TabsOnJobs is a personal job-search assistant. Its core features — discovering jobs from public job boards, scoring how well a role fits your resume, tailoring resumes, drafting replies to recruiters, preparing for interviews, and tracking applications — work from a regular account and do not require you to connect Gmail.
Connecting Gmail is an optional beta feature. If you choose to connect it, TabsOnJobs can additionally surface job-related email from your inbox. You can use the entire app without it. This policy explains what we collect, why, who we share it with, and how you can delete it.
By creating an account, you agree to this policy.
Account information. Your email address and a password (stored only as a salted one-way hash — we never store your plaintext password).
Google account data (via OAuth) — only if you connect Gmail. Gmail is an optional beta feature. If you choose to connect it, then with your explicit consent on Google's permission screen, TabsOnJobs accesses your Gmail using Google OAuth. If you never connect Gmail, none of the data below is collected. Depending on the scopes you grant, this can include:
We store the OAuth tokens Google issues so the app can act on your behalf. We do not receive or store your Google password.
Resume and profile content. Resume files you select or upload, the parsed text extracted from them, and any notes or instructions you add.
Job and application data. Jobs detected from your inbox or added manually, fit scores, tailored resumes, interview-prep packets, recruiter reply drafts, follow-up reminders, saved searches, and the status you assign to each job.
Browser extension data (only if you install it). TabsOnJobs offers an optional Chrome browser extension ("Bulk Add") that helps you import job postings from pages you are already viewing. When you open the extension on a supported page (such as a company careers page or a job board) and click to scrape, it reads the job postings shown on that page — typically the role title, company, location, and apply link. Nothing is collected automatically or in the background: the extension only reads a page when you explicitly open it and ask it to, and it only transmits the specific postings you select. Selected postings are sent to your TabsOnJobs account (to your "Discovered" jobs) using your existing logged-in session, so you must be signed in to TabsOnJobs for the import to work. The extension does not collect browsing history, passwords, or page content unrelated to job postings, and it stores only your chosen server address and preferences locally in your browser.
AI-generated content. Text produced when you tailor a resume, generate a draft, or prepare for an interview.
Technical/usage data. Standard server logs (timestamps, request paths, error details) and an internal AI activity log (provider, model, latency, and error codes for each AI call). We design logs to avoid storing full email bodies or secret values.
TabsOnJobs' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
To generate summaries, fit scores, tailored resumes, drafts, and prep content, TabsOnJobs sends relevant text — which can include resume content, job descriptions, and excerpts of recruiter messages — to third-party AI providers configured for the service:
These providers process the text to return a result. We rely on their respective enterprise/API terms, which state that API inputs are not used to train their models by default. We never send your Google OAuth tokens or password to AI providers.
Other subprocessors:
We use the data above to: authenticate you; fetch and organize job-related email; compute fit scores; generate and store tailored resumes, prep packets, and drafts; send email or create calendar events when you explicitly request it; maintain your job pipeline; operate, secure, debug, and improve the service; and comply with legal obligations.
We do not sell your data. We share it only with: the AI providers and hosting provider listed above (as needed to run the features); Google (to read/send mail and create events you request); and authorities where required by law. If the service is ever transferred to another operator, we will require equivalent privacy protections and notify you.
We retain your account data, tokens, resumes, and job data for as long as your account is active. OAuth tokens are kept until they expire or you disconnect Gmail. You can delete individual items (resumes, tailored versions, saved searches) in the app at any time. When you delete your account, we delete your associated data within 30 days, except where we must retain limited records to comply with law.
We protect data with HTTPS in transit (with HSTS) and security headers (Content-Security-Policy, X-Frame-Options, and others). Passwords are stored only as salted PBKDF2-SHA256 hashes. Sessions use signed cookies with a bounded lifetime and server-side revocation. Each user's data is stored in a separate per-user namespace with access controls, and state-changing requests are protected against cross-site request forgery. We rely on our hosting and storage providers (Render and Cloudflare R2) for encryption of data at rest on their infrastructure. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
Your data may be processed in countries other than your own, including by the subprocessors above. Where required, we rely on appropriate safeguards for such transfers.
TabsOnJobs is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has provided us data, contact us.
We may update this policy. We will post the new effective date here and, for material changes, take reasonable steps to notify you.
Questions or requests: [email protected].
← Back to TabsOnJobs