← The Job Hunt

Privacy Policy

Effective September 2, 2026. Operated by Project Carbon Fiber LLC.

This policy explains exactly what The Job Hunt collects, who else processes it, how long it is kept, and how to get it back or have it deleted. It describes what the service does today, not what it may do later; it is updated when the service changes.

1. Who we are

The Job Hunt is operated by Project Carbon Fiber LLC. For any privacy question, correction, or deletion request, contact [email protected]. We answer privacy requests within 30 days.

2. What we collect

Named specifically, by what it is and why we hold it.

Account

We never receive or store your password. Authentication is handled entirely by Amazon Cognito.

Your resume and profile

Jobs you apply to

Documents we generate for you

Recruiter outreach: information about other people

When you use the recruiter outreach feature, we retrieve and store business contact information about people at the employer you are applying to: name, job title, LinkedIn profile URL, work email address, and work phone number, along with the messages drafted for them. These people are not users of The Job Hunt and did not give us this information themselves; it is obtained from our data provider (below).

Usage, settings, and support

We do not use advertising trackers, and we do not sell personal information to anyone.

Cookies and browser storage

We do not use advertising or tracking cookies. To keep you signed in and remember your preferences, we store a small amount of data in your browser's local storage: your Amazon Cognito sign-in tokens, your theme choice, a timestamp of your last activity, and your progress through an in-flight application. This data stays in your browser, is not shared with anyone, and is cleared when you sign out or clear your site data.

3. Who else processes your data

These are every third party your data reaches, what they receive, and why.

ProcessorWhat it receivesWhy
Amazon Web Services (us-east-1)Everything described aboveCognito for sign-in, RDS PostgreSQL for the database, SES for email we send you, and EC2 and Amplify for hosting
Anthropic Claude models, via Amazon BedrockYour resume content, the job description, and your refinement answersGenerating tailored resumes, cover letters, and outreach drafts. Requests are processed inside AWS through Bedrock; they are not sent to Anthropic directly, and Bedrock does not use them to train models
Enrich.soThe employer's company name and domainFinding the recruiter and hiring-manager contact details described in section 2
FirecrawlThe job posting URL you supplyRetrieving the job description text from that page
CloudflareRequest metadata, including IP addressDNS and proxying for our API domain
StripeYour email, your payment details, and your subscription and billing historyProcessing payments for paid subscriptions. We never receive or store your full card number; Stripe holds your card details under its own privacy policy

Data is stored and processed in the United States. Payments for paid subscriptions are processed by Stripe (above); we do not receive or store your full card number.

4. How long we keep it

5. Your rights and controls

6. Security

Traffic is encrypted in transit with TLS, database connections verify the server certificate, and data at rest is encrypted by AWS. Access to production data is limited to the operator of the service. No system is perfectly secure, and we will notify affected users without undue delay if a breach affects their personal data.

7. Children

The Job Hunt is not intended for anyone under 16, and we do not knowingly collect their data.

8. Our publishing tools and platform APIs

Separately from The Job Hunt, Project Carbon Fiber LLC operates an internal marketing tool that researches and publishes our own educational videos and posts to our own social media accounts. It is not part of The Job Hunt, it has no users other than us, and it never reads, receives, or processes any of the job-seeker data described above. To decide what to make, it reads publicly available content from social and community platforms (for example, public posts on X, and public post titles on Reddit and Hacker News), and it may store limited public information about creators we might engage, such as a username, follower count, public bio, and a sample public post.

This marketing tool relies on its own service providers to operate: Amazon Web Services (Bedrock, S3, and SNS), Google (Gemini) for drafting and quality checks, ElevenLabs for voiceover, Creatomate for video assembly, and Pexels for stock footage. None of these providers receive any job-seeker data from The Job Hunt.

YouTube

This tool uses YouTube API Services. By using it we agree to the YouTube Terms of Service, and Google's handling of any data it receives is governed by the Google Privacy Policy.

TikTok, LinkedIn, X, and Instagram

The same tool posts to our own accounts on these platforms and stores only the identifier each platform returns for a post we made. Our use of TikTok's APIs is subject to the TikTok Developer Terms of Service. Aside from the public research described above, we do not access private data belonging to other users of these platforms.

Revoking access

Authorisation for these tools can be withdrawn at any time. For Google and YouTube, use the Google security permissions page. For TikTok, use Manage app permissions in your TikTok account settings. Revoking access stops the tool immediately and does not delete anything already published.

9. Changes

If we change this policy we update the effective date above, and we email registered users before any material change takes effect.

Privacy PolicyTerms of ServiceHome