Data and processing
We store account identity, career profile and preferences, uploaded resumes, imported and saved jobs, fit evidence, approved answers, application materials and history, reminders, plan/usage records, session metadata and privacy-request records. Required session cookies are HttpOnly. Onboarding drafts and your deletion receipt may be stored in this browser; signing out clears the app’s draft data.
If you join the beta waitlist, we store your name, email, optional LinkedIn link, referral source, consent and invitation status, plus a hashed network address for abuse controls. Resend delivers confirmation and invitation emails. Your matching waitlist record is included in account export and deletion. If you have no account, contact the privacy contact below for access or removal.
Sign-in is handled by Supabase and the provider you select. This app does not collect passwords. Email sign-in uses a one-time code. Provider-side records and configuration are separate from our application database.
When you upload or request AI features, relevant content is sent to the configured Anthropic or Gemini API. Parsing may require the full document, including contact details present in it. Fit/tailoring reduce unnecessary contact information, but career history remains personal data. Enter a profile manually if you do not want to upload. Do not include protected or sensitive personal details that are unnecessary for your job search.
The extension has broad website permissions to support job boards and direct career sites. It analyzes forms and job content through its feature flows and inserts the profile answers you choose. Its credential stays in extension storage and is not delivered to employer pages. Website access does not mean every form or site is supported.
Product analytics, session replay, surveys and feedback collection are not enabled. Security logs use request references and status information, without resume text or credentials. Payment providers process checkout and keep their own financial records; we store plan and reconciliation references.
Export in settings provides machine-readable records and owned files. Account deletion immediately blocks access and new processing, then removes local data and requests storage, identity and billing cleanup. You do not need to cancel renewal first. The receipt shows separate cleanup checkpoints and any work requiring attention. Source-file deletion retains confirmed profile facts and approved exports; version deletion removes that version; account erasure covers the full account.
Active content is retained for the service until account erasure or an approved inactivity policy applies. Production must publish approved retention periods, processor locations, transfer arrangements and legal bases before launch. Backups and processor-held records have separate policies; we do not claim an account cleanup job has erased those backups or legally retained financial records.
You can request access, correction, erasure, portability, restriction or objection through Account and privacy or the privacy contact. Applicable rights and exceptions depend on the reviewed jurisdictional policy. This draft is for adult users; age and regional requirements remain release-review decisions.