JobPilot

Privacy Policy

Effective 4 September 2026. This policy describes what JobPilot collects when you use getjobpilot.ca and the product at app.getjobpilot.ca, how we use it, who else can see it, how long we keep it, and how you can export or delete it. It also describes Google user data if you Sign in with Google or later connect Gmail. Questions: support@getjobpilot.ca.

This page is public. You do not need an account to read it.

Contents

  1. Google user data
  2. Limited Use and Google API Services User Data Policy
  3. What we hold about you
  4. Why we hold it
  5. Who else sees it
  6. Where it is kept
  7. How long we keep it
  8. Your rights, export, and deletion
  9. If something goes wrong
  10. Children

Google user data

Sign in with Google

If you choose Sign in with Google, we request only Google’s identity scopes: openid, email, and profile. Google shares your email address, display name, and profile photo so we can create or resume your JobPilot session. We do not receive Gmail contents, contacts, Calendar events, Drive files, or any other Google product data from sign-in. We do not keep Google access tokens or refresh tokens after the sign-in handshake. The only Google user data we retain from that flow is the verified email address used as your JobPilot account identifier, and optionally your display name.

Optional Gmail connect

Connecting Gmail later, from Profile or Settings, is a separate consent screen. That request includes the restricted scope https://www.googleapis.com/auth/gmail.readonly (“View your email messages and settings”) so we can look up a career-site registration verification code in the inbox you choose.

How that data is accessed, used, stored, and shared:

Gmail access is not required to sign in, match jobs, draft applications, or submit applications. You can disconnect Gmail at any time. Disconnect revokes the Google grant and deletes the stored tokens.

Limited Use and Google API Services User Data Policy

JobPilot’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we hold about you

Why we hold it

To provide the service you asked for: finding jobs, scoring them, drafting application material, filling and (on your instruction) submitting forms, and showing you what happened. Where the law requires a lawful basis, ours is performance of the contract with you; for security records it is our legitimate interest in keeping the service running safely.

We do not sell your data, we do not share it with recruiters or data brokers, and we do not use your résumé to train models.

Who else sees it

Where it is kept, and how

Each account has its own database plus uploaded résumés and proof screenshots. Sessions are hashed tokens. Gmail refresh tokens are encrypted at rest (AES-256-GCM) with a server-held key. Processing by the third parties above may take place outside Canada. This is a small operator-hosted application; it makes no SOC 2 or ISO certification claim.

How long we keep it

Your records stay for as long as your account exists, because application history is the product. Old proof artifacts are pruned by housekeeping. Gmail tokens stay until you disconnect Gmail or delete the account. After you delete your account we delete the stored records promptly, except records we must keep for tax or accounting purposes. In-memory verification codes expire within fifteen minutes.

Your rights, export, and deletion

Export and deletion are available in Settings on app.getjobpilot.ca and take effect immediately. Deletion is irreversible and does not cancel billing — cancel the subscription separately. You can edit your profile, résumés and answers at any time. You can disconnect Gmail without deleting the rest of the account. Depending on where you live you may also object to or restrict processing, or complain to a data protection authority. Email support@getjobpilot.ca.

We cannot recall an application that has already been sent. Once an employer has it, ask them.

If something goes wrong

If your data is exposed we will tell you what happened, what was affected, and what to do about it without undue delay (and within 72 hours of discovery where that is required), and notify regulators where required.

Children

JobPilot is for people who are old enough to enter a contract and apply for jobs where they live. We do not knowingly collect data from children.

About JobPilot · Terms