Privacy
Last updated September 30, 2026 (version 2026-09-30)
The short version
JobWhat is a browser extension. Everything you put into it — your profile, resume, cover letter, application log, settings — is stored by Chrome on your computer, in the extension's own storage. We never sell your data. Optional community features (the map, company locations and logos, interview reviews, company ratings, pay & benefits, and employer communities) are off by default; if enabled, they share only anonymous or voluntary data with other JobWhat users. The company directory is always on: it sends only public company information seen on LinkedIn pages, as described below. A few service providers process data on our behalf so the product works: Cloudflare hosts our server (the “Worker”) and its storage, Stripe processes payments, Google Sheets holds our subscription records, error reports and feedback, Google Analytics receives anonymous usage counts, OpenRouter runs the AI features you switch on, and logo.dev serves company logos. Each gets only what its feature needs. Your profile, resume details and job log leave your browser only for AI features you switch on, cloud sync you turn on, and the reports described below.
What the extension sends, and when
- Payments and subscription check. Stripe processes your payment; your card details go to Stripe and never reach us. When you subscribe or unlock Pro, the email address you use is sent to our Worker, which asks Stripe whether it has a live subscription and returns a signed token the extension keeps locally and re-checks every few days. We keep a subscription record in a private Google Sheet: your email, Stripe customer and subscription ids, status, plan and product, amount and currency, the current billing period's end date, and when the record was written. Stripe's own handling of your payment is covered by Stripe's privacy policy.
- AI answers. Optional, on Free and Pro, and off by default (“Use AI models for unknown questions”). When a form has questions the built-in rules cannot answer, the extension sends to our Worker: those questions and their answer options, your saved profile — including any voluntary EEO / demographic answers you saved (gender, race / ethnicity, Hispanic / Latino, sexual orientation, transgender status, veteran status, disability and age range) — your saved custom Q&A, the job title and company, the fields already filled on that form and their values, and, for essay questions, a text summary of your resume. Never your resume or cover letter file, passwords or job log. The Worker forwards this to our AI provider, OpenRouter, which runs it on TypeSafe's AI model or a language model (by default Google Gemini) solely to generate the answers; TypeSafe is called directly only as a fallback. We don't keep the request; the Worker keeps only a daily count of questions per subscription or free account. OpenRouter and the model provider process it under their own privacy policies.
- AI resume scoring and analysis. Also optional and behind the same setting (Free and Pro). When you score or analyze a job — or automatically, if you turned automatic analysis on — the extension sends to our Worker the job's title, company, location, link and description, a text summary of your resume (name, contact details, work history, education, skills), your skills list, your saved profile (including any voluntary EEO / demographic answers) and saved custom Q&A. The Worker forwards what the scoring needs to OpenRouter (TypeSafe's AI model and a language model; TypeSafe directly only as a fallback) solely to produce the score and suggestions. Your resume file itself is not sent. We don't keep your data from these requests; the only thing cached is the list of requirements extracted from the public job description (up to 7 days, shared across users, with nothing about you in it), plus monthly usage counts.
- Quick AI match and title match. Optional scoring helpers on job boards. Quick AI match sends a short résumé summary and the job's title and description to our Worker for a quick fit score. Title match sends the listing title and your desired job titles when a local check can't decide; the Worker returns a fit level. Both use your AI allowance, like every AI feature. Never your résumé or cover letter file.
- Interview prep. Optional, and only when you ask for a prep brief on a job: the company name, job title, location, link, and up to a capped amount of the public job description go to our Worker, which uses OpenRouter to produce the brief. Your résumé and profile are not sent. Shared company/job briefs may be cached without anything about you; fresh generation uses your AI allowance.
- Daily AI brief (Pro). When you make a brief: brief facts (counts, job titles and companies in the brief, reminder times), your first name, chosen tone, voice, language and optional profession go to our Worker, which uses AI providers to write the script and (for audio or video) synthesize speech. Optional About you details (gender, age band, ethnicity or background) are sent only for a Video brief and only after you consent — and only to draw the main character, never for the script or voice. Facts and About you are not stored by us. Brief video, audio or slides you make are kept privately for 30 days (or until you delete them), then removed. AI providers process the request under their own privacy policies.
