Job Grinder

Last updated October 8, 2026

Privacy Policy

JobGrinder helps people manage job search materials and application workflows. This policy explains the personal data we collect, why we use it, and your choices and data controls.

Who operates Job Grinder

Operator
Wojciech Jelen
Address
Cedrowa 3/2, 55-040 Bielany Wroclawskie, Poland
support@job-grinder.xyzHelp and privacy requests

Purposes and rights

  • We process account and application data to provide the service you request. Service security and abuse prevention support our legitimate interests. Optional reminder emails use your chosen settings and can be stopped at any time.
  • Subject to applicable law, you can request access, correction, erasure, restriction, portability, or object to processing using the public support contact. Where processing relies on consent, you can withdraw it. You may complain to your local data protection supervisory authority.
  • Some providers or model endpoints may process data outside the EEA. Applicable destinations, contractual safeguards, and any adequacy decisions must be confirmed in the launch provider register. Do not treat this draft policy as a completed transfer assessment.

What we collect

  • Account identifiers from the sign-in provider, such as user ID and email address.
  • Profile and resume information you provide or import, including work history, education, skills, contact details, and work preferences.
  • Job search settings, discovered jobs, application status, generated resumes, cover letters, reminder preferences, and gamification progress.
  • Operational data needed to run the service, such as timestamps, source URLs, generated document metadata, and error or security logs.

How we use data

  • We use your data to run the job search workspace, tailor resumes and cover letters, preserve application history, send requested reminders, and keep your progress in sync.
  • Clerk handles sign-in, Convex stores workspace data and files, and Vercel hosts the application and routes requested AI work through AI Gateway. The provider details below describe what each service receives.
  • We do not sell your personal data.

Providers and the data they receive

  • Resume PDF import sends the uploaded PDF through Vercel AI Gateway using the Interfaze model to extract structured profile information. When the PDF contains a text layer, we also send that resume text to an OpenAI model through AI Gateway in parallel, even if the Interfaze result is used. This includes the personal and career information in the document. The applicable retention, data-use settings and transfer arrangements for both import paths still require verification.
  • OpenAI models receive relevant resume and job text for resume parsing, tailoring, cover letters, application answer drafts, and search analysis through Vercel AI Gateway. Application answer drafts can include profile, resume, cover-letter and job-description evidence. Google models receive the uploaded PDF for model-based text extraction and form/page text when the browser automation fallback is needed. Server model overrides can change the selected model.
  • AI Gateway can serve OpenAI models through OpenAI or Amazon Bedrock; both appear in our project request logs. Interfaze also appears as a serving provider for PDF import. A model name alone does not identify the service processing a request, and the provider allowlist is disabled. The destinations and contractual settings of these serving providers still require review.
  • Browserbase receives job-page content, candidate details, approved answers, uploaded PDFs and screenshots during cloud auto-apply. Session recording is enabled. Form classification and submission checks send labels, options, previously answered question text, and visible page or confirmation text through AI Gateway to OpenAI, with Google as fallback. Visible page text can include personal details already entered into the form.
  • Firecrawl receives the job URL and retrieves posting content when extraction uses its configured service. Apify receives search keywords, location and job filters for configured LinkedIn discovery, and stores run results. These extraction requests do not include your full CV. Employers and their applicant-tracking services receive the application information you authorize us to submit; their retention is separate from JobGrinder.
  • PostHog receives pseudonymous workflow events, operation identifiers and usage costs, without CV text, job descriptions or application answers. Userback receives your user ID, name and email when the signed-in feedback widget loads, and the feedback, page/browser details and any screenshot or recording you submit. Check attachments for personal information before sending feedback.
  • Resend receives the recipient email and reminder message, including the job details and links in that message, when reminders are enabled. Polar receives your account identifier, selected product and checkout email when you request billing services. Payment details entered in its checkout are handled by Polar and its payment providers. Account cleanup schedules cancellation of Polar subscriptions that have not ended. It does not erase records held by Polar or its payment providers.

