JobShifu Privacy Policy

Last updated: October 1, 2026

The short version. Your career vault lives in your private, access-controlled account so the product can work across your browser, the extension, and your applications. This page explains what we collect, how we use it, and the third-party services we rely on to run JobShifu. You can erase everything with one click.

What we collect

How your data is used

Where it lives

Your vault is stored with our database provider (Supabase) with row-level security: every record is scoped to your account, and no other user can read it. Traffic to and from JobShifu is encrypted in transit (HTTPS/TLS), and our hosting providers encrypt stored data at rest. The website and app are served through Cloudflare, which also provides the anti-bot check on our public forms. Payment records live with Stripe / the app stores.

Importing from Google Drive

If you choose "Add from Google Drive" when adding your resume, JobShifu asks Google for the drive.file permission. That permission is per file: JobShifu can open only the files you select in Google's own file picker, and it has no access to anything else in your Drive. When you select a file we retrieve its contents once and store it as a source document in your vault, the same way an uploaded file is stored. A native Google Doc is exported to Word format on the way in so it can be read by the same parser. We do not browse, list, modify or delete anything in your Drive, and we do not keep standing access to the document. JobShifu's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Deleting your data

Third parties we rely on

Changes & contact

If this policy changes materially, we'll note it in the app before the change takes effect. Questions or deletion requests: privacy@jobshifu.com.