Overview
JobTailor ("we," "our," or "us") operates jobtailor.io, an AI-powered resume analysis and cover letter generation platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
By accessing or using JobTailor, you agree to the collection and use of information in accordance with this policy. If you disagree with any part of this policy, please discontinue use of our service.
We are committed to GDPR and CCPA compliance. We never sell your personal data to third parties.
Information We Collect
Information You Provide Directly
- Account information: Your name, email address, and password when you register.
- Resume content: PDF files you upload for analysis. These are processed by our AI and stored in your account history.
- Job descriptions: Text or URLs you submit to compare against your resume.
- Cover letter data: Job-related inputs used to generate cover letters.
- Payment information: Billing details processed securely by Stripe. We do not store your full card number.
Information Collected Automatically
- Usage data: Pages visited, features used, analysis counts, and timestamps.
- Device information: Browser type, operating system, IP address, and referring URLs.
- Cookies and tracking: Session cookies and analytics identifiers (see Cookies section).
How We Use Your Data
We use the information we collect to:
- Provide, operate, and improve the JobTailor service
- Analyze your resume against job descriptions and generate AI-powered feedback
- Generate cover letters based on your inputs
- Manage your account, subscription, and billing through Stripe
- Enforce usage limits (free tier daily limits, Pro tier hourly limits)
- Send transactional emails such as account confirmations and billing receipts
- Respond to customer support requests
- Monitor for abuse, fraud, and security threats
- Comply with legal obligations
Your resume content is sent to OpenAI's API for AI analysis. OpenAI does not use API inputs to train their models. See OpenAI's privacy policy for details.
Data Storage & Security
Your data is stored in a PostgreSQL database hosted on Vercel's infrastructure, protected by industry-standard security practices including:
- Encryption in transit via TLS/HTTPS for all data transfers
- Encryption at rest for your stored data
- Access controls limiting data access to authorized personnel only
- Regular security reviews and dependency updates
- API route protection via authenticated middleware
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
Your data is primarily stored in the United States. If you are accessing JobTailor from outside the United States, you consent to your data being transferred to and processed in the United States.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request that we delete your account and associated data ("right to be forgotten").
- Portability: Request your data in a machine-readable format.
- Objection: Object to certain types of processing, including direct marketing.
- Restriction: Request that we restrict processing of your data under certain circumstances.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
If you are located in the European Economic Area (EEA) or United Kingdom, you have rights under GDPR. If you are a California resident, you have rights under CCPA/CPRA. Contact us to exercise any of these rights.
To exercise your rights, contact us at privacy@jobtailor.io. We will respond within 30 days.
Data Retention
We retain your data for as long as your account is active or as needed to provide you with our services:
- Account data: Retained for the duration of your account plus 90 days after deletion.
- Resume and analysis history: Retained while your account is active. Deleted within 30 days of account deletion.
- Cover letters: Retained while your account is active. Deleted within 30 days of account deletion.
- Payment records: Stripe retains billing records per their own retention policy (typically 7 years for legal compliance). We retain subscription history indefinitely for audit trails and resubscription flows โ this includes your Stripe Customer ID even after cancellation.
- Logs and analytics: Aggregated usage logs are retained for up to 12 months.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you via email if the changes are material
- Post a prominent notice on our website
Your continued use of JobTailor after any changes to this policy constitutes your acceptance of the updated terms. We encourage you to review this policy periodically.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us:
We are committed to resolving any privacy concerns promptly. If you feel we have not adequately addressed your concern, you have the right to contact your local data protection authority.