Privacy Policy
Effective September 2, 2026. Operated by Project Carbon Fiber LLC.
This policy explains exactly what The Job Hunt collects, who else processes it, how long it is kept, and how to get it back or have it deleted. It describes what the service does today, not what it may do later; it is updated when the service changes.
1. Who we are
The Job Hunt is operated by Project Carbon Fiber LLC. For any privacy question, correction, or deletion request, contact [email protected]. We answer privacy requests within 30 days.
2. What we collect
Named specifically, by what it is and why we hold it.
Account
- Your email address and the account identifier issued by Amazon Cognito when you register.
- Your subscription tier and monthly usage counters, used to apply plan limits.
We never receive or store your password. Authentication is handled entirely by Amazon Cognito.
Your resume and profile
- Contact details: name, email, phone number, city and region.
- Links you add: LinkedIn, GitHub, portfolio, personal website, and employer LinkedIn pages.
- Professional summary, work history (employers, job titles, locations, dates, and bullet points), education (institutions, degrees, fields of study, dates), skills, and certifications.
- The resume file you upload is read in memory to extract its text, then discarded. We store only the extracted text and structured fields, in our database, never the original file.
- Voluntary equal-opportunity information, if and only if you choose to enter it. This can include demographic characteristics, which in the UK and EU is "special category" data. It is optional, it is never required to use the service, it is never used to rank, score, or filter you, and it is never shared with employers or any third party by us. Leave it blank and nothing is stored.
Jobs you apply to
- Job title, company name, location, the source URL, and the full text of the job description you paste or that we retrieve from that URL.
- Keywords and requirements extracted from that description, and the application status you set on your board.
Documents we generate for you
- Tailored resume content, cover letter text, and the answers you give during the refinement step.
- ATS match scores, letter grades, matched and missing keywords, and the diagnostics behind them.
- Your chosen template and colour palette, and any rating you leave. Exported PDF and DOCX files are generated on demand and streamed to your browser; we do not keep a copy.
Recruiter outreach: information about other people
When you use the recruiter outreach feature, we retrieve and store business contact information about people at the employer you are applying to: name, job title, LinkedIn profile URL, work email address, and work phone number, along with the messages drafted for them. These people are not users of The Job Hunt and did not give us this information themselves; it is obtained from our data provider (below).
- It is used only to help you make a professional approach about a live job opening.
- We do not sell it, publish it, or build a marketing list from it.
- It is deleted when you delete the associated application or your account.
- If you are one of these people and want your details removed, email [email protected] and we will delete them from our systems and tell you which provider supplied them.
Usage, settings, and support
- For each AI operation: which step ran, which model, token counts, estimated cost, and how long it took. This is how the cost figures in your Plan and Billing tab are produced.
- Your theme, default page size, and notification preferences.
- Feedback you submit: category, star rating, message, and which page you sent it from.
- If you join the alpha waitlist: your name, email, which form you used, and how many times you submitted it.
- Standard technical data on each request, including your IP address, which is used for rate limiting and abuse prevention.
We do not use advertising trackers, and we do not sell personal information to anyone.
Cookies and browser storage
We do not use advertising or tracking cookies. To keep you signed in and remember your preferences, we store a small amount of data in your browser's local storage: your Amazon Cognito sign-in tokens, your theme choice, a timestamp of your last activity, and your progress through an in-flight application. This data stays in your browser, is not shared with anyone, and is cleared when you sign out or clear your site data.
3. Who else processes your data
These are every third party your data reaches, what they receive, and why.
| Processor | What it receives | Why |
|---|---|---|
| Amazon Web Services (us-east-1) | Everything described above | Cognito for sign-in, RDS PostgreSQL for the database, SES for email we send you, and EC2 and Amplify for hosting |
| Anthropic Claude models, via Amazon Bedrock | Your resume content, the job description, and your refinement answers | Generating tailored resumes, cover letters, and outreach drafts. Requests are processed inside AWS through Bedrock; they are not sent to Anthropic directly, and Bedrock does not use them to train models |
| Enrich.so | The employer's company name and domain | Finding the recruiter and hiring-manager contact details described in section 2 |
| Firecrawl | The job posting URL you supply | Retrieving the job description text from that page |
| Cloudflare | Request metadata, including IP address | DNS and proxying for our API domain |
| Stripe | Your email, your payment details, and your subscription and billing history | Processing payments for paid subscriptions. We never receive or store your full card number; Stripe holds your card details under its own privacy policy |
Data is stored and processed in the United States. Payments for paid subscriptions are processed by Stripe (above); we do not receive or store your full card number.
