Privacy Policy for Jobweave
Effective: 2026-08-24
This policy covers the Jobweave web app, API and your account. The Jobweave browser extension is covered separately, in the extension privacy policy.
Who we are
Jobweave is operated by Jobweave, Inc., 5055 W Hacienda Ave Unit #1096, Las Vegas, NV 89118. For any privacy question or request, including the requests described below, contact support@jobweave.app. This is also the designated address for requests under Nevada Revised Statutes chapter 603A.
What we collect
- Your account details. The email address you sign up with.
- What you put in your resume profiles. Name, email, phone, location, and any LinkedIn, website or GitHub links you add.
- Your career history. Roles, employers, titles, dates, achievements, projects, skills and education — everything you enter so that resumes can be built from it.
- Your applications and the documents you make. The jobs you track, including company, role, status, your notes, and the text of the job posting; the resumes, cover letters, outreach messages and interview prep generated alongside them; and your tasks.
- GitHub repository details — repository name, primary language and star count — but only if you choose to connect GitHub.
- Credentials you give us. If you supply a GitHub token or your own Anthropic or OpenAI API key, we store it so the feature you enabled can work. These are encrypted before they are written to the database.
- Sign-in security information. A device identifier, a hashedversion of your IP address, and your browser's user agent, so we can recognise a new device and tell you about it. We do not store your IP address itself.
- A record of actions on your account — what was done, to what, when, and whether it succeeded.
Who else sees it
We use a small number of other companies to run Jobweave. Each one receives only what the feature you used requires.
- An AI provider — OpenAI or Anthropic. This is the important one. When you use any AI feature, the text needed for that feature is sent to the provider we have configured. Depending on the action, that includes your career history, your resume text, and the job posting you are applying to. If you have supplied your own API key, the request goes out under your key instead of ours.
- Supabase — sign-in, and the database that holds everything described above.
- Amazon Web Services — sends our transactional email, so it processes your address and the message.
- GitHub — only if you connect it. We call the GitHub API as you, using the token you provided.
- Vercel and Render — hosting for the web app, the API, and the service that renders your resume PDFs.
We do not sell your data, we do not share it for advertising, and we do not use it to train anyone's models.
What we do not do
Jobweave runs no analytics. There is no Google Analytics, no product-analytics tool, no advertising network and no third-party tracker anywhere in the app. The only cookie we set is one that recognises your device at sign-in, so we can alert you to a sign-in from somewhere new.
How long we keep it
Your account and everything in it is kept until you delete it. Credentials you supply are kept until you remove them in Settings. Connection tokens are kept until you revoke them or delete the connection.
Two things worth stating plainly rather than leaving you to assume. First, our database is backed up, and a deleted record continues to exist in those backups until they age out — deletion is not instant everywhere. Second, we currently keep the record of actions on your account indefinitely; we do not yet expire it.
Getting your data out, and getting it deleted
You can export everything on your account at any time from Settings, as a file you keep.
You can delete your account yourself, from Settings. It removes your career history, resumes, applications, cover letters and tasks, and any connection tokens you have created stop working immediately. It cannot be undone, so export first if you want a copy.
Two things we keep, and why. Deleted records remain in our database backups until those age out, as described above. And we keep the record of actions taken on the account — what was done and when — with your identity removed from it, so the security history stays intact without pointing at you.
If you would rather we did it, or something goes wrong, email support@jobweave.app and we will handle it within 30 days.
You can also ask us what we hold about you, ask us to correct it, or object to how we use it, at the same address.
Security
Access to your data requires your sign-in. Any GitHub token or AI provider key you give us is encrypted before storage. Your IP address is hashed rather than stored. No system is perfectly secure, and we do not claim otherwise.
Children
Jobweave is not intended for anyone under 16, and we do not knowingly collect their data.
Changes to this policy
If what we collect or how we use it changes, we will update this page and change the effective date. If a change materially affects you, we will tell you by email before it takes effect.