Privacy Policy
Last updated: May 2026
1. Information We Collect
We collect information you provide directly: name, email, resume PDF, job preferences, and writing style samples. We also collect activity data such as which jobs you applied to, application timestamps, and per-platform application counts.
2. How We Use Your Information
Your data is used to: find matching jobs, generate personalized cover letters via the Anthropic Claude API, submit applications on your behalf, and surface usage statistics in your dashboard. We never sell your personal data to third parties.
3. The JobFlow Chrome Extension
The JobFlow Chrome extension runs only on indeed.com and on the JobFlow dashboard domain. On indeed.com it reads job titles, company names, and form fields, then uses your stored profile to autofill the application; it submits an application only after you explicitly start a campaign in the extension popup or on the dashboard.
The extension stores your Supabase session token in chrome.storage.local so it can authenticate API requests; this token never leaves your browser except when calling the JobFlow backend. Cached profile data is stored for 5 minutes to reduce API load. No data is shared with any third party other than the JobFlow backend, the Anthropic API (cover letters), and Supabase (storage).
JobFlow is not affiliated with Indeed. Users are solely responsible for ensuring their use of automation tools complies with Indeed's terms of service and any other platform's terms they apply on.
4. Data Storage & Security
Your data is stored in Supabase with row-level security so each user can only access their own rows. Resume PDFs are stored in a private Supabase Storage bucket keyed by your user ID and downloaded only by the backend during application submissions. All transport is HTTPS.
5. Third-Party Services
We use Supabase (auth + Postgres + Storage), Anthropic Claude (cover letter generation), Google OAuth (optional sign-in), and the job platforms you connect (Indeed, RemoteOK, Wellfound). We share with each only the data needed for its function.
6. Your Rights
You can view, update, or delete your personal data at any time through your account settings or by emailing us. Account deletion removes your profile, resume, and stored sessions across all devices and extensions within 30 days.
7. Contact
Questions about this privacy policy or about data we hold on you: support@jobflow.app.