Privacy Policy
Last updated September 27, 2026
Who we are
JobCubby ("JobCubby", "we", "us") is a job-application tracker that helps you organise and run your job search. This policy explains what personal data we collect, why we collect it, how we use and share it, and the choices you have. If you have any questions, email support@jobcubby.com.
Information we collect
Information you provide
- Account details — your email address. If you sign up with Google, we receive your email and basic profile information from Google (see Google user data).
- Your job-search content — the applications you track (company, role, status, dates, salary, posting links), notes, interviews, your profile (headline, summary, skills, work history, education), and any résumé files you upload.
- Job postings you save with the browser extension — the text and address of a page, sent only when you click the extension's button on it (see Browser extension).
Information collected automatically
- Essential cookies and similar technologies that keep you signed in and remember basic preferences (see Cookies).
- Analytics, but only if you accept it — pages viewed, referrer, approximate location and device type, collected through Google Analytics (see Analytics).
- Technical data such as IP address and browser type, recorded in server logs for security, debugging, and reliability.
- Push device tokens, if you install a JobCubby mobile app and turn on push notifications. A token identifies your device to Apple or Google so a notification can be delivered to it; the notification's title and body travel with it.
Payment information
Paid plans are sold by Creem, our merchant of record, which processes your payment details on its own systems; we do not store full card numbers. We receive from Creem the customer and subscription identifiers we need to apply your plan to your account.
How we use your information
- To provide and operate JobCubby — tracking applications, generating documents, and scheduling interviews.
- To authenticate you and keep your account secure.
- To generate the AI materials you request (see AI processing).
- To send essential service messages, such as sign-in links and notifications you enable.
- To maintain, debug, and improve the service.
- To process payments and manage subscriptions.
We do not sell your personal data, and we do not use it for advertising or cross-site tracking.
AI processing
When you use an AI tool (such as cover letter, résumé tailoring, or interview prep), the content you select — the application, your profile, and any résumé you choose — is sent to an AI provider to generate the result. We currently use Anthropic, either directly or through a routing relay that forwards the request to it on our behalf; the relay we use is named in the sub-processor list below. These providers process your content only to return the result and do not use it to train their models. AI output can be inaccurate or incomplete — always review it before relying on it.
Google user data
JobCubby offers three optional Google connections. For each one, we request only the permission the feature needs:
- Sign in with Google — we receive your email address and basic profile information, used to create and authenticate your account.
- Google Calendar (optional) — if you connect it, we use the calendar-events permission only to add and update events in your calendar for the interviews you schedule in JobCubby. We do not read, store, or analyse your other calendar data.
- Gmail (optional) — if you connect it, we use the send-only permission to send the follow-up emails you write and approve from your own address. This permission does not allow us to read your inbox, and we never do.
To keep these connections working, we store the tokens Google issues to us, encrypted at rest. We use Google user data only to provide the features described above. We do not sell it, use it for advertising, transfer it to third parties, use it to train AI or machine-learning models (including generalised AI models), or allow humans to read it, except with your explicit permission, where necessary for security, or where required by law.
You can disconnect Google Calendar or Gmail at any time in Settings → Account, which deletes the stored tokens immediately; deleting your account removes them as well. You can also revoke JobCubby's access from your Google Account security settings.
JobCubby's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Browser extension
The JobCubby browser extension saves the job posting you are looking at into your tracker. It is optional, and it does nothing at all until you click its button in the toolbar.
- What it reads — when you click the button, and only then, the extension reads the text of that one tab, along with any structured job-posting data the page publishes for search engines. It has no access to your other tabs, and no access to that tab either until the click.
- What it sends — that text and the page's address go to JobCubby over HTTPS, where they are turned into an application in your account. As with the AI tools in the app, the text is sent to Anthropic to pull out the fields (company, role, location, salary, description) — see AI processing. The saved application is yours, and you can edit or delete it like any other.
- What it stores on your device — the session tokens that keep you signed in, held in the browser's extension storage. Page content is never kept there.
- Signing in — with your email and password, or, in Chrome, with Google through the browser's own sign-in broker, so the extension never sees your Google password (see Google user data).
The extension does not read your browsing history, monitor the sites you visit, run in the background, or contain advertising or analytics code. The only server it contacts is JobCubby's. Uninstalling it deletes the stored tokens; anything you already saved stays in your account until you delete it.
How we share information
We share personal data only as needed to run JobCubby:
- Service providers (processors) — the companies listed in the sub-processor list below. Each one processes your data only on our instructions, for the purpose named there.
- Our staff — we may access your account to investigate a support request or a security issue. Every such access is recorded in an internal audit log, and while it is happening a banner at the top of your account says so.
- Apps you authorise — if you grant a third-party AI client access through our developer/MCP integration, it can read the data you approve on the consent screen. You can revoke that access at any time.
- Public sharing — if you enable a public progress link, the information you choose to include becomes viewable by anyone with the link. You can anonymise it, hide salary, or disable it entirely.
- Legal reasons — when required by law, or to protect the rights, safety, and integrity of JobCubby and its users.
