Privacy policy
Draft. This policy is under legal review and is not in effect yet. It describes how Job Planter will work when it opens to users.
The short version
- We can't read your data. Your resumes, jobs, answers and applications are encrypted on your device before they reach us, and only your devices hold the keys.
- We see only what we need to run your account: your email address, your plan, how much you use the AI features, and basic facts about your devices. The full list is below.
- Your most sensitive answers never reach us. Answers about demographics, disability, veteran status, health or criminal history stay in your browser.
- AI features see only what a task needs, without your contact details, and nothing is kept afterwards.
- We don't sell your data, show ads, or use analytics or tracking scripts.
- Because we can't read your data, we can't recover it. Keep your recovery key safe.
Contents
- Who we are
- How your data is protected
- What we collect and can read
- What we store but can't read
- What we never collect
- AI features
- The Chrome extension
- Cookies and browser storage
- Who we share data with
- How long we keep data
- Your choices and rights
- Security
- Where data is stored
- Age limit
- Changes to this policy
- Contact us
1. Who we are
Job Planter is run by [company legal name], [registered address] ("Job Planter", "we", "us"). This policy covers the Job Planter web app at app.jobplanter.com, the Job Planter Chrome extension, and this website. For personal data we process to run the service, we are the controller.
2. How your data is protected
Job Planter is end-to-end encrypted. When you save a resume, a job, an answer or anything else, your browser encrypts it before sending it to us. We store only the encrypted version. Without your keys it's unreadable to us, to our hosting provider, and to anyone who gets a copy of our servers or backups.
Your keys stay on your devices. They're unlocked by your passkey, by your recovery key, or by approval from another device you're already signed in on. We never receive them.
That has one consequence you should know about: if you lose your passkeys, your recovery key and every device you're signed in on, nobody can recover your data, including us. Your account and subscription stay, and you can start again with empty data.
3. What we collect and can read
A few things have to stay readable for the service to work. This is the complete list. We won't add to it without updating this policy.
| Data | Why we need it | Legal basis (EU and UK) |
|---|---|---|
| Your email address | Signing in, account emails (codes, security alerts, receipts) and legal notices | Contract |
| Sign-in details: your account id, how you signed in (password, passkey or Google), sign-in times and IP addresses | Keeping your account secure and preventing abuse | Contract; legitimate interests (security) |
| Your plan, and the Stripe customer and subscription ids and status | Billing | Contract |
| Usage: which AI feature ran, the model, the amount of text processed (token counts), the cost and the time | Plan allowances, billing, controlling costs, and tax records | Contract; legal obligation |
| Sync information: an id, type, size, version and timestamps for each encrypted item | Keeping your devices in sync | Contract |
| Devices: an id, a short name such as "Chrome on Windows", a public key, and when it was last used | Listing your devices, approving new ones, and removing lost ones | Contract; legitimate interests (security) |
| Records of what you agreed to (which version of these terms and this policy, and when), and security events such as a device being added or a recovery key being replaced | Proof of consent, and account security | Legal obligation; legitimate interests (security) |
We don't hold your name, postal address or card details. Stripe collects those when you pay. When you sign in with Google, we ask Google only for your email address and whether it's verified, not your name or profile picture.
The sync information and usage records show some patterns: roughly how many items you have, their sizes, and when you use the AI features. They never show what those items contain.
4. What we store but can't read
Everything you put into Job Planter is stored encrypted: your profile, resumes and their tailored versions, cover letters, saved answers, the jobs you save (postings, notes, match results and summaries), your applications and tracker board, scanned application forms, learned form patterns, and your settings. We can't read, search, analyze or share any of it.
5. What we never collect
- Sensitive answers. Answers about gender, race or ethnicity, disability, veteran status, sexual orientation, religion, health, criminal history, or your date of birth or age never reach our servers, not even encrypted. The extension keeps them in your browser, in Chrome's own sync storage. If Chrome sync is on, Google stores them in your Google account and syncs them to your other Chrome browsers. Google encrypts them end to end only if you've set a Chrome sync passphrase. If sync is off, they stay on that one device.
- Passwords for job sites. The extension leaves password fields alone, so Chrome's password manager can save and fill them.
- Government ID numbers, bank or card numbers, and verification codes. Job Planter doesn't ask for them or save them.
- Your browsing history. The extension doesn't record which sites you visit.
6. AI features
Tailoring a resume, writing a cover letter, matching you to a job, summarizing a job and its company, and importing a resume use AI models. For each task:
- Your device sends only the text that task needs, over an encrypted connection. It removes your contact details (name, email, phone, address and profile links) first, and puts them back into the result.
- Our servers process the text in memory while the task runs and don't store or log it. The result goes back to your device, which encrypts it before saving.
- We send the text to AI model providers through OpenRouter, using settings that require the providers not to retain it and not to train on it. Matching uses the Jev model from TypeSafe. Job and company summaries may look up the company's public website; they send only the job and company details, not anything about you.
