Privacy
Last updated 19 August 2026
The short version
JobPilot fills job applications for you and then stops, so you can read them and press Apply yourself. It never submits an application. Your resume and answers live in your own account, are used to fill your own applications, and are deleted — completely — when you delete your account.
The parts worth reading properly are what gets sent to the AI providers, and what the browser extension can see. Both are below.
This policy is part of the Terms of Service, which covers everything else about using JobPilot.
What the browser extension does
The extension only runs on job application pages for the 11 application systems it supports (Greenhouse, Lever, Ashby, Workable, Recruitee, JazzHR, Teamtailor, Breezy, Jobvite, Paylocity and Dayforce), plus your own JobPilot dashboard. On any other site it is not running at all.
On a supported page it reads the form’s fields and fills them in with answers from your JobPilot account. The filling happens in your browser. It always stops at the review step — there is no code path that presses Submit, and that is a fixed product rule rather than a setting.
It does not read pages you browse, it does not track where you go, and it sends nothing to anyone except your own JobPilot account.
What we store
- Your email address and password (the password is hashed by Supabase; we never see it).
- Your master resume and the details applications ask for — name, address, phone, work authorization, education, and any voluntary self-identification you choose to give.
- Your search preferences, and the jobs matched to you along with your yes/no swipes.
- Answers you type into application questions, so the same question is never asked twice.
- Which applications you have filled and their status, and what the AI features cost.
- If you use them: the text of your own LinkedIn profile, and a writing-style profile.
- If you connect a mailbox: for each message that turns out to be a reply about a job, the outcome, the sender’s domain and the provider’s message id — not the subject line, the preview, or the body.
- If you press “Report a problem with this form”: a stripped-down copy of that application page’s form structure — the fields, labels and options, with everything you typed removed before it leaves your browser — plus what JobPilot did with each field and the note you wrote. That is what lets us fix a form that misbehaved.
What gets sent to the AI providers
This is the part most people want to know. JobPilot uses Anthropic and OpenAI to score jobs, tailor resumes, write cover letters, and work out which answer belongs in which form field. To do that it sends them:
- the job description being scored or applied to;
- the relevant parts of your resume and saved answers;
- the labels and questions on the application form — so the model can decide what goes where;
- if you connect a mailbox: for each message that matches the recruiting search, the sender’s domain (not their address), the subject line and your provider’s short preview — so the model can say whether it is a rejection, an interview request or an offer. Never the message body.
Anthropic and OpenAI process this to return a result, and neither is given your password. What a connected mailbox sends them is the three fields listed above and nothing else — no bodies, no addresses, and nothing from mail that didn’t match. Answers already worked out once are remembered and reused, so a form you fill again is not sent a second time.
If you press Scan profile, the extension opens your own LinkedIn profile in a background tab in your own signed-in browser, reads the text you can see, and saves it to your account as extra context for tailoring. It only ever opens your profile, only when you press the button, and it never changes your master resume — the text is kept separately.
Mailboxes
Connecting Gmail or Outlook is optional and off by default. You can disconnect at any time, which deletes the stored token.
What we receive. Gmail is requested with format=metadata and an explicit list of three headers, so we are sent the sender, subject and date, plus Gmail’s own one-line preview of the message. Outlook is asked for the same five fields. The message body is never sent to us and cannot be — that is enforced by Google, not by a promise in our code.
What we do with it. Those fields are used once to work out whether a message is a reply to a job application and which of your applications it belongs to. Working that out calls OpenAI, which is sent the sender’s domain, the subject and the preview — never the body, and never an email address. Nothing from your mailbox is used to train anyone’s models, shown to anyone else, or used for advertising.
What we keep. Only the outcome — rejected, interview or offer — the sender’s domain, and the provider’s message id so a later sync doesn’t read the same mail twice. The subject line and the preview text are never written down, and neither is anyone’s email address.
JobPilot’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who else sees your data
JobPilot stores data with Supabase (database and file storage) and runs on Vercel. AI features call Anthropic and OpenAI as described above — including the step that reads a mailbox reply and decides what it means. If you connect a mailbox, that is Google or Microsoft — and information received from Google APIs is handled under the Limited Use requirements set out under Mailboxes above. On free accounts, sponsored cards involve Adzuna — see Sponsored cards below for the three things it is sent.
If you subscribe, Stripe processes the payment. Your email address and your account identifier go to Stripe so a payment can be matched to an account; your card details are typed on Stripe’s own screens and never reach us. What comes back is the plan, the status and the renewal date — never a card number. Stripe uses that data as its own controller for fraud prevention and its legal obligations.
Email we send you — the daily digest, and account mail like a password reset — goes out through Resend. It receives your address, the subject and the message, which for a digest means the job titles and companies already on your own screen. Never your resume, your saved answers, or anything out of an employer’s message. Every digest carries a one-click unsubscribe that works without signing in, and the same switch lives in Settings › Notifications. Turning it off changes nothing about account mail.
That is the whole list. Your data is never sold, and never used to train anyone’s models. The one thing that goes to an advertiser is the job-title-and-location search described below, and only on a free account. Each account can only ever read its own rows; that is enforced by the database itself, not by application code.
Page-view analytics on the dashboard record the URL pattern and nothing else. Alongside them we count a short, fixed list of moments in the product: that setup was finished or skipped, that a first search was run, that the extension was paired, that a first card was swiped, that a form was filled, that a first application was recorded, and that someone joined the Pro wishlist. Those counts carry a number or a fixed word — “yes”, “manual”, “settings” — and nothing else: no name, no email address, no job title, no employer, no résumé text, none of the answers you typed, and no identifier for your account. The whole list lives in one file, and the code will not build if anyone adds free text to it.
Sponsored cards
Free accounts see the occasional sponsored card in the deck — roughly one in every twelve — and a small panel beside it on wide screens. Sponsored cards are always labelled. Pro removes them, and Pro accounts can switch them back on if they’d rather keep them.
Some of those cards are JobPilot’s own. The rest are real job postings supplied by a job advertising network, Adzuna, which pays us when you follow one.
To find postings worth showing you, JobPilot sends that network three things and no more: one job title from your preferences, one location from your preferences, and a country. That is the whole list.
It never sends your resume, your name, your email address, your saved answers, the jobs you have swiped or applied to, or the salary you are looking for. It sends no account identifier, so the network is not told that the same person came back. And nothing is sent at all for a Pro account with sponsored cards switched off — the request is refused before it is made.
Postings from the network are shown to you and linked to. They are not copied into your account or into JobPilot’s own job catalogue.
JobPilot separately records that a card was shown, followed or dismissed, so it can tell whether the slots are worth keeping. That record is an internal identifier for the card and a timestamp; it stays with us, is not linked to the job you were looking at, and is deleted with your account.
How it is protected
Stored secrets — mailbox tokens and any saved credentials — are encrypted with AES-256-GCM under a key that lives only in the server environment, never in the database. Resumes and personal details are never written to logs.
Deleting it
Settings → Account has two buttons. Reset my data clears your deck, applications and generated documents but keeps your login and resume. Delete my account removes everything, including your uploaded files, and cannot be undone. Both ask for your password.
Changes to this policy
If the data flow changes, this page changes with it, and the date at the top moves. A change that alters what we do with your data — a new provider, a new category of information — is announced in the app rather than left for you to notice.
The Terms of Service are versioned separately, and a material change there asks you to accept it before you carry on.
Notice for California users
Under California Civil Code § 1789.3, California users are entitled to this notice: the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs may be contacted in writing at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210.
Contact
Questions about any of this: contactjobpilot@gmail.com.