Privacy Policy
Last updated: September 10, 2026
This Privacy Policy explains what information Job Umbrella (“we”, “us”) collects when you use the app at jobumbrella.com, how we use it, and the choices you have. By using Job Umbrella you agree to this policy.
Information we collect
- Account information — your email address, optional name, and a securely hashed password (or Google sign-in identifier).
- Profile and career data — the work history, education, skills, target job titles, and resumes you enter, upload, or generate.
- Resume reviews before sign-up — if you use the free resume review without an account, the text we extract from your resume and the review itself are stored encrypted for up to 7 days so they can be attached to an account you create, then deleted. The uploaded file itself is not kept. A hashed form of your IP address is stored for the same period to limit abuse.
- Job-search activity — the applications you track (company, role, status, notes, dates, contacts) and how they move through your Board.
- Usage data — a daily count of AI generations for rate limits, and basic technical data needed to run the service.
- Cookies — a sign-in session cookie that keeps you logged in. Once ads start, Google also sets third-party advertising cookies and identifiers (see “Advertising and cookies” below, which says when that begins and where those run).
How we use your information
- To provide and operate the application and your account.
- To power AI features (resume building, resume tailoring, and job-title suggestions) — see “AI processing” below.
- To email you about your job search — new job matches, a weekly summary, and a notice if we pause matching because you haven’t been back in a while. Every such email has a one-click unsubscribe link, and you can turn them off in Settings. Account and security emails (verification, password changes) are sent regardless.
- To secure the service, prevent abuse, and comply with the law.
- To display ads on the free tier once ads start — see “Advertising and cookies” below.
We do not sell your personal information for money. Some US state privacy laws define “sale” or “sharing” broadly to include the use of advertising cookies for personalized ads. See “Advertising and cookies” for your choices.
AI processing
When you use an AI feature, the relevant profile or resume text is sent to an AI provider to generate a result. By default this is Google’s Gemini API; if you add your own API key (“bring your own key”), your text is sent to the provider you choose instead. These providers process your text under their own terms and privacy policies. Any API key you provide is stored encrypted at rest.
Sharing with a case manager or career coach
If you are working with a career case manager, coach, or advisor— for example through a workforce-development, outplacement, or coaching program — you may authorize Job Umbrella to share your job-search history with that designated person or organization. This may include your profile, tracked applications and their statuses, target titles, and overall progress.
- This sharing happens only at your direction and with your consent.
- You choose who the case manager or coach is, and you can revoke access at any time from your account settings.
- We share only the job-search data needed for coaching — not your password or any stored API keys.
Browser extension
The Job Umbrella browser extension (“One-click Job Capture”) reads the job posting on the page you’re viewing — title, company, location, salary, and description — only when you click the extension button. It also stores your Job Umbrella app URL and access token locally in your browser, obtained through the extension’s one-click “Sign in to connect” flow.
- What’s sent, and where — the captured job details and your access token are sent only to the Job Umbrella app URL you’ve configured (by default, jobumbrella.com), to save the job to your own account. Nothing is sent to any other third party.
- Permissions — the extension uses
activeTabandscriptingto read the page only after you click the button,storageto remember your app URL and token on your device, andidentitysolely to complete the sign-in flow and receive your access token back. It requests no broad host permissions and includes no analytics, ads, or remote code. - It does not collect your browsing history, other tabs, or data from any site you haven’t chosen to capture from.
Other sharing
Aside from the coaching carve-out above, we share personal data only with service providers that help us run Job Umbrella (hosting and database, AI processing, email, and advertising), and only as needed to operate the service — or when required by law. Links to external job sites (from Find Jobs and the browser extension) take you to those sites, which have their own privacy practices.
Advertising and cookies
Current status: ads are not running yet. No advertising cookie is set, no consent message appears, and no advertising or consent script loads on any page. We plan to show ads on the free tier to keep the core service free. The rest of this section describes what happens once ads start, and we will update this status line on the day they do.
Where ads appear. Once ads start, they appear only for signed-in users on the free plan. There are three placements: your Board, your Applications list, and Find Jobs. No ad appears on the public site, and none appears for a signed-out visitor. A paid plan removes ads.
Where the advertising code runs. This is broader than where ads appear, and we want to be plain about it. Once ads start, the Google advertising and consent scripts load on every page of Job Umbrella. That includes pages that never display an ad, and pages you visit before you sign in. Google can therefore set and read cookies, and receive your IP address, on any page, not only on the three that show an ad.
We use Google AdSense, a third-party advertising service. To serve ads, Google and its partners may set and read cookies and similar identifiers on your device. They may collect information such as your IP address, your device and browser details, and how you interact with ads. Google may use this information to show you personalized (interest-based) ads.
You can learn how Google uses information from sites that use its services, and control the ads you see, at policies.google.com/technologies/ads and myadcenter.google.com.
Your consent choices. Where required — for example, for visitors in the European Economic Area and the United Kingdom — we present a consent message before any personalized ad is served, and you can accept, decline, or manage your choices. Declining does not remove ads entirely. You may still see non-personalized ads.
US state privacy rights. As noted above, we do not sell your personal information for money, but some US state laws (such as the California Consumer Privacy Act) treat the use of advertising cookies for personalized ads as a “sale” or “share.” You can opt out through the “Do Not Sell or Share My Personal Information” control we make available, or by declining in the consent message.
What advertisers never receive. We do not share your resume content, the specifics of your job applications, your target job titles, your notes, or any API key with advertisers. We do not use any of it to target an ad. The advertising code sees standard web data, described above. It does not see your career data.
Data retention and your rights
- We keep your data while your account is active.
- You can access and edit your data in the app, export your applications as CSV, and deleteyour account, which removes your associated data from our database.
- Depending on where you live, you may have additional rights (access, correction, deletion, portability). Contact us to exercise them.
Security
We use encryption in transit, store passwords as salted hashes, and encrypt any API keys you provide. No system is perfectly secure, but we work to protect your information.
Children
Job Umbrella is not directed to children under 16, and we do not knowingly collect their data.
Changes and contact
We may update this policy; we’ll revise the “last updated” date above. Questions or requests: [email protected].