Provider retention and international transfers

  • As checked on October 8, 2026, our Vercel team-level zero data retention control and provider allowlist are disabled. Our application code does not request zero retention or prompt-training restrictions on individual calls. We cannot promise zero retention or a particular training restriction for every routed request.
  • OpenAI publishes a default abuse-monitoring period of up to 30 days for API data, with endpoint, caching, safety and legal exceptions. Google publishes limited logging for abuse prevention under its paid Gemini API terms. These are provider policies, not proof of the endpoint or contractual settings used by our Gateway account; the actual routing and applicable retention still require verification.
  • Interfaze publishes a policy against training AI models on data stored in its services, and describes US processing and processing in its subprocessors’ regions. Its published privacy policy uses account activity and service needs as retention criteria, with legal and business exceptions, rather than a fixed PDF-retention period. These published terms do not establish the agreement or retention settings applicable to our Gateway requests. Amazon Bedrock retention also depends on the model, endpoint, region and account settings; those settings have not been verified for our routed requests.
  • Browserbase publishes recording retention of up to 30 days after a session ends for projects without customer-owned storage, and 24 hours for recording sources on customer-owned-storage projects. Copies archived in customer storage have their own lifecycle. Ending a browser session does not delete its recording. Our project storage arrangement and any exceptions have not been verified.
  • As checked on October 8, 2026, our production Convex deployment is in Europe (Ireland), its dashboard backup schedule is Never, and the dashboard lists no backups. This does not establish Convex’s internal recovery-copy or log retention. Clerk’s published processing terms describe deletion within 90 days after our provider agreement ends; this is not a promise of deletion within 90 days of each JobGrinder user’s account closure.
  • PostHog publishes event and metadata retention windows of one year on free plans and seven years on paid plans. Our project plan and erasure settings have not been verified. Userback publishes feedback and replay retention while our Userback customer account is active plus 30 days after closure, with exceptions; archived projects are retained for 12 months. Closing a JobGrinder account does not close our Userback account.
  • Resend publishes email and log retention of 30 days on Free, Pro and Scale plans, and deletion of remaining customer data within 90 days of provider-account termination. Firecrawl’s privacy policy retains personally identifiable information until a written deletion request; it does not establish an API scrape-cache expiry. Apify’s run and storage retention depends on plan and settings, and named stores can remain indefinitely. Polar describes retention for account and service needs, with legal, tax, accounting, dispute and fee exceptions. Our provider-specific overrides and erasure procedures still require verification.
  • Provider identity records, analytics, feedback, delivery records, extraction results, recovery copies and hosting logs are outside JobGrinder app account cleanup. A provider-account termination period describes the end of our relationship with that provider, rather than an automatic deadline triggered by one user deleting JobGrinder data.
  • Providers may process data outside the European Economic Area, including in the United States. Our production application runs in Vercel’s US region. Production configuration points to Convex’s EU deployment, an EU Browserbase region and PostHog’s EU endpoint. Userback publishes US hosting and transfers to the US, Australia and other service-provider countries. These EU settings do not establish EU-only processing by all providers. Remaining processing destinations, backup periods and applicable transfer safeguards have not yet been verified. Do not treat this draft policy as a completed transfer assessment.
  • Use Help and privacy requests for provider-copy erasure questions, retention details, or a request for information about transfer safeguards. Include the account email and the service or operation concerned; avoid sending a CV unless it is needed to handle your request. App deletion alone is not confirmation that all provider copies have been erased.

AI and sensitive search data

  • Resume text, job descriptions, and generated materials can contain sensitive personal and career information. JobGrinder uses this content to provide the requested generation or analysis. Provider retention and data-use conditions are described above.
  • Do not add information you do not want processed by JobGrinder or its service providers.

Your choices

  • You can export your account data from Account and data settings.
  • You can delete JobGrinder application data from Account and data settings. This leaves your sign-in account open. To close your sign-in account, use Manage sign-in account on the same settings page to open Clerk account settings, then select Security and Delete account.
  • You can opt out of reminder emails from reminder settings or from the unsubscribe link in reminder emails.

Retention and security

  • Profiles, application records, generated materials, labels, and automation history remain until you delete them or close your account. Account deletion schedules bounded cleanup batches and blocks new writes for that identity. Stored PDF and screenshot artifacts are included.
  • Unfinished onboarding drafts expire 30 days from their last edit and are removed when this browser next reads them. Profile save or reset clears them immediately. Account deletion clears this browser draft. Other devices must clear their local drafts separately.
  • The free beta deletes account-linked subscription, credit, and usage rows during account cleanup. Aggregate cost totals contain no account identifier. A minimal deletion marker remains for the lifetime of the closed identity to prevent stale tokens or background work from recreating deleted content. Unattached uploads are removed after a 24-hour grace period by the next daily sweep. Expired security rate-limit windows are removed after 24 hours by the next hourly sweep.
  • Copies held in provider backups, browser recordings, and operational logs follow the configured provider retention settings. The operator must disclose the actual provider retention and transfer arrangements before public launch.
  • We use reasonable technical and organizational safeguards, but no online service can guarantee absolute security.

Provider policy sources

Provider sources checked October 8, 2026. These sources describe the providers’ published policies; they do not establish our account settings or replace the pending operator review.

Manage account dataRead terms