Privacy Policy
Last updated: 9 September 2026
Job Watcher helps you find roles, prepare your application, and fill in application forms. This policy sets out what personal data we process, who else sees it, and what you can ask us to do about it.
1. Who is responsible for your data
I, Honghao Zhang, am the controller of the personal data described here. You can reach me at the contact address at the end of this policy. Elsewhere in this policy, "we" and "us" mean that same operator of Job Watcher.
2. Personal data we process
Account
When you sign in with Google we receive and store an account identifier, your email address and your display name. We request only the standard sign-in scopes and receive nothing else from your Google account.
Contact details
The first name, last name, email address, phone number and postal address you enter for use on applications, along with any additional fields you choose to add for forms that ask for them, and optionally a profile image and a signature image.
Your CV and career record
The CV file you upload, the text extracted from it, your employment history (employer, job title, city and dates) and your education history (institution, degree, field of study, city and dates).
Supporting documents
Certificates, references, transcripts, identity documents and similar files you upload, together with the type you pick for each one and the short description you write for it. We store the file exactly as you sent it. We do not read it, and we do not send it to anyone.
Cover letters and generated documents
Cover letters you upload, and cover letters and tailored CVs that we generate for you.
Applications and job tracking
The applications you track and any notes you write on them, the searches you save, the jobs those searches surface, and the match scores together with the written explanation of why a role does or does not fit your profile.
Preferences and conversations
Your work authorisation, preferred employment types, working languages, work mode, target region and target companies. If you use the career advisor, the full transcript of that conversation.
Derived and technical data
Technical data needed to operate the service: short-lived session state while the apply assistant is running, and operational logs. We filter known sensitive field names out of those logs and do not log your CV or letter content.
3. Where it comes from
- You, when you upload a document, fill in your profile, write a note, or talk to the advisor.
- Google, when you sign in.
- Our browser extension, when you use it on a job posting or an application form.
- Public job boards and employer career pages. This is information about vacancies, not about you.
4. Why we process it, and on what basis
We process your data to provide the service you asked for: to read and structure your CV, to find and rank roles, to draft tailored documents, and to help you complete application forms. Under the GDPR the legal bases are:
- Article 6(1)(b), performance of a contract — everything that makes up the core service.
- Article 6(1)(a), consent — optional features you switch on, such as uploading an identity document.
- Article 6(1)(f), legitimate interests — keeping the service available, secure, and free from abuse.
A CV can contain special categories of personal data under Article 9 — health, religious or philosophical beliefs, trade union membership, or data revealing racial or ethnic origin. We do not ask for any of it and we recommend you leave it out. Where you do include it, we process it on the basis of your explicit consent under Article 9(2)(a), given by uploading the document, and you may withdraw that consent by removing the document.
5. Who else processes your data
We use the following processors. We do not sell your data, and we do not share it with anyone for advertising or marketing.
Nebius
- Purpose
- All AI work that involves you: reading your CV, scoring roles against your record, the advisory conversation, writing cover letters and tailored CVs, and deciding how to fill an application form.
- Receives
- The text of your CV — including the contact details printed on it — your cover letters, your career record, your conversations with the advisor, job descriptions, and the structure of application forms you open with the extension. Contact details needed on a form are filled in by our own servers after the model has decided which field they belong in. Supporting documents you upload are never sent.
- Location
- European Union (Finland and France)
DeepSeek
- Purpose
- Reading a job posting you paste in, summarising a vacancy's requirements, and working out where an application form lives.
- Receives
- Public job-posting text and employer application instructions only. Nothing about you: no CV, no career record, no contact details. Email addresses and phone numbers found on an employer's page are removed before the page is sent.
- Location
- People's Republic of China
Google Cloud — Vertex AI
- Purpose
- Converting text into numeric representations so documents can be matched to roles.
- Receives
- The text of cover letters you upload.
- Location
- European Union (Frankfurt)
Google Cloud — Run, Storage and Logging
- Purpose
- Running the service, storing your PDF files, and operational logging.
- Receives
- All uploaded and generated PDF files, and service logs.
- Location
- European Union (Frankfurt)
Firebase Authentication (Google)
- Purpose
- Signing you in and keeping you signed in.
- Receives
- Your email address, display name and account identifier.
- Location
- Google infrastructure, which may include the United States
Neon
- Purpose
- The database holding everything described in section 2 other than files.
- Receives
- All stored personal data other than the PDF files themselves.
- Location
- European Union
Upstash
- Purpose
- Short-lived cache for an apply assistant session while it is running.
- Receives
- Session state for the apply assistant. Deleted automatically one hour after last use.
- Location
- European Union
Sentry
- Purpose
- Telling us when the service breaks, so we can fix it.