Sub-processors
These are the third parties that process personal data on our behalf. We keep this list current; if you would like to be told before we add one, email support@jobcubby.com.
| Provider | What it does for us | What it receives |
|---|---|---|
| Anthropic | Generates the AI output you ask for | The application, profile and résumé content you select for that request |
| OpenLux (AI routing relay) | Forwards our AI requests to Anthropic when the relay is the active channel | The same content as the request it forwards |
| Google — Sign-in, Calendar, Gmail | Sign in with Google, and the two optional connections (see Google user data) | Your email and basic profile on sign-in; the interview events you schedule; the follow-up emails you approve |
| Google Analytics | Measures how the site is used — only if you accept analytics cookies | Pages viewed, referrer, IP address, device and browser |
| Google — Firebase Cloud Messaging | Delivers push notifications to Android devices | Your device token and the notification's title and body |
| Apple | Sign in with Apple, and push delivery to iOS devices | The identifier Apple issues for you; device token and notification text |
| Creem | Merchant of record — payment, invoicing and sales tax on paid plans | Your email and the payment details you give it at checkout |
| Resend | Sends our email — sign-in links, notifications, digests and product updates | Your email address and the content of the message |
| Our hosting provider | Runs the servers, the database and the object storage the service is built on | All of the data you store in JobCubby, at rest and in transit. Ask us at support@jobcubby.com and we will name the provider and the region. |
Two things that look like third parties are not: our error monitoring (GlitchTip) and the storage that holds uploaded résumé files (SeaweedFS) both run on our own infrastructure. The typefaces the site uses are served from our own servers too, so loading a page does not contact a font provider.
Legal bases for processing
If you are in the EEA or the UK, we rely on these bases under the GDPR:
- Performance of a contract — running your account and the features you use: tracking applications, generating the AI output you request, scheduling interviews, and billing you for a paid plan.
- Legitimate interests — keeping the service secure and available, preventing abuse, keeping server and audit logs, and telling you about changes to the product. You can object to any of this at support@jobcubby.com.
- Consent — analytics cookies, the optional Google Calendar and Gmail connections, push notifications, and non-essential email. You can withdraw any of these at any time, without affecting what was done before you did.
- Legal obligation — tax and accounting records for payments.
Cookies and similar technologies
These cookies are strictly necessary to run the service, and we set them without asking:
- a session cookie that keeps you signed in,
- an optional "remember me" cookie (valid for up to 14 days) if you choose to stay logged in,
- a short-lived cookie used to show one-off status messages.
Your theme preference (light or dark) and your answer to the cookie notice are stored in your browser's local storage, not in a cookie. On the billing page, Creem may set cookies needed to process checkout securely. We do not use advertising cookies, and JobCubby carries no advertising.
Analytics
We use Google Analytics 4 to understand which pages people use and where they arrive from. It is not essential to the service, so it is off until you accept it. The notice at the bottom of the page offers "Accept analytics" and "Reject" with equal weight, and nothing is loaded from Google until you choose to accept.
If you accept, Google Analytics sets first-party cookies (_ga and _ga_<id>, which last up to two years) and receives the pages you view,
the address you came from, and your IP address and device type. It also receives which
features you use, as bare events: that you signed up or signed in (and how), finished
onboarding, added a résumé, tracked an application or moved it to a new stage, ran or saved a
job search, used an AI tool, or opened the upgrade checkout. It does not receive your name,
your email, your search terms, your applications' contents, your notes or your résumé, and
it does not receive payment amounts.
When you are signed in, these events carry a random-looking identifier derived from your account, so that visits from the website and the JobCubby app count as one person. Google cannot turn it back into your account or your email. Our mobile app asks for the same consent separately, uses Google Analytics for Firebase for the same events, and collects nothing until you accept there.
You can change your mind at any time: the Cookie settings link in the footer of every public page clears your answer and brings the notice back, so you can accept or reject afresh. Clearing your browser's site data has the same effect.
Data retention
We keep your account data — applications, notes, interviews, profile and résumés — until you delete the item or delete your account, whichever comes first. Deleting your account removes your data, including the résumé files in our storage. Some records have shorter fixed lifetimes:
| Data | How long we keep it |
|---|---|
| Notifications you have read | 90 days, then deleted |
| Developer/MCP audit log (what a connected AI client did) | 60 days, then deleted |
| Mobile API request keys (used to stop a retry doing the same thing twice) | 48 hours |
| Revoked mobile sessions | 30 days after revocation, then deleted |
| Sign-in sessions and the "remember me" cookie | Valid for 14 days, after which they stop working |
| Account data (applications, notes, profile, résumés) | Until you delete the item or your account |
We may retain limited records for longer where needed for legal, security, or accounting reasons — for example an invoice, or a security audit entry.
Your rights
Depending on where you live — for example, the EEA and UK under the GDPR, or California under the CCPA/CPRA — you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can edit most of your data directly in the app, or email support@jobcubby.com to exercise any of these rights. We will not discriminate against you for doing so.
Security
We use industry-standard measures, including encryption in transit and access controls, to protect your data. No system is perfectly secure, but we work to keep your information safe and to notify you of material incidents where required by law.
International transfers
JobCubby and its service providers may process your data in countries other than your own. Where required, we rely on appropriate safeguards for these transfers.
Children
JobCubby is not intended for anyone under 16, and we do not knowingly collect personal data from children.
Changes to this policy
We may update this policy from time to time. We will revise the "last updated" date above and, for material changes, give notice within the app.
Contact
Questions about privacy or this policy? Email support@jobcubby.com. See also our Terms of Service.