JobShifu Privacy Policy
Last updated: October 1, 2026
The short version. Your career vault lives in your private,
access-controlled account so the product can work across your browser, the extension, and
your applications. This page explains what we collect, how we use it, and the third-party
services we rely on to run JobShifu. You can erase everything with one click.
What we collect
- Account data: your email address and sign-in credentials (or your
Google/LinkedIn identity if you sign in with OAuth).
- Your career vault: the resumes, work history, skills, answers, and
documents you upload or confirm. This is the product's working data; you control it.
Parts of it are turned into numeric embeddings (by Voyage AI) so we can match your
experience to postings.
- Job data: postings you save or capture, applications you track, and
the tailored documents JobShifu builds for you.
- Billing data: handled by Stripe (web) or Apple/Google via RevenueCat
(mobile). We never see or store your card number.
- Service metering: token counts and task names for AI requests, used
for plan limits and abuse prevention. Apart from Shifu conversations (below), the content
of AI requests is not stored.
- Shifu conversations: if you use the Shifu assistant, we store your
messages, Shifu's replies and a record of the steps it took (for example which parts of
your vault or which saved jobs it read), so you can return to a conversation. Our team may
review these conversations to improve answer quality and fix problems. Conversation text
is deleted after 90 days, or at any time with "Erase all data". The cost and token counts
of each message are kept for usage limits.
- Product analytics: how the website and app are used (pages viewed, signup-link clicks, features used,
and similar events) via PostHog and in our own database, so we can understand and improve
the product.
- Extension usage: when the Chrome extension is signed in, we record which
account the installation belongs to (a random installation identifier, its version, and
when it was last seen) and, for each autofill run, counts and outcomes only: how many fields
were attempted, filled, skipped or failed, and which applicant-tracking system it was. We
never record the page address, field labels or the values filled. Both are deleted with
your data.
- Uninstall feedback: if you remove the Chrome extension, your browser
opens a short optional survey page. Whatever you choose to answer there is recorded, along
with a few facts about that installation: how many days it had been installed, its version,
whether you were signed in, whether the panel was ever opened, and rough activity bands
(none / 1–4 / 5+) for jobs saved and autofills run. The response carries the
installation's random identifier, not your name or email. Because we also record which
account an installation is signed in to (see Extension usage), a response from an
installation you were signed in to can be linked to your account. Your IP address is not
stored; a salted, one-way hash of it is kept for up to two hours purely to limit spam, then
erased. You can answer nothing and simply close the tab.
- How you found us: the website that linked you here and any campaign
tag or click identifier on the link, recorded once when you create an account so we know
which channels are worth our time. It is kept with your account and deleted with it. No
cookie is used: the value is held in your browser's session storage for the current tab
only. Where you arrived from an ad, we may send that click identifier and the time you
signed up back to the advertising platform (for example Google Ads) so it can count the
signup against its own click. We do not send your name, email, or anything from your
vault with it.
- Email: job alerts, digests and account emails are delivered by
Resend, which receives your email address and the contents of that message. You can
turn alert and update emails off in Settings; account and billing emails are
transactional and are not marketing.
- Error monitoring: automatic crash and error reports via Sentry, so we
can find and fix bugs. Resume and job content is scrubbed from these reports.
- Diagnostics (opt-in only): troubleshooting events you explicitly
enable. Off by default, content-free, and deleted with your data.
How your data is used
- To run JobShifu: tailoring resumes, matching jobs, filling applications, tracking
your search, all scoped to your account.
- AI features send the relevant parts of your vault and the job posting to Anthropic's
Claude API to generate results. Anthropic processes these requests as a service
provider and does not train on this data.
- Job matching also sends short pieces of your vault and of job postings to Voyage AI,
which returns numeric embeddings used to rank how well a posting fits you.
- To understand product usage and improve JobShifu, using the analytics described above.
- Advertising: JobShifu shows no advertising inside the product. We buy
ads on other platforms, and the only thing that goes back to one of them is the click
identifier and signup time described above. Nothing from your vault is sent with it.
- Sale of personal information: JobShifu does not sell your personal
information. If that ever changes, this page will say so before it takes effect and will
carry the opt-out the law requires.
Where it lives
Your vault is stored with our database provider (Supabase) with row-level security:
every record is scoped to your account, and no other user can read it. Traffic to and from
JobShifu is encrypted in transit (HTTPS/TLS), and our hosting providers encrypt stored data
at rest. The website and app are served through Cloudflare, which also provides the
anti-bot check on our public forms. Payment records live with Stripe / the app stores.
Importing from Google Drive
If you choose "Add from Google Drive" when adding your resume, JobShifu asks Google for
the drive.file permission. That permission is per file: JobShifu can open only
the files you select in Google's own file picker, and it has no access to anything else in
your Drive. When you select a file we retrieve its contents once and store it as a source
document in your vault, the same way an uploaded file is stored. A native Google Doc is
exported to Word format on the way in so it can be read by the same parser. We do not
browse, list, modify or delete anything in your Drive, and we do not keep standing access
to the document. JobShifu's use of information received from Google APIs adheres to the
Google API
Services User Data Policy, including the Limited Use requirements.
Deleting your data
- One-click wipe: Settings → "Erase all data" deletes your entire
vault and every derived record (match profiles, feeds, saved jobs, diagnostics,
per-user telemetry and usage logs). A wipe keeps: billing records (purchase and
subscription history), the current month's free-usage counter (so a wipe can't reset
the free allowance), and any active community moderation records; expired ones are
deleted. Community posts you authored are anonymized in place ("[deleted]") so
conversations aren't torn apart.
- Account deletion: Settings → "Delete account" removes your account
itself, cancels any active subscription, and wipes your vault in the same step. You do
not need to email us. We retain only what the law requires: purchase records and
content-free usage metering.
Third parties we rely on
- Supabase: database and authentication hosting.
- Anthropic: AI processing (Claude API), as described above.
- PostHog: product analytics.
- Sentry: error monitoring and crash reports.
- Voyage AI: text embeddings for job matching.
- Resend: delivery of alert, digest and account email.
- Cloudflare: website and app hosting, content delivery, and the
anti-bot check on public forms.
- Stripe / RevenueCat: payments and subscriptions.
- Google Ads: receives the click identifier and signup time described
above when you arrive from one of our ads. Nothing from your vault is sent.
- logo.dev: company logos shown beside job listings. Your browser
requests the logo image directly, so logo.dev sees that request.
- Your browser's speech service: if you use the microphone button in
Shifu, your browser turns what you say into text. Chrome sends the audio to Google, Edge
to Microsoft, and Safari to Apple. The audio goes to that company, not to us; Shifu
receives only the text, which is kept like any other Shifu message.
Changes & contact
If this policy changes materially, we'll note it in the app before the change takes
effect. Questions or deletion requests: privacy@jobshifu.com.