- Sensitive answers (section 5) are never sent to an AI model.
AI output can be wrong. You review everything before you use it, and the extension never submits an application for you. Answers with legal weight, such as your work authorization, are only ever filled from answers you gave.
7. The Chrome extension
The extension reads job postings you choose to save, and application forms on job sites when you use it to fill them. It uses what it reads to save the job and fill the form with your answers. It never submits a form.
It asks for broad site access and the debugger permission because application forms live on many different job sites and are often built in ways ordinary page access can't fill. It uses these only on pages where you use it or on known job sites, and not to collect browsing data.
Job Planter's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data the extension handles is used only to provide its features to you. It is not sold, not used for advertising or creditworthiness, and not read by people except with your permission, for security, or where the law requires.
8. Cookies and browser storage
The web app sets one cookie, which keeps you signed in. Your browser also stores your encryption keys and an encrypted copy of your data, so the app works quickly. These are strictly necessary for the service, and signing out removes them.
We don't use analytics, advertising or tracking cookies, and we load no third-party scripts, with one exception: the billing page loads Stripe's payment script, which Stripe uses to process payments and prevent fraud. This website sets no cookies at all.
9. Who we share data with
We don't sell your personal information, and we don't share it for advertising.
We use these service providers, under contracts that limit them to providing their service to us:
| Provider | What for | What they receive |
|---|---|---|
| Amazon Web Services | Hosting, storage, sign-in (Amazon Cognito) and account emails (Amazon SES) | The readable data in section 3, and your encrypted data |
| Stripe | Payments, receipts and tax | Your email, and the payment details you give Stripe directly |
| OpenRouter, and the AI model providers it routes to | AI features | The text of each task, without your contact details, not retained |
| TypeSafe | Job matching (the Jev model) | The text matching needs, without your contact details, not retained |
| "Sign in with Google", if you use it | Only the sign-in itself | |
| Cloudflare | Domain name service, and hosting this website | Nothing from the app: app traffic doesn't pass through Cloudflare |
Legal requests. We disclose data only in response to valid legal process, only what the request covers, and we tell you first unless the law forbids it. Even then, all we can hand over is the readable data in section 3 and encrypted data we can't decrypt. We'll publish a yearly count of the requests we receive.
Business transfers. If Job Planter is sold or merged, your data would move under this policy, and we'll tell you before it does. Your encrypted data stays unreadable to the new owner too.
10. How long we keep data
| Data | Kept for |
|---|---|
| Your account and encrypted data | Until you delete it or your account, or after [24] months without signing in. We email you before deleting an inactive account |
| Copies after you delete something | Old file versions for up to 30 days; encrypted backups for up to 35 days |
| Server logs | 30 days. They contain ids and error codes, never your content |
| Security records (sign-ins, devices added or removed) | 1 year |
| Billing and usage records | As long as tax law requires. After your account is deleted they're no longer linked to your email |
When you delete your account, we delete your data, devices and keys, your sign-in account and your Stripe customer record right away, apart from the backup and record-keeping windows above. Backups hold only encrypted data, and if we ever restore one, deletions made since are applied again before it's used.
11. Your choices and rights
- See and export your data. In the app, export everything as a file. Your device builds it from your decrypted data.
- Correct it. You can edit everything in the app.
- Delete it. Delete items, or your whole account, in the app.
- Ask us. Email privacy@jobplanter.com for anything else.
Depending on where you live, the law may give you further rights. In the EU and UK: to object to or restrict our processing, to data portability, and to complain to your data protection authority. In California and other US states: to know what we collect, to delete and correct it, and not to be treated differently for exercising these rights. We honor these requests for everyone, wherever you live, and we answer within 30 days. We'll ask you to confirm the request from your signed-in account, or from your account's email address. Someone you authorize can make a request for you.
If you've lost access to your encrypted data, we can give you the readable data in section 3, but not the rest.
12. Security
Besides end-to-end encryption, we protect the service with encrypted connections, strict limits on who can access our systems and how, and monitoring for changes to the code we deliver to your browser. If a breach affects your personal data, we'll tell you and the authorities as the law requires. To report a vulnerability, see our security page.
13. Where data is stored
We store data in the United States ([AWS region]). If you're outside the US, your data is transferred there. For people in the EU, UK and Switzerland, we rely on the European Commission's standard contractual clauses and equivalent safeguards in our contracts with service providers.
14. Age limit
Job Planter is for people 18 and older. We don't knowingly collect data from anyone younger. If you believe someone under 18 has an account, tell us and we'll delete it.
15. Changes to this policy
If we make a significant change, we'll email you and show a notice in the app at least 30 days before it takes effect. We'll never start reading data we can't read today: changing that would take a different product, not a policy update. Earlier versions of this policy stay available on request.
16. Contact us
Email privacy@jobplanter.com, or write to [company legal name], [postal address]. [EU and UK representative, if required]