Privacy Policy
Last updated August 2026.
What this site is
Pipeline is a job-search tool run by a single site owner for their own use and for a small number of people the owner has given access to. There is no open public sign-up - access is invite-only. If you've been invited, you create your own account by signing in with Google or a one-time email link at the address the invite was sent to; the owner controls who's on that invite list and can revoke access at any time.
What's collected
- Job postings you paste, link to, or score from the browser extension, and the analysis generated from them. The posting's text is kept for 30 days if you never save the role, and for as long as the role exists if you do; the score itself stays either way.
- Profile information you provide: work history, résumé content, contact info, and any notes or corrections you add.
- Pipeline entries: roles you save, their status, and generated documents (resumes, cover letters, and - once you've marked a role "Interviewing" and generate it - AI-drafted interview-prep talking points). Optionally, a personal "evidence bank" of interview stories you build and choose to save to your profile.
- Aggregate usage counters for a paid or free account - how many times you've used each metered feature (analyses, salary analyses, tailored resumes, cover letters, interview prep) in the current billing period, plus your purchased AI Credit balance if you've bought any - shown back to you on the Billing page. Counts only, no timestamps or content.
- Separately, the site owner's own internal, owner-only support view can additionally see account-level usage and status detail for real accounts: your email, current plan and purchased credit balance, a rolling 30-day trend of how many times you've used metered features per day, and counts of your saved pipeline entries (by status), résumés, and cover letters, and whether your profile is filled in - never the content of your résumé, job postings, profile details, or generated documents themselves. Used only to help with account support (e.g. troubleshooting a billing issue), never shown to any other account, sold, or shared. From that same view, the owner can also permanently delete an account and everything it owns (profile, pipeline, saved documents, billing state) - this is what backs the data-removal request described below, and cancels any live paid subscription in the process.
- A login session cookie, used only to keep you signed in.
- Feedback you submit through the feedback widget: your message, an optional category and thumbs rating, the page you were on (page path only, never a query string), and - only if you choose to type one in - a reply email address. You can submit feedback without an account; a submission from a signed-in account includes your account name/email, since it isn't anonymous the way a guest submission is.
- If you choose to install the Pipeline browser extension: a separate sign-in token (shown to you once, revocable any time from the Extension page), and, only when you actively use it, the content of whatever page you click "Score this posting" or "Add to pipeline" on - see "The browser extension" below for specifics.
How it's used
Job postings and profile data are sent to Anthropic's Claude API to generate fit analysis, salary breakdowns, resumes/cover letters - job-tailored or, for a general-purpose resume built without a specific job posting, generated from your profile alone - and interview-prep talking points, and only for the purpose of generating your results. If you subscribe to a paid plan or purchase AI Credits, your email address and payment details are sent to Stripe, our payment processor, solely to process that transaction - Stripe never receives your job postings, profile, or generated documents. Magic-link sign-in emails, a short notification when you submit feedback, and an invitation email to someone the app owner has invited, are all sent via Resend, our email provider - only the addresses and content each of those specific emails needs. If you leave a reply email on a feedback submission, you'll also receive a short automated confirmation that it was received, quoting your own message back to you - sent only to the address you typed in, never anywhere else. An invited email address, along with who invited it and when, is retained only until the invite is accepted or revoked by the app owner. Separately, on a schedule, a full backup snapshot - every account's profile, résumé and cover-letter content, and pipeline entries - is emailed as a file to the site owner via Resend, for disaster recovery if the app's primary storage were ever lost. Unlike every other email described here, this one isn't scoped to a single account or a single purpose - it's a full export, so it persists in that mailbox until the owner deletes it. Deleting an account (see above) removes it from the live app immediately, but doesn't retroactively scrub any backup snapshot already sent before the deletion - a copy of a deleted account's data can still exist in an older backup email until the owner separately deletes that email too. When you save a role to your pipeline, we make a best-effort guess at the company's domain from its name, fetch that domain's favicon from Google's public favicon service to show a logo next to the company, and separately check whether{domain}/careers resolves, to link the role directly to the company's careers page when it does (falling back to the plain homepage otherwise) - only the guessed domain name is sent to either lookup, nothing about you. If your profile has a location and the role isn't remote, we also estimate a commute cost: your saved location and the role's location are sent to OpenStreetMap (Nominatim, for geocoding) and to OSRM's public routing service (for driving distance and time) - both free, keyless services with no account tied to the request beyond the location text itself. If a Google Maps API key is configured for this deployment, a small embedded map may also load from Google Maps for that same commute. None of these lookups ever receive your job postings, résumé, or generated documents. Feedback submissions are also periodically reviewed by an automated internal process that posts a summary to our team's private Slack workspace - that summary is a truncated preview (the full message and any reply email are never included), used only to triage recurring issues and ideas. Application errors are captured by Sentry, our error-monitoring provider, and are also periodically reviewed the same automated way for triage - error data is technical (what broke, where) rather than submitted content, though it can occasionally include a fragment of the request that triggered it. Nothing here is sold, shared with advertisers, or used to train models beyond what each provider's own terms govern.
