bettershell.ai

Privacy Policy

Effective date: July 29, 2026

Last updated July 29, 2026: this Policy now describes our use of PostHog for product analytics and session replay, including how session replay is masked, and the browser storage that goes with it. A previous version stated that no analytics or session-replay tool was in use.

This Privacy Policy explains how bettershell.ai ("bettershell.ai," "we," "us," or "our"), operated by Spencer Seay, an individual, collects, uses, shares, and protects information when you use our website and AI-powered resume tailoring service (the "Service"). By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.

Information We Collect

Account information. Your email address, and either a hashed password (if you sign up with email and password) or basic profile information from Google — such as your name, email address, and profile photo — if you sign up using Google OAuth.

Profile and resume content. Information you enter to build your profile and generate resumes, including your name, contact information (such as phone number, email address, and mailing address if you choose to include it), work history, education history, skills, and any other resume content you provide. We treat this content as sensitive, since it can reveal detailed personal and career history.

Imported source material. If you choose to build your profile by importing rather than typing it in: resume files you upload (PDF or Word), prose you type into the import box, and — for the LinkedIn import — the profile URL you provide and the public profile information returned for it. We treat this content as sensitive on the same basis as profile and resume content above.

Job posting content. The text or link of job postings you paste into the Service so that we can extract job details and tailor your resume to them.

Generated content. The tailored resume text and PDF files the Service generates for you.

Payment information. Stripe processes your payment directly. We receive limited transaction information from Stripe, such as the amount paid, the date, and a payment confirmation, but we never receive or store your full card number or other sensitive payment card details.

Usage and technical information. Basic technical data such as your IP address, browser type, device information, and how you interact with the Service, to the extent reasonably necessary to operate, secure, and improve the Service.

How We Use Your Information

We use the information described above to:

  • create and maintain your account;
  • generate tailored resumes based on the profile and job posting information you provide;
  • populate your profile from documents or profiles you choose to import;
  • process one-time purchases of credit packs through Stripe;
  • communicate with you about your account, purchases, or support requests;
  • detect, prevent, and address technical issues, fraud, or abuse; and
  • maintain, secure, and improve the Service.

How We Share Your Information

We do not sell your personal information. We share your information only with the following service providers, each of whom is authorized to use your information solely to provide services on our behalf:

  • Supabase, Inc. — our database and authentication provider. Supabase stores your account information, profile and resume content, and generated resumes on our behalf, on infrastructure hosted in the United States.
  • Anthropic, PBC — the AI provider we use to generate and tailor your resume content. When you generate a resume, we send the relevant profile information and job posting content to Anthropic's API so it can produce tailored resume text. If you import a resume that cannot be read reliably by automated text extraction alone, we also send that document's contents — or, for a scanned or image-based file, the document itself — to Anthropic's API so it can be parsed into profile entries.
  • OpenAI, L.L.C. — a secondary AI provider we use as a fallback if our primary AI provider is unavailable, using the same categories of data described above.
  • Bright Data Ltd. — the provider we use for the optional LinkedIn import. If you choose to import from LinkedIn, we send the profile URL you provide to Bright Data, which retrieves the publicly available profile information at that URL and returns it to us. We do not send your account information, your existing profile content, or your resumes to this provider, and nothing is sent to it unless you start a LinkedIn import.
  • Stripe, Inc. — our payment processor. When you purchase a credit pack, Stripe collects and processes your payment information directly; we do not see or store your full card details.
  • PostHog, Inc. — our product analytics and session-replay provider. PostHog receives information about how you use the Service — pages visited, actions taken, device and browser information, and your account identifier once you sign in. It does not receive your resume content, profile content, or the job postings you paste. See "Product Analytics and Session Replay" below for detail, including how session replay is masked.

Both Anthropic and OpenAI process this data under their own commercial API terms. As of the effective date of this Policy, neither provider uses data submitted through their commercial APIs to train their AI models by default, and each has stated that inputs and outputs sent through their APIs are typically deleted from their systems within approximately 30 days, except where longer retention is required by law or otherwise separately agreed. We do not control these providers' independent data practices beyond what is described here, and we encourage you to review their own privacy policies for further detail.

We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you as described in "Changes to This Policy" below.

Product Analytics and Session Replay

We use PostHog, Inc. for product analytics and session replay, to understand how the Service is used and where it fails. This section describes what PostHog receives and, just as importantly, what it does not.