- Resume AI. Only when you ask it to rewrite your resume for a job: the job details, your resume text (up to 12,000 characters) and summary, your name, email, phone and location for the resume header, an optional photo you added for it, and the analysis results go to our Worker, which uses OpenRouter to rewrite the text and then builds the PDF. Not stored by us beyond a daily usage count. Template downloads (Pro) send the same résumé text, header details and optional photo so our Worker can lay out the PDF; that request doesn't go to OpenRouter and is neither stored nor logged.
- Detect Careers Page. Off by default, and only on company sites you add (Chrome asks you to allow each site). On those sites the extension reads the page's address, its title and up to 3,200 characters of its visible text, and treats the page as a job posting: when resume analysis runs for it (automatically if automatic analysis is on, otherwise when you press Analyze), that address, title and text go through our Worker to OpenRouter, exactly like AI resume scoring above. Pages on sites you haven't added are never read or sent.
- Job Alerts list scan. When you add a non-LinkedIn job list as a source (for example a public GitHub file or Google Sheets link), the extension asks our Worker to fetch that URL. It sends your Pro token or free-account identity, the public http(s) URL, and optionally a content hash so an unchanged list can skip a re-fetch. The Worker downloads the page, extracts job links (URL, company, title, location and link kind), and caches that extracted list by URL and content hash for about six hours in Cloudflare's edge cache — not in a per-user database. The source URL itself is not stored as a user record; rate limits track how often your identity and IP request scans.
- Community activity. The community map is not enabled by default. If it is enabled for you and “Share anonymous activity with the community map” is on, when you apply to, watch or view a job the extension records an anonymous city-level count (event type, city, month). Counts are batched on your computer and sent together every few minutes (or sooner once enough distinct cities are buffered), so individual events aren't sent as they happen. No job titles, companies, links, names or account ids.
- Company locations and logos. Also part of the map feature, which is not enabled by default. If the map is on, to pin jobs the extension asks our shared cache for a company's location using only the company and city names; misses are looked up on OpenStreetMap's Nominatim, which your browser contacts directly (so Nominatim sees the city or company name and your IP address, as any website would). Locations found are written back to the shared cache so other users don't have to look them up again.
- Company logos from logo.dev. Company logos come from logo.dev, a logo service. The extension doesn't save or share LinkedIn logo links; your browser loads each logo straight from logo.dev (img.logo.dev), so logo.dev receives the company's website domain and, as with any image on the web, your IP address and browser details. No page address is sent (referrer is turned off), and nothing about you or your job log. To find a company's domain, our Worker sends logo.dev only the company name. Logos are provided by logo.dev under its own privacy policy; see docs.jobwhat.app/image-credits.
- Company directory. Always on, with no separate switch, because it holds only public company information, never anything about you. On LinkedIn pages you view, the extension reads the company names shown on the page together with LinkedIn's public company number and company page name (for example “acme-robotics”), plus the company's website domain when a job's outside apply link already showed it (only the bare domain, such as “acme-robotics.example”, never the link). These are batched on your computer and sent to our Worker at most a few times an hour, each company at most once a month. Never your identity or LinkedIn account, the jobs you look at (titles, descriptions, ids or links), your searches or filters, page addresses, or any logos or images. The Worker stores only a keyed hash of your random install id and of your network (never the id or your IP address), so it can require several different people on different networks to report the same company before publishing it. The combined list of company names, LinkedIn company numbers, page names and website domains is published publicly so JobWhat users can pick companies by name. Company logos shown with it are loaded by your browser from Logo.dev using only the company's website domain, without sending the page address.
- Reviews, pay and interview feedback. Company reviews, pay & benefits and interview reviews are not enabled by default. If enabled for you: only what you type into those forms, and only when you press submit. Stored with an anonymous install id so you can edit or delete it — never your name, email or job log.
