Overview
Job Application Assistant helps you manage your job search, tailor resumes, analyze job postings, and autofill applications. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
We do not sell your personal information or use it for targeted advertising. We process information needed to provide and secure the features you choose to use. The App uses a database and backend services, and optional features may send relevant data to services you select, such as an identity or AI provider.
1. Scope and responsibility
This policy applies to the Job Application Assistant web application, related APIs, and browser extension. Job boards, applicant tracking systems, identity providers, and AI providers have their own privacy practices. This policy does not control information you submit directly to those services.
The operator of Job Application Assistant is responsible for personal information processed to provide and secure the App. If you operate a self-hosted installation, the person or organization operating that installation also determines how its infrastructure, logs, and backups are managed.
2. Information we collect
Depending on how you use the App, we process the following:
- Account and authentication information: name, email address, profile image, sign-in method, account status, and security and session information needed to authenticate and protect your account.
- Profile and resume information: contact details, location, professional links, compensation and work preferences, work history, education, skills, resume files and extracted text, and other information you add to your profile. If you choose to provide them, this may also include voluntary compliance or demographic fields such as work authorization, sponsorship need, veteran status, disability status, gender, or race/ethnicity.
- Job-search and application information: job titles, employers, locations, descriptions, URLs, ATS type, application status and dates, follow-up and interview details, notes, recruiter or professional contact details you save, and related links.
- Generated and analyzed content: fit analyses, match scores, tailored resumes, cover letters, interview preparation, application-answer drafts, and temporary analysis caches.
- AI configuration and usage: selected provider and model, encrypted API keys when you choose to save them, masked key hints, and counters used to enforce feature or usage limits.
- Extension and autofill information:extension version and connection state; job-page content needed for analysis; application-form hosts, labels, field and form fingerprints, mapping choices, saved autofill text, "never fill" preferences, fill outcomes, confidence values, and non-readable representations of completed values used to improve matching.
- Technical and security information: essential cookies or authentication tokens, request and error information, rate-limit counters, and logs generated by our application, hosting, database, or email infrastructure.
We do not currently use advertising pixels. Optional product analytics (PostHog) and error monitoring (Sentry) may run when configured by the operator. Those tools receive account identifiers and technical event names only — not resume text, application answers, or other sensitive profile contents.
3. How we obtain and use information
We receive information from you, from the browser extension when you use job-search features, from sign-in providers you select, and automatically as needed to operate and secure the App. We use it to:
- create, authenticate, and protect your account;
- provide profiles, resumes, fit analysis, tailoring, application tracking, autofill, exports, and support;
- remember your settings and improve form-recognition and autofill accuracy;
- send verification, password-reset, email-change, deletion, and other service messages;
- prevent abuse, enforce limits, troubleshoot failures, and protect users and the App; and
- comply with law and enforce our terms.
Where law requires a legal basis, we rely on performance of our contract with you to provide the App, legitimate interests in securing and improving it, consent for optional features where required, and compliance with legal obligations. You may withdraw consent at any time, but doing so does not affect earlier processing and may prevent the related optional feature from working.
4. Authentication, cookies, and connected accounts
Authentication is implemented using Better Auth. Email/password accounts store a securely hashed password rather than the password itself. We use essential session cookies and authentication tokens to maintain sessions, secure account access, connect the extension, prevent cross-site attacks, and apply rate limits. Cookie security protections are applied by the authentication framework according to the deployment and browser context. These technologies are necessary for the App and are not used for advertising.
On email/password sign-in you can choose "Stay signed in." When that option is off (the default), you are signed out when you close the browser. When it is on, you can stay signed in on this device for up to about thirty days (or until you sign out). Use "Stay signed in" only on devices you trust. Signing out ends your current session. We do not store your password in the browser.
If you sign in with Google, GitHub, or LinkedIn, that provider may give us your provider account identifier, name, email address, profile image, email-verification status, and authorization tokens or scopes needed to maintain the connection. The exact information depends on the provider and the permissions shown during sign-in. Those providers also receive information about your sign-in attempt and process it under their own privacy policies.
5. AI providers
AI-powered features send prompts to the provider configured for the feature, such as Google Gemini, OpenAI, Anthropic, or another compatible service you configure. Depending on the feature, a prompt may contain resume and profile information, job descriptions, employer names, application questions, interview or essay context, and voluntary compliance or demographic fields you have saved. The provider returns analysis or generated content to the App.
Some autofill features may also send form-label text to an embeddings service (currently OpenAI-compatible embeddings) so the App can match unfamiliar questions to your profile fields. That call can occur even when a different provider is configured for scoring or document generation.
If you save your own AI API key, the App encrypts it at rest and uses it only to authenticate requests to that provider. AI providers process prompts according to the terms, privacy policy, and configuration associated with your account or API plan. Review those terms and data-use settings before enabling an AI feature. You can stop future AI processing by removing your configuration or not using AI features.
6. Browser extension permissions
Because job listings and application forms appear across many websites, applicant tracking systems, and embedded frames, the extension requests permission to access pages where job searches and applications may occur. Browser permissions for tabs, scripting, navigation, storage, and optional trusted typing allow it to detect ATS patterns, extract job details, display fit information, fill application controls, and recognize multi-step forms.
