JobShifu Privacy Policy
Last updated: July 2, 2026
The short version. Your career vault lives in your private,
access-controlled account so the product can work across your browser, the extension, and
your applications. This page explains what we collect, how we use it, and the third-party
services we rely on to run JobShifu. You can erase everything with one click.
What we collect
- Account data — your email address and sign-in credentials (or your
Google/LinkedIn identity if you sign in with OAuth).
- Your career vault — the resumes, work history, skills, answers, and
documents you upload or confirm. This is the product's working data; you control it.
- Job data — postings you save or capture, applications you track, and
the tailored documents JobShifu builds for you.
- Billing data — handled by Stripe (web) or Apple/Google via RevenueCat
(mobile). We never see or store your card number.
- Service metering — token counts and task names for AI requests
(never the content of those requests), used for plan limits and abuse prevention.
- Product analytics — how the app is used (pages viewed, features used,
and similar events) via PostHog, so we can understand and improve the product.
- Uninstall feedback — if you remove the Chrome extension, your browser
opens a short optional survey page. Whatever you choose to answer there is recorded, along
with a few facts about that installation: how many days it had been installed, its version,
whether you were signed in, whether the panel was ever opened, and rough activity bands
(none / 1–4 / 5+) for jobs saved and autofills run. This is deliberately not linked to
your account: the identifier is a random value generated inside the extension, never your
user ID, and the counts are bands rather than exact numbers, so a response cannot be traced
back to you. Your IP address is not stored; a salted, one-way hash of it is kept for up to
two hours purely to limit spam, then erased. You can answer nothing and simply close the
tab.
- How you found us — the website that linked you here and any campaign
tag or click identifier on the link, recorded once when you create an account so we know
which channels are worth our time. It is kept with your account and deleted with it. No
cookie is used: the value is held in your browser's session storage for the current tab
only. Where you arrived from an ad, we may send that click identifier and the time you
signed up back to the advertising platform (for example Google Ads) so it can count the
signup against its own click. We do not send your name, email, or anything from your
vault with it.
- Error monitoring — automatic crash and error reports via Sentry, so we
can find and fix bugs. Resume and job content is scrubbed from these reports.
- Diagnostics (opt-in only) — troubleshooting events you explicitly
enable. Off by default, content-free, and deleted with your data.
How your data is used
- To run JobShifu: tailoring resumes, matching jobs, filling applications, tracking
your search — all scoped to your account.
- AI features send the relevant parts of your vault and the job posting to Anthropic's
Claude API to generate results. Anthropic processes these requests as a service
provider and does not train on this data.
- To understand product usage and improve JobShifu, using the analytics described above.
Where it lives
Your vault is stored with our database provider (Supabase) with row-level security:
every record is scoped to your account, and no other user can read it. Payment records
live with Stripe / the app stores.
Deleting your data
- One-click wipe — Settings → "Erase all data" deletes your entire
vault and every derived record (match profiles, feeds, saved jobs, diagnostics).
- Account deletion — contact us (below) to delete your account itself.
We retain only what the law requires: purchase records and content-free usage metering.
Third parties we rely on
- Supabase — database and authentication hosting.
- Anthropic — AI processing (Claude API), as described above.
- PostHog — product analytics.
- Sentry — error monitoring and crash reports.
- Stripe / RevenueCat — payments and subscriptions.
Changes & contact
If this policy changes materially, we'll note it in the app before the change takes
effect. Questions or deletion requests: privacy@jobshifu.com.