What PostHog receives. Pages you visit within the Service; product actions you take, such as creating an account, requesting a resume generation, starting a checkout, or saving an application; technical information about your device and connection, including browser and operating system, referring page, and an approximate location derived from your IP address; and, once you sign in, the account identifier assigned to you by our authentication provider. Server-side events also record identifiers, counts, timings, and the cost of a generation to us.

What PostHog does not receive. We do not send your resume content, profile content, or the job postings you paste to PostHog. Product events carry identifiers and counts — for example, "a resume was tailored, with this many bullets, taking this long" — not the text itself.

Session replay, and how it is masked. Session replay records a reconstruction of your interactions with the interface so we can see where the product is confusing or broken. Because resume content is by nature sensitive, replay is configured to mask rather than to record:

  • All text is masked by default, rather than specific fields being masked individually.
  • All form inputs are masked.
  • The areas most likely to contain personal information — the resume preview, the profile editor, and the job posting field — are excluded from recording entirely, not merely masked.

Anonymous browsing. Before you sign in, PostHog records events without creating a profile for you. A profile is created when you sign in, and is tied to your account identifier. When you sign out, we instruct PostHog to detach your device from that profile.

PostHog processes this information on our behalf under its own commercial terms. If you would like us to delete the analytics records associated with your account, email us at support@bettershell.ai.

Cookies and Local Storage

bettershell.ai does not use advertising cookies, and we do not participate in advertising networks or cross-site ad targeting. We use the following browser storage mechanisms:

  • Authentication session storage. Our authentication provider, Supabase Auth, stores a session token in your browser's local storage (or, depending on configuration, a cookie) to keep you logged in between visits. This is required for the Service to work and cannot be disabled while remaining logged in.
  • Checkout session storage. When you purchase a credit pack, our checkout flow temporarily stores your pre-purchase credit balance in your browser's session storage so the app can correctly update your balance once Stripe confirms payment. This data is cleared automatically when you close the browser tab or complete checkout.
  • Analytics storage. Our analytics provider, PostHog, stores an identifier in your browser so that repeated visits from the same browser can be recognised as one session and one returning visitor. This identifier is used only within bettershell.ai. See "Product Analytics and Session Replay" above.
  • Interface preferences. We store small preferences locally — such as which parts of the interface you have dismissed or how you last sorted your applications — so the app behaves consistently between visits. These never leave your browser.

We do not use any of these storage mechanisms to track you across other websites.

Data Retention

We retain your account information and profile and resume content for as long as your account remains active. If you delete your account or request deletion of your data, we will delete your personal information within 30 days of a verified request, except where we need to retain certain information to comply with legal, tax, or accounting obligations, resolve disputes, enforce our agreements, or prevent fraud. Content sent to our third-party AI providers (Anthropic and OpenAI) is retained by those providers according to their own default practices, which, as of the effective date of this Policy, is typically within approximately 30 days for content submitted through their APIs, unless a longer period is required by law.

Your Rights and Choices

You can view and update most of your profile information directly within your account. To request access to, correction of, or deletion of your personal information, or if you have any other privacy question, email us at support@bettershell.ai. We will take reasonable steps to verify your identity — typically by confirming the request comes from the email address associated with your account — before fulfilling a request, and we aim to respond within a reasonable time, generally within 30 days.

International Users and Regional Privacy Laws

bettershell.ai is operated from the United States and is intended primarily for individuals located in the United States. We do not direct our marketing at, or specifically target, residents of the European Union, United Kingdom, or other jurisdictions with region-specific data protection laws such as the GDPR. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country. Regardless of where you are located, if you would like to access, correct, or delete your personal information, or otherwise exercise rights you may have under the laws of your jurisdiction, you may contact us at support@bettershell.ai and we will make a good-faith effort to respond to your request.

Children's Privacy

bettershell.ai is not directed to, and is not intended for use by, anyone under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at support@bettershell.ai.

Data Security

We use commercially reasonable administrative, technical, and physical safeguards designed to protect your information. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, provide additional notice, such as by email or an in-app notice. Your continued use of the Service after a change takes effect constitutes acceptance of the revised Policy.

Contact Us

If you have questions about this Privacy Policy or would like to exercise any of the rights described above, contact us at support@bettershell.ai or by mail at:

Spencer Seay bettershell.ai 3830 Valley Centre Dr #705 San Diego, CA 92130