (localStorage, sessionStorage and IndexedDB), which works in a similar way. Below, "cookie" covers all of them. By default (before you accept optional categories) ResumeCaliper does not load advertising or analytics pixels and does not use them for cross-site advertising. If you accept analytics and/or ads, the vendors listed below may set their own cookies or similar identifiers, which can involve cross-site advertising or measurement technology under those vendors' policies.

These are needed for the site and app to work securely and to respect the choices you make. They are set on first visit, are first-party, and cannot be switched off. Theme and language cookies are shared between the marketing site and the app so that your preference follows you.

NameTypePurposeLifetime
fjs_sessionCookie (app)Signed-in session and CSRF protection; HttpOnly, SameSite=Lax; Secure when the app is served over HTTPS14 days
mm-themeCookie + localStorageYour light/dark theme choice1 year
mm-ui-langCookie + localStorageYour interface language1 year
mm-site-notice-v2Cookie + localStorageRecords the cookie choices you made and the policy version they refer to (shared across marketing and app on the same host)Until you change them, the policy version changes, or 24 months
mm-upload-privacy-acksessionStorageRemembers that you acknowledged the upload notice during this browser sessionSession
resumecaliper.visited.v1localStorageDistinguishes first from returning visits to route you to the right start pageUntil cleared
resumecaliper.hybrid.v1sessionStorage (app)Active Check session: anonymised CV text and the local contact restore map for the current tab (never sent to ResumeCaliper servers)About 2 hours, or until download / sign-out
resumecaliper.restore.v1localStorage (app)Short-lived vault of per-run contact restore maps so you can finish a PDF download after closing the tab (browser only; never uploaded)Up to 48 hours, or until download / sign-out / account erase
Firebase Authentication (firebaseLocalStorageDb)IndexedDBKeeps you signed in (email and password, or Google account)Until sign-out
Cloudflare security cookies (for example __cf_bm, cf_clearance) and TurnstileCookie (third-party infrastructure)Bot detection and DDoS protection for the site; the Turnstile check may appear before a free analysisMinutes to hours

When you are signed in, ResumeCaliper also stores a copy of your cookie choices against your account so that they can be demonstrated (GDPR Art. 7(1)).

Not a cookie, but disclosed here: to show the price list for your region, ResumeCaliper uses the country code Cloudflare attaches to your request (CF-IPCountry). No extra cookie is set for this, no profile is built, and your browser does not call a separate geolocation service; only a country-level result (Europe, US/Canada/Australia, or elsewhere) is used. This is based on ResumeCaliper's legitimate interest in showing correct prices; see the Privacy Policy for how to object.

3. Optional — analytics

Only on the marketing site, only if analytics identifiers are configured for this deployment, and only after you accept analytics in the cookie notice: Google Analytics 4, Google Tag Manager and/or Microsoft Clarity may set cookies (for example _ga, _ga_*, _clck, _clsk) to measure how the site is used. Events never contain CV or job-description text. The product app does not load third-party analytics. Microsoft Clarity, when enabled and accepted, may use session-measurement technology under Microsoft's terms; it is not controlled by Google Consent Mode.

Google Consent Mode v2. When Google Analytics or Tag Manager identifiers are configured, the marketing site sets Consent Mode defaults to denied for analytics_storage, ad_storage, ad_user_data and ad_personalization until you grant the matching choices in the cookie notice; ResumeCaliper then sends a consent update. Google tags that require consent do not load until you accept. Clarity (if configured) loads only after analytics consent, independently of Consent Mode.

4. Optional — advertising

Only if advertising identifiers are configured for this deployment and only after you accept ads: Google AdSense (adsbygoogle.js) may set advertising cookies (for example __gads, __gpi, IDE) to show and measure display ads. Those cookies may be used for advertising measurement across sites under Google's terms. CV content is never sent to advertisers. Rejecting ads does not block the product: free checks use ResumeCaliper's own first-party unlock step, and paid packages never involve ads. Consent Mode (above) also updates advertising storage signals when you change ads consent.

5. Free-check unlock (first-party)

The free tier may show a short first-party unlock step (on-screen entitlement check and/or bot verification) before an analysis. It is operated on ResumeCaliper's own servers as an entitlement token, is not third-party advertising and does not set advertising cookies. Buying a package skips it.

6. Third-party pages

When you use Google sign-in, Google's sign-in window is operated by Google under Google's cookie policy. Stripe's checkout page is operated by Stripe under Stripe's cookie policy. Email-and-password sign-in stays on the ResumeCaliper app and uses Firebase Authentication storage described above.

7. Your choices