Privacy Policy
Last updated: 2026-08-03
The short version
JobStraight is local-first. Your resume, profile, saved answers, applications and interview history are stored in your own browser (localStorage) — not on our servers. We don't have a server that receives your resume.
What we store, and where
Everything you enter stays in your browser. You can export a full backup or delete all of it at any time from Settings → Your data. Clearing your browser data removes it permanently.
Optional encryption
For extra protection (e.g. on a shared computer), Settings → Encrypt my data locks your API keys and, if you choose, your resume and contacts with a passphrase using AES-256 (PBKDF2 + AES-GCM) — all in your browser. Your passphrase is never stored or transmitted, and there's no recovery if you forget it. You unlock once per session.
How we protect the app
The site ships a strict Content-Security-Policy that only allows scripts from the app itself and trusted CDNs, and only permits network calls to the specific APIs listed below. Third-party CDN scripts are pinned with Subresource Integrity, so if a CDN were ever compromised the browser refuses to run altered code. Framing of the app is blocked, HTTPS is enforced (HSTS), and the microphone is used only for the voice interview features (camera, location and payment are disabled).
Backups & recovery
So you never lose your work, JobStraight mirrors your data to a second store in your browser and keeps rolling, restorable snapshots — you can undo a bad edit or recover after an accidental wipe from Settings → Data safety, and export a full backup file anytime. If you enable encryption, those snapshots are stored as ciphertext too. If you connect the optional cloud sync, every sync also writes an append-only version that the server rules make impossible to delete or alter — even by us — so your history can't be erased.
AI features (optional)
If you add your own AI provider key (Anthropic or OpenAI) in Settings, the specific text you choose to process is sent directly from your browser to that provider using your key, governed by their privacy policy. We never see your key or that traffic. Without a key, all AI features run locally with no network calls.
Job listings
The live job feed and job pages fetch public postings from third-party job APIs (Remotive, Arbeitnow, Jobicy, RemoteOK, and Adzuna if you add a key). Following a listing takes you to that source site, governed by its own policy. JobStraight is not the employer.
The optional autofill extension
The JobStraight Chrome extension reads your profile from your browser and fills application forms you open. It never auto-submits and never sends your data anywhere. It only acts when you click it.
Analytics
If enabled, we use privacy-friendly, cookie-less analytics (Plausible) that counts page views in aggregate. It does not track individuals, use cookies, or collect personal data.
Children
JobStraight is intended for job seekers aged 16 and over.
Contact
Questions about this policy? Email info@jobstraight.com.
Changes
We'll update the date above when this policy changes.
Questions? This is an independent, local-first tool. Return to JobStraight.