Effective date: June 30, 2026  |  Last updated: June 30, 2026  |  Jurisdiction: Texas, United States

Privacy Policy

Fitted Lab ("Fitted," "we," "us," or "our") is a brand operated by Hand Consulting LLC, a Texas limited liability company. This Privacy Policy explains how we handle information when you use our service at fittedlab.com.

The short version: your resume and job description are processed by our AI to generate your optimized resume, then returned to you. We do not store them. We do not sell your data. When your session ends, your content is gone.

Information we process

When you use Fitted, the following information is processed:

What we do not do

How your data flows

Your resume and job description travel from your browser to our secure proxy server (hosted on Cloudflare, Inc., a US-based provider), and then to Anthropic, PBC's AI API to generate your optimized resume. The result is returned to your browser. At no point is your resume or job description written to a database or retained in persistent storage.

Our AI provider is Anthropic, PBC (San Francisco, CA). We have configured our integration to explicitly opt out of model training on user data. You can review Anthropic's privacy practices at anthropic.com/privacy.

Our infrastructure provider is Cloudflare, Inc. Traffic is routed through Cloudflare's network for security and performance. Cloudflare's privacy policy is available at cloudflare.com/privacypolicy.

Fitted does not currently process payments. If paid plans launch in future, this policy will be updated to name the payment processor used and link to their privacy policy.

Cookies and tracking

Fitted does not use advertising cookies, tracking pixels, or third-party analytics. We may use a single session cookie to maintain your in-progress session while you use the application. This cookie is deleted when you close your browser or click "Start over." We do not use persistent tracking cookies.

California residents — CCPA / CPRA rights

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to:

Because we do not store resume content, most deletion requests are automatically satisfied — there is nothing to delete. For requests related to any stored information (such as email addresses), contact us at hello@fittedlab.com. We will respond within 45 days.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

Texas residents — TDPSA rights

If you are a Texas resident, you have rights under the Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, including the right to access, correct, delete, and obtain a copy of your personal data, and to opt out of the sale of personal data or targeted advertising. To exercise these rights, contact us at hello@fittedlab.com. We do not sell personal data.

Data retention

Resume content, job descriptions, and gap answers exist only for the duration of your browser session. When you close the tab, click "Start over," or your session times out, this content is gone.

Anonymous technical logs (timestamps, error codes, general usage counts — no personal content) are retained for up to 30 days for service monitoring, then automatically deleted.

If you provide an email address, we retain it until you request deletion.

Security

All data is transmitted over encrypted HTTPS connections. Our proxy server does not log resume content. We use Cloudflare's security infrastructure including Web Application Firewall (WAF) protection. We limit what we collect to limit what can be exposed.

No system is perfectly secure. If you believe your information has been compromised, contact us immediately at hello@fittedlab.com.

Data breach notification

In the event of a data breach affecting your personal information, we will notify affected users in accordance with applicable state law. Texas law requires notification within a reasonable time. California law requires notification within 72 hours of discovery.

Third-party links

Our service may contain links to third-party websites (such as job posting sites). This Privacy Policy does not apply to those sites. We encourage you to review their privacy policies before providing any personal information.

Children

Fitted is not directed at children under 13, and users must be 18 or older to use the service. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided information to us, contact us and we will promptly delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page. Continued use of Fitted after a policy update constitutes acceptance of the revised policy. We will not reduce your privacy protections without clear notice.

Contact us

For privacy questions, data requests, or concerns:

Fitted Lab
a brand operated by Hand Consulting LLC
Houston, TX

Email: hello@fittedlab.com
We aim to respond within 5 business days.