Legal
Privacy Policy
Last updated: March 17, 2026 · Effective immediately
Summary: JobOrbit AI stores your job portal credentials encrypted with AES-256. We use them only to apply to jobs on your behalf. We never sell your data. You can delete your account and all data at any time.
1. Who we are
JobOrbit AI ("JobOrbit", "we", "us", "our") is an autonomous job application service operated at joborbit.ai. We help job seekers automate their job applications on LinkedIn, Indeed, Monster, and other platforms. Our contact email is hello@joborbit.ai.
2. What data we collect
We collect the following categories of information:
- Account information: Your name, email address, and password (stored as a bcrypt hash — we never store your plain-text password).
- Profile information: Your resume, skills, years of experience, target roles, target locations, salary expectations, university, degree, graduation year, visa type, and OPT/CPT dates — provided by you to configure the agent.
- Portal credentials: Your LinkedIn, Indeed, and Monster email and password, stored encrypted with AES-256-GCM. After your first login, we store session cookies instead of your password for ongoing use.
- Gmail OAuth tokens: Access and refresh tokens for your Gmail account, used by the email agent to read and reply to recruiter emails. We never store your Gmail password.
- Application data: Records of every job application submitted on your behalf — company, role, status, date, match score, tailored resume, and cover letter generated for each role.
- Email data: Summaries and classifications of recruiter emails processed by the email agent. We do not store full email bodies beyond what is needed to draft replies.
- Payment information: Billing is handled entirely by Stripe. We store only your Stripe customer ID and subscription status — we never see or store your card number.
- Usage data: Agent activity logs, application counts, scan results, and error logs for debugging and service improvement.
3. How we use your data
We use your data solely to provide and improve the JobOrbit AI service:
- To scan job portals and identify matching roles for you
- To tailor your resume and cover letter for each job
- To submit job applications on your behalf
- To monitor your inbox and respond to recruiter emails
- To alert you when human decisions are needed
- To process your subscription payment via Stripe
- To improve our AI scoring and matching algorithms
- To send you transactional emails (account, payment receipts, alerts)
We do not sell, rent, or share your personal data with third parties for marketing purposes. Ever.
4. How we protect your data
- Portal passwords: Encrypted with AES-256-GCM using a key derived via PBKDF2 with 200,000 iterations. The encryption key is stored separately from your data — never in the database.
- Account passwords: Hashed with bcrypt. Plain-text passwords are never stored or logged.
- Gmail tokens: Stored encrypted. Used only to perform the email agent functions you authorized.
- Data in transit: All communication between your browser, our API, and our database is encrypted via TLS/HTTPS.
- Database: Our PostgreSQL database is restricted to our internal network — it has no public IP address and cannot be accessed directly from the internet.
- Session cookies: After your first portal login, we use session cookies rather than your raw credentials for all subsequent agent activity.
5. Third-party services
We use the following third-party services to operate JobOrbit AI:
- Anthropic (Claude API): Powers our AI resume tailoring, job scoring, email classification, and cover letter generation. Your resume and job descriptions are sent to Anthropic's API for processing. See Anthropic's Privacy Policy.
- Stripe: Processes all subscription payments. We never see your card details. See Stripe's Privacy Policy.
- Google (Gmail API): Used with your explicit OAuth authorization to read and reply to recruiter emails. See Google's Privacy Policy.
- Railway: Hosts our backend API and database. See Railway's Privacy Policy.
- LinkedIn, Indeed, Monster: When the agent submits applications, it interacts with these platforms using your credentials. Your use of these platforms is also governed by their respective privacy policies.
6. Data retention
We retain your data for as long as your account is active. If you cancel your subscription:
- Your account data is retained for 30 days in case you reactivate
- After 30 days, your credentials, Gmail tokens, and resume are permanently deleted
- Application history records are anonymized and retained for product improvement
- You can request immediate deletion at any time by emailing hello@joborbit.ai
7. Your rights
You have the right to:
- Access: Request a copy of all data we hold about you
- Correction: Update any inaccurate information in your profile
- Deletion: Request deletion of your account and all associated data
- Portability: Export your application history as a CSV
- Revoke Gmail access: Disconnect Gmail at any time from the Connections page or via Google's account permissions
- Disconnect portals: Remove your LinkedIn, Indeed, or Monster credentials from the Connections page at any time
To exercise any of these rights, email us at hello@joborbit.ai. We respond within 5 business days.
8. Cookies
We use minimal cookies — only what is necessary to keep you logged in to the JobOrbit dashboard. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
9. Children's privacy
JobOrbit AI is not intended for use by anyone under the age of 18. We do not knowingly collect data from minors. If you believe we have collected data from a minor, contact us immediately at hello@joborbit.ai.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify active users by email at least 7 days before the changes take effect.
11. Contact us
For any privacy questions, data requests, or concerns: