Skip to main content

Privacy Policy

Effective August 5, 2026

What we collect

Account data: the email address you use to sign in. If you sign in with Google, we also receive your name and profile photo from your Google account, never your Google password. If you use email and password sign-in, we store a salted, one-way password hash, never your plaintext password.

Content you provide: the professional background you enter, job descriptions you paste or point us to, and the resumes we generate for you.

Billing data: handled entirely by Stripe. We never see or store your card number — only a Stripe customer reference and your credit balance.

Technical and usage data: for security and reliability, we may record the requested page path without query strings or fragments, a blocked resource path, and browser or device user agent for up to 30 days. The public landing experience records a random identifier for each browser tab, an event name, a scene number, and short diagnostic metadata for up to 30 days. Abuse controls use an account email or IP address identifier as a temporary Upstash rate limit counter key for the applicable window, normally minutes and never more than 24 hours. These records do not include resume or job description content.

How we use it

Your content is used to provide the career features you request, including tailored resumes, cover letters, interview preparation, job fit and matching, outreach drafts, and career identity tools. We send the content needed for those features to Anthropic's Claude API. Anthropic states that commercial API inputs and outputs are not used to train its models by default unless the account explicitly opts in or submits materials as feedback. Anthropic states that standard API inputs and outputs may be retained for up to 30 days, with longer retention in limited safety or legal circumstances. We do not sell your data, show ads, or share your content except with the service providers below.

How it's protected

All traffic is encrypted in transit (TLS). We additionally apply AES-256-GCM application-layer encryption to saved backgrounds, raw job text, structured resume content, and selected submitted fields before storage. Derived analysis and report data, filenames, and rendered documents are protected by database-level disk encryption and application access controls, but are not yet all inside that additional application-layer envelope. Those fields follow the purge schedule below. Resume content is never written to logs.

Retention and deletion

New raw job descriptions and generated resume records are assigned a purge date 90 days after creation and are automatically purged when that date arrives. Some older records created before purge dates were assigned are pending a controlled retention repair after backup and restore verification; until then, those records are not covered by the automatic schedule. The purge includes resume and cover-letter content, reports, interview and learning plans, filenames, outreach drafts, and tracked outreach contacts. Resolved or dismissed feedback is removed after a further 90-day support window. Security diagnostics and landing experience telemetry are deleted after 30 days. Temporary rate limit counters expire when their applicable window ends. Identifiable account references are removed from internal action logs when you delete your account, and remaining operational log metadata is deleted after one year. Encrypted backups are not edited in place and can retain prior copies until their rolling 90-day expiration. You can delete any generation immediately from its page. If you do not own a recruiter workspace, you can delete your account, including app-held profiles, jobs, personal generations, and credit history, from the account page. Workspace owners must contact support@landthejobai.com so we can verify the request, transfer or delete the workspace as directed, and then erase the account. Account page deletion is immediate and irreversible. Verified owner requests are completed after the workspace is resolved. These processes support GDPR Article 17 and CCPA deletion rights. Stripe may retain transaction records under its own legal obligations and retention policy.

Service providers

Vercel (hosting), Supabase (managed PostgreSQL storage), Stripe (payments), Anthropic (requested AI career features), Google (sign-in only, as described under Account data), our configured transactional email provider (verification delivery, including the recipient address and one-time verification link), and Upstash (temporary abuse prevention counters, which can include an account email or IP address identifier but no resume or job content). Job discovery also queries Remotive and USAJOBS using target-role search terms and, for USAJOBS, your saved location and radius. If you select a public employer board, it queries that board through Greenhouse, Lever, Ashby, or SmartRecruiters using the selected public-board identifier. These job-data sources do not receive your resume or pasted job-description body. Each recipient receives only what its function requires.

Who at LandTheJobAI can see your data

Routine internal access is limited to account metadata — email, credit balance, and timestamps — for operating the service. Application-encrypted source and structured fields are decrypted for internal review only to resolve an issue you asked us to look at, such as a bug report you submitted. Derived artifacts use the storage controls described above. Every support access to user content is recorded in an internal audit log.

Cookies

We use only essential cookies — the ones that keep you signed in and protect the Service against cross-site request forgery. There are no advertising cookies and no third-party analytics cookies.

Do Not Track and opt-out signals

We do not track you across other websites, build advertising profiles, or sell or share personal information — so there is nothing for a "Do Not Track" or Global Privacy Control signal to switch off, and the Service behaves the same whether or not your browser sends one.

Browser extension

The LandTheJobAI Job Clipper reads a page only when you click its button, captures the job posting or LinkedIn profile page you choose to clip, and transfers that text directly into a new LandTheJobAI tab through a URL fragment that browsers do not send to servers. The app removes the fragment before processing it. Until you submit the form, the text is held in page memory and the current tab's session storage, which is cleared when the tab closes. Submitted content follows the encryption and retention rules above. The extension has no access to your browsing history, does not track you in the background, and collects nothing beyond the page you deliberately clip. Only clip profile content you are authorized to use. The extension's use and transfer of information received through Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Recruiter workspaces

When a recruiting organization uses a workspace, the candidate information it adds is processed for one purpose: generating application materials for that organization. Candidate source content uses application-layer encryption. Derived workspace artifacts use the other storage controls described above and follow the same retention rules. Each organization must have each candidate's permission (see our Terms); if your information was added to a workspace and you want it removed, email support@landthejobai.com.

Contact

Privacy questions or data requests: support@landthejobai.com. We respond to verified requests within 30 days.