Privacy policy
Last updated 27 September 2026
This page lists what this instance of jobfetch keeps about you, why, who else sees it, and for how long. It is run by one person for their own job search and for the people they invite. Your data is not sold, and it is not used for advertising.
What is kept for your account
- Sign-in. Your user name and a hash of your password. The password itself is never stored.
- Your search. The postings you mark, their status history, your notes and dates, the people you add as contacts, your home page and alert preferences.
- Your profile. The answers you give for application forms, your resume source and PDF, and any transcripts you upload. These sit in a private folder on the server that only your account reads.
- What is written for you. Tailored resumes, cover letters and form answers, with the list of changes made.
- The browser extension. When it fills a form: the address of the application page, the questions the form asked, the options it offered, what was filled or left blank, and the answer used. It signs in with a token you can revoke from your Profile.
- Alerts. Each Discord webhook address you add and its filters. The webhook is shown back to you masked and never logged.
- Mail status. Only when the person who runs the instance connects their own mailbox. It is opened read-only, and for each application email it recognises it keeps the sender, subject, date and what it changed.
Sign-ins and page views
Every sign-in, failed sign-in and page view is recorded with your IP address and your browser's user agent, to spot misuse. The people who administer the instance can see this record. It is deleted after 90 days.
Cookies
One session cookie keeps you signed in and protects forms from being sent by another site. It signs you out after a period of inactivity. There are no tracking or advertising cookies.
Who else sees your data
- Anthropic. When you ask for a tailored resume, a cover letter or form answers, your resume source, the posting and the profile answers needed are sent to Anthropic's Claude to write them.
- Discord. An alert sends the title, employer and link of matching postings to the webhook you gave.
- Microsoft Azure. The server runs on an Azure virtual machine in the United States.
- Google Fonts. Your browser loads the page's typeface from Google, which sees your IP address when it does.
- Employers. Only what you submit on their own application forms.
Backups
The database and the private files are copied every night. The server keeps the 14 nightly backups it made most recently, and the person who runs the instance copies them to their own computer.
Your choices
- See and change your profile, preferences and alerts yourself, from Profile, Home and Alerts.
- Revoke an extension token from your Profile at any time.
- To have your account and everything kept for it deleted, ask the person who invited you. Backups made before that roll off within 14 days.
Changes
This policy can change. The date at the top says when it last did. The terms of service cover how the tool may be used.