4. How long we keep it
- While your account is open: your profile, applications, generated documents, and settings are kept so the service works.
- When you delete your account: we immediately cancel any active subscription and permanently delete the contact details of third parties you looked up. Your own account data (profile, applications, generated documents, usage logs, and subscription status) is then retained, inaccessible to you and to everyone else, for up to 12 months — so you can restore the account by signing back in, and so we can prevent repeat-signup abuse — after which it is permanently purged.
- Backups: encrypted database backups are retained on a rolling basis and are overwritten within 30 days, after which deleted data is gone from backups too.
- Waitlist entries: kept until launch and for 12 months afterwards, then deleted. You can be removed sooner on request.
- Feedback: kept for 24 months so we can act on it and see patterns over time.
5. Your rights and controls
- Export: Settings → Data lets you download everything we hold about you, at any time, without asking us.
- Delete: Settings → Data deletes your account and all associated records. This cannot be undone.
- Correct: edit your profile directly, or email us.
- Depending on where you live, you may also have the right to object to or restrict processing, to data portability, and to complain to your data protection authority. Email [email protected] and we will act within 30 days. We never charge for these requests.
6. Security
Traffic is encrypted in transit with TLS, database connections verify the server certificate, and data at rest is encrypted by AWS. Access to production data is limited to the operator of the service. No system is perfectly secure, and we will notify affected users without undue delay if a breach affects their personal data.
7. Children
The Job Hunt is not intended for anyone under 16, and we do not knowingly collect their data.
8. Our publishing tools and platform APIs
Separately from The Job Hunt, Project Carbon Fiber LLC operates an internal marketing tool that researches and publishes our own educational videos and posts to our own social media accounts. It is not part of The Job Hunt, it has no users other than us, and it never reads, receives, or processes any of the job-seeker data described above. To decide what to make, it reads publicly available content from social and community platforms (for example, public posts on X, and public post titles on Reddit and Hacker News), and it may store limited public information about creators we might engage, such as a username, follower count, public bio, and a sample public post.
This marketing tool relies on its own service providers to operate: Amazon Web Services (Bedrock, S3, and SNS), Google (Gemini) for drafting and quality checks, ElevenLabs for voiceover, Creatomate for video assembly, and Pexels for stock footage. None of these providers receive any job-seeker data from The Job Hunt.
YouTube
This tool uses YouTube API Services. By using it we agree to the YouTube Terms of Service, and Google's handling of any data it receives is governed by the Google Privacy Policy.
- What it accesses: it uploads video files, together with the titles, descriptions, and tags we write ourselves, to our own YouTube channel.
- What it stores: the video identifier and link that YouTube returns, so that the same video is never uploaded twice.
- What it does not do: it does not read, collect, cache, display, or share any other YouTube data, and it accesses no data belonging to any YouTube user other than the account that authorised it. It calls a single endpoint, videos.insert.
TikTok, LinkedIn, X, and Instagram
The same tool posts to our own accounts on these platforms and stores only the identifier each platform returns for a post we made. Our use of TikTok's APIs is subject to the TikTok Developer Terms of Service. Aside from the public research described above, we do not access private data belonging to other users of these platforms.
Revoking access
Authorisation for these tools can be withdrawn at any time. For Google and YouTube, use the Google security permissions page. For TikTok, use Manage app permissions in your TikTok account settings. Revoking access stops the tool immediately and does not delete anything already published.
9. Changes
If we change this policy we update the effective date above, and we email registered users before any material change takes effect.