Draft, pending lawyer review. This page says exactly what the software does today. A lawyer has not checked the wording yet. If anything here turns out to be wrong, the software is what we will change, not this page.
Privacy
Plain version: we hold your resume and your answers so we can apply for jobs for you. We keep them encrypted. You can see everything, take a copy, or have it destroyed, and you do not have to ask a person for any of that.
What we collect, and why
- Who you are. Your name, email address, phone number, and the town and postal code you apply from. We need these because every employer form asks for them.
- Your resume and work history. Jobs, dates, employers, education, skills. This is what we write each application from.
- Your stories. The things you told us about your own work, in your words. We use them to answer "tell us about a time when..." questions truthfully instead of inventing an answer.
- Your instructions. Which jobs you want, the least pay you will accept, where you will work, and the employers we must never contact.
- Every answer we gave on a form, field by field, kept so you can check what was sent in your name.
- Every reply an employer sends to the email address we run for you, and what we decided it meant.
- What we did and when. Sign-ins, the applications we sent, and a record of every time a sensitive field of yours was read and why. You can read that record yourself on your security page.
- Race, ethnicity, gender, veteran status, disability only if you chose to give them. The default is "do not wish to disclose", and we never answer such a question in any words but yours.
- We never collect a Social Security Number. We do not ask for one.
How it is stored
Every personal field is encrypted with a key belonging to you alone. There is one key per customer, and destroying it makes everything else about you unreadable. Sign-in is a one-time link sent to your email, never a password of yours.
One exception, and it is important. Some employers, Workday in particular, will not accept an application unless you first create an account on their site. When that happens we create the account in your name and we do store the password for it, encrypted with your key, so we can use the account again for the next job at that employer. That is a password on the employer's system, never a password to us. It is destroyed when your data is destroyed. Before we do this at all, you have to have agreed to it during sign-up, and you can withdraw that agreement at any time from your security page.
Where it is processed
Right now everything runs on one computer in the owner's home, in the United States. Nothing about you is stored on a rented server. When this service grows it will move to a cloud host in the United States, and this page will say so before the move happens, not after.
Who else sees it
These are all of them. There are no others.
- Local software on that same computer. The programs that read your resume and write your documents run on the machine itself. Nothing leaves it. This is how most of the work is done.
- OpenRouter. When the local software cannot do a piece of writing, the text is sent to OpenRouter, a company that passes requests on to whichever model vendor is cheapest or best for the job. That means the text also reaches the vendor OpenRouter picks, which today is OpenAI and can be Google. What is sent is the job posting and the parts of your resume and stories that are needed to write that document. Your email address, phone number and postal address are not part of that text.
- Amazon Web Services (SES). Sends the email we send to you and receives the employer replies to the address we run for you. Amazon handles the message in transit.
- Google. While this service is being tested, the owner's own test account sends and receives through Gmail. That applies to the owner's own test data only, and it stops when the service goes live on its own domain.
- The employers you apply to. They receive your application, which is the whole point. We tell you every one.
We do not sell anything about you. We do not advertise. No advertising company, data broker or analytics company receives anything.
How long we keep it
If an employer has not replied after 30 days, we mark the application "no reply yet". At 45 days we move it out of your main list into an archive; nothing is deleted, and it is one click away. A reply at any time, even after archiving, brings it straight back and is handled normally. If you pause the service, nothing at all is deleted. A pause is not a departure, and you can restart whenever you want. If you close your account and do not ask us to erase you, we keep your data for 90 days in case you come back, then delete it automatically. You can ask us to delete it sooner, from your security page, at any time, and we finish within 7 days of the day you ask. You can cancel that request until the day it runs. Deleting means your encryption key is destroyed, which turns everything encrypted with it into unreadable bytes. For 30 days after the deletion the key sits in a locked recovery folder, in case the deletion was a mistake or a court asks us to stop. At the end of those 30 days the key file itself is erased from the disk, and after that nobody, including us, can read any of it. After a deletion, three things survive on purpose: a bare record proving what we submitted to which employer and when, with no words of yours in it; your signed agreement and consents; and your reply email address, switched off and never given to anybody else. The first two are deleted 730 days later. The email address is kept for good, because handing it to a new customer would send your old mail to a stranger. Everything else is gone.
Your rights, and how to use each one
| Right | How |
|---|---|
| Access - see everything we hold | Your dashboard shows every application and every answer. Security page shows every sensitive read. |
| Export and portability - take a copy in a machine-readable file | Export everything about me. It is a JSON file you can hand to anybody. |
| Correct - fix something wrong | Change it on your preferences page, or reply to any email from us. Corrections are stored as corrections, so the old value is never silently swapped. |
| Erase - have it destroyed | Security page, "Delete my data". Or reply DELETE from your sign-in address to any email we send. We finish inside the deadline stated under "How long we keep it" above, counted from the day you ask, and you can cancel until the day it runs. |
| Object and withdraw consent - tell us to stop | Reply STOP from your sign-in address, or use the pause switch on your dashboard: applying stops and nothing is deleted. To take back one specific permission, use "Withdraw a permission" on your security page; that also pauses applying. |
| Complain | Reply to any email from us and say so. If you are in the UK or the EU you can also complain to your national data protection authority, and you do not have to talk to us first. |
Deletion, in detail
You can ask us to delete your data at any time, from your security page, without asking a human. We send you a written report of what is about to go before it goes. If that report cannot be delivered for any reason, we delete on time anyway and record that the report went unsent, because the deadline is about your data and not about our mail.