Privacy Policy

Effective and last updated: 21 August 2026

This Privacy Policy explains how Oren Software, operating JobFitsMe, handles personal information across the public website, Chrome extension, backend, and related support and billing services.

1. Information we process

  • Account and security: your Google account identifier, email address, authentication session identifiers, hashed refresh-token data, IP address, browser user agent, and security timestamps.
  • Resume information: the PDF you choose to upload, its extracted text, and structured work history, skills, domains, dates, evidence statements, and derived resume versions.
  • Job information: LinkedIn job identifiers, title, company, location, job description submitted for an AI action, hidden or saved state, and the resume selected for a job.
  • AI and product information: match scores, gaps, explanations, generated resume wording, cover letters, user directions, feedback, provider/model metadata, token counts, latency, and errors.
  • Billing: plan, subscription state, billing periods, AI credits, checkout and provider identifiers, and limited checkout details received from Lemon Squeezy. JobFitsMe does not receive full payment-card details.
  • Website use: page paths, referral and campaign values, interactions, scroll depth, session duration, device/browser details, approximate location, and analytics identifiers.

2. How we collect and use information

We collect information from you, from the LinkedIn page where you invoke an extension feature, from Google during sign-in, from Lemon Squeezy during billing events, and automatically from service and website operation.

We use it to authenticate and protect accounts; analyze resumes and requested jobs; generate match explanations, tailored resume content, and cover letters; synchronize job activity; provide subscription access and credits; process support, security, billing, and reliability work; comply with law; and measure the public website. We do not sell personal information or use extension data for advertising.

3. Raw resume files and persistent derived data

Raw processing: the PDF and its complete extracted text may contain your name, contact details, education, links, and other personal information. They are encrypted in transient processing storage for no longer than 15 minutes and are deleted earlier after processing reaches a terminal state where possible. The full extracted text is sent to OpenAI for initial resume analysis. JobFitsMe does not promise that personal identifiers are removed first.

Persistent data: structured experience, skills, domains, derived resume wording, match results, and generated documents are stored in the JobFitsMe database so history, restoration, and later requested features work. They remain until you delete the relevant resume or account, subject to the billing and backup exceptions below.

4. OpenAI processing and feature-level transfers

JobFitsMe selects and pays for the AI provider. OpenAI is the only AI processor approved for the private beta; users do not supply an API key or select a provider.

  • Initial resume analysis: full extracted resume text.
  • Job matching: job title, full job description, and stored structured work experience.
  • Match explanation: job context and the calculated match evidence needed for the explanation.
  • Cover letter: your direction, structured work experience, and full job description.
  • Resume derivation: the selected structured experience and target gap context, not the raw PDF.

Job descriptions and short-lived queue result copies use the same maximum 15-minute transient window and are not kept in the persistent application database. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in; OpenAI may retain data under its own API data-control terms. See OpenAI API data controls.

5. Service providers and disclosures

  • Google Identity provides the beta's Google-only sign-in and supplies account identity and email.
  • OpenAI processes the feature inputs described above.
  • Lemon Squeezy is merchant of record and provides hosted checkout, tax handling, receipts, subscriptions, customer portal, refunds, and billing webhooks.
  • DigitalOcean hosts the beta backend, database, and transient queue infrastructure.
  • Cloudflare provides public website DNS, edge delivery, and network security.
  • Contentsquare provides production website visitor-behavior analytics. Website analytics is not joined to your extension account by JobFitsMe.

6. Retention schedule

CategoryRetention
Raw PDF, extracted text, and sensitive queue payloadMaximum 15 minutes; deletion is attempted immediately after terminal processing.
Terminal queue result copies15 minutes after the terminal state.
Structured resumes, jobs, generated outputs, feedback, and AI historyWhile the account exists, then deleted or irreversibly de-identified through account deletion.
Expired or revoked sessions and security metadata30 days after expiry or revocation, then deleted or de-identified.
Operational errors and log-linked data containing user contextMaximum 30 days, unless an active legal or security hold requires longer retention; then deleted or irreversibly de-identified.
Minimum billing and tax recordsGenerally five years after the record or related transaction, or longer only where law or a dispute requires it; direct identity is removed where it is no longer needed.
BackupsDeleted data may remain for no more than 30 days in access-controlled disaster-recovery backups. Restores must not return deleted data to active use.

7. Browser and local storage

The extension uses Chrome local storage for authentication/session state, signed-out job visibility actions awaiting synchronization, pending checkout synchronization, and development-only controls. The current extension deletes its legacy IndexedDB database and does not use it as an active product store. The website's cookies and browser storage are described in the Cookie and Local Storage Policy.

8. Chrome Web Store Limited Use disclosure

JobFitsMe uses data obtained through Chrome extension permissions only to provide or improve the user-facing LinkedIn job-search features described in the extension. It reads job-page information when you use the relevant interface; it does not scan browsing activity in the background.

Extension data is transferred only when necessary to provide those features, protect security, comply with law, or complete a permitted business transfer. It is not sold, used for personalized advertising, creditworthiness, lending, or unrelated profiling. Human access is prohibited except with your specific consent for support, when necessary for security or legal compliance, or for internal use of aggregated and de-identified data.

9. Authorized human access and security

Stored account, job, structured resume, match, and operational data may be accessed only by explicitly authorized JobFitsMe operators when needed for user-requested support, security or abuse response, billing investigation, legal compliance, or service reliability and debugging. Access should be least-privilege and auditable. Raw resume PDFs are not intended to be available to operators because they are transient. We use reasonable technical and organizational safeguards, but no system can guarantee absolute security.

10. Access, correction, export, deletion, and complaints

You can export a versioned copy of your account data or permanently delete your account from the extension's Account section. Account deletion revokes sessions, cancels active subscriptions, clears queued sensitive work, and deletes or de-identifies linked product data. Minimum billing records may remain as described above, and provider-side or backup copies follow their applicable retention cycle.

To request access or correction, ask a privacy question, or make a complaint, email support@jobfitsme.com. Include enough information for us to identify the issue without sending unnecessary sensitive data. We will acknowledge and investigate privacy complaints and respond within a reasonable period. You may also contact the privacy regulator available in your jurisdiction.

11. International processing

Our providers may process information outside Australia, including in the United States and European Union, depending on their infrastructure and your location. Provider locations and subprocessors can change. We use providers under their applicable contractual, privacy, and security terms and limit transfers to the data needed for the service.

12. Changes and contact

We may update this policy as JobFitsMe, its providers, or legal requirements change. We will publish the revised policy here with a new effective date and provide additional notice when a change materially affects users. Contact support@jobfitsme.com.