JOBolar legal documents
Privacy Policy
Last Updated: September 3, 2026
This Privacy Policy explains how JOBolar.Ai ("Jobolar", "we", "us") collects, uses, discloses, and protects your information when you use our services.
This document is for informational purposes and does not constitute legal advice. Rights and obligations may differ by jurisdiction (e.g., GDPR, CCPA).
Product-specific data and device processing
The data Jobolar handles depends on the products and optional connections you choose.
- Job Search & Matching may process profile, target role, location, preference, opportunity, alert, and analytics data.
- Email Auto Apply may process the connected Gmail send token, selected application documents, public recipient address, application content, delivery metadata, schedule, and controls. The Gmail Send scope does not grant inbox-reading access.
- Smart Apply and the Chrome extension may read and process compatible external job-application form fields and page context in the active tab, browser-local Smart Form data, saved answers, selected résumé content, application answers, task status, and content you choose for AI generation or refinement. Sensitive fields, signatures, and unsupported flows may remain manual.
- Résumé and cover-letter tools may process uploaded or structured résumé content, Career Profile information, job descriptions, previews, generated documents, and usage records.
- Interview Assistant may process typed questions, microphone or system audio, transcripts, session context, selected résumé and role data, device tokens, and usage. Camera-based delivery coaching is processed on-device where the product states this.
- Live support is optional. Tawk.to is not loaded until you choose Live Chat. If you enable it, Tawk.to may process cookies or similar technologies, device information, and the content you submit to support. Do not send passwords, full payment credentials, or information unrelated to your support request.
Backend and AI processing
Browser-local data stays on the device unless you invoke a connected or AI feature. When you do, the selected résumé, form, answer, job, or task context needed for that feature may be transmitted to Jobolar’s authenticated backend and contracted hosting, security, monitoring, or AI service providers to generate or refine content, operate automation, prevent abuse, and troubleshoot the service. Jobolar does not ask Smart Apply to collect job-site passwords, cookies, session tokens, CAPTCHA or MFA codes, or payment credentials.
Browser-local and backend retention
Browser-local Smart Form, résumé, and saved-answer data remains under your browser and extension controls and may persist until you clear or replace it, reset or remove the extension data, or the browser removes it. Backend application records, selected context, generated outputs, and operational records are retained only as reasonably necessary to provide the feature, maintain your history, secure the service, meet legal obligations, and apply the retention periods described below.
Deletion and controls
You can clear browser-local data, replace saved résumé or answer data, pause or cancel supported application automation where controls are offered, disconnect Gmail or extension access, delete available records, and request account deletion. Interview Assistant sessions cannot be paused once started. Account deletion removes active account data from Jobolar systems, subject to the limited security logs, encrypted disaster-recovery backups, payment, fraud-prevention, dispute, and legally required records described below.
JOBolar.Ai Smart Apply Chrome extension
- The extension processes supported job-page content and visible application-form fields in the user’s browser, using the user’s existing signed-in session. LinkedIn, Indeed, and other supported sites are not affiliated with or endorsing JOBolar.Ai.
- Smart Form data, the selected résumé, preferences, saved answers, schedules, and the purpose-scoped Jobolar extension credential are stored in browser-local extension storage, including IndexedDB. Users can replace or clear this local data through extension controls or Chrome’s extension-data controls.
- When the user requests a connected or AI feature, the selected job description, résumé, form/question context, requested answer or application content, and task metadata needed for that feature may be transmitted over HTTPS to Jobolar’s authenticated backend and necessary contracted AI or service providers.
- The extension does not request or collect job-site passwords, cookies, CAPTCHA responses, MFA codes, or payment-card information. Autofill and application automation are user-controlled and stop at the product’s sensitive, legal, security, uncertain, and unsupported boundaries.
JOBolar’s use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
1) Information We Collect
A. Account & Identity
- Primary Google Account email address and public profile info (name, profile photo, preferred language) via Google OAuth.
- Country/region, time zone, and interface language (derived from device/browser settings).
B. Job Search Profile
- Targets (roles, locations—local and abroad, preferred platforms/boards).
- Daily send limits, pause/resume state, notification preferences.
C. Content You Provide
- Uploaded files (resumes/CVs, certificates - optional).
