Privacy & data
Draftly is a browser-based resume builder with local-first storage and optional account sync. When you are signed out, your work is kept in this browser. When you sign in, Draftly syncs the saved work needed for your account across devices. We explain both paths below rather than hiding the difference behind legalese.
Local-first until you sign in
Before you sign in, resumes, cover letters, jobs, and preferences are saved in this browser’s local storage. They are not sent to Draftly’s backend on the anonymous path. This means work is tied to that browser and device until you sign in, export it, or clear the browser’s site data.
Importing a PDF or Word file happens on your device
When you import an existing resume, the file is read and parsed entirely inside your browser. The original file is not uploaded by the importer. The editable resume created from it stays local while signed out; if you are signed in, that saved resume can then be synchronized to your account like any other saved resume.
What account sync stores
When you sign in, Draftly synchronizes your saved resumes, cover letters, job tracker entries, library indexes, and preferences to your account. This includes the content you choose to save, such as contact details, work history, job descriptions, and notes. The keyword match still runs in your browser; syncing is what makes the saved data available on another signed-in device.
What does leave your device: analytics
To understand how the site is used and to keep it fast, Draftly runs Vercel Web Analytics and Vercel Speed Insights on every page. These collect anonymous, aggregate data — things like which pages are viewed, the referrer, rough device and browser type, and performance timings (how quickly pages load). This is the one place data does leave your device.
This analytics data is not intended to include the contents of your resume, letters, or job tracker. It is separate from account sync and is used for site usage and performance rather than for the content of your documents.
Fonts are loaded from Google
The site loads its typeface from Google Fonts. Like any third-party asset, your browser makes a request to Google’s servers to fetch it, which means Google receives your IP address and standard request metadata as part of serving the font. This is a normal part of how web fonts work, but we’d rather you know it’s happening.
Accounts and synchronization
Draftly supports accounts using email and password or Google sign-in. Account sync is opt-in: it begins when you sign in. The backend stores your account email, display name when provided, sign-in provider, and the saved data listed above so it can be restored on your other signed-in devices. Passwords are stored as one-way password hashes, never as plain text. Google ID tokens are verified by the backend and are not stored as document content.
The trade-off of local-first
Signed-out work lives only in your browser, so clearing site data, using private/incognito mode, or changing devices can remove access to it. Signed-in work has an account copy, but you should still export a PDF or DOCX when you finish important work so you always hold a copy you control. If a sync request fails, Draftly keeps the local copy and retries rather than pretending it reached the account.
Questions
This page describes how Draftly works as of the date above; if the app changes in a way that affects your data, this page changes too. See also our Terms of Use.