- Plan usage. Monthly counts of metered actions (for example autofills and queued jobs), and how much of your AI allowance has been used, recorded against your install id or the email you subscribed with, so your plan's limits can be enforced.
- Anonymous usage analytics. Feature events such as “autofill used” or “job logged”, with a random install id created on your computer, are queued on your computer and sent in a batch through our Worker to Google Analytics about every three hours (and sooner for a few realtime events such as install and upgrade). The one exception is a single “first visit” ping at install, which the extension sends straight to Google Analytics (google-analytics.com) with the same random id, the extension version and build. No user id and nothing derived from your email is sent, including for Pro subscribers. Never job titles, companies, links, emails or resume content. Turn it off any time in Settings → Advanced with “Send anonymous usage analytics”; anything still queued is discarded.
- Cloud sync (Pro, including VIP codes). Only if you turn on Sync my data to the cloud: your profile (including any voluntary EEO / demographic answers you saved), settings, job log, Workday answers, custom Q&A and resume text summary are backed up to our Worker's storage on Cloudflare so you can restore them on another computer. Résumé and cover letter files are not synced, only their names. Passwords are never synced: your saved Workday account password stays on this computer. A backup is deleted automatically 90 days after your Pro subscription or VIP code ends.
- Shared form questions. When a form asks a required question that nothing could answer — not the built-in rules, not your saved answers, not the AI — the extension sends that question's label and its answer options (for example “Which office is closest to you?” and “Austin / Denver”), the board's job id and, for a queued job, the LinkedIn job id to our Worker, so the next person who queues that job is asked before their queue runs. Never your answers, never anything from your profile. Off in Settings if you prefer.
- Error reports. When a saved answer doesn't match a form's options or a field fails to fill, the extension sends a report so we can fix it: the field's label and type, the value it tried to enter (up to 80 characters; password and social security number fields are redacted), the field's answer options, the page address without its query string, the application site, the extension build, your browser version and user agent. Because the value comes from your profile, it can include contact details or a voluntary EEO answer. Reports are stored in our private Errors Google Sheet and used only to debug and fix autofill, and kept only as long as needed to fix the issue. Each report carries a random ticket id that isn't linked to your install; the extension checks those ticket ids once a day and tells you in the extension when your issue is fixed. For fields a fix targets, it also sends counts of whether the fill worked (fix, build, application site, field and outcome — no addresses, values or labels). When a Job Alerts source check fails, the extension may also send a redacted report once per distinct error per day (source type, host and path with token-like query values stripped, failed stage, message, status, time, extension build, browser, and a short stack trace) to our Worker, which writes it to Cloudflare Workers Logs only — not to a database. All of this is off with “Share when a saved answer doesn't match a form's options”.
- Account check. So the free AI can't be claimed again by reinstalling, your free account is tied to one job-board account. The extension reads the id of the account you're signed in with (below), turns it into a one-way SHA-256 hash on your computer, and sends only that hash to our Worker. The id itself is never sent or stored, and the hash cannot be turned back into you. Until a board account is found, a hash of a random id created at install is used instead.
- Account check: LinkedIn. The extension loads your own LinkedIn profile page (linkedin.com/in/me) with your LinkedIn session and reads your member id from it.
- Account check: Indeed and Glassdoor. The extension reads your account id — or, when the page shows no id, your account email — from an Indeed or Glassdoor page. It tries a tab you already have open first and, for Indeed, a background request to indeed.com; if that doesn't work, it opens indeed.com or glassdoor.com in an inactive background tab, reads the id, and closes the tab.
- Account check: ZipRecruiter. The same for ZipRecruiter: an open ZipRecruiter tab, then ZipRecruiter's own account-identity request, then up to four ZipRecruiter pages (home, about, resume and job-seeker home) opened one at a time in inactive background tabs and closed again. The id can come from the page, the site's local storage or readable cookies, or the account email shown.