- Application materials generated with JOBolar AI ("AI Chatty Buddy").
D. Application & Usage Data
- Application metadata (timestamp, recipient, subject, job title/company, delivery status).
- Device/technical logs (IP, user agent, browser/OS, crash logs) for security and diagnostics.
E. Gmail Integration (Sensitive Scope Use)
The only Gmail credential stored by JOBolar is a securely encrypted refresh token. This token allows sending emails initiated by the user; we do not store your Gmail password and we never read your inbox or access other Gmail data. The token is encrypted at rest and used exclusively for sending user-triggered job-application emails.
F. Non-Collection Notice
We do not collect, read, or access your Gmail inbox, email bodies, subjects, attachments, or any other Gmail message data. We do not ask for or store Gmail passwords.
G. Payment Information
We do not store full payment credentials such as credit card numbers or bank account details. Payments are processed securely by third-party providers:
- Stripe — Stripe (for card payments)
- Flutterwave — Flutterwave (for bank transfer and mobile money payments)
These providers may collect and process payment-related information in accordance with their own privacy and security policies.
AI Interview Assistant Data
When you use AI Interview Assistant, we may collect and process the information needed to provide and secure the feature, including:
- microphone audio, typed text, an image you explicitly upload, or a locally cropped question-area capture you explicitly take during a live session;
- audio- or image-derived transcripts, interview questions, generated talking points and answers, session history, timestamps, mode selections, and usage-minute records;
- résumés, job descriptions, preferences, and other context you choose to use for résumé-grounded guidance; and
- device, browser, permission, connectivity, diagnostic, and error information used to operate and troubleshoot the feature.
We use this information to transcribe questions, generate and personalize guidance, maintain session history, enforce purchased allowances, prevent abuse, provide support, and improve reliability and safety.
Audio, cropped question images, transcripts, prompts, and related context may be transmitted to service providers that supply hosting, speech recognition, optical-character recognition, artificial-intelligence processing, monitoring, or security services. Those providers process information on our behalf under their applicable terms and safeguards.
Microphone and display-capture permissions are controlled by your browser and operating system. You can decline them and use text-only or uploaded-image input where available. A display source is requested only after you choose Capture Question Area; your browser requires you to choose a tab, window, or screen whenever sharing starts, and JOBolar.Ai cannot silently grant or permanently remember that permission. Do not capture another person’s voice, image, or confidential content unless you have any consent and authorization required by applicable law and the relevant interview, employer, and platform rules.
Assistant records are retained only as reasonably necessary to provide the service, maintain session history and billing records, meet legal obligations, resolve disputes, and protect the service. You may request access or deletion as described in the Your Rights section, subject to legal and operational retention requirements.
Web question-area screen capture
The Web Interview Assistant does not take screenshots until you explicitly select Capture question. Your browser locally decodes the chosen tab, window, or screen and JOBolar.Ai shows a live selector preview. Only the selected pixels are copied into a crop-sized local canvas and sent temporarily for text extraction; the extracted question then requests an answer automatically. Complete display frames are not encoded, uploaded, or stored. Normalized crop coordinates last for the current interview, or remain in this browser only when you select the optional reuse setting; cropped image previews are cleared after processing.
Interview Assistant Desktop privacy
The supported Windows and macOS Desktop app presents a versioned privacy disclosure before account connection, device access, or an interview session.
- On Windows, Live Interview captures the default speaker output; on macOS, it captures compatible display/system audio. This may include audio from other applications playing at the same time, so users should close or mute unrelated applications. Manual Listen uploads a segment when the user stops it or at the existing five-minute safety limit. Optional Smart Listen detects speech locally and uploads short detected-speech segments for private transcription; only a confirmed interview question requests an AI-generated answer.
- Mock Interview uploads microphone answers the user chooses to submit. The microphone device check uses temporary local audio. Optional Visual Delivery Coaching processes reduced-resolution camera frames on-device; images and video are not uploaded or stored, and only non-biometric summary coaching measurements are kept locally and separately from the main interview score.
- Résumé content, job descriptions, candidate profile information and interview context are transmitted only when the user chooses to use them. A question screenshot is uploaded only after the user selects or pastes it, processed temporarily to extract editable text, and not stored; the user confirms that text before requesting an AI answer. Temporary images and audio are deleted after processing under the service's privacy controls.
