Version 2026-10-05 · invite-only beta, non-commercial
Your data lives on a machine and encrypted disk of your own (Singapore).
AI processing goes through the OpenAI API: not used for training; OpenAI may keep it up to 30 days for abuse monitoring.
joblander only drafts — it never sends anything on your behalf. No selling data, no ads.
You can export everything or delete your account completely at any time (Settings).
Who runs this
joblander is open source (GitHub). The cloud version is run personally by the
project's author as a free, invite-only beta. "I" below means the operator.
What is collected
Account: Google sign-in only shares your email address (scopes openid + email) — not your mail, calendar or contacts.
What you provide: resume, achievement bank, target pay and red lines, company files, interview notes, invitations or JDs you paste.
What the system generates: fit assessments, research reports, interview briefs, tailored resumes, diaries and weekly reports.
Usage records: model, tokens, cost and time of each AI call (for credit metering).
Feedback: what you submit, the page you were on and your browser's user agent.
Technical logs: request time, status code and IP address for troubleshooting and abuse prevention; page paths and content are not logged.
Where it is stored
Hosted on Fly.io in Singapore. Each user gets a dedicated machine and a dedicated disk encrypted at rest;
users are isolated at the network level and cannot reach each other's space. Account and usage records live in the gateway database
(same region, encrypted disk). The platform snapshots disks daily and keeps snapshots for 5 days for disaster recovery.
Who processes it
Service
Purpose
Data involved
Fly.io
Servers and storage
Everything (stored in Singapore)
OpenAI
AI generation and assessment
Resume excerpts, JDs and notes needed for the task at hand. API data is not used for training by default; may be retained up to 30 days for abuse monitoring; processed in the US
Tavily
Web search for company research
Search terms (company names, role keywords) — not your resume
Google
Sign-in
Email address
Resend
Forwarding your feedback to the operator
Only the feedback you submit and your email
LinkedIn and MyCareersFuture are only used to read public job listings; none of your data is sent to them.
What I don't do
No selling or renting your data, no advertising.
No training models on your data.
No sending emails or messages on your behalf — everything that goes out, you send yourself.
No asking for or storing email passwords, bank or job-site logins.
What the operator can see
As the server administrator I am technically able to access the machine holding your data. My commitment: I don't look at your content.
I access it only when you explicitly ask for help troubleshooting and agree, or when the law requires it — and I'll tell you.
I do see account and usage summaries (email, credit, spend) to run the service.
Your rights
Access and correction: everything is in the interface and can be edited directly.
Export: Settings → "Export all my data" downloads every file in your space, plus your account and usage records.
Reset: wipe your space but keep the account, and start over.
Delete completely: Settings → "Delete account" immediately destroys your machine and disk and deletes your account, usage, feedback and invite records from the gateway.
Platform snapshots expire within 5 days; OpenAI within 30 days. Deletion cannot be undone.
Withdrawing consent: same as deleting your account.
Other people's information you record
Interview notes may include names of recruiters or interviewers. Please record only what your job search needs; this information is protected
like the rest of your data and is erased when you delete your account.
Security measures
HTTPS everywhere; session cookies are signed, HTTPS-only and not readable by scripts.
Each user machine only accepts gateway requests carrying its own token; user machines have no public entry point.
Disks encrypted at rest; AI calls go through a metering proxy, so no real OpenAI key is stored on user machines.
Access logs do not record page paths or content.
Breaches
If a security incident may affect you, I'll notify affected users as soon as possible and report to authorities as required by applicable law (such as Singapore's PDPA).
Contact and changes
Questions or requests: use "Feedback" in the sidebar after signing in, or open a GitHub issue
(don't post personal information in public issues). If this notice changes materially, you'll be asked to confirm again at your next sign-in.