EnterJobs
Pricing
⚠️ Draft — pending review. This page describes EnterJobs' privacy approach in plain language. It is being finalized and reviewed before launch; it is not yet the final legal policy.

Privacy Policy

Last updated: · Draft

The short version

EnterJobs is built privacy-first. Your documents, résumés, application answers, AI keys, and personal data stay on your own device — they do not pass through our servers. What does reach our servers is limited, named plainly below, and explained so you know exactly what you're sharing and why.

What stays on your device

The app runs locally on your computer. The following never leaves your machine through us:

  • Your résumés, cover letters, writing samples, and voice recordings — every generated version
  • Your profile, answers, verified-facts file, and communication-style profile
  • The content of your applications (what you type into forms) and your full local application database
  • Your skill memory (the app's learned form-filling know-how, stored locally)
  • Your AI model API keys — stored in your OS keychain (macOS Keychain, Windows Credential Store, or Linux Secret Service), never in plaintext, never uploaded
  • The job-site accounts you sign into — those sessions live in your local browser profile
  • Your AI model inputs and outputs — EnterJobs servers never see the prompts sent to your model or the responses it returns

What we do collect

To run accounts, billing, authentication, and to support you when something goes wrong, a defined set of data is handled on our side. We name it plainly:

Account identity

Your email address (lowercased), optional name, and a securely hashed password — so you can sign in, verify your email, and reset your password. If you sign in with Google or Apple, we receive your Google account email or Apple-assigned subscriber identifier and relay email instead of a password.

If you enable SMS two-factor authentication, we also store your phone number (and a verified flag) and process SMS delivery via Twilio Verify.

Billing

Payment processing is handled by Stripe (and optionally PayPal). Your card details are entered directly on Stripe's secure forms and never touch our servers. We keep only a billing reference (Stripe customer ID), your subscription tier, expiry date, and lifetime-access flag.

Session and security metadata

To protect your account, we log:

  • Login IP address and user-agent string, per session
  • Login-attempt records (for rate-limiting and anomaly detection)
  • Trusted-device tokens (valid for 30 days — these let you skip two-factor verification on devices you recognize)
  • Terms-of-service acceptance records — document version, method of acceptance, user-agent, and a truncated IP address (last octet removed)

Device check-ins

On every authenticated API call, the app sends a small check-in: device ID, app version, platform (macOS / Windows / Linux), and first/last-seen timestamps. This is how the app authenticates and how we know what version you're running when you need support. There is no independent opt-out from device check-ins — they are a required part of how authentication works.

Diagnostics telemetry — default ON, you can turn it off

To support users and diagnose field issues remotely, the app uploads run summaries at the end of each session. This is on by default. Here is exactly what it includes:

  • Run summaries — run ID, timestamps, app version, total counts (applied / no-fit / blocked), and the browser identity used
  • Round summaries — outcome, reasons, counts, a short narrative from your assistant, and a ticker snapshot
  • Per-candidate decisions — for each position evaluated: the job URL, title, and company, plus the verdict (applied / vetoed / skipped) and why
  • Application records — for each application submitted: job title, company, URL, and submitted timestamp

This means that with diagnostics on (the default), our servers do receive the titles, companies, and URLs of jobs you apply to, so we can help you if something goes wrong and fix issues in the field.

How to turn it off: open the app's diagnostics setting in Preferences, or set diagnostics.upload: false in your preferences file, or set the environment variable ENTERJOBS_DIAG_UPLOAD=0. The applications sub-feed and on-demand log channel have separate switches (ENTERJOBS_DIAG_APPS, ENTERJOBS_DIAG_QUERY).

On-demand log channel

The app automatically uploads a coverage index — which days have local logs and their approximate sizes. Actual log content is sent only when our support tooling requests a specific slice while the app is open. When that happens, the app shows a visible in-app event so you know a diagnostic query was answered.

API usage logs

Our servers log the endpoint called and timestamp for each authenticated API request. Our hosting infrastructure (Railway / GCP) also records IP addresses in standard transit logs.

Transactional email

Email verification, password reset, and magic-link emails are delivered via SendGrid. Your email address is shared with SendGrid for this purpose.

Your AI model and data privacy (BYOM)

EnterJobs does not provide an AI model — you bring your own. Your data privacy for AI processing depends on the model you choose:

  • Sign in with Claude (the default tier): uses your own Anthropic subscription via OAuth. Your data is governed by Anthropic's privacy policy.
  • Your API key (Anthropic, OpenAI, Gemini, DeepSeek, xAI, Groq, and others via a local proxy on your machine): your key stays in your OS keychain and never leaves your device through us. Data sent to those providers for processing is governed by their policies.
  • Local model (Ollama on capable hardware): all processing happens on your device — nothing leaves your machine for inference.

EnterJobs does not store, access, or control data exchanged between your device and your chosen AI provider. We recommend choosing a provider with an inference-only data policy. Review your AI provider's privacy policy before use.

Shared form-filling arsenal

To keep the shared form-filling library learning, the app automatically contributes techniques it discovers for operating application-form widgets (for example, how a particular portal's dropdown or file-upload control works), along with signals about whether those techniques succeeded. These submissions describe form mechanics — category, problem, technique, portal type, confidence level — and are human-reviewed before being shared with other users. They are not designed to carry your personal application content. There is no separate opt-out toggle for this today.

What we don't collect

We do not collect or store:

  • Your résumés, cover letters, writing samples, or voice recordings
  • The content of your applications — your answers, essays, or form responses
  • Your job-site login credentials
  • Your AI model inputs or outputs (prompts and completions stay between your device and your chosen model provider)
  • Your communication-style profile or voice data
  • Recruiter outreach emails — those are drafted and sent from your device; we do not receive copies

Third parties

  • Stripe / PayPal — payment processing (card data lives with them, not us)
  • Twilio — SMS verification, when you enable two-factor authentication via phone
  • SendGrid — transactional email (verification, password reset, magic links)
  • Hosting infrastructure (Railway / GCP) — our servers; standard request logs including IP addresses
  • Your chosen AI model provider — the app sends prompts to the model you select to do its work; that relationship is governed by that provider's terms and privacy policy

Age requirements

EnterJobs is intended for users aged 16 and older. Users between the ages of 16 and 18 should review these terms with a parent or legal guardian before use. We do not knowingly collect personal information from users under the age of 13. If we become aware that a user under 13 has created an account, we will take steps to remove their information promptly.

Security and your responsibility

Because most of your data lives on your device, keeping that device secure is important — if your device is compromised, the data on it could be exposed. We protect the limited account and billing data we hold using standard industry practices including encryption in transit and at rest, hashed passwords, and rate-limited authentication.

Your choices and data deletion

You can delete the local EnterJobs data on your device at any time through the app or by removing the app's data directory. You can cancel your subscription and request deletion of your account information (email, billing reference, session records, device check-ins) by contacting us. We will process deletion requests promptly.

Changes to this policy

When we update this policy, we will update the date above and, for material changes, notify you by email or in-app notice. Continued use after a material change constitutes acceptance of the updated policy.

Contact

Questions about privacy? Email support@enterjobs.pro.

© EnterJobs Home · Terms · Log in