Privacy Policy

Last updated: 9 September 2026

Job Watcher helps you find roles, prepare your application, and fill in application forms. This policy sets out what personal data we process, who else sees it, and what you can ask us to do about it.

1. Who is responsible for your data

I, Honghao Zhang, am the controller of the personal data described here. You can reach me at the contact address at the end of this policy. Elsewhere in this policy, "we" and "us" mean that same operator of Job Watcher.

2. Personal data we process

Account

When you sign in with Google we receive and store an account identifier, your email address and your display name. We request only the standard sign-in scopes and receive nothing else from your Google account.

Contact details

The first name, last name, email address, phone number and postal address you enter for use on applications, along with any additional fields you choose to add for forms that ask for them, and optionally a profile image and a signature image.

Your CV and career record

The CV file you upload, the text extracted from it, your employment history (employer, job title, city and dates) and your education history (institution, degree, field of study, city and dates).

Supporting documents

Certificates, references, transcripts, identity documents and similar files you upload, together with the type you pick for each one and the short description you write for it. We store the file exactly as you sent it. We do not read it, and we do not send it to anyone.

Cover letters and generated documents

Cover letters you upload, and cover letters and tailored CVs that we generate for you.

Applications and job tracking

The applications you track and any notes you write on them, the searches you save, the jobs those searches surface, and the match scores together with the written explanation of why a role does or does not fit your profile.

Preferences and conversations

Your work authorisation, preferred employment types, working languages, work mode, target region and target companies. If you use the career advisor, the full transcript of that conversation.

Derived and technical data

Technical data needed to operate the service: short-lived session state while the apply assistant is running, and operational logs. We filter known sensitive field names out of those logs and do not log your CV or letter content.

3. Where it comes from

  • You, when you upload a document, fill in your profile, write a note, or talk to the advisor.
  • Google, when you sign in.
  • Our browser extension, when you use it on a job posting or an application form.
  • Public job boards and employer career pages. This is information about vacancies, not about you.

4. Why we process it, and on what basis

We process your data to provide the service you asked for: to read and structure your CV, to find and rank roles, to draft tailored documents, and to help you complete application forms. Under the GDPR the legal bases are:

  • Article 6(1)(b), performance of a contract — everything that makes up the core service.
  • Article 6(1)(a), consent — optional features you switch on, such as uploading an identity document.
  • Article 6(1)(f), legitimate interests — keeping the service available, secure, and free from abuse.

A CV can contain special categories of personal data under Article 9 — health, religious or philosophical beliefs, trade union membership, or data revealing racial or ethnic origin. We do not ask for any of it and we recommend you leave it out. Where you do include it, we process it on the basis of your explicit consent under Article 9(2)(a), given by uploading the document, and you may withdraw that consent by removing the document.

5. Who else processes your data

We use the following processors. We do not sell your data, and we do not share it with anyone for advertising or marketing.

Nebius

Purpose
All AI work that involves you: reading your CV, scoring roles against your record, the advisory conversation, writing cover letters and tailored CVs, and deciding how to fill an application form.
Receives
The text of your CV — including the contact details printed on it — your cover letters, your career record, your conversations with the advisor, job descriptions, and the structure of application forms you open with the extension. Contact details needed on a form are filled in by our own servers after the model has decided which field they belong in. Supporting documents you upload are never sent.
Location
European Union (Finland and France)

DeepSeek

Purpose
Reading a job posting you paste in, summarising a vacancy's requirements, and working out where an application form lives.
Receives
Public job-posting text and employer application instructions only. Nothing about you: no CV, no career record, no contact details. Email addresses and phone numbers found on an employer's page are removed before the page is sent.
Location
People's Republic of China

Google Cloud — Vertex AI

Purpose
Converting text into numeric representations so documents can be matched to roles.
Receives
The text of cover letters you upload.
Location
European Union (Frankfurt)

Google Cloud — Run, Storage and Logging

Purpose
Running the service, storing your PDF files, and operational logging.
Receives
All uploaded and generated PDF files, and service logs.
Location
European Union (Frankfurt)

Firebase Authentication (Google)

Purpose
Signing you in and keeping you signed in.
Receives
Your email address, display name and account identifier.
Location
Google infrastructure, which may include the United States

Neon

Purpose
The database holding everything described in section 2 other than files.
Receives
All stored personal data other than the PDF files themselves.
Location
European Union

Upstash

Purpose
Short-lived cache for an apply assistant session while it is running.
Receives
Session state for the apply assistant. Deleted automatically one hour after last use.
Location
European Union

Sentry

Purpose
Telling us when the service breaks, so we can fix it.
Receives
Technical details of an error: the message, the line of code it came from, the page or endpoint involved and your account identifier. We turn off the option to collect your IP address, and known sensitive fields — such as an email address or the text of a CV — are removed before an error is sent. It is not analytics: nothing is recorded unless something has gone wrong.
Location
European Union (Frankfurt)

EURES (European Commission)

Purpose
Searching public job vacancy databases.
Receives
Search terms only — such as a job title, a region and a date range. Your identity, your CV and your account are never sent.
Location
European Union

6. Data that leaves the EEA

Your CV, your career record, your cover letters and your conversations with the advisor do not leave the EEA. The AI models that read them run on Nebius in Finland and France. This changed in September 2026; before that they were processed in China.