- The purpose-scoped Desktop credential is stored in Windows Credential Manager or macOS Keychain. Necessary settings, bounded session history and only the accepted disclosure version and timestamp are stored locally. The app does not receive Jobolar or Google passwords, payment information, SmartApply credentials or backend secrets.
- Screen-share privacy is best effort and depends on the operating system, meeting software and capture method; it is not guaranteed. Users must obtain any consent required by applicable law, the interviewer, employer and meeting platform.
- Privacy & Data remains available in the app to review this disclosure, withdraw consent and clear the Desktop credential, consent, settings, local history, interview context and temporary audio. An active interview must be confirmed ended before the app closes or completes that cleanup.
Chrome Web Store Interview Assistant disclosure
The Chrome Interview Assistant does not process or upload screen video and does not upload candidate microphone audio. For browser meetings, it uses audio from the selected meeting tab. For installed Zoom or Teams, the user may explicitly open Chrome’s screen/window picker to share compatible app/window or system audio. Chrome supplies a required display video track with that stream; JOBolar disables it immediately and never renders it, reads its pixels, records it, encodes it, processes it, or uploads screen video. System audio may include notifications or other applications, so users should close or mute unrelated apps. Manual Listen sends a selected-source audio segment when the user stops it, or automatically when an unfinished segment reaches the five-minute safety limit. If the user enables optional Smart Listen, local voice detection automatically sends short detected-speech segments from the selected source for private transcription. A question image or selected screenshot crop is sent only after the user explicitly pastes, chooses, or captures it; JOBolar temporarily extracts the question and automatically requests an answer, then discards the image. The visible Translucent Focus Overlay is injected into the selected browser meeting tab. Adjusting answer-background transparency does not hide it from screen sharing or recording.
JOBolar's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
2) How We Use Your Information
- Send job applications via your Gmail with attachments you upload or generate (resume, cover letter, certificates).
- Provide job-matching, dashboards, notifications (daily summaries), and status tracking.
- Generate or refine resumes and cover letters using AI Chatty Buddy at your request.
- Protect the service through authentication, Firebase App Check, feature-specific usage limits, and infrastructure-level abuse protections.
- Improve the Services (quality, reliability, deliverability) using aggregated, de-identified metrics.
- Comply with legal obligations and enforce our Terms, including investigating misuse.
Jobolar requests consent where required, including for Google OAuth and optional device permissions. Other processing may be necessary to provide and secure the service or comply with legal obligations.
3) Google Permissions & OAuth Scopes
We use Google OAuth to connect your Gmail. Requested scopes are limited to what is necessary to perform email-based applications:
- openid – verify your identity with Google
- email – see your primary Google Account email address, used to identify your account and route notifications
- profile – basic public profile (name, photo, preferred language) for personalization
- gmail.send – send email on your behalf for job applications sent from your Gmail address
- We request the minimal scope required and do not request full read access to your inbox contents. The gmail.send scope does not permit reading inbox messages.
- You can revoke access anytime in Google Account → Security → Third‑party access. https://myaccount.google.com/permissions
- Google OAuth connection and Gmail sending occur only after you grant the requested permission. We maintain limited operational records for selected actions.
Gmail Token Handling
- We store an encrypted Gmail refresh token on our servers to enable sending emails on your behalf.
- The token is encrypted at rest using industry-standard encryption.
- Token usage is limited exclusively to sending user-triggered job-application emails.
- We do not store your Gmail password at any time.
- Disconnecting Gmail through Jobolar deletes the stored Gmail credential. Revoking access through Google Account settings prevents further authorized Gmail access.
- Gmail credentials are retained only while your Gmail connection is active and are deleted when you disconnect Gmail through Jobolar.
Limited Use & Google API Compliance
JOBolar's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not use Gmail data for advertising purposes.
- We do not use Gmail data to train generalized AI models or for any purpose unrelated to providing the job-application service.
- We do not permit human access to your Gmail data without your affirmative consent.
- Gmail data is used solely to send job-application emails you initiate and approve.
4) Data Storage, Retention & Deletion
We use Firebase (Google Cloud) for hosting and storage. Data is encrypted in transit and at rest. Access is role-restricted.
