π¦ Job Lobster
Privacy Policy
Last updated: 2026-07-11
This policy explains what Job Lobster collects, how the product uses that data, and how to export or delete your account data.
1. What we collect
Data you provide
- Email address β used only for the magic-link sign-in and (if you opt in) the daily digest. Never sold, never shared with employers.
- Resume file (PDF, DOCX, or TXT) β parsed into structured fields used to ground job scoring and tailoring.
- Intake answers β target titles, comp range, location preferences, track (Finance / SWE / PM), and any clarifying answers you provide when preparing a tailored package.
- Application history β which jobs you prepared packages for, stage transitions (applied / interviewing / rejected), follow-up notes, outreach threads.
Data we generate about you
- Match scores + gap analyses β written to the database so the shortlist is consistent across sessions.
- Tailored resumes, cover letters, LinkedIn messages β stored as both text fields and downloadable DOCX / PDF files under your per-user directory.
- LLM usage history β timestamped log of each AI model call made on your behalf, with provider, model, token counts, and cost where available. Used for your Billing tab and for per-user budget enforcement.
- Anonymous product analytics β a random first-party visitor ID (expires after 90 days of inactivity), a random session ID (rolls after 30 minutes of inactivity), page path, referring host, campaign parameters, and coarse funnel events. These IDs are generated randomly; they are not device fingerprints and do not contain your resume, application materials, or private notes.
Data we do NOT collect
- We do not fingerprint your device.
- We do not read email from your inbox or submit applications on your behalf.
2. Where your data goes
Storage
All of your data is stored in a single SQLite database plus a filesystem directory on a Fly.io virtual machine operated by the Job Lobster operator. Rows are scoped to your user ID so other users cannot see them. Downloaded DOCX/PDF files live under data/users/<your-id>/applications/.
Third-party processors
- AI model providers: when you score a job, prepare a package, or run any LLM-driven workflow, the relevant prompt (which includes your profile summary + the job description + any answers you provided) is sent to the configured third-party AI model provider for processing under our account.
- Google Analytics: we use Google Analytics to measure page views and usage events on Job Lobster. Google receives standard browser/device metadata and page URLs for those visits. We do not intentionally include resume text, generated application content, or private notes in analytics events.
- Microsoft Clarity: we use Microsoft Clarity for session replay, heatmaps, clicks, and scrolling diagnostics. Microsoft receives standard browser/device metadata, page URLs, and interaction data. Form inputs are masked, and the signed-in app's main content is additionally masked so rΓ©sumΓ©s, profiles, chat, and application content are not readable in replays. See Microsoft's privacy statement.
- Resend: when the operator enables email delivery, sign-in links and daily digests are sent via Resend. Your email address plus the digest / link content passes through Resend. See Resend's privacy policy.
- Fly.io: our host. They operate the VM, volume, and edge network. See Fly.io's privacy policy.
- Public ATS endpoints (Greenhouse, Ashby, Lever, Workday, SmartRecruiters, Workable, Recruitee, Pinpoint, Teamtailor, SuccessFactors, UltiPro, Gem): we read publicly-posted job listings from these APIs. We do not send them your information. Your data never leaves Job Lobster's infrastructure when we scan jobs.
3. Your rights
Every Job Lobster user can, at any time, without needing to contact us:
- Export everything β Setup β π Your data β "β¬ Export my data (JSON)". You get a single JSON file with every row we have about you: applications, outreach, coaching rows, LLM usage history, your profile, and a manifest of your artifact files.
- Delete everything β same drawer β "Delete my dataβ¦". Removes every per-user row plus your profile file, resume file, and application DOCX directory. Irreversible.
- Delete your account β "Delete account + dataβ¦". In addition to the above, removes the user record and any live sessions. You are logged out immediately.
- Sign out β from the sidebar.
The delete operations are real deletes, not soft-deletes. Your data does not sit in a "trash" waiting for a retention window β it is removed from the database and file system when you click.
If applicable law gives you additional access, correction, deletion, or portability rights, you can contact us using the address below and we will respond as required by that law.
4. Data retention
Data you provide is retained as long as your account is active. When you delete your account, we remove it from our primary store within seconds. Backups and Fly.io's infrastructure redundancy may retain fragments for up to 30 days before full erasure.
AI model provider and email-provider retention is governed by each provider's policy. We do not control their internal retention windows.
5. Security
- Sessions use a 32-byte random token; only the SHA-256 hash of the token lives in our database.
- Cookies are set
HttpOnly; Secure; SameSite=Lax.
- All traffic to Job Lobster is TLS (HTTPS) via Fly.io's edge. We do not accept plain HTTP.
- Per-user database rows are scoped by
user_id β there is no "view as another user" mode.
- Per-user file downloads are ownership-checked server-side; guessing another user's application ID returns 404, not the file.
6. Children
Job Lobster is a professional tool and not intended for anyone under 16. We do not knowingly collect data from children under that age.
7. Changes
We may update this policy. Material changes will be surfaced in the app. Continued use after a change constitutes acceptance.
8. Contact
For privacy questions or data requests that the self-serve flows do not cover, contact: hello@joblobster.ai.