Legal

Privacy Policy

Last updated: July 14, 2026

1. Overview

JobFlow is a private job search workspace. We collect only what we need to authenticate you, run your pipeline, send transactional email, and improve the product. We do not sell your application data.

2. Data we collect

  • Account: name, email, password hash, email verification status, timezone, optional avatar
  • Profile: professional title, locations, remote preference, experience, technologies, target roles, salary expectations
  • Workspace content: applications, companies, contacts, interviews, tasks, notes, résumés, and analytics derived from them
  • Technical: session tokens, security logs, and email delivery metadata for verification and password reset

3. How we use data

  • Provide and secure your private dashboard
  • Send verification, password reset, and welcome emails
  • Calculate job search analytics from records you create
  • Enforce ownership checks so users cannot access each other’s data
  • Power optional AI features later — only on your structured JobFlow entities

4. Sharing

We use infrastructure providers (database hosting, email delivery such as Resend, app hosting) strictly to operate the service. We do not share your applications with employers or third-party recruiters through JobFlow. Credentials auth is email/password only — no Google or GitHub login data is collected.

5. Retention & deletion

Account and workspace data persist while your account is active. Soft-deletion may be used internally before hard removal. You may request account deletion; we will remove or anonymize personal data subject to legal retention requirements (for example security logs).

6. Security

Passwords are stored hashed. Sessions use Auth.js JWT strategy. Protected routes are gated server-side. Sensitive APIs apply rate limits and validation. No authentication secrets are exposed to the browser bundle.

7. Your choices

You can update profile fields in settings (as features ship), reset your password, and contact us to ask about export or deletion. For product questions, use the Contact page.

8. Changes

We may update this Privacy Policy. The “Last updated” date at the top will change when we do. Continued use means you acknowledge the revised policy.