Skip to main content
← Back to home

Privacy Policy

Last updated: July 8, 2026

Who runs this and how to reach us

Lynt is run by a solo developer. For privacy questions or to exercise your rights, contact contact@lynt.space: see Contact for other channels.

What we collect

  • Account: Lynt signs you in with Google only: there is no separate Lynt password. We receive your email, name, and profile picture from Google to create and run your account.
  • Your documents: Resumes, cover letters, and their formatting (markdown and CSS), version history, uploaded photos, and typed or drawn signatures.
  • Imports: If you import from a PDF, DOCX, image, LinkedIn export, or transcript, we extract the text needed to build your document. LinkedIn export archives are parsed in memory and are not stored.
  • Job search data: Job postings you paste for tailoring, and the applications, statuses, and notes you save in the application tracker.
  • AI activity: Your conversations with Lynt AI (chat and workspace sessions) and the suggestions it generates, so you can review your history and we can improve the feature.
  • Public page activity: If you publish a public resume page, its content is visible to anyone with the link, and we log aggregate view counts. We do not persist visitor IP addresses: an IP is used only transiently to rate-limit views and is not stored.
  • Technical: Browser, device, and basic request logs for security, abuse prevention, and debugging. Error reports and performance data go to our monitoring provider (below) with your email, user ID, and IP stripped before they leave our servers.

How we use it

We use your data to run the app (including AI features), manage your account, prevent abuse, and improve the product. We don't sell your data or use your content to train third-party AI models.

AI and your data

When you use Lynt AI, we send your current document content and recent chat messages to our AI provider, OpenRouter, to generate a response: nothing more. We do not send your email, user ID, or IP address to OpenRouter; it cannot identify you from what it receives. OpenRouter routes the request to the underlying model provider under its own data-processing terms; see openrouter.ai/privacy.

Who we share data with

We use a small number of service providers to run Lynt, each processing data on our behalf:

  • Supabase: database, file storage, and authentication.
  • Google: sign-in (Google is our only sign-in method).
  • OpenRouter: AI provider for Lynt AI features (see above).
  • Sentry: error and performance monitoring. Session replay is enabled to help us debug issues, but every replay masks all text, inputs, and media by default: we never see the literal content of your screen.
  • Vercel: hosting and privacy-focused, cookieless product analytics.

We don't sell your data to anyone, and we don't share it with data brokers or advertisers.

Retention and deletion

You can delete your account yourself from Settings. Deleting your account disables it immediately: your public page goes offline and no further reads or writes are possible: then permanently removes your data after a 30-day recovery window, in case you change your mind. Contact us during that window to restore an account. Deleting an individual document works the same way. We may retain limited records past that window where the law requires it (for example, security or audit logs).

Deleting your Lynt account does not retroactively delete prompts already processed by OpenRouter; that retention is governed by their own privacy policy.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your data, or to object to or restrict certain processing. You can also withdraw consent or complain to a data protection authority. Contact us to exercise these rights; we'll respond as required by law.

Cookies and local storage

We use cookies to keep you signed in and to keep the app secure: that's it; we don't use advertising or cross-site tracking cookies. Our product analytics (Vercel) is cookieless by design. You can control cookies in your browser, though blocking the sign-in cookie will prevent you from staying logged in.

Security, kids, and updates

We take reasonable technical and organizational steps to protect your data: including row-level access controls on your account's data and encrypted connections everywhere: but no system is 100% secure. See Security for more, including how to report a vulnerability. Lynt isn't aimed at children under 16; we don't knowingly collect their data. We may update this policy; we'll change the "Last updated" date and, where the law requires it, notify you. Continued use means you accept the new policy. Questions? Contact us via contact@lynt.space.