Data we handle
Depending on the features you use, Job Finder handles account and profile data; resumes and generated files; job searches, imports, matches, and where each job was found; application packages and application history; reusable answers; Workday candidate-account email, status, and an encrypted app-generated password when Auto-Apply creates that account; interview questions, finalized answers, corrections, and scores; support requests; usage and billing records; consent records; and operational records that contain no personal content.
Private files are stored in Job Finder’s own resume and application-package storage. Provider credentials, live browser links, and access tokens are excluded from user exports and kept out of logs.
Purposes and consent
Data is used to provide requested job-search, application-drafting, resume, application-tracking, interview, billing, security, and reliability functions. Versioned confirmation is required before application drafting transfers resume, profile, and job details to configured AI providers.
Text interview practice requires consent to store finalized answers and correction history. Before first voice use under a policy version, the user separately approves microphone capture and OpenAI speech processing. Browser microphone permission is controlled separately by the browser and can be changed in site settings. Voice consent can be withdrawn from an interview by switching back to typing.
Job Finder’s use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Extension data is used only to provide or improve the application assistant’s disclosed single purpose.
Chrome extension collection, use, and local storage
The Chrome extension acts only when the account holder presses Save this job or when an application already approved through Auto-Apply is ready to run. Save this job reads the exact current job-page URL and a bounded copy of the posting title, company, location, compensation, application URL, posting date, and description for review and import into the account. Auto-Apply reads the authorized employer-form URL, field labels, field types, required markers, supplied options, page-structure signatures, recognized submit controls, and whether a field already has a value. The form census does not send the raw value a person typed directly into the employer form.
Job Finder sends the extension only the current user’s authorized application bundle: the employer URL, final answers, selected resume or cover-letter files, and the identifiers needed to record one attempt. For a claimed Workday application it can also send the candidate-account email and app-generated password created for that employer. The extension uses those data to preview or save a posting, fill the authorized form, upload the selected files, detect CAPTCHA, login, validation, or unsupported-page stops, press the verified submit control when authorized, and record the observed employer response. It does not use extension data for advertising or unrelated product features.
Depending on the posting, the user’s profile, files, and explicitly saved application answers can include identifying and contact information, location, health or disability information, compensation or other financial answers, an app-generated Workday credential, cover-letter or free-text communications, employer-page content and URLs, and records of the user-authorized extension action and its outcome. Job Finder does not infer or collect those categories from unrelated browsing; it handles them only when they are part of the saved account data, selected posting, or authorized application.
Chrome local storage holds a signed, expiring Auto-Apply executor credential, its expiry, the last compatibility or claim result, and scheduler timing. Chrome session storage can temporarily hold a pending job clip plus the current queue and session identifiers, employer-tab identifier, execution phase, authorized page URL or signature, and submit-click evidence needed to recover safely after a service-worker restart. Pending clips are removed after transfer, completed execution checkpoints are cleared, and Chrome session storage ends with the browser session. Application answers and files are used for the authorized run and are not turned into a general browser-history record.
The extension does not collect the user’s general browsing history, cookies, existing Job Finder or employer passwords, payment-card data, keystroke logs, screenshots, unrelated tabs, or unrelated website content. A Workday run handles only the separate app-generated candidate-account credential described above. Job-page content is read only after Save this job, and employer-form content is read only for the server-authorized application.
Chrome extension storage, retention, and sharing parties
Extension requests go only to Job Finder at myjobfinder.live over HTTPS. Cloudflare hosts those requests, stores current application records in D1 and private resume and application files in R2, and runs the queues and scheduled work needed to prepare and settle the application. Imported job postings and application history remain with the account until account deletion unless the account holder removes the content earlier. Finished queue records are generally retained for 90 days and system and older application events for 365 days, subject to the retention ranges stated below.
When an ordinary application answer must be prepared, Job Finder may share with OpenAI the value-free form structure and the current user’s tenant-scoped profile, application package, tailored resume and cover-letter text, confirmed Answer Vault entries, job posting, source, location, and preferences. OpenAI does not receive browser cookies, general browsing history, unrelated tabs, screenshots, existing passwords, or access to the user’s computer. The extension receives the resulting authorized answer plan from Job Finder; OpenAI does not connect to Chrome.
When an authorized application is submitted, the selected employer and its applicant-tracking-system provider receive the final field values and files that the application requires. For a Workday run, the relevant employer’s Workday site also receives the candidate-account email and app-generated password used to create or access that account. Resend may receive the account email address and safe status text needed to deliver a transactional application notice, but not application answers, verification codes, credentials, resumes, or cover letters. Firebase processes account identity and sign-in data for Job Finder; it does not receive employer-page content from the extension.
Job Finder does not sell extension data, use it for personalized advertising, or allow a human to read it except with the user’s specific support consent or when necessary for security or legal compliance. It shares extension data only with the service providers and the selected employer and applicant-tracking-system provider described above, as needed to deliver the user-requested feature.
AI and service providers
Configured providers may process the minimum data needed for a requested feature. Current integrations include Firebase for identity, Cloudflare D1 and R2 for current app data and private files, Cloudflare for hosting and queued and scheduled background work, OpenAI for application drafting, resume tailoring, job scoring, answering application questions from your own data, text-interview and speech processing, Stripe for billing, and Resend for transactional email. Browserbase is retained only for cleanup of historical sessions.
The Subprocessors draft identifies which integrations are currently active, test-only, disabled, or conditional. Provider retention can differ from app-controlled retention and remains pending legal and vendor review.
Retention
Career content is generally kept while the account exists or while the content remains visible and useful. Application history remains until account deletion. Account-linked support requests are deleted with the account, and resolved support requests are kept for 365 days by default. Operational records are kept for 90 days for background job runs and finished queue entries and 365 days for system events and older application events. Those windows can be set between 30 days and 10 years.
The application does not store raw voice audio. It stores conversation transcript text, finalized answer revisions, consent history, and safe voice-operation/usage metadata. Provider-side processing and temporary retention are separate and require legal and vendor review.
Export and deletion
Export requires authentication within the last five minutes and produces a single archive: a machine-readable manifest, one file per data domain covering account, resumes, jobs, application packages and their versions, applications, saved answers, browser assistance, interviews, voice records, usage and costs, billing, and operational records, plus the account’s own resume, package, and builder resume files. A successful archive contains every requested domain and owned file, with counts and file hashes in its manifest. If a required domain or owned file cannot be read, the export fails and no archive is delivered; the user can retry.
Account holders must authenticate within the last five minutes to request deletion. Administrators use an authenticated admin session, typed confirmation and target-account checks; the admin route does not require a new five-minute authentication. The account is made unavailable first, then new work is stopped, sessions and provider authority are revoked, owned files are removed, and career content is deleted. Each step is recorded separately, so an interrupted deletion resumes from the step that failed and never returns the account to service.
After deletion, the service keeps only a minimum billing record and a deletion audit record. Those hold provider and transaction identifiers, plan and billing period, amounts and credit quantities, timestamps, step names, and safe status codes, identified by a pseudonymous reference rather than the account. They contain no resume, job, application, answer, interview, transcript, or voice content, no email address, and no provider tokens or file locations. How long those records are kept is not yet decided and requires legal review.
Messages and choices
Current email consists of transactional service messages about requested job-discovery or application activity and private alerts to the support operator when a person submits a support request. The support alert contains the requester email and subject but keeps the full message inside the private Admin area. Marketing messages are not implemented. If marketing is added later, it must use separate consent, unsubscribe, and suppression controls.