Retention
- Account data: retained while your account is active.
- Application metadata & generated docs: retained for your dashboard history unless you delete them.
- Limited residual copies may remain temporarily in security logs, backups, or service-provider systems and are removed according to applicable retention schedules.
Deletion
- Self‑service deletion from dashboard for documents and profile items.
- When account deletion completes, Jobolar immediately removes the user's active account data. Limited residual copies may remain temporarily in security logs, backups, or service-provider systems and are removed according to applicable retention schedules.
- You may also revoke OAuth access at any time from your Google Account.
5) AI Processing (AI Chatty Buddy)
- Creates/updates resumes and generates job‑specific cover letters using your inputs.
- Stores outputs under your account to attach to applications and reuse later.
- Jobolar uses DeepSeek and Google's paid Gemini API for selected AI features. DeepSeek has confirmed Jobolar's training opt-out, and Google states that paid Gemini API prompts and responses are not used to improve its products.
- AI outputs may require your review for accuracy and compliance with job requirements.
6) Sharing & Disclosure
- Employers/Recipients: We share only the materials you instruct us to send (email body, resume, cover letter, certificates).
- Service Providers: Service providers may include Google/Firebase and Gemini, Vercel, Contabo, DeepSeek, Microsoft, and Tawk.to, depending on the feature you choose.
- Payment Processors: We share necessary transaction information with Stripe and Flutterwave to process payments securely. These providers handle payment authorization, settlement, and fraud prevention in accordance with their own privacy and security policies.
- Legal: Disclose where required by law or to protect rights, safety, and security.
- We do not sell or rent personal data. We avoid unnecessary third‑party sharing.
7) Security Measures
- We maintain limited operational and security logs for selected actions, including application attempts, usage enforcement, and service errors.
- Secrets management and tokenization for OAuth credentials; no storage of Gmail passwords.
- We use authentication, Firebase App Check, feature-specific usage limits, and infrastructure-level abuse protections to protect the service.
- Access to production systems and provider accounts is restricted to authorized personnel.
8) Your Rights
- Access, correction, deletion, and portability of your personal data.
- Withdraw consent (e.g., revoke Google OAuth) without affecting prior lawful processing.
- Object to or restrict processing (subject to applicable law).
- Lodge a complaint with a supervisory authority in your jurisdiction.
Contact support@jobolar.ai to request access, correction, deletion, restriction, or a portable copy of your personal data. After verifying your identity, Jobolar will respond within the period required by applicable law and may withhold information where disclosure would affect another person's rights, security, confidentiality, or a legal exemption applies.
9) Data Processing Agreements (DPAs) & International Transfers
- Where required by applicable law, Jobolar enters into or relies on applicable data-protection terms provided by service providers that process personal data on its behalf.
- Providers may process data outside your country. Where required by law, Jobolar relies on applicable contractual or other transfer safeguards made available by those providers.
10) Operational & Security Records
- We maintain limited records for selected actions, including application attempts, usage enforcement, service errors, and relevant consent or connection events.
- These records are used for security, service operation, troubleshooting, and legal compliance—not advertising—and are retained only as reasonably necessary.
11) Limitation of Liability
- We are not liable for losses due to user negligence (e.g., insecure devices, shared credentials).
- No liability for service interruptions or third‑party outages beyond our reasonable control.
- No warranty on AI output accuracy, completeness, or suitability; users should review before sending.
- To the extent permitted by law, our aggregate liability is limited to fees paid (if any) for the Services.
12) Governing Law, Regional Rights & Dispute Resolution
We honor regional privacy rights. Depending on your residence, you may have additional rights under GDPR (EU/UK), CCPA/CPRA (California), LGPD (Brazil), or other local laws.
- Governing law: determined by the operating jurisdiction of JOBolar.Ai unless local law requires otherwise.
- Disputes: where permissible, resolved via mediation or binding arbitration before court proceedings.
- Venue & jurisdiction: exclusive venue consistent with applicable law; users consent to such jurisdiction.
Contact support@jobolar.ai with rights requests or dispute inquiries.
13) Contact
Questions about this Privacy Policy or your data? Contact us at:
- Email: support@jobolar.ai
- Physical Address:
330 2nd Ave S 200 1319
Minneapolis, MN 55401
USA