JobPilot Privacy Policy
Last updated: April 26, 2026
This Privacy Policy applies solely to the JobPilot Chrome extension, published by Extensions Market. It fully discloses what data JobPilot collects, how that data is used, with whom it is shared, and how it is stored and retained. By installing or using JobPilot, you agree to this policy.
1. What data JobPilot collects
Account data
- Email address โ collected when you create a JobPilot account. Used for authentication, email verification, and account management. Stored in Google Firebase Authentication.
- User ID (UID) โ a unique identifier assigned by Firebase upon account creation. Used internally to link your usage data to your account.
- Password โ never stored by Extensions Market. Authentication is handled entirely by Google Firebase Authentication.
Usage and subscription data
- Usage counter โ the number of cover letters you have generated in the current day. Used solely to enforce free plan limits. Resets daily. Stored in Google Firestore.
- Subscription plan โ whether your account is on the free or paid plan, and your usage reset date. Stored in Google Firestore.
Resume and job data processed on request
- Resume text โ the resume content you enter or paste into JobPilot is stored locally in
chrome.storage.local on your device only. When you generate a cover letter, your resume text is transmitted from your browser to our server over HTTPS and forwarded to Anthropic's API to produce the cover letter. Your resume is not stored on our servers after the request completes.
- Job description text โ the job listing details visible on the page you are viewing are read locally and transmitted to our server along with your resume for cover letter generation. Job description text is not stored on our servers after the request completes.
- Generated cover letters โ returned to your browser and not stored on our servers.
Local browser storage
- Resume text โ stored locally in
chrome.storage.local on your device for reuse across sessions. Never uploaded to our servers except transiently during cover letter generation.
- Firebase authentication tokens โ stored in
chrome.storage.local on your device to maintain your session. Cleared when you sign out.
2. Data we do NOT collect
- We do not store your resume, job descriptions, or generated cover letters on our servers after the request completes.
- We do not collect your browsing history on any website.
- We do not use tracking pixels, advertising networks, or third-party analytics SDKs inside the JobPilot extension.
- We do not sell, rent, or share your personal data for advertising purposes.
3. How your data is used
- To authenticate your account and maintain your session
- To enforce daily usage limits based on your subscription plan
- To generate personalized cover letters by forwarding your resume and job description to Anthropic's API
- To process subscription payments and manage billing via Stripe
- To send transactional emails (email verification, password reset) via Firebase
4. Third parties your data is shared with
| Third Party | Data Shared | Purpose | Their Privacy Policy |
| Google Firebase |
Email address, UID, usage counter, subscription plan |
Authentication (Firebase Auth) and database (Firestore) |
firebase.google.com/support/privacy |
| Anthropic |
Resume text, job description text |
AI cover letter generation via Anthropic's Claude API. Anthropic does not use API-submitted content to train its models by default. See Anthropic's privacy policy for details. |
anthropic.com/privacy |
| Stripe |
Email address, Firebase UID |
Payment processing and subscription management. Card details go directly to Stripe and never touch our servers. |
stripe.com/privacy |
| Railway |
Resume text, job description text (in transit only) |
Cloud infrastructure hosting our API servers. Data passes through in memory only and is not stored. |
railway.app/legal/privacy |
5. Data storage and retention
- Email address, UID, usage counter, subscription plan โ stored in Google Firebase/Firestore for as long as your account is active. Deleted within 7 days of an account deletion request.
- Resume text โ stored locally on your device in
chrome.storage.local. Transmitted transiently during cover letter generation and not retained on our servers.
- Job description text and cover letters โ processed in memory on our servers and discarded after the response is returned. Never written to disk or logs.
- Authentication tokens โ stored locally on your device. Cleared on sign-out.
6. Extension permissions
- Access to job listing pages (LinkedIn, Indeed, and similar) โ to read publicly visible job description details for cover letter generation. JobPilot only activates on job listing pages.
- chrome.storage โ to store your Firebase authentication tokens and resume text locally on your device.
7. Data security
All communication between JobPilot and our servers uses HTTPS/TLS encryption. Firebase Authentication tokens are short-lived and automatically refreshed. Resume text and job descriptions are never written to server logs. Anthropic does not train on API-submitted content by default.
8. Your rights
- Access โ request a copy of the personal data we hold (email, UID, usage data).
- Correction โ ask us to correct inaccurate account data.
- Deletion โ request deletion of your account and all associated data within 7 days. Your locally stored resume can be cleared from the extension settings at any time.
- Portability โ request your account data in a machine-readable format.
To exercise any of these rights: [email protected]
9. Children's privacy
JobPilot is not directed to children under 13. We do not knowingly collect personal information from children under 13.
10. Changes to this policy
We may update this policy as JobPilot evolves. The "Last updated" date at the top reflects the most recent revision. Continued use constitutes acceptance of the updated policy.
11. Contact
[email protected]