Privacy Policy
Last updated: 28 September 2026
Jobbital is operated by Kausora Technologies Limited. This policy describes the information Jobbital processes through the web app, Chrome extension, connected-agent/MCP integrations, and supporting APIs.
Information You Provide
Depending on the features you use, Jobbital processes:
- account details, authentication information, preferences, and settings;
- CVs, resumes, profile information, and generated or tailored CV drafts;
- job searches, saved jobs, application records, notes, reminders, calendar events, and documents you attach to applications;
- Career Profile and memory items you choose to store in the web app;
- chat messages, tailoring discussions, interview-preparation content, and saved Interview Coach transcripts; and
- support or contact messages you send to us.
Chrome Extension Data
The extension accesses an active tab only when you invoke a feature that needs page context. Depending on that action, it may process the page URL and title, visible text, structured job metadata, and visible screenshots.
- A generic current-page read is text-only.
- Structured job extraction may capture a screenshot as a fallback when page text is insufficient. The screenshot is sent for job-field extraction; it is not used by generic page-reading actions.
- When the user starts Browser Agent or Application Assist, the extension uses Chrome's debugger interface to capture full, unmasked screenshots of the controlled tab and to perform visual mouse, keyboard, typing, scrolling, and navigation actions proposed through GPT-5.4 Responses computer use. It does not extract an application-form schema or use DOM field setters for these workflows.
- Before an activating action is returned to Chrome, a separate stateless AI visual risk check evaluates the screenshot and proposed action batch. Browser Agent is limited to read-oriented search and research. Application Assist applies the user's selected submission mode to grounded final, CAPTCHA, and supported declaration actions. Authentication/account, payment, government-identifier, secret-bearing, destructive, unsupported-upload, and unclear actions remain blocked.
- Application Assist supplies a bounded context from the selected or default CV, profile, relevant read-only Career Profile/memory, and current job. It pauses rather than inventing a missing or ambiguous candidate fact.
- Browser Agent receives the requested objective and minimal page context. Application Assist receives the bounded candidate context described above. Screenshots are not masked or redacted and can contain answers, personal information, and other content visible in the tab. They are sent through Jobbital's API to the configured AI provider. Do not start Application Assist or Browser Agent on a page containing information you do not want processed in this way. Oversized lossless captures may be recaptured as a bounded JPEG of the same visible viewport before transfer.
- Application Assist may click an initial Apply control and advance non-final Next or Continue steps. It may follow a normal HTTPS applicant-tracking-system transition in the same tab or a new tab in the controlled Chrome window under the original user request.
- When the shared agent has bound one exact Jobbital CV/version to a run, Application Assist may upload that PDF after the visual model identifies the resume/CV control. It does not browse the user's local files. Unsupported or unrelated file choosers, login or account creation, passwords, one-time codes, payment details, government identifiers, and other authentication or secret-bearing steps remain manual boundaries.
- Provider safety checks pause the run and continue only after the pending protected interaction is shown in the extension and confirmed for its bound run, sequence, action, and check set. Page content, model output, speech, and general chat confirmation cannot approve a safety check.
- Application Assist stops before final Apply, Submit, Send, or an equivalent submission. The public extension does not offer automatic submission: the user reviews the application and submits on the employer's site. Older automatic-submission preferences cannot authorize new runs.
- If Continue in background is enabled, the extension moves the exact controlled tab into a dedicated, unfocused Chrome window so the user can browse elsewhere. It controls only the active tab in that Jobbital-owned window, and this preference does not permit final submission.
- The extension may read relevant CV, application, job-search, and Career Profile/memory data from the user's Jobbital account. Extension memory access is read-only for this release; durable memory is managed in the web app.
- Voice mode uses the microphone only after the user starts it. Ordinary speech uses a direct Azure OpenAI Realtime WebRTC session for native speech-to-speech conversation. Input transcription is an auxiliary chat record and does not gate spoken responses. Only Jobbital account, CV, application, page, search, generation, or mutation work is delegated to the shared Jobbital agent.
Before each Browser Agent or Application Assist run, the extension shows the starting site, the selected CV/version when applicable, and a disclosure of unmasked screenshot sharing. Nothing is captured for that run until the user chooses Share screenshots and start. This approval expires after five minutes and is never restored after a worker or browser restart.
By default, authentication, chat, drafts, voice transcripts, CV preview payloads, and temporary browser-task state stay in Chrome session storage and are cleared when the browser session ends. Temporary task state may include a pending full screenshot and bounded candidate context.
