Privacy
AI Job Copilot is a Chrome extension that runs in your browser and uses an AI API key you provide. You pick a provider, Anthropic or OpenAI, by pasting the corresponding key. Your master CV, your API key, and the jobs you analyse are stored only in your browser.
When you run an analysis or generate a draft, the relevant parts of your CV and the job description are sent to your chosen AI provider so it can do the work. AI Job Copilot does not operate any server. The current version of the extension does not include analytics, telemetry, or third-party trackers.
Who is responsible
AI Job Copilot is operated by Dmytro Svarytsevych, a natural person resident in Poland, as a non-registered personal project (nierejestrowana działalność). For the purposes of EU data protection law, the publisher is the data controller for the data this Privacy Policy describes.
Contact: job.copilot@svarytsevych.com.
Your rights under EU law
Most of what AI Job Copilot handles is stored in your browser, which means you control it directly: open the extension's Settings to view it, edit it, or delete it. Where the publisher does act as a controller (for example, an email you send to the contact address above), the General Data Protection Regulation gives you the following rights:
- Access, rectification, erasure, restriction of processing, and data portability.
- The right to object to processing.
- The right to lodge a complaint with a supervisory authority. In Poland that is the President of the Personal Data Protection Office (UODO), uodo.gov.pl.
To exercise any of these rights, write to the contact address above.
What this extension does
AI Job Copilot reads job descriptions from supported job sites (LinkedIn, Lever, Greenhouse, Workday, Ashby) and uses your chosen AI provider (Anthropic's Claude or OpenAI's GPT models) to assess fit, draft tailored CVs and cover letters, and pre-fill application forms. It runs in your browser and talks to the AI provider directly, using an API key you supply.
Data that stays in your browser
The following is stored locally in chrome.storage.local and does not leave your device unless you explicitly send it (see the next section):
- Your AI provider API key. Either an Anthropic key (recognised by the
sk-ant-prefix) or an OpenAI key (recognised by thesk-prefix). The extension detects which provider the key belongs to from its prefix, so there is no separate provider toggle. The key is stored as plain text inchrome.storage.localwith no encryption-at-rest, so the extension can authenticate calls toapi.anthropic.comorapi.openai.comon your behalf. One key at a time; pasting a different key replaces the previous one. - Your master CV. The CV you upload (markdown, PDF, or DOCX) or import from LinkedIn. Contains the personal data you put in it (name, email, work history, and so on).
- Profile data for form auto-fill. Optional structured fields you enter in Settings: name, address, contact, work-authorisation, salary expectation, and optional demographic fields. Some of those optional fields (for example gender, pronouns, sexual orientation, race or ethnicity, disability status) are categories considered special under GDPR Article 9. You provide them only if you choose to; "Decline to answer" is always a valid value. They are stored locally and never inferred from anything else.
- Snoozed companies and filter preferences. Names of companies you have hidden, your job filters, your jurisdiction settings.
- Application sessions. Per-job state: the parsed job description, the analysis result, generated CV and cover letter drafts, and a timestamp. A session lives while you have a tab open on the job; it is removed when the last tab pointing at that job closes or when you end the session manually.
- Cached analyses. Analysis results are cached locally for seven days per job so the same page does not get re-analysed and re-billed on revisit.
How long data is kept
- API key, master CV, profile data, snoozes, filters: stored until you delete them in Settings, reset the extension, or uninstall it.
- Application sessions: while a tab on the job is open; removed when the last tab closes or you end the session.
- Analysis cache: seven days per job, then removed automatically.
Other surfaces (Chrome Sync, Chrome Web Store)
If you have Chrome Sync enabled for extensions, the contents of chrome.storage.local — including your API key and master CV — are synced between your Chrome profiles via Google's servers under Google's privacy policy. Chrome Sync is a Google Chrome feature, not something this extension does. See Google's documentation on Chrome Sync for what is synced and how to turn it off.
Google and the Chrome Web Store also collect install, uninstall, version, and crash data independently of this extension, under Google's policies.