- Account check: when it runs. When you link a board during setup or in Settings, and automatically — at most once an hour per board — when you visit LinkedIn, Indeed, Glassdoor or ZipRecruiter while your free account isn't yet tied to a job-board account. It stops once an account is linked. Background tabs open without taking focus and close as soon as the id is read or after about 20 seconds.
- Feedback. Only when you press Send in the feedback form (or answer the uninstall survey): your star rating, category, message, optional email, the extension's build and version, your plan and your browser's user agent — on the website form, also the page address — plus an optional PNG, JPG or TXT attachment up to 5 MB. Stored in our Worker's private storage on Cloudflare and deleted after one year, attachments included. Nothing from your profile or log.
- Abuse protection. If a request to our Worker is rate-limited, we log the time, the path, your IP address and, for subscription checks, the email used, so we can stop abuse.
That is the complete list. The pages you visit are not transmitted, except as described above: the job posting you score or analyze, form questions sent for AI answers or shared form questions, text from pages on sites where you turn on Detect Careers Page, a public job-list URL you add for Job Alerts, Daily AI brief facts (and optional About you for Video), the address of an application page in an error report, a redacted Job Alerts source URL in a check-failure error report, the job-board account id read for the account check (sent only as a hash), and public company names, LinkedIn company numbers, page names and website domains for the company directory. Your job log leaves the browser only with cloud sync on. With AI features and cloud sync off (the defaults), your profile and form answers are never sent, apart from the single attempted value in an error report (if error reports are on).
AI-generated briefs, audio and video
Scripts, synthetic voices and video visuals in Daily AI briefs are produced by AI models — not written or reviewed by a person before you see or hear them — and can be inaccurate. Some tones (especially opt-in tones like Disparaging, and sarcastic or humorous personas) can include strong language, profanity, sarcasm or themes some users may find offensive; you choose the tone and can switch or turn it off at any time. AI voices are synthetic and are not clones of any real person; any resemblance to you or someone you know (voice, accent, name or situation) is coincidental. We instruct the AI to stay civil within these limits (no slurs, hate or identity attacks, threats, self-harm content, or targeting real people) and apply automated safety checks, but we can't guarantee every output. Report problems through jobwhat.app/support or Send feedback in the extension. Output comes from AI models; to the extent allowed by law, JobWhat isn't liable for it, and it isn't professional, legal or career advice.
Community data
Some features get better when JobWhat users pool what they see: the community map, company locations on the map, interview reviews, company ratings, pay & benefits, and employer communities. All of these are off by default (not enabled until we turn them on for your install). Here is what they would cover if enabled, and how to control them.
- What's shared (only if the feature is enabled). City-level activity counts (applied, watched, viewed), company locations and website domains (for logos) for the map, and the interview reviews, company reviews and pay & benefits you choose to submit. Never your profile, resume, job log or answers to application questions.
- Anonymized and aggregated. Community data carries no name, email or account id, and is shown as aggregates. The activity map shows city-level totals only. Reviews, ratings and pay stay hidden until enough people have contributed — for example, a pay median needs at least 5 submissions and a company rating at least 3.
- Company activity for JobWhat Insights. This Insights feed is also off by default. When it is enabled and “Share anonymous company activity (JobWhat Insights)” is on, the extension also sends, for jobs you apply to, save or view: the company name, a role family worked out on your computer from the job title (for example “data” or “design”, never the title itself), the job's location text (which the server reduces to a metro area), whether it's remote, hybrid or on-site, and the day. The server replaces your random install id with a keyed hash that changes every day, and never stores the id, your IP, job links, job titles or the location text. A one-time notice in the extension explains this before anything is sent. Nothing is shown until enough different people contribute (at least 5 for a map area, 8 for a trending company); small groups are hidden, numbers are rounded, and everything publishes with a 2-day delay. Sample/mock jobs are never sent, and the setting is off whenever community activity sharing is off.
