Privacy Policy
Effective date: June 5, 2026
1. Who we are
Job Panda (“we”, “our”, “us”) is an AI-powered job search tool. Our service is available at www.jobpanda.app. Questions about this policy can be sent to hello@jobpanda.app.
2. What data we collect
- Account data: Email address and name when you sign up via email or OAuth (Google, GitHub).
- Resume content: Text extracted from the resume or CV you upload. We use this to ground your mock interview questions and coaching in your real experience (and, in our job-search tools, to match you to roles and tailor application materials).
- Interview practice recordings: When you practice, we access your camera and microphone. Your video is recorded only in your browser for replay and is never uploaded to our servers. Your audio is sent to OpenAI solely to transcribe your answer and is never stored. When you evaluate an answer, the transcript of what you said, the coaching feedback, scores, and your improved answer are saved to your account so your results persist and we can give you an end-of-mock debrief.
- Job preferences: Target roles, location, work arrangement, salary range, and country you provide in your profile.
- Usage data: Page views and feature interactions collected via Vercel Analytics and PostHog (product analytics) to understand and improve the product.
3. How we use your data
- Generating tailored interview questions, transcribing and scoring your spoken answers, and producing improved answers grounded in your résumé
- Job-search tools: matching you to roles and generating tailored resumes and cover letters
- Sending transactional and (optional) digest email — you can unsubscribe at any time
- Improving the service and diagnosing errors
We do not sell your data to third parties. We do not currently use your data to train AI models. If we do so in the future, we will ask for your explicit consent before doing so.
4. Third-party services
We rely on the following sub-processors:
- Supabase — database and authentication (data stored in AWS us-east-1)
- OpenAI — transcription of your spoken answers, interview coaching, and resume tailoring (audio, transcripts, and inputs are not used to train OpenAI models per their API terms)
- Stripe — payment processing for paid subscriptions (we never see or store your card details)
- PostHog — product analytics to understand how the service is used
- Resend — transactional and digest email delivery
- Google — OAuth login (Google Sign-In)
- Vercel — hosting and analytics
5. How we protect your data
We apply the following technical and organisational measures to protect your personal data:
- Encryption in transit: All data transmitted between your browser, our servers, and third-party sub-processors is encrypted using TLS 1.2 or higher.
- Encryption at rest: Your data (including resume content and authentication tokens) is stored in Supabase (AWS us-east-1), which applies industry-standard encryption at rest via our infrastructure provider.
- Access controls: Production database access is restricted to server-side application code using Row-Level Security (RLS). Your data is isolated by user ID and cannot be accessed by other users.
- No AI training on your data: Your resume content and personal information are never used to train AI or ML models — neither by us nor by our sub-processors (OpenAI API terms explicitly prohibit training on API inputs).
- Breach notification: In the event of a data breach affecting your personal data, we will notify affected users and, where required by applicable law, relevant authorities without undue delay.
6. Data retention and deletion
Your data is retained as long as your account is active. You can delete your account at any time by emailing hello@jobpanda.app. Upon deletion, all personal data (resume, preferences, application history) is permanently removed within 30 days.
7. Your rights
Depending on your jurisdiction (GDPR, PIPEDA, CCPA), you may have the right to access, correct, export, or delete your personal data. To exercise any of these rights, contact us at hello@jobpanda.app.
8. Cookies
We use a session cookie for authentication and product-analytics cookies/local storage (PostHog, Vercel) to understand usage and improve the service. We do not use third-party advertising cookies.
9. Chrome Extension
The Job Panda Chrome Extension (“the extension”) supplements the web app with the following behaviour:
- Authentication token: When you connect the extension to your Job Panda account, a device-specific API token is stored locally in
chrome.storage.local. This token is used solely to authenticate requests to the Job Panda API on your behalf. No password or OAuth credential is stored in the extension. - Job page content: When you click “Save Job” on a supported job board (e.g. LinkedIn, Indeed, Workday, Greenhouse, Lever), the extension reads the job title, company name, and page URL from the active tab and sends them to your Job Panda account. No other page content is collected.
- Application autofill: On supported ATS platforms (Workday, Greenhouse, Lever), the extension reads form field labels from the active tab and fills them with answers from your saved profile. Form data is read locally within your browser; answers are fetched from and saved to the Job Panda API only when you initiate autofill.
- No passive monitoring: The extension does not track your browsing history, record keystrokes, monitor pages in the background, or collect data from any page without an explicit action by you.
10. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email to registered users. The effective date at the top of this page will always reflect the latest version.
11. Contact
For any privacy-related questions or requests, email us at hello@jobpanda.app.
