Job Planter

Privacy policy

Effective [date] · Last updated [date]

Draft. This policy is under legal review and is not in effect yet. It describes how Job Planter will work when it opens to users.

The short version

  • We can't read your data. Your resumes, jobs, answers and applications are encrypted on your device before they reach us, and only your devices hold the keys.
  • We see only what we need to run your account: your email address, your plan, how much you use the AI features, and basic facts about your devices. The full list is below.
  • Your most sensitive answers never reach us. Answers about demographics, disability, veteran status, health or criminal history stay in your browser.
  • AI features see only what a task needs, without your contact details, and nothing is kept afterwards.
  • We don't sell your data, show ads, or use analytics or tracking scripts.
  • Because we can't read your data, we can't recover it. Keep your recovery key safe.

Contents

  1. Who we are
  2. How your data is protected
  3. What we collect and can read
  4. What we store but can't read
  5. What we never collect
  6. AI features
  7. The Chrome extension
  8. Cookies and browser storage
  9. Who we share data with
  10. How long we keep data
  11. Your choices and rights
  12. Security
  13. Where data is stored
  14. Age limit
  15. Changes to this policy
  16. Contact us

1. Who we are

Job Planter is run by [company legal name], [registered address] ("Job Planter", "we", "us"). This policy covers the Job Planter web app at app.jobplanter.com, the Job Planter Chrome extension, and this website. For personal data we process to run the service, we are the controller.

2. How your data is protected

Job Planter is end-to-end encrypted. When you save a resume, a job, an answer or anything else, your browser encrypts it before sending it to us. We store only the encrypted version. Without your keys it's unreadable to us, to our hosting provider, and to anyone who gets a copy of our servers or backups.

Your keys stay on your devices. They're unlocked by your passkey, by your recovery key, or by approval from another device you're already signed in on. We never receive them.

That has one consequence you should know about: if you lose your passkeys, your recovery key and every device you're signed in on, nobody can recover your data, including us. Your account and subscription stay, and you can start again with empty data.

3. What we collect and can read

A few things have to stay readable for the service to work. This is the complete list. We won't add to it without updating this policy.

DataWhy we need itLegal basis (EU and UK)
Your email address Signing in, account emails (codes, security alerts, receipts) and legal notices Contract
Sign-in details: your account id, how you signed in (password, passkey or Google), sign-in times and IP addresses Keeping your account secure and preventing abuse Contract; legitimate interests (security)
Your plan, and the Stripe customer and subscription ids and status Billing Contract
Usage: which AI feature ran, the model, the amount of text processed (token counts), the cost and the time Plan allowances, billing, controlling costs, and tax records Contract; legal obligation
Sync information: an id, type, size, version and timestamps for each encrypted item Keeping your devices in sync Contract
Devices: an id, a short name such as "Chrome on Windows", a public key, and when it was last used Listing your devices, approving new ones, and removing lost ones Contract; legitimate interests (security)
Records of what you agreed to (which version of these terms and this policy, and when), and security events such as a device being added or a recovery key being replaced Proof of consent, and account security Legal obligation; legitimate interests (security)

We don't hold your name, postal address or card details. Stripe collects those when you pay. When you sign in with Google, we ask Google only for your email address and whether it's verified, not your name or profile picture.

The sync information and usage records show some patterns: roughly how many items you have, their sizes, and when you use the AI features. They never show what those items contain.

4. What we store but can't read

Everything you put into Job Planter is stored encrypted: your profile, resumes and their tailored versions, cover letters, saved answers, the jobs you save (postings, notes, match results and summaries), your applications and tracker board, scanned application forms, learned form patterns, and your settings. We can't read, search, analyze or share any of it.

5. What we never collect

6. AI features

Tailoring a resume, writing a cover letter, matching you to a job, summarizing a job and its company, and importing a resume use AI models. For each task:

AI output can be wrong. You review everything before you use it, and the extension never submits an application for you. Answers with legal weight, such as your work authorization, are only ever filled from answers you gave.

7. The Chrome extension

The extension reads job postings you choose to save, and application forms on job sites when you use it to fill them. It uses what it reads to save the job and fill the form with your answers. It never submits a form.

It asks for broad site access and the debugger permission because application forms live on many different job sites and are often built in ways ordinary page access can't fill. It uses these only on pages where you use it or on known job sites, and not to collect browsing data.

Job Planter's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data the extension handles is used only to provide its features to you. It is not sold, not used for advertising or creditworthiness, and not read by people except with your permission, for security, or where the law requires.

8. Cookies and browser storage

The web app sets one cookie, which keeps you signed in. Your browser also stores your encryption keys and an encrypted copy of your data, so the app works quickly. These are strictly necessary for the service, and signing out removes them.

We don't use analytics, advertising or tracking cookies, and we load no third-party scripts, with one exception: the billing page loads Stripe's payment script, which Stripe uses to process payments and prevent fraud. This website sets no cookies at all.

9. Who we share data with

We don't sell your personal information, and we don't share it for advertising.

We use these service providers, under contracts that limit them to providing their service to us:

ProviderWhat forWhat they receive
Amazon Web Services Hosting, storage, sign-in (Amazon Cognito) and account emails (Amazon SES) The readable data in section 3, and your encrypted data
Stripe Payments, receipts and tax Your email, and the payment details you give Stripe directly
OpenRouter, and the AI model providers it routes to AI features The text of each task, without your contact details, not retained
TypeSafe Job matching (the Jev model) The text matching needs, without your contact details, not retained
Google "Sign in with Google", if you use it Only the sign-in itself
Cloudflare Domain name service, and hosting this website Nothing from the app: app traffic doesn't pass through Cloudflare

Legal requests. We disclose data only in response to valid legal process, only what the request covers, and we tell you first unless the law forbids it. Even then, all we can hand over is the readable data in section 3 and encrypted data we can't decrypt. We'll publish a yearly count of the requests we receive.

Business transfers. If Job Planter is sold or merged, your data would move under this policy, and we'll tell you before it does. Your encrypted data stays unreadable to the new owner too.

10. How long we keep data

DataKept for
Your account and encrypted data Until you delete it or your account, or after [24] months without signing in. We email you before deleting an inactive account
Copies after you delete somethingOld file versions for up to 30 days; encrypted backups for up to 35 days
Server logs30 days. They contain ids and error codes, never your content
Security records (sign-ins, devices added or removed)1 year
Billing and usage records As long as tax law requires. After your account is deleted they're no longer linked to your email

When you delete your account, we delete your data, devices and keys, your sign-in account and your Stripe customer record right away, apart from the backup and record-keeping windows above. Backups hold only encrypted data, and if we ever restore one, deletions made since are applied again before it's used.

11. Your choices and rights

Depending on where you live, the law may give you further rights. In the EU and UK: to object to or restrict our processing, to data portability, and to complain to your data protection authority. In California and other US states: to know what we collect, to delete and correct it, and not to be treated differently for exercising these rights. We honor these requests for everyone, wherever you live, and we answer within 30 days. We'll ask you to confirm the request from your signed-in account, or from your account's email address. Someone you authorize can make a request for you.

If you've lost access to your encrypted data, we can give you the readable data in section 3, but not the rest.

12. Security

Besides end-to-end encryption, we protect the service with encrypted connections, strict limits on who can access our systems and how, and monitoring for changes to the code we deliver to your browser. If a breach affects your personal data, we'll tell you and the authorities as the law requires. To report a vulnerability, see our security page.

13. Where data is stored

We store data in the United States ([AWS region]). If you're outside the US, your data is transferred there. For people in the EU, UK and Switzerland, we rely on the European Commission's standard contractual clauses and equivalent safeguards in our contracts with service providers.

14. Age limit

Job Planter is for people 18 and older. We don't knowingly collect data from anyone younger. If you believe someone under 18 has an account, tell us and we'll delete it.

15. Changes to this policy

If we make a significant change, we'll email you and show a notice in the app at least 30 days before it takes effect. We'll never start reading data we can't read today: changing that would take a different product, not a policy update. Earlier versions of this policy stay available on request.

16. Contact us

Email privacy@jobplanter.com, or write to [company legal name], [postal address]. [EU and UK representative, if required]