- Communities. Employer communities are off by default. Only if the feature is enabled and you join one: to suggest communities for the employers on your resume, the extension sends those employer names to our Worker. When you join, you get a random handle; messages, direct messages, pins and reports you post are stored by our Worker and shown to that community's members (and its moderators), never with your name, email, resume or job log. You can leave a community and delete your messages, or delete all your community data at once.
- Never sold. Community data is shared only with other JobWhat users. We don't sell it, and we don't give it to advertisers or recruiters.
- Opting out. In Settings → Advanced, turn off “Share anonymous company activity (JobWhat Insights)” to stop company activity for Insights, “Share anonymous activity with the community map” to stop activity counts and location write-backs, and “Send anonymous usage analytics” to stop analytics. “Show community interview reviews”, community pay & benefits and community company ratings each switch that feature — and its network calls — off. “Share the questions a form asked that nothing could answer” and “Share when a saved answer doesn't match a form's options” control form sharing.
- Deleting your submissions. Open your review or pay entry from the job log and press Delete; it is removed for everyone straight away. Activity counts are anonymous and merged into city totals, so they can't be traced back to you or removed individually. For anything else, use Send feedback in the extension.
What the extension reads
To do its job the extension reads the pages it runs on: job application forms on Greenhouse, Ashby, Lever, Workday, Gem and Rippling, job cards on LinkedIn and Indeed (and Glassdoor, ZipRecruiter and Craigslist if you turn them on), and company careers pages you add for Detect Careers Page. It uses what it reads to fill fields, place its buttons and colour cards, and to record the title, company, location and link of jobs you log, view, hide or queue — in your local log only. For the account check it also reads your account id from the job-board pages described above. For a Job Alerts list source, our Worker fetches only the public URL you added.
Pro waitlist
If you join the Pro waitlist we store your name, your email and when you joined, and email you a confirmation and, once you're approved, the steps to switch Pro on. We don't send marketing emails and never sell your details. You can leave with the link in the confirmation email or in the extension's Plan tab. We delete a waitlist entry 12 months after you join if you're never approved, and 12 months after your waitlist Pro ends if you are.
Signup waitlist
If you join the signup waitlist we store your email, when you joined, and — if you choose to answer — what you dislike about your job search process today. Optional feedback answers are stored indefinitely so we can improve onboarding, and are viewable by JobWhat staff. You can ask us to delete your waitlist entry and feedback through the existing account-deletion path (jobwhat.app/support or Send feedback in the extension). We email you when you join and when a seat opens; you can unsubscribe anytime. We never sell your details.
Your control
Settings → Your data exports everything as JSON (saved passwords are left out) or erases it. Uninstalling the extension deletes its local storage, including any downloaded model; delete reviews or pay you submitted first if you want them gone too. Turning cloud sync off stops backups; the last backup is deleted automatically 90 days after your Pro subscription or VIP code ends, or sooner if you ask us. Switching off “Use AI models for unknown questions” stops all AI requests, and each sharing and analytics switch in Settings → Advanced stops that data straight away. The company directory has no switch of its own (it holds only public company information); it stops when you uninstall the extension, and you can ask us to remove a company from the published list. Pro can be cancelled at any time from the Plan tab; subscription records are kept as long as we need them for billing, tax and accounting. To have your cloud backup, error reports or subscription record deleted, contact us as below.
Terms acceptance and link opens
When you accept the Terms of Use and this Privacy Policy during extension onboarding, we store a consent record on our Worker (Cloudflare KV) keyed by your install id and, if you have unlocked Pro, your email: the Terms version, Privacy version, acceptance time, onboarding surface and extension build. If you open the Terms or Privacy links from that flow, we also store the time of each open (terms_opened / privacy_opened). We use this only to answer “did this user accept, and which version?” for support and compliance — not for advertising. No résumé, job log or profile answers are stored in that record. You can ask us to delete it through support. See also the Terms of Use.
Contact
Questions or requests about your data: use Send feedback in the extension (the speech bubble in the header) and include an email if you want a reply. That form is the support channel. See also the Terms of Use.