JobJet

Privacy Policy

← Back to App
Effective Date: August 29, 2026  |  Last Updated: August 29, 2026

This privacy policy describes how JobJet ("we", "us", "our") collects, uses, and protects your personal information when you use JobJet, our AI-powered job application assistant, available as a web application and Chrome browser extension (collectively, the "Service").

Located in the United States. For privacy questions or data requests, contact getjobjet@gmail.com.

1. Data We Collect & Why

CategoryDataPurpose
Account Email address, hashed password (scrypt) Authentication and account management
Profile Name, contact info, tagline, professional summary Populating your resume and application materials
Resume & Work History Uploaded resume text, parsed work history, skills Tailoring resumes and generating cover letters via AI
Job Descriptions Job postings you paste or retrieve via job search Matching your profile to job requirements
API Key (BYOK users) Your Gemini API key, encrypted at rest (Fernet) Calling Google Gemini on your behalf
Usage Data Generation counts, plan type, subscription status Enforcing usage limits and billing

We do not collect browsing history, location data, or data from sites other than the supported job platforms where the Chrome extension operates.

2. How Your Data Is Processed

AI Processing via Google Gemini

When you use features like resume tailoring, cover letter generation, or screening question answers, your resume text and the job description are sent to Google's Gemini API for processing. This is essential to how JobJet works — AI-powered document generation requires sending text to the language model.

For managed-plan users, we send data through our API key. For BYOK (bring-your-own-key) users, data is sent using your personal Gemini API key. Google's use of this data is governed by Google's Gemini API Terms.

Chrome Extension

The JobJet Chrome extension autofills job application forms on supported sites (Lever, Workday, iCIMS, LinkedIn, Indeed) using your saved profile data. The extension never submits a form — you always review the filled content and click submit yourself.

Job Listings

Job search results come from public APIs (Arbeitnow, Adzuna). We do not scrape any website.

3. Third-Party Processors

ProcessorPurposeData Shared
Google (Gemini API) AI text generation Resume text, job descriptions
Stripe Payment processing Email (for customer lookup). We never see or store card numbers.
Fly.io Application hosting All data stored in the application database

4. Data Retention & Deletion

  • Your data is stored for as long as you maintain an active account.
  • You can export all your data at any time from Settings → Your Data → "Download my data" (JSON format).
  • You can delete your account from Settings → Your Data → "Delete my account". Deletion requires password confirmation.
  • Deleted accounts enter a 30-day recoverable soft-delete period. During this time, you can contact us to restore your account.
  • After 30 days, all your data is permanently and irreversibly purged.
  • Account deletion automatically cancels any active Stripe subscription.

5. Your Rights (GDPR / CCPA)

Depending on your location, you may have the right to:

  • Access — obtain a copy of your personal data (use the export feature).
  • Rectification — correct inaccurate data (edit your profile).
  • Erasure — delete your account and all associated data.
  • Portability — receive your data in a structured, machine-readable format (JSON export).
  • Restriction / Objection — contact us to restrict processing.
  • Withdraw consent — stop using the Service at any time; delete your account.

To exercise any right, email getjobjet@gmail.com or use the in-app controls. We will respond within 30 days.

California residents (CCPA): We do not sell your personal information. You have the right to know what data we collect, request deletion, and opt out of sale (not applicable — we do not sell data).

6. Security

  • Passwords are hashed with scrypt and never stored in plaintext.
  • BYOK API keys are encrypted at rest with Fernet symmetric encryption.
  • All traffic is served over HTTPS with HSTS in production.
  • Session cookies are HttpOnly and Secure.
  • Content Security Policy headers are applied to all responses.

7. Cookies

JobJet uses a single session cookie for authentication. We do not use tracking cookies, advertising cookies, or third-party analytics. The cookie expires after 30 days or on sign-out.

8. Children

JobJet is not intended for users under 16 years of age. We do not knowingly collect data from children.

9. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. For material changes, we will notify you by email or in-app notification.

10. Contact

If you have questions or requests regarding this privacy policy, contact:

JobJet Team
United States
Email: getjobjet@gmail.com