Last updated: August 2026
Your job applications stay on your computer. We never receive a company name you typed, a street address, a city, or a full ZIP code. If you opt in to community sharing, your device converts what it knows into codes from a fixed list before anything is sent, and nothing is published — or even stored in our published statistics — until at least five separate contributors are in a group. We don't sell your data. We don't track you across the web. We don't serve ads.
This policy describes what actually happens in the software as it ships today. Where something is technical, we say what it is rather than summarizing it away.
The desktop application stores everything you enter in a local SQLite database on your own machine. That includes:
Company names, job titles, application dates, statuses, contact names and details, notes, job descriptions, salary information, follow-up history, and any résumés you attach.
Résumés never leave your computer. There is no résumé upload, no server-side file storage, and no cloud copy. The same is true of job descriptions and contact details.
Your personal intelligence model — the one that learns which of your applications are likely to get a response — is also trained and stored locally. Its training examples never leave your device.
To sell and manage a license, our server stores:
Your email address (from checkout, used to identify your license and send transactional email), your license key, and a device fingerprint — a SHA-256 hash of hardware identifiers. The hash cannot be reversed to identify your hardware, and we do not store the underlying identifiers.
We also store activation and transfer history for your key, so the three-transfers-per-year policy can be enforced and so support can help you when a device change goes wrong.
This data is required for the product to function and is not optional. It is separate from community data sharing, which is.
Community statistics are built from anonymous snapshots that are only sent if you explicitly turn sharing on. Sharing is off until you consent, you can turn it off at any time in Settings, and turning it off stops all future submissions immediately.
A snapshot is a set of counts and codes describing your search. It contains:
Counts and rates: how many applications you've sent, how many received a response, how many reached an interview, how many became offers, how many were ghosted, and the rates derived from those.
Timing: the month and week of the snapshot, how long you've been searching, how many applications you sent this week and this month, and how many days in the last 30 you were active.
Field of work — a bucket such as "technology," not your job title.
Where you're applying, as codes: a ZIP3 (the first three digits of a ZIP code — an area of roughly 700 square miles containing hundreds of thousands of people), and a metro market code such as los_angeles drawn from a fixed list of 56. Your device also sends a coverage figure — how many of your applications it was able to place at all — so the statistics can state an honest denominator.
Employers, as codes: your device matches what you typed against a catalog of 1,133 known employers compiled into the application and sends the matching code. It never sends what you typed.
Application sources — LinkedIn, Indeed, referral, company site, and so on.
Your personal model's coefficients: if your local model has trained, the snapshot includes its accuracy, its evaluation score, the number of examples it learned from, and eleven numeric weights. These are learned coefficients over the bounded features above. No application, employer, location, date, or piece of text can be recovered from them.
An anonymous identifier derived from your device, used to make sure one contributor counts once. It is not your email, your name, or your license key.
Your full ZIP code. Your street address. Your city. Your name. Your email. Your job titles. Your notes. Your job descriptions. Your contacts. Your résumés. Your salary figures. Any company name as you typed it.
Two of these are worth explaining, because they're the parts people assume must be happening:
The ZIP is truncated on your device, at the moment you type it. The application keeps only the first three digits and discards the rest before storing or sending anything. Your full ZIP never reaches our server because it never leaves the input field.
Employer names are resolved on your device, against a catalog shipped inside the application. The server has no way to accept a free-text company name — it validates every code against a fixed vocabulary and rejects anything else.
If you apply somewhere our catalog doesn't know, your device sends a normalized version of the name only — lowercased, punctuation stripped, suffixes like "Inc." removed — capped at ten per submission, so that the catalog can grow. A person reviews these and decides whether to add them to the published vocabulary in a future release.
These entries are stored with your anonymous identifier and the market code, and nothing else. They are used to improve the catalog, are never published as a list, and are deleted if you delete your account. If you would rather this didn't happen at all, turn community sharing off.
A five-contributor minimum, enforced when the statistic is written — not when it is displayed. If fewer than five separate contributors are in a group, that group is never written into our published statistics table at all. There is nothing to leak, because nothing was recorded. This applies to every dimension: employer, field, region, metro, and state.
The map cannot say "nobody is here." A place with four contributors and a place with none look identical on the map and in the API, deliberately. Distinguishing them would disclose exactly what the threshold exists to hide.
Map locations come from a fixed catalog, never from contributors. Every dot on the map sits at a published coordinate for that metro or region. No coordinate is calculated from where contributors actually are, which means a bubble can never drift toward the people inside it.
Contributors are counted as devices. When you see "24 contributors," that counts distinct devices that have shared data, not verified individuals.