We still use DeepSeek, in the People's Republic of China, for three narrow tasks that involve no information about you: reading a job posting you paste in, summarising what a vacancy asks for, and finding where an employer's application form lives. What is sent is the employer's own published text. Email addresses and phone numbers appearing on an employer's page are removed first. The European Commission has not adopted an adequacy decision for China, so if you would rather no request of yours reached it at all, tell us and we will say what that means for the features above.

Transfers to Firebase Authentication may involve the United States and are covered by Google's own Standard Contractual Clauses.

7. How long we keep it

  • Apply assistant session cache: deleted automatically one hour after it was last used.
  • Sign-in cookie: 14 days.
  • Everything else: retained until we confirm erasure of your account after you ask us to delete it.

We do not currently delete inactive accounts or age out old data automatically. If you want your data gone, ask us and we will erase it — see the next section.

8. Erasing your data

Email jobwatchersupports@gmail.com from the address on your account and ask us to erase it. We will remove your database records, your stored files, any cached session data and your sign-in account within 30 days, and confirm to you when it is done.

The delete control inside the product records your request; erasure is then completed by us within that period. Emailing us is the supported route.

9. Your rights

Under the GDPR you have the right to access your data, to correct it, to have it erased, to restrict or object to how we process it, to receive it in a portable form, and to withdraw consent where processing rests on consent. Withdrawing consent does not affect processing that already happened.

Write to the contact address below and we will respond within 30 days. You also have the right to lodge a complaint with the data protection supervisory authority where you live or work. For Germany that is typically your state data protection authority (Landesdatenschutzbeauftragte), or the Federal Commissioner for Data Protection and Freedom of Information (BfDI).

10. How we protect it

  • All traffic to and from the service uses HTTPS.
  • Every request to our services carries your sign-in token and is checked before anything is returned.
  • Your files are stored in a private bucket under a path scoped to your account, with no public access. Downloads are served through our API against your token, never from a public URL.
  • Our infrastructure providers encrypt data at rest using their platform defaults.
  • Known sensitive field names are filtered out of operational logs.

No service can promise perfect security, and we do not. If a breach affects your personal data we will notify the relevant supervisory authority and, where the law requires it, you.

11. What we do not do

  • We do not sell your personal data, and we do not share it for advertising or marketing.
  • We do not use analytics, tracking pixels, advertising tags or any third-party scripts. The site loads none.
  • We do not train any AI model on your data. Data sent to our AI provider is processed by them to produce the output you requested, under their API terms.
  • We do not submit an application on your behalf without you approving it.

12. Cookies

We set one cookie. It is named jw_session, it keeps you signed in, it lasts 14 days, and it cannot be read by scripts in your browser. It is strictly necessary for the service to work. We set no analytics or advertising cookies, which is why you do not see a cookie banner. The Cookie Policy covers this in full, including what else is kept in your browser.

13. The browser extension

The Job Watcher extension fills in application forms for you. Because a job application can be hosted on any employer's website, the extension asks for permission to access all sites — there is no list of domains we could declare in advance. What it actually does with that permission is narrow:

  • The only script that loads automatically runs on Job Watcher's own pages, and exists to pass your sign-in to the extension.
  • The script that reads a page is injected only into the tab you explicitly opened for an application, and only when you start that flow. It does not run on your other tabs.
  • It reads the visible text of the job posting (up to 20,000 characters) and the structure of the application form — field labels, field types, options, error messages and the values currently in the fields.
  • It sends that to our servers, which pass it to our AI provider to work out the next step. It then fills fields and attaches the PDFs we generated for you.
  • It will not press the final submit button. The extension refuses to click controls labelled submit, apply now, send application and similar. You submit the application yourself.
  • Your sign-in token is held in the browser's session storage and is cleared when you close your browser.

14. Automated processing

We score and rank roles against your profile and generate draft documents automatically. These are suggestions and drafts for you to review, not decisions about you: nothing we produce has a legal or similarly significant effect within the meaning of Article 22 GDPR, no employer decision is made by us, and every application is submitted by you. AI-generated text can be inaccurate — check it before it goes anywhere.

15. Children

Job Watcher is not intended for anyone under 16, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will erase it.

16. Changes to this policy

If we change how we handle your data we will update this page and the date at the top before the change takes effect. Material changes will be described here rather than made quietly.

17. Contact

Honghao Zhang, Theresienstr. 7, 85386 Eching, Germany.

Questions: jobwatchersupports@gmail.com