Privacy
This page describes what Joblyapply AI does with the information you give it. It describes how the service currently works, in plain terms.
What we collect
We collect only what the product needs to do its job:
- Your account. Your email address, the name you enter at signup, and your password, which is handled and stored by our authentication provider and is never visible to us in readable form.
- CVs you upload. The file itself, and the structured details extracted from it — such as your contact details, work history, education, skills and certifications.
- Job descriptions you paste, and the requirements extracted from them.
- Applications you generate, including the tailored resumes, cover letters, evidence matrices and exported PDF and DOCX documents, plus a record of which applications you are tracking and their status.
- Usage and billing records, such as how many analyses you have run in the current period and your subscription status.
How we use it
Your CV and the job descriptions you paste are used to analyse how well your experience matches a role, to build an evidence matrix showing which requirements your CV actually supports, and to draft a tailored resume and cover letter. Usage records are used to apply the limits of your plan. We do not sell your data, and we do not use your CV or job descriptions for advertising.
Who we share it with
Joblyapply AI relies on the services below. Some are only used when the service has been configured for a given deployment.
- Supabase
Hosts the account system, the application database, and the private file storage where uploaded CVs and generated documents are kept.
What it receives: Your email address, your account credentials, every record described above, and your uploaded CV and generated document files.
- OpenAIused only when configured
Performs the language-model work: reading a CV into structured data, reading a job description into structured requirements, and drafting a tailored resume and cover letter.
What it receives: The text of your CV and of the job descriptions you paste, along with the structured data derived from them.
- Stripeused only when configured
Processes subscription payments.
What it receives: Your billing details, which you enter on Stripe's own hosted pages. Card details are never sent to or stored by this application.
- Resendused only when configured
Delivers the application-package emails you request, sent only to the email address on your own account.
What it receives: Your email address and the resume or cover letter documents attached to that message.
- Sentryused only when configured
Collects error reports so faults can be diagnosed and fixed.
What it receives: Technical error information. Session replay is not enabled, and request bodies, cookies and sensitive headers are stripped before an error report is sent.
- PostHogused only when configured
Records product analytics so we can see which features are used.
What it receives: Page views and four product events (a job analyzed, an application package generated, an application tracked, a subscription checkout started), associated with your user id. CV, job-description and generated-application text is never sent.
Your control over your data
- You can delete an individual CV or a tracked application at any time from your dashboard.
- You can download a copy of your data from your account page, as a single JSON file.
- You can delete your account from your account page. Doing so removes your account, your database records, and your uploaded and generated files. This cannot be undone.
Storage and access
Uploaded CVs and generated documents are held in private storage. They are not publicly accessible, and links to your files are short-lived and issued only to you. The database restricts every record to the account that owns it.
Contact
Questions about your data can be sent to privacy@example.com.
See also our Terms of Service.