A lightweight detector runs on pages to identify supported job or ATS patterns. Full autofill and panel features are generally activated on likely job or application pages. Job-page URLs or content are sent to the App backend when a job or application workflow requires them; we do not use the extension to build or sell a general browsing-history profile.
The extension stores connection settings, session material, and working state in browser extension storage. Some preferences may use browser sync storage and therefore may sync through your browser account if that feature is enabled. Certain web features, such as interview-preparation drafts, may also keep temporary copies in browser local storage until you clear them.
7. Autofill fingerprints and learning
The App may maintain shared structural fingerprints that describe the layout of job application forms, such as the host, path pattern, field labels, section names, page title, and form structure. Shared fingerprints and accepted label-to-profile-field mappings are not linked to a user account and are designed not to contain your submitted answer text.
Personal autofill mappings, blocked fields, and session events are linked to your account. When you save or confirm an unmatched answer, the App may store that answer as personal saved text for later autofill. Autofill learning may record form labels, mapping choices, outcomes, non-readable value representations, and aggregate counts, but is designed not to store raw essay responses as passive telemetry. Personal autofill data is not shared with other users.
8. When we disclose information
We may disclose information only as needed to:
- Service providers: host the application and database, deliver transactional email, provide rate limiting and security infrastructure, or perform other processing on our instructions.
- Services you direct us to use: authenticate with an OAuth provider, process an AI request, or submit information to a job board or ATS when you choose to do so.
- Legal and safety recipients: comply with a valid legal request or protect the rights, safety, and security of users, the public, or the App.
- Transaction participants: evaluate or complete a merger, financing, reorganization, acquisition, bankruptcy, or transfer of assets, subject to appropriate confidentiality and notice where required.
We do not sell personal information, share it for cross-context behavioral advertising, or use it to serve targeted ads. We do not allow service providers to use account content for their own advertising purposes.
9. Storage and retention
Account and job-search information is stored in the App's account-scoped database, which may be hosted locally or by managed infrastructure depending on the deployment. Browser extension state is also stored in your browser. Documents you export are written to a location you select and remain there until you delete them. Local or self-hosted deployments may also create filesystem working copies needed to generate candidate context or exports.
- Account content is generally retained until you delete it or your account.
- Sessions, verification records, rate-limit data, and temporary caches are retained according to their configured expiration and operational cleanup processes. Some records are removed lazily after they expire. Autofill learning events do not currently have a separate time-based expiration.
- Deleting your account removes user-scoped profile, resume, application, document, settings, analysis-cache, and personal autofill records from the active database. Shared structural fingerprints, shared label mappings, and related aliases are not user-scoped and may remain.
- Limited records may be retained longer when reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, or backup recovery. They are deleted or de-identified when no longer needed.
Account deletion does not delete files you already exported, data held by an AI or identity provider, information you submitted to employers and job platforms, or copies remaining in your browser or extension storage until you clear or disconnect them. Local or self-hosted filesystem working copies may also require operator cleanup. You must manage those copies directly.
10. Security
We use reasonable technical and organizational safeguards designed to protect personal information. These include HTTPS for deployed non-local connections, hashed passwords, encrypted stored AI API keys, least-privilege and user-scoped application access controls, expiring sessions and extension tokens, origin checks, and rate limiting. Self-hosted operators are responsible for securing their own server, database, encryption keys, backups, and network.
No system is completely secure. You are responsible for protecting your account credentials, AI provider keys, browser profile, device, and exported files. If we discover a breach affecting your personal information, we will provide notice as required by applicable law.
11. Your privacy rights
You can edit much of your profile and settings in the App. From Settings → Account, you can download a JSON export of core profile, document, application, contact, settings, and personal autofill content, or request permanent account deletion. The standard self-service export does not include every security, operational, shared, or browser-local record. You can also disconnect extension sessions and remove AI configuration.
Depending on where you live, you may have rights to access, correct, delete, or obtain a portable copy of personal information; restrict or object to certain processing; withdraw consent; and appeal or complain to a data-protection authority. These rights may be subject to legal exceptions. We may need to verify your identity before completing a request.
California residents may also have rights to know the categories, sources, purposes, and recipients of personal information; request correction or deletion; limit certain uses of sensitive personal information; and receive equal service when exercising privacy rights. We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act. An authorized agent may submit a request where permitted by law, subject to verification.
12. International processing
The App and its service providers may process information in the United States and other countries whose data-protection laws may differ from those where you live. Where required, we use lawful mechanisms for international transfers and require service providers to protect information consistently with their contractual and legal obligations.
13. Children's privacy
The App is intended for adults seeking employment and is not directed to anyone under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information, contact us so we can investigate and delete it where required.
14. Changes to this policy
We may update this policy as the App, service providers, or law changes. We will update the date above and, when required, provide additional notice through the App, by email, or by another appropriate method. Material changes apply prospectively unless law permits otherwise.
15. Contact
For privacy questions or to exercise a privacy right, email [email protected] or use the Contact page. Please include "Privacy request" in the subject line and identify your jurisdiction and request. Do not include passwords, AI API keys, or unnecessary sensitive information.