Privacy
Last updated 2 October 2026
In short: your job search lives in your own Notion workspace and on your own computer. We don't run a database of your data and we don't sell or share anything.
What Job Pilotto stores, and where
- Your Notion workspace (the page you connect): job matches, applications, replies, interviews, insights, your Profile, standard answers and search settings. You can read, edit or delete everything there.
- Your computer: your keys (encrypted by the operating system), your CV and tailored CVs, call recordings, and a cache of job listings. Settings → Your data lets you export or delete them.
- Optional, only if you connect them: Gmail and Calendar (read-only, to track replies and interviews), Telegram (to send you matches), a private GitHub repository (to run while your computer is off), and the AI provider you give a key for (Anthropic), which receives job postings and the parts of your profile needed to score jobs and draft answers.
Technical reports from the app
To fix problems for everyone, the app sends us technical reports, on by default: errors and crashes, jobs that failed (which step, the error line), form fields it couldn't fill (the site, the field's label and type, never your answer), how the form's special controls (Yes/No buttons, custom dropdowns, date fields) behaved, described only by an anonymous structural fingerprint and counts of worked or failed, counts of how the AI answered a form's questions (how many it was sent, answered, left empty or put under a wrong field, and how long it took, per AI engine; never a question or an answer), and once a day the app version, operating system, which features are on, and anonymous counts of how it helped you (jobs matched, forms filled, applications, replies, interviews, offers). Each report carries a random install number, not your name, and the channel the install came from (a label such as "reddit-devops" or "linkedin.com"): set by the install command's tagged link, or, for a download button, asked once at the first start from the download click made on the same network in the 7 days before. For that match the website keeps a salted hash of the network address of a download click for 8 days, then deletes it; never the address itself.
Before anything leaves your computer, the app removes personal data: your answers, CV, cover letters, emails, Notion content, names, email addresses, phone numbers, keys, file paths and the query part of links. We keep reports for 90 days, use them only to improve Job Pilotto and to publish overall numbers (never about one person), and never sell them. Settings → Advanced → Technical reports shows exactly what was sent, and turns them off.
Crash reports and usage steps (Sentry and PostHog)
While Technical reports are on, an installed Job Pilotto also uses two services, with the same rules. Sentry (hosted in the EU) receives crash and error reports: the kind of error, a cleaned-up message, which parts of the app's code it passed through, the app version, your operating system and the random install number. PostHog (hosted in the EU) receives which steps people take, so we can see where setup or applying gets stuck: for example "setup step: CV", "search finished", "kit prepared", "application started", "marked applied", and which page was opened (Jobs, Settings…), never what is on it. Neither service receives your answers, CV, cover letters, emails, jobs, companies, names, keys or file paths, and neither records your screen, keystrokes or IP-based location. Both are off in a copy run from source and when Technical reports is off. A crash report also carries the last few of those step names. Beta testers (who switched the beta on) have one more switch, off until they turn it on: when a search fails or hangs, the last 200 lines of its log are attached to that report, with emails, folder paths, keys, links' query parts and numbers removed first.
This website also tells PostHog (EU) which page was viewed, where the visit came from (for example a search engine) and when the Download button was clicked. It sets no cookie, keeps no id between page views, and discards IP and location.
Shared fixes from our service
Forms differ, so Job Pilotto learns from everyone's failed fills. While Technical reports are on, the app and the Chrome extension ask our website for shared fixes for the special controls on the form in front of you. The request holds only the anonymous structural fingerprints of those controls and your random install number, never the form's text, your answers or your CV. A fix is a small data record (for example which element counts as the "Yes" button); it can only change how one control is filled, never press Submit or tick a consent box, and you still review and click Submit yourself. The form panel tells you when it used one. For Apply with Claude, the app also asks our website for notes about the job board's forms (the board's name only). We limit these requests per install and may block an install that tries to copy the shared data. Settings → Advanced → Technical reports turns reports and shared fixes off together; everything else keeps working.
When you tell Job Pilotto how an application went (a reply, a call or interview, an offer, a rejection, no answer), it is saved in your Notion, and, while Technical reports are on, counted anonymously by job board, the outcome and a rough number of days (for example 8–14) since you applied, to learn which applications get answers. Never the company, the role, the job's address or your answers, and the count is not kept per person.
The same goes for a few more counts about your search, while Technical reports are on: which role words you add to widen it (from a fixed list), how much of the market your role keywords catch, why you dismiss a job if you tap a reason (seniority, location, technology, company, kind of role), and once a day how many of your jobs sit in each fit-score band and what became of them (new, saved, applied, replied ...) and, for each kind of job board, how many you acted on or dismissed. When you mark how an application went, the job's fit-score band is counted with it. When you change by hand an answer that was filled in, only the form's own question wording (for example "Notice period") is counted, never what you wrote. They are grouped by a coarse kind of role and region from fixed lists. Never a job, its title, its company, its link or any text, and they are not kept per person. They help us make the score and the suggestions better for everyone.
Help the pool grow
Job Pilotto downloads a shared list of employer career pages (with a random install number and an access token from our website, a few times a day at most). Every install also helps it grow, on by default (you can turn it off): as each run finds them, the app sends the public career pages and job boards your searches read (company, job-board system and address; how many jobs each listed and matched, and how many of those you saved, applied to or got an interview or offer from, with their language, seniority and remote counts; never the jobs themselves) and labels from fixed lists: your kind of role and role family, your country, region and city area, with a random install number. Never your jobs, applications, CV, answers, emails, Notion content or keys. We check every page ourselves before adding it, take up an employer you added by hand only once at least three people added the same one, publish a label for a page only when several people agree, keep this data for 90 days and never sell it. Settings → Help the pool grow shows the exact message under See what would be sent, and turning it off stops it at once.
Connect with Notion
When you connect Notion, Notion asks you which pages Job Pilotto may use. Our server receives a one-time code from Notion, trades it for your access token and hands that token to the Job Pilotto app on your computer. The token is held for at most 10 minutes, only until your app collects it, then deleted; it is never logged. Job Pilotto only reads and writes the pages you chose. You can remove its access at any time in Notion (Settings → Connections).
Website
If you join the Pro early-access list, we keep the email address (and the role you typed) to write to you about it, and nothing else. Ask us to delete it any time.
The website counts visits and Download clicks without cookies: the page, where you came from (for example google.com), country and device type. Visitors are told apart for one day by a one-way hash, so we never store your IP address. Cloudflare Web Analytics measures page speed and visits the same way, without cookies.
Contact
Questions or deletion requests: open an issue at github.com/GarryOne/job-pilotto.