- Receives
- Technical details of an error: the message, the line of code it came from, the page or endpoint involved and your account identifier. We turn off the option to collect your IP address, and known sensitive fields — such as an email address or the text of a CV — are removed before an error is sent. It is not analytics: nothing is recorded unless something has gone wrong.
- Location
- European Union (Frankfurt)
EURES (European Commission)
- Purpose
- Searching public job vacancy databases.
- Receives
- Search terms only — such as a job title, a region and a date range. Your identity, your CV and your account are never sent.
- Location
- European Union
6. Data that leaves the EEA
Your CV, your career record, your cover letters and your conversations with the advisor do not leave the EEA. The AI models that read them run on Nebius in Finland and France. This changed in September 2026; before that they were processed in China.
We still use DeepSeek, in the People's Republic of China, for three narrow tasks that involve no information about you: reading a job posting you paste in, summarising what a vacancy asks for, and finding where an employer's application form lives. What is sent is the employer's own published text. Email addresses and phone numbers appearing on an employer's page are removed first. The European Commission has not adopted an adequacy decision for China, so if you would rather no request of yours reached it at all, tell us and we will say what that means for the features above.
Transfers to Firebase Authentication may involve the United States and are covered by Google's own Standard Contractual Clauses.
7. How long we keep it
- Apply assistant session cache: deleted automatically one hour after it was last used.
- Sign-in cookie: 14 days.
- Everything else: retained until we confirm erasure of your account after you ask us to delete it.
We do not currently delete inactive accounts or age out old data automatically. If you want your data gone, ask us and we will erase it — see the next section.
8. Erasing your data
Email jobwatchersupports@gmail.com from the address on your account and ask us to erase it. We will remove your database records, your stored files, any cached session data and your sign-in account within 30 days, and confirm to you when it is done.
The delete control inside the product records your request; erasure is then completed by us within that period. Emailing us is the supported route.
9. Your rights
Under the GDPR you have the right to access your data, to correct it, to have it erased, to restrict or object to how we process it, to receive it in a portable form, and to withdraw consent where processing rests on consent. Withdrawing consent does not affect processing that already happened.
Write to the contact address below and we will respond within 30 days. You also have the right to lodge a complaint with the data protection supervisory authority where you live or work. For Germany that is typically your state data protection authority (Landesdatenschutzbeauftragte), or the Federal Commissioner for Data Protection and Freedom of Information (BfDI).
10. How we protect it
- All traffic to and from the service uses HTTPS.
- Every request to our services carries your sign-in token and is checked before anything is returned.
- Your files are stored in a private bucket under a path scoped to your account, with no public access. Downloads are served through our API against your token, never from a public URL.
- Our infrastructure providers encrypt data at rest using their platform defaults.
- Known sensitive field names are filtered out of operational logs.
No service can promise perfect security, and we do not. If a breach affects your personal data we will notify the relevant supervisory authority and, where the law requires it, you.
11. What we do not do
- We do not sell your personal data, and we do not share it for advertising or marketing.
- We do not use analytics, tracking pixels, advertising tags or any third-party scripts. The site loads none.
- We do not train any AI model on your data. Data sent to our AI provider is processed by them to produce the output you requested, under their API terms.
- We do not submit an application on your behalf without you approving it.
13. The browser extension
The Job Watcher extension fills in application forms for you. Because a job application can be hosted on any employer's website, the extension asks for permission to access all sites — there is no list of domains we could declare in advance. What it actually does with that permission is narrow:
- The only script that loads automatically runs on Job Watcher's own pages, and exists to pass your sign-in to the extension.
- The script that reads a page is injected only into the tab you explicitly opened for an application, and only when you start that flow. It does not run on your other tabs.
- It reads the visible text of the job posting (up to 20,000 characters) and the structure of the application form — field labels, field types, options, error messages and the values currently in the fields.
- It sends that to our servers, which pass it to our AI provider to work out the next step. It then fills fields and attaches the PDFs we generated for you.
- It will not press the final submit button. The extension refuses to click controls labelled submit, apply now, send application and similar. You submit the application yourself.
- Your sign-in token is held in the browser's session storage and is cleared when you close your browser.
14. Automated processing
We score and rank roles against your profile and generate draft documents automatically. These are suggestions and drafts for you to review, not decisions about you: nothing we produce has a legal or similarly significant effect within the meaning of Article 22 GDPR, no employer decision is made by us, and every application is submitted by you. AI-generated text can be inaccurate — check it before it goes anywhere.
15. Children
Job Watcher is not intended for anyone under 16, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will erase it.
16. Changes to this policy
If we change how we handle your data we will update this page and the date at the top before the change takes effect. Material changes will be described here rather than made quietly.
17. Contact
Honghao Zhang, Theresienstr. 7, 85386 Eching, Germany.
Questions: jobwatchersupports@gmail.com