The browser extension
Pipeline offers an optional browser extension, available only to signed-in real accounts via a separate sign-in token you generate and can revoke at any time. It opens as a side panel that stays docked as you browse, rather than a popup that closes each time you click away.
What it does on its own: it reads pages you visit that look like job postings (a known job-board address, or a web address containing something like "/jobs" or "/careers") so it can show you the position, company, and description already filled in. That reading happens entirely inside your own browser - nothing is sent anywhere, and nothing is saved, until you act on it. It does not read pages that don't look like job postings.
This reading now happens whether or not the side panel is open, because the extension also shows a small marker on a page where it recognized a posting - so it has to do the same local check to know whether to show it. On a page it doesn't recognize, nothing is shown and nothing is read beyond that check. The marker is display-only: it sends nothing, and clicking it just opens the panel.
What sends data off your browser: only your own click. "Save to Pipeline" stores the position, company, description, and URL shown in the panel to your pipeline - no AI involved. "Score this posting" sends the description shown in the panel, along with the URL, to Anthropic to generate a fit score, the same way pasting a posting into the app itself works - what gets sent is exactly the text in that box, including any edits you make to it before clicking. On a page the panel couldn't read on its own, "Read this page anyway" sends that page's full HTML for extraction, not just the visible text - and if you clear the description box and score anyway, scoring falls back to sending the full HTML the same way. That is why each of these is a separate, explicit click rather than something that happens automatically. Saving also triggers the same salary-analysis (Anthropic), company-logo (Google favicon), and commute-estimate (OpenStreetMap/OSRM) lookups described above.
Scoring stores as well as sends. The split above is about what leaves your browser, not about what's kept afterwards. A scored posting is recorded to your account's analysis history - the description text that was scored, the URL it came from, and the result - whether or not you go on to save the role to your pipeline. The text is what lets "Full analysis" and "Add to pipeline" re-open that posting without a second AI call or a second credit.
That text is kept for 30 days. After that, a scored posting you never saved has its description dropped, and only the score, the role, the company and the date remain in your history. Save the role to your pipeline and its description is kept for as long as the role is - it's a posting you're actively working. A 30-day-old link to a full analysis will tell you the text is gone rather than reopening it; pasting the posting again re-analyzes it.
Because a job posting's own page often names a recruiter or hiring contact alongside the description, that text can end up in the description saved with the role. Revoking your extension token stops all future extension activity immediately but doesn't delete anything already saved to your pipeline - manage or delete saved entries the same way you would anything else added from the app itself.
Where it's stored
Your data is stored either as files on the server running this app or in a Redis database, depending on how this instance is deployed. It's scoped to your account and isn't visible to other accounts on the same instance, other than the site owner's.
Cookies
A single signed session cookie is used to keep you logged in. There are no analytics, advertising, or tracking cookies on this site. Your browser's local storage is also used for a few functional, non-tracking preferences local to your device - your theme choice, whether the sidebar is collapsed, and one-time flags for onboarding steps you've already seen (so a guided walkthrough doesn't reappear once you've been through it). None of this is sent to us or to anyone else.
Questions or data removal
If you'd like your data removed or have a question about any of this, see the Contact page. A removal request results in your account and everything it owns being permanently deleted from the live app (see "What's collected" above) - the one exception is a backup snapshot already sent before your request, which isn't automatically scrubbed (see "How it's used" above for what that means in practice).