Privacy Policy

Last updated: December 30, 2024

1. Introduction

At Jobbris, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our resume optimization service. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the service.

2. Information We Collect

We collect information that you provide directly to us, including:

  • Account information (name, email address)
  • Resume content and documents you upload
  • Job descriptions you provide for analysis
  • Payment information (processed securely by our payment provider)
  • Communications you send to us

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Analyze your resume against job descriptions
  • Generate personalized optimization suggestions
  • Process transactions and send related information
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and customer service requests

4. Data Security

We implement appropriate technical and organizational security measures to protect your personal information. Your resume data is encrypted both in transit (TLS/SSL) and at rest (AES-256). We do not sell, trade, or otherwise transfer your personal information to outside parties. Your resume content is used solely to provide you with our optimization services. We employ Row-Level Security (RLS) policies, secure authentication, and regular security audits to protect your data.

5. Third-Party Service Providers

We use trusted third-party service providers to operate our service. These providers have access to your information only to perform specific tasks on our behalf and are obligated to protect your data. We have appropriate data processing agreements and security measures in place with each provider.

Supabase (Database & Authentication)

Hosts our database and manages user authentication. Data stored in secure cloud infrastructure with encryption.

Dify AI (Resume Analysis)

Processes your resume and job descriptions to provide AI-powered optimization suggestions. Your data is processed securely and not used for training their models.

DodoPay (Payment Processing)

Handles all payment transactions securely. We do not store your complete payment card details on our servers.

Vercel (Application Hosting)

Hosts our web application with enterprise-grade security and global content delivery.

Sentry (Error Monitoring)

Monitors application errors and performance to maintain service quality. Error reports may contain anonymized usage data but no personal resume content.

Telegram Bot API (Optional Integration)

If you choose to connect Telegram, we use their API to enable mobile job submissions. You can disconnect at any time.

Logo.dev (Company Logos)

Retrieves company logos for job listings. Only company names are shared, no personal information.

6. Data Retention

We retain your personal information only as long as necessary to provide our services and comply with legal obligations. Here are our specific retention periods:

  • Active Accounts: Data is retained indefinitely while your account remains active and in use
  • Account Deletion: When you delete your account, all personal data, resumes, job applications, and analysis results are permanently deleted within 24 hours
  • Inactive Accounts: Accounts with no activity for 36 months will receive a notification. If no response, the account and all data will be deleted after 90 days
  • Resume Files: Deleted immediately when you remove them or delete your account
  • Analysis Results: Deleted when associated job application or account is deleted
  • Payment Records: Retained for 7 years for tax, accounting, and legal compliance purposes, then securely deleted
  • Backups: Deleted data may remain in encrypted backups for up to 30 days before permanent deletion

You can delete your account at any time through your Settings page. This action is immediate and permanent.

7. Your Rights (GDPR & Privacy Laws)

Under GDPR and other privacy laws, you have the following rights regarding your personal data:

  • Right to Access: View all personal information we hold about you through your account dashboard
  • Right to Rectification: Update or correct inaccurate information through your Settings page
  • Right to Erasure ("Right to be Forgotten"): Delete your account and all associated data permanently through Settings → Delete Account
  • Right to Data Portability: Export your data in a machine-readable format (contact us at hello@jobbris.app)
  • Right to Object: Opt out of marketing communications or specific data processing activities
  • Right to Restrict Processing: Request temporary restriction of data processing
  • Right to Withdraw Consent: Withdraw consent for optional features (e.g., Telegram integration) at any time

To exercise any of these rights, visit your Settings page or contact us at hello@jobbris.app. We will respond to your request within 30 days.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to provide and improve our service:

  • Essential Cookies: Required for authentication and core functionality (cannot be disabled)
  • Analytics Cookies: Help us understand how you use our service to improve user experience (Vercel Analytics)
  • Performance Monitoring: Track errors and performance issues (Sentry)

You can control cookies through your browser settings. Note that disabling essential cookies will prevent you from using our service. Most browsers allow you to refuse cookies or delete existing ones. Consult your browser's help documentation for specific instructions.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws different from your jurisdiction. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your personal data in accordance with this Privacy Policy and applicable laws.

10. Children's Privacy

Our service is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately so we can delete such information.

11. Changes to This Policy

We may update our Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this policy. For significant changes, we will provide a more prominent notice (such as an email notification). We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

12. Contact Us & Data Protection Officer

If you have any questions about this Privacy Policy, your data rights, or wish to file a complaint, please contact us:

Email: hello@jobbris.app

Response Time: We aim to respond to all inquiries within 48 hours and complete data requests within 30 days as required by GDPR.

If you are located in the European Economic Area (EEA) and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.