Privacy Policy
Effective 4 September 2026. This policy describes what JobPilot collects when you use getjobpilot.ca and the product at app.getjobpilot.ca, how we use it, who else can see it, how long we keep it, and how you can export or delete it. It also describes Google user data if you Sign in with Google or later connect Gmail. Questions: support@getjobpilot.ca.
This page is public. You do not need an account to read it.
Contents
- Google user data
- Limited Use and Google API Services User Data Policy
- What we hold about you
- Why we hold it
- Who else sees it
- Where it is kept
- How long we keep it
- Your rights, export, and deletion
- If something goes wrong
- Children
Google user data
Sign in with Google
If you choose Sign in with Google, we request only Google’s identity scopes: openid, email, and profile. Google shares your email address, display name, and profile photo so we can create or resume your JobPilot session. We do not receive Gmail contents, contacts, Calendar events, Drive files, or any other Google product data from sign-in. We do not keep Google access tokens or refresh tokens after the sign-in handshake. The only Google user data we retain from that flow is the verified email address used as your JobPilot account identifier, and optionally your display name.
Optional Gmail connect
Connecting Gmail later, from Profile or Settings, is a separate consent screen. That request includes the restricted scope https://www.googleapis.com/auth/gmail.readonly (“View your email messages and settings”) so we can look up a career-site registration verification code in the inbox you choose.
How that data is accessed, used, stored, and shared:
- Accessed — only after you click Connect and approve Google’s consent screen. JobPilot stores encrypted OAuth refresh tokens on the application server. Tokens never appear in the browser, in URLs, or in API JSON sent to the client.
- Used — only to search recent messages from allowlisted career-site senders (for example Greenhouse) during a verification helper session that you start. We look for a one-time registration code. Password-reset, MFA, banking, government, tax, health, payroll, and payment-related mail is rejected and not shown.
- Stored — the encrypted refresh token, the connected Gmail address, granted scopes, and the time you connected. Message bodies and verification codes are not written to the database. Codes are kept in server memory for at most fifteen minutes, then discarded.
- Shared — Gmail message contents are not sold, not used for advertising, not used to train models, and not sent to employers, recruiters, or data brokers. They are not sent to Anthropic or other model providers. Hosting infrastructure (Cloudflare for the websites; the operator’s application servers) may process the encrypted tokens in transit.
Gmail access is not required to sign in, match jobs, draft applications, or submit applications. You can disconnect Gmail at any time. Disconnect revokes the Google grant and deletes the stored tokens.
Limited Use and Google API Services User Data Policy
JobPilot’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide or improve user-facing features that are prominent in the app (identity for sign-in; verification-code lookup if you connect Gmail).
- We do not use Google user data for serving advertisements, including personalized, retargeted, or interest-based advertising.
- We do not sell Google user data or transfer it to third parties, except (a) as necessary to provide or improve the user-facing features described here, (b) for security purposes, or (c) to comply with applicable law.
- We do not allow humans to read Google user data unless you give us permission to do so for support, it is necessary for security purposes, we are required by law, or the data has been aggregated and anonymized.
- We do not use Gmail data to train generalized artificial intelligence or machine learning models.
What we hold about you
- Identity and contact — your email address (used to sign you in), and the name, phone number and location in your profile.
- Résumés — the files you upload, kept unchanged so an employer form can receive the exact document you meant to send, plus the plain text extracted from them for scoring and drafting.
- Application answers, including sensitive ones — work authorisation and sponsorship status, and anything you save to the Answer Bank. Employers sometimes ask about disability, veteran status, race or gender; if you store an answer to a question like that, we store it.
- Job search activity — jobs discovered for you, fit scores, which you approved, skipped or blocked, every application and its event history.
- Proof artifacts — screenshots of filled-in application forms and dry-run transcripts. These contain personal data because they are pictures of forms with your details.
- Email, if you connect it — encrypted Gmail OAuth tokens and the connected address, as described above. When inbound employer email is otherwise connected, the sender, subject and text of employer replies we are given, so replies and rejections can be matched to applications.
- Operational records — server logs and your settings. Sessions are cookie-based. There is no advertising or analytics tracking in the application.
- Billing — Stripe holds card numbers. We receive email, subscription status, and invoice history from Stripe.
Why we hold it
To provide the service you asked for: finding jobs, scoring them, drafting application material, filling and (on your instruction) submitting forms, and showing you what happened. Where the law requires a lawful basis, ours is performance of the contract with you; for security records it is our legitimate interest in keeping the service running safely.
We do not sell your data, we do not share it with recruiters or data brokers, and we do not use your résumé to train models.
Who else sees it
- Employers and job boards — when an application is submitted, its contents go to that employer’s system and are then governed by their privacy policy. This only happens when live submission is on.
- Job board APIs — public posting providers (for example Greenhouse, Lever, Ashby, Workable, SmartRecruiters, Recruitee, Adzuna) are queried for listings. Your personal data is not sent to them during discovery.
- Anthropic — if the server is configured with an Anthropic API key, job descriptions together with relevant parts of your profile and résumé are sent to the Claude API to score fit and draft text. Google user data from Gmail is not sent. If no key is configured, scoring stays on the server.
- Wikipedia and Hacker News — queried by company name for employer background. The company name is sent; nothing about you is.
- Stripe — subscriptions and payment details. We never receive your card number.
- Google — only if you Sign in with Google or connect Gmail, as described above. Google is the source of that data; we request it through OAuth.
- Hosting — Cloudflare delivers the websites. Application data is stored on the operator’s application servers used to run app.getjobpilot.ca.
Where it is kept, and how
Each account has its own database plus uploaded résumés and proof screenshots. Sessions are hashed tokens. Gmail refresh tokens are encrypted at rest (AES-256-GCM) with a server-held key. Processing by the third parties above may take place outside Canada. This is a small operator-hosted application; it makes no SOC 2 or ISO certification claim.
How long we keep it
Your records stay for as long as your account exists, because application history is the product. Old proof artifacts are pruned by housekeeping. Gmail tokens stay until you disconnect Gmail or delete the account. After you delete your account we delete the stored records promptly, except records we must keep for tax or accounting purposes. In-memory verification codes expire within fifteen minutes.
Your rights, export, and deletion
Export and deletion are available in Settings on app.getjobpilot.ca and take effect immediately. Deletion is irreversible and does not cancel billing — cancel the subscription separately. You can edit your profile, résumés and answers at any time. You can disconnect Gmail without deleting the rest of the account. Depending on where you live you may also object to or restrict processing, or complain to a data protection authority. Email support@getjobpilot.ca.
We cannot recall an application that has already been sent. Once an employer has it, ask them.
If something goes wrong
If your data is exposed we will tell you what happened, what was affected, and what to do about it without undue delay (and within 72 hours of discovery where that is required), and notify regulators where required.
Children
JobPilot is for people who are old enough to enter a contract and apply for jobs where they live. We do not knowingly collect data from children.
About JobPilot · Terms