Privacy Policy

Last updated: July 19, 2026

SearchSteward ("we", "us") operates a hosted job-search workspace. This policy explains what data we collect, why, where it goes, and the rights you have under the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Quebec's Act respecting the protection of personal information in the private sector (Law 25). If anything below is unclear, email [email protected].

1. Data we collect

  • Account identity: email, password hash, verification state, role.
  • Job-search profile: target companies, search preferences, salary expectations, location filters, resume text and generated resume variants.
  • Application records: applications you save, statuses, notes, contacts, interview events, offers.
  • Email signals (if you connect Gmail): sender, subject, snippets, classification labels, interview metadata. We process only messages that match job-related heuristics.
  • Calendar signals (if you connect Google Calendar): event metadata used to surface interview reminders.
  • Operational telemetry: request logs, scraper run logs, LLM usage and cost records, background-job payloads, audit events.

2. Why we process it (GDPR Art. 6 legal bases)

  • Performance of a contract — running the workspace you signed up for (matching, application tracking, generated artifacts).
  • Legitimate interests — security, abuse prevention, debugging, and improving scoring quality, balanced against your rights.
  • Consent — analytics cookies, marketing email, optional Gmail/Calendar integrations. You can withdraw consent at any time without affecting prior processing.
  • Legal obligation — tax records on paid plans, lawful requests we are required to honor.

3. Third-party processors

We share data only with the providers needed to run the product:

  • Railway — application hosting and managed Postgres (US region).
  • Zoho Mail — transactional and account email.
  • OpenAI and Google (Gemini) — LLM inference for resume tailoring, job-fit analysis, and outreach drafting. Prompts may include your resume and job-description text; we do not send unrelated personal data.
  • Stripe — billing (only once you start a paid plan).
  • Google (Gmail / Calendar) — only if you connect them. OAuth tokens are stored per user.

Some processors are located in the United States. Where you are in the EU/EEA or UK, transfers rely on Standard Contractual Clauses or equivalent safeguards offered by each provider.

If you are in Canada: your personal information is stored and processed on servers in the United States. While it is outside Canada it is subject to US law and may be accessible to US courts, law enforcement, and national security authorities. We remain accountable for it under PIPEDA and require each processor, by contract, to protect it to a comparable standard.

4. Cookies and analytics

We use a small number of first-party cookies and localStorage entries for authentication, CSRF protection, and feature state. These are necessary for the product to function and are not subject to opt-in consent.

We use no third-party analytics or advertising cookies. No analytics identifiers are stored in your browser.

5. Retention

  • Account profile, applications, and resumes: retained while your account is active.
  • Email signal raw excerpts: retained for up to 90 days after receipt, then redacted; the structured classification (labels, interview metadata) is kept.
  • Operational logs: 30–90 days depending on log type; security audit logs are kept 12 months.
  • Backups: rolling 35-day window. Deleted data ages out of backups within that window.
  • Billing records: 7 years (US tax requirement) on paid plans.

6. Your rights

Subject to verification, you can:

  • Access — download a copy of your data via Settings → Export, or request it from us.
  • Rectify — edit profile, preferences, applications, and notes from within the app.
  • Erase — delete your account from Settings → Privacy. We honor erasure requests in line with GDPR Art. 17 and CCPA § 1798.105.
  • Restrict / object — pause specific processing (e.g. disconnect Gmail) without deleting the account.
  • Portability — receive your data in a machine-readable JSON export.
  • Withdraw consent — disable analytics, disconnect integrations.
  • Non-discrimination (CCPA) — exercising any of these rights does not affect service quality or price.
  • Lodge a complaint — with your local supervisory authority (EU/EEA), the California Privacy Protection Agency, the Office of the Privacy Commissioner of Canada (OPC), or, in Quebec, the Commission d'accès à l'information (CAI).

Exercise any of these by emailing [email protected] or using the controls under Settings → Privacy. We respond within 30 days (the timeline PIPEDA and GDPR both require), free of charge.

6a. Canadian users (PIPEDA and Quebec Law 25)

We comply with PIPEDA and, for Quebec residents, with Law 25. Our designated Privacy Officer — the person in charge of the protection of personal information — is Eric DiPietro, reachable at [email protected].

  • Consent — we collect your resume, salary expectations, and employment history with your express consent, given at signup, for the purposes described in this policy. You can withdraw consent at any time by deleting your account.
  • Access and correction — you may access and correct your personal information as described in Section 6, at no cost, within 30 days.
  • Cross-border transfer — see Section 3: your data is processed in the United States.
  • Complaints — contact our Privacy Officer first; you may also complain to the OPC or, in Quebec, the CAI.

7. Sale and sharing of personal information (CCPA)

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. The third parties above act as service providers under written contracts that prohibit using your data for their own purposes.

8. Security

We use TLS in transit, encrypted storage at rest at our hosting provider, field-level encryption for credentials such as Gmail app passwords and integration tokens, role-based access controls for support staff, and audit logging on administrative actions. No system is perfectly secure. If a breach involving personal data occurs, we notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and, where the breach creates a real risk of significant harm, notify affected individuals, the Office of the Privacy Commissioner of Canada, and (for Quebec residents) the CAI as soon as feasible, in line with PIPEDA ss. 10.1–10.3 and Law 25. We keep records of all breaches, whether or not they meet the notification threshold, for at least 24 months.

9. Browser extension (Browser Assist)

SearchSteward Browser Assist is an optional browser extension (Chrome, Edge, Firefox) that saves the job posting on your current tab into your SearchSteward account. It reads page content only when you act: when you open the extension popup, or on supported job sites (LinkedIn, Greenhouse, Lever, Ashby, Indeed, Wellfound, Built In) when the page loads, to prepare a capture preview. It does not read pages in the background, does not track your browsing history, and contains no analytics, telemetry, or remote code.

  • What is sent when you click Capture:the page URL and title, the extracted job title, company, and location, the visible text of the posting (capped at 12,000 characters), and a compact snapshot of the page's structured metadata (page title, social-preview meta tags, and any JSON-LD "JobPosting" data the site publishes). Nothing is transmitted until you click Capture.
  • Where it goes: over HTTPS, exclusively to the SearchSteward API host configured in the extension, into your SearchSteward account — covered by the rest of this policy. The extension sends data to no other party.
  • Credentials:signing in sends your username and password directly to the SearchSteward API; only the resulting session token is stored, on your device, in the browser's extension storage. Your password is never stored. Signing out deletes the token.
  • Permissions: storage (your settings and session token), activeTab/scripting (read the posting on the current tab when you use the extension), tabs(the active tab's URL, to pick the right extractor), and site access on the job sites listed above (automatic capture preview).
  • Deletion: removing the extension deletes all locally stored extension data. Captured jobs live in your account and can be deleted there at any time.

10. Children

SearchSteward is not directed to children under 16 and we do not knowingly collect data from them.

11. Changes to this policy

We will post material changes here and, where required, notify you by email. The "Last updated" date reflects the most recent revision.

12. Contact

Data controller: SearchSteward Operations. Privacy Officer: Eric DiPietro. For privacy questions, GDPR, CCPA, PIPEDA, or Law 25 requests, or to report a concern, email [email protected].