Data sent to your AI provider
When you trigger an action that needs the AI model (Analyse, Generate CV, Generate cover letter, Generate LinkedIn invite, Auto-fill) the extension sends the following to api.anthropic.com if you configured an Anthropic key, or to api.openai.com if you configured an OpenAI key, using your API key:
- The job description text and URL from the page you are on.
- Relevant parts of your master CV.
- Your stated voice and jurisdiction settings.
- For auto-fill: the form-field labels, types, length limits, placeholder text, and option lists on the application page. The extension also reads existing field values locally so it can skip fields you have already filled, but those values are not sent to the AI provider. The structured profile data named above (including any GDPR Article 9 fields you have set) is sent only when needed to answer a matching field, and only for that request.
Anthropic and OpenAI act as independent data controllers for any data sent under your account with them. They process that data under their own terms with you, not under a contract held by AI Job Copilot:
AI Job Copilot does not relay this traffic. It goes from your browser to the provider's API directly.
On model training. Whether Anthropic or OpenAI uses the data you send through their API to train their models is governed by your account settings and the terms you accepted with them. Both providers state that data submitted through their APIs is not used to train their models by default. Check your account preferences with each provider to confirm and adjust.
Transfers outside the EEA
Anthropic and OpenAI are headquartered in the United States and process API traffic on infrastructure that may be located outside the European Economic Area. Both providers publish their transfer mechanisms (typically a combination of the EU-US Data Privacy Framework and Standard Contractual Clauses) in their privacy policies linked above. Because your account with the provider is the contract under which that data flows, those mechanisms apply to your use of the API directly.
What is not collected
The current version of the extension does not include analytics, telemetry, crash reporting, third-party trackers, geolocation, health-data collection, payment processing, or remote backups. The list is exhaustive for this version. If it changes in a future release, this section will be updated before the change takes effect.
This website
Everything above describes the AI Job Copilot browser extension. The public website it is served from (jobcopilot.svarytsevych.com) is a separate surface with its own, lighter data handling. The website uses PostHog analytics configured for privacy: it is hosted in the European Union, sets no cookies and stores nothing on your device (so no consent banner is required), records only aggregate page views and in-page clicks with no cross-site tracking, and is never linked to any identity. It exists solely to show which pages and referral sources are useful. It is entirely separate from the extension, which — as stated above — collects nothing at all.
Third-party services
Three services may be involved, depending on your configuration:
- Anthropic. If you configured an Anthropic API key, this is the AI provider that processes your calls. Anthropic's privacy policy governs that processing.
- OpenAI. If you configured an OpenAI API key, this is the AI provider that processes your calls. OpenAI's privacy policy governs that processing.
- Ko-fi. Used for optional tips. A link in the extension opens
ko-fi.com/dsvarytsin a new browser tab. The extension itself does not see who tips, the amount, or any payment data. Tips are processed by Ko-fi on its own site. Ko-fi's privacy policy applies once you click through.
The extension only talks to one AI provider at a time, the one whose key you have currently stored. If you switch keys, the old provider no longer receives any traffic from the extension.
Your control over your data
You can remove anything stored by the extension at any time:
- Open the extension's Settings, then Reset extension. This clears all stored data, including the API key, master CV, profile data, snoozes, and cached sessions.
- Or, in Chrome, go to
chrome://extensions, click Details on AI Job Copilot, then Site settings and clear extension data. - Or uninstall the extension. Chrome removes the extension's storage when you do.
To delete anything stored on your AI provider's side, use the controls in your Anthropic or OpenAI account.
If something goes wrong
If a personal-data breach occurs and is likely to result in a risk to your rights and freedoms, a notice will be published at this URL within 72 hours of the publisher becoming aware of it, as required by GDPR Article 34, and affected users will be notified to the extent reasonably possible. The notice will describe what happened, what data was involved, and what steps to take.
Age
The extension is intended for users aged 16 and older. By using it, you confirm you are at least 16 years old. The extension does not verify age.
Changes to this policy
If this policy changes, the new version will be published at this URL and the Last updated date at the top will change. Material changes will be flagged in the Chrome Web Store release notes for the version that introduces the change.
Contact
Questions or concerns: job.copilot@svarytsevych.com.