Users may explicitly choose Keep me signed in and save recent chat on this device at sign-in. This stores sign-in tokens in Chrome local storage until sign-out or invalidation, and keeps the most recent 100 chat messages (up to 12,000 characters each) and the composer draft on this device for up to seven days of inactivity. Expired history is removed when the extension next loads it. Restoration includes conversation text only, not page/CV context, tool state, pending approvals, screenshots, or browser actions. Signing out or clearing chat removes the saved conversation and draft. Signing out also removes sign-in tokens. This history is not synced to a Jobbital cloud conversation service.
Limited local metadata includes the selected default CV, saved-application context, saved tailored-CV identifiers and section-change labels, and theme. Preferences such as voice speed may use Chrome sync storage. A feedback email includes extension version, Chrome major version and interface surface only if the user opts in; the user can inspect these details and controls sending the email.
Connected Agents and MCP
If you create a connected-agent token, Jobbital stores a hash of the token, client name, granted scopes, expiry/revocation state, and last-use information. The secret is shown only when created. MCP tools can access only data permitted by those scopes, and tool calls create a bounded audit record. Audit records are designed not to duplicate full CV/contact data, memory content, application notes, interview transcripts, tailored CV payloads, signed URLs, or the client's confirmation text.
Sensitive connected-agent reads and mutations use a Jobbital-hosted two-phase approval. The original tool call stores exact private arguments and performs no effect. The signed-in user reviews a bounded server-created summary in Jobbital, and only an approved proposal can be resumed with those stored arguments. Client-supplied confirmation fields are rejected. Revoke a lost or untrusted connection in Settings immediately.
How We Use Information
We use this information to authenticate users; provide search, ranking, tailoring, application tracking, calendar, interview, voice, and agent features; maintain security and rate limits; diagnose failures; provide support; and improve reliability and usability.
Jobbital does not sell personal information, use it for targeted advertising, or share it with recruiters or employers unless the user chooses to do so. The public Chrome extension stops before employer application submission. The user reviews and submits on the employer's site.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use and transfer extension user data only as needed to provide or secure Jobbital's disclosed job-search and application-copilot purpose. We do not use it for personalised advertising or lending decisions. We do not permit human access to extension user data except when the user asks us to review specific information for support, when necessary to investigate security or abuse, when required by law, or when the data has been aggregated and anonymised for lawful internal operations.
AI Processing and Service Providers
When you invoke an AI feature, the content needed for that request may be sent to Microsoft Azure OpenAI. This can include selected page/job text, CV content, full unmasked visible-tab screenshots and browser-action results during Browser Agent or Application Assist, chat instructions, or voice audio, depending on the feature. Responses computer-use sessions use provider-side storage for safe multi-step continuation and are subject to Microsoft Azure's retention and data controls.
Current key service providers and connected services also include Cloudflare for API delivery, security, short-lived run state, and private file storage; Vercel for the web app, authentication server, analytics, and performance data; Neon for PostgreSQL database hosting; Render for CV document rendering; RapidAPI-hosted job-data providers such as JSearch and Active Jobs DB for requested searches; Polar for subscriptions and usage billing; Resend for service and support email; and Microsoft or Google services for a user-connected sign-in, calendar, or email integration, or for a disclosed anti-abuse check. Each receives only the information needed for its configured function and processes it on Jobbital's behalf or under its own terms where the user connects the service.
Do not place credentials, payment details, government identifiers, or other unnecessary sensitive information into chat messages, CV instructions, notes, or application fields sent to AI features.
Storage, Security, and Retention
Jobbital uses access controls and encryption in transit and uses the security features of its cloud providers for stored data. No online service can promise absolute security.
Account data is retained while needed to provide the service and meet legal, security, fraud-prevention, backup, and accounting obligations. Different data categories and service-provider backups can have different deletion periods. Session-scoped extension data follows the browser-session behavior described above. A user-bound Browser Agent or Application Assist continuation record may remain in Jobbital's Worker for up to 30 minutes; it retains bounded run context and the provider response identifier but does not intentionally store raw screenshots. Revoked connected-agent tokens stop authorizing new requests; their bounded audit records may be retained for security and accountability.
Your Choices and Rights
Depending on your location, you may have rights to access, correct, export, restrict, object to, or delete personal information. Jobbital also provides in-product controls for preferences, memories, saved data, and connected-agent revocation. Contact us to make a privacy or account-deletion request. We may need to verify the request and may retain information where legally required.
Contact
Questions and privacy requests can be sent to contact@jobbital.com.
We may update this policy as the product or legal requirements change. Material changes will be communicated through an appropriate in-product or email notice.