Privacy and data handling
What is processed, what is kept, where it goes — and what this service cannot do.
Provided by Tiraisoft, Jl. Rahayu Sungai Paring, Martapura, Indonesia. Privacy contact: privacy@tiraisoft.com.
Last updated 28 August 2026.
This describes exactly what happens to a document sent to this service. It is written to be checked, not to reassure: every statement below is a statement about code, and the ones that are limits are stated as limits.
It is a description, not a warranty. The service is provided as is, under the Terms of Use, and this page carries no promise about what the service will do in future — only an account of what it does now. Where the account stops being true, this page changes with it.
1. Who is responsible for what
When you call the API, the resume you send is personal data about somebody who is not you. You are the controller: you decide why the document is processed and you need a lawful basis for it. Tiraisoft is a processor, acting only on your instruction, and your instruction is the API call itself.
When somebody uses the free parser on this site, they are sending their own CV about themselves. For that use Tiraisoft is the controller, the purpose is running the parse the person asked for, and the document is discarded when the response is returned.
2. What is processed
The document you send, and nothing else. There are no accounts, no sign-up, no profile, and no identifier that follows a caller between requests.
3. What is kept
Documents are not kept. They are held in memory for the duration of the request and are gone when the response is returned. There is no database, no object store and no queue in this service — the response is the only copy of the extraction and it goes to you.
No copy of a document, and no text taken from one, is written to a log.
Operational metadata is kept, and it is a fixed list: which endpoint was called, whether it succeeded, the error code if it did not, how long it took, the HTTP status, and which of three classes the caller belongs to (internal, subscriber, unknown). No IP address, no API key, no filename, no document text. It is written to Cloudflare Workers Analytics Engine and used to run the service and to know it is working.
4. Model processing, and the policy sent with every call
The extraction is performed by a third-party large-language-model provider. The document is sent to it to perform your request and for nothing else.
Every call carries a data policy that excludes any provider endpoint permitted to retain the document or to train on it. It is not a preference and not an account setting that could be changed without anybody noticing: it is sent on the request, it is a constant in the source, and a test named after this promise fails if it is removed. If no endpoint will accept a call under that policy, the call is refused rather than sent to one that would keep the document.
Prompt logging is off for this service's account with that provider, verified by reading a completed request back: it carries token counts, cost and timing, and no prompt or completion text.
5. Where processing happens
The service itself runs on Cloudflare Workers, at whichever of Cloudflare's locations is closest to the caller. The model leg is routed globally.
No residency option is offered — not EU-only, and not US-only. If your obligations require processing inside a named jurisdiction, this service cannot meet them today. That is a limit, not a detail, and it is stated here rather than left to be discovered during procurement.
Two separate things would have to change for it, and neither is a document: the model endpoint would have to be one pinned to that jurisdiction, and Cloudflare's regional processing controls are an enterprise add-on this service does not carry.
International transfers by the model provider are covered by that provider's own transfer mechanism, including standard contractual clauses under Article 46 GDPR. The provider is named in the sub-processor list, which is sent to customers on request; it is not named on this page.
6. Sub-processors
Two, by category:
- The platform that runs the service — Cloudflare, for compute, TLS termination, bot challenge on the free tool, and the operational metadata above.
- A large-language-model provider, for the extraction itself.
Both are named, with their roles and their locations, in the sub-processor list. Ask at privacy@tiraisoft.com and it is sent to you.
When a sub-processor changes, this page is updated and carries a new date at the top. Your subscription is with RapidAPI rather than with us, so we hold no address for you unless you give us one — write to privacy@tiraisoft.com if you want to be told directly.
7. Cookies and the browser tools
This site sets no cookies of its own and runs no analytics script. There is no tracking pixel, no advertising tag and no session identifier.
The free parser page loads one third-party script: Cloudflare Turnstile, the challenge that keeps the free endpoint from being farmed. It checks that a browser is a browser. It does not read the document you upload, and this site does not enable its pre-clearance cookie.
8. Security
- In transit: TLS, terminated by Cloudflare, on every request. There is no plaintext path to this service.
- At rest: nothing to protect, because nothing is stored. That is the strongest form of this control and it is the one this service uses.
- Credentials are held in the platform's secret store, are not in source control, and are separate per product.
- Access: no person can read the content of a parse, because no copy of it exists after the response.
9. Data-subject requests
Because no document is retained, this service cannot find, export, correct or delete a resume after the response has been returned. There is nothing left to act on — not as a matter of policy, but because no copy exists. A request about a resume processed through the API belongs with the customer who sent it, who is the controller of that data.
For anything else, or for a request about the free tool on this site, write to privacy@tiraisoft.com.
10. Personal-data breach
Article 33(2) GDPR requires a processor to notify its controller of a personal-data breach without undue delay, and that duty applies here whatever this page says. It is recorded rather than promised: the obligation comes from the regulation, not from this document.
What reduces the exposure is the architecture rather than the paperwork. No document is stored, so a breach of this service cannot disclose a resume that passed through it — there is no store to breach.
11. Automated decisions
This service makes none. It extracts what a document states and returns it as JSON. It produces no score, no ranking, no recommendation and no assessment of any candidate, and it is not designed to be used as the sole basis for a decision affecting a person.
12. Changes
Material changes are reflected on this page with a new date at the top. There is no mailing list and no notification undertaking: this page is the record, and it is the version in force.