Community statistics reflect people who are currently searching. If a contributor hasn't sent an updated snapshot in eight weeks, they stop counting toward the current community figures. This means the community number goes down in a quiet week, and that is correct behaviour rather than a loss of data — a response rate that included people who stopped searching months ago would describe a job market that no longer exists.
Community statistics include a seeded baseline. Where the community is small, our figures include a synthetic baseline population so the intelligence layer has something to work with. Anywhere we publish a community figure, we tell you whether a seeded baseline is included and when the numbers were last computed.
This website is a static site served by Cloudflare. We use Cloudflare Web Analytics, which is privacy-focused, sets no cookies, and does not track individual visitors across sites. We do not use Google Analytics, advertising pixels, session recording, or any third-party behavioural tracking.
The Member Portal holds your session in browser memory only — no cookies, no localStorage, no sessionStorage. Closing the tab ends the session.
The public map shows only community statistics that have already cleared the five-contributor minimum, using coordinates from a fixed catalog. It shows volume, not outcomes. Viewing it requires no account and sets no identifier.
Payments are processed by Stripe. We never receive, store, or have access to your card number. Stripe provides us with your email address, the product purchased, a payment reference, and subscription status. Stripe's own privacy policy governs payment data: stripe.com/privacy.
We do not publish anything derived from your payment. Purchase activity shown on our Community page is aggregated counts over a time period, never an individual purchase, and never a location.
Transactional email — license key delivery, gift notifications, expiry warnings, and account notices — is sent via Resend. These emails are part of the service you purchased. We do not send marketing email, and we do not sell or share your address with anyone else.
If you link your Discord account to your license, we store your numeric Discord user ID and nothing else — no username, avatar, nickname, message history, or activity. The ID is used to assign community roles matching your tier. Community statistics posted to Discord are counts only.
We do not sell, rent, or trade your personal information. Ever.
We share data only with the service providers that make the product work: Stripe (payments), Resend (transactional email), and Cloudflare (hosting, CDN, DNS). Each has its own privacy policy.
Community aggregates are shared with other members and, for the geographic layers, with the public — but only in aggregate form, only above the five-contributor minimum, and only as codes from a published vocabulary.
We may disclose information if legally required to do so. We will tell you if that happens unless we are prohibited from doing so.
Access. You can request a copy of the data we hold about you.
Export. You can export your application data from the desktop app at any time, in a portable format. This data is yours and lives on your machine.
Opt out. You can turn community sharing off at any time in Settings. Future submissions stop immediately.
Correction. You can update your email address by contacting us.
Deletion. You can request deletion of your account data from our servers. Here is exactly what that does:
Deleted: your community snapshots, the historical archive of those snapshots, any unrecognized employer names you contributed, and the link between your license and your Discord account. Your license key is marked deleted and cannot be reused or restored.
Retained: a record that a submission occurred, containing your device-derived anonymous identifier and a timestamp, but no longer linked to your license. We keep this so that community activity figures remain honest and cannot be inflated or deflated by deletions. This identifier is derived from your device — it is not your name, email, or key — but it is a persistent identifier, and we would rather tell you it survives than describe the deletion as more complete than it is.
Also retained: records we are required to keep for tax and accounting purposes, such as the fact and amount of a payment, held by us and by Stripe. And any employer name that a human reviewer previously added to our public catalog stays in the catalog — a vocabulary entry is a product decision about a word, not a record about you.
To exercise any of these rights, email privacy@joblogist.com, or use the account deletion option in the desktop app.
California residents have the right to know what personal information we collect and why, to request deletion, to request correction, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. The rights above are how you exercise these.
JobApp is operated from the United States, and your data is processed there. If you are in a jurisdiction with additional data protection rights, contact us at privacy@joblogist.com and we will honour access, correction, and deletion requests regardless of where you are.
Licensing data is retained for as long as your license exists, and afterwards only as required for tax and accounting.
Community snapshots are retained until you delete your account. Your most recent snapshot represents your current state; the historical archive keeps prior submissions so that trends over time can be computed. Both are deleted on account deletion.
The internal job queue that recomputes statistics keeps completed entries for 30 days.
All data in transit is encrypted (HTTPS/TLS). Device fingerprints are SHA-256 hashed. Administrative endpoints require a separate secret and fail closed — if that secret is missing, they refuse every request rather than allowing any. License keys are not logged in plaintext. We do not store passwords; your license key is the credential.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you promptly and tell you what happened.
JobApp is not intended for anyone under 13, and we do not knowingly collect data from children. If you believe a child has provided us with information, contact privacy@joblogist.com and we will delete it.
We may update this policy. If a change materially affects what we collect or how we use it, we will notify you by email and in the application before it takes effect. The "last updated" date at the top always reflects the current version.
For privacy questions, requests, or concerns: privacy@joblogist.com