Privacy Policy
Version 1.2 — effective 2026-07-12.
The short version
Job-title scans are anonymous and use precomputed data — no resume and no AI call. If you choose the resume finder, we delete the uploaded file immediately after extraction; sanitized text may be sent to Anthropic to identify your occupation and held encrypted for up to 24 hours. The paid report processes the work text you submit through Anthropic to extract tasks and write the plan. We don’t sell data, we don’t require accounts, and you can request deletion.
What we collect
- Site measurement and job-title scans: an anonymous session cookie (
jr_sid, random ID, 180 days), the occupation you selected, page and button events, first/latest referrer and UTM campaign parameters, and coarse device class and technical data from standard server logs. Campaign attribution is snapshotted with an order so purchases and refunds can be measured by source. No name, email, resume, fingerprint, or advertising pixel is used for this measurement. Aggregate counters may be analyzed by the growth operator described below. - Optional resume finder: if you upload a resume or job description (PDF/DOCX/TXT), it is virus-scanned, its text is extracted, and the file itself is discarded immediately. Obvious emails, phone numbers, links, and long account-number-like strings are removed before sanitized text may be sent to Anthropic to identify your occupation. The extracted text is held encrypted for up to 24 hours so it can prefill a personalized report, then deleted automatically if you do not continue. Uploads are disabled whenever the virus scanner is unavailable.
- Paid report: the work description you paste (stored encrypted), optional seniority/industry, your email address (collected by Stripe at checkout; stored by us encrypted, used to deliver and recover your report), and payment state. Card details never touch our servers — payment is processed by Stripe Checkout.
- Support: whatever you send us, plus your email so we can reply.
- Email updates: only with explicit opt-in; consent is recorded and revocable, and every email includes an unsubscribe path.
AI processing
The job-title scan never calls an AI model. The optional resume finder may send sanitized extracted text to Anthropic only to identify the best-matching occupation. For paid reports, your sanitized work description is sent to Anthropic to extract tasks, propose mappings, and estimate time shares you did not provide; the application validates mappings and calculates the final score and confidence. A structured summary of that result is then sent to generate the written plan. We warn you before submission not to include confidential employer information, client secrets, passwords, or personal identifiers.
Our internal growth operator may send Anthropic aggregate funnel and campaign counters, public occupation/task facts, public Search Console or Bing performance rows that meet a minimum-impression threshold, deterministic public-page audit findings, and public prospect pages found through web search. If an OpenAI API key is configured, a validated draft and the same aggregate/public evidence may be sent to OpenAI for independent review. The growth boundary rejects raw visitor IDs, resumes, work descriptions, personalized reports, email addresses, orders, support messages, secrets, and private application URLs. Growth output is an internal draft and cannot publish, contact anyone, or spend money.
Anthropic states that commercial API inputs and outputs are not used to train its models by default unless the customer explicitly opts in or submits feedback; we do not intentionally opt report content into training or submit it as feedback. Under Anthropic’s standard API terms, it says inputs and outputs are deleted from its backend within 30 days, with exceptions for services or agreements with different retention, Usage Policy enforcement, and legal obligations. JobAIRisk does not promise zero-data-retention processing.
OpenAI states that API inputs and outputs are not used to train its models by default unless an organization explicitly opts in. The OpenAI review integration is optional and currently remains inactive until its separate API credential is configured.
Retention
- Resume-finder extracted text: encrypted and deleted automatically after 24 hours if you do not continue to a report.
- Unpaid report input: deleted automatically within 48 hours.
- Paid report input and outputs: retained so you can reopen your report; deleted on request.
- Analytics events: retained in aggregate; raw rows pruned periodically.
- Order records: retained as required for accounting and fraud prevention.
Processors
Stripe (payments), Anthropic (paid-report and aggregate/public growth processing), OpenAI when optional growth review is configured, and our hosting provider. Each receives only what its function requires.
Your rights
Request a copy or deletion of your data any time via the contact page (choose “data deletion”). Deletion covers report content, inputs, email records, and support threads controlled by JobAIRisk; order records that must be retained for accounting are minimized instead. Private backup copies age out within seven days and are used only for disaster recovery; a restored deletion request is re-applied. Data already sent to a processor remains subject to that processor’s stated retention schedule and legal or policy exceptions.
Cookies
jr_sid: a random anonymous session ID, retained for up to 180 days.jr_rp_{reportId}: a signed, Secure, HttpOnly, Strict SameSite cookie scoped to one report-status endpoint for up to two hours. It lets a browser poll a report it is already authorized to open; it cannot open other reports.- Admin authentication: a signed, Secure, HttpOnly cookie scoped to
/admin, used only by staff.
Your explicit light/dark theme choice is stored in browser local storage, not a cookie. There are no third-party advertising or analytics cookies.
Contact for privacy matters: jobairisk.com/contact.