Privacy Policy
Last updated: June 15, 2026
1. Who we are
Jobby.dev (“Jobby”, “we”, “us”) operates the platform at jobby.dev. We connect job seekers with recruiters via live video interviews. Contact us at hi@jobby.dev.
For GDPR purposes, Jobby is the data controller for personal data collected through the Service. When recruiters use Jobby to process candidate data, Jobby acts as a data processor on the recruiter's behalf — see our Data Processing Agreement.
2. What we collect
- Account data — name, email address, role (job seeker or recruiter), company name.
- Profile data — job title, skills, experience, salary expectations, resume, location.
- Interview data — video session metadata (duration, timestamps). We do not record video unless you are on a Power Play plan with recordings enabled.
- Billing data — Stripe handles payment details. We store only subscription status and usage minutes.
- Usage data — pages visited, actions taken, browser/device type, IP address.
- Consent records — timestamps of your Terms of Service acceptance, marketing email preferences, cookie consent choices, and do-not-sell preferences.
3. Lawful basis for processing (GDPR)
We process personal data under the following lawful bases as defined in GDPR Article 6:
| Purpose | Lawful basis |
|---|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b)) |
| Matching job seekers with recruiters | Contract performance (Art. 6(1)(b)) |
| AI-powered resume/job parsing and scoring | Contract performance (Art. 6(1)(b)) |
| Billing and subscription management | Contract performance (Art. 6(1)(b)) |
| Transactional emails (verification, alerts) | Contract performance (Art. 6(1)(b)) |
| Marketing emails (product updates, tips) | Consent (Art. 6(1)(a)) |
| Analytics cookies | Consent (Art. 6(1)(a)) |
| Live chat support (Intercom) | Consent (Art. 6(1)(a)) |
| Error monitoring and reliability | Legitimate interest (Art. 6(1)(f)) |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance and dispute resolution | Legal obligation (Art. 6(1)(c)) |
4. How we use your data
- To provide and improve the Jobby service.
- To match job seekers with recruiters using AI-powered scoring.
- To parse and extract structured data from resumes and job descriptions using AI models.
- To generate interview report cards, match evaluations, and other AI-assisted features.
- To process billing and prevent fraud.
- To send transactional emails (account verification, password reset, usage alerts).
- To send marketing emails, only if you opted in during signup or in your account settings.
- To monitor errors and improve reliability via third-party services.
- To comply with legal obligations.
We do not currently sell your personal data to third parties. However, we reserve the right to share, license, or sell aggregated, de-identified, or anonymized data that does not personally identify you, for any purpose including commercial purposes, without further notice or compensation. In the event of a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity.
5. Data sharing & third-party services
We share data only with the following third-party service providers, solely to operate and improve the Service:
- Supabase — database hosting and user authentication.
- Daily.co — video interview infrastructure. For Power Play subscribers, Daily.co may process recordings and transcriptions on our behalf.
- Stripe — payment processing. Stripe receives your billing details directly; we never store card numbers.
- Resend — transactional email delivery (e.g. verification, alerts).
- Vercel — hosting and edge network.
- Anthropic (Claude AI) — AI model provider. See Section 6 below for details on what data is sent to AI models.
- Upstash — rate limiting and usage tracking infrastructure.
- Cloudflare — bot protection (Turnstile) during signup.
- Sentry — error monitoring and performance tracking. PII is scrubbed before transmission; only technical metadata is sent.
- Intercom — live chat support (loaded only with your consent).
- Vercel Analytics — anonymous, aggregated usage analytics (loaded only with your consent).
For a complete list of sub-processors including data locations, see our Sub-processors page.
Each provider processes your data under their own privacy policy and data processing agreements. We require all providers to handle your data securely and only for the purposes described above. However, we do not control and cannot guarantee how third-party providers handle your data beyond our contractual agreements. Data transmitted to third-party services is subject to their own privacy practices and security measures. You acknowledge that sharing data with third-party providers carries inherent risks.
We may add, remove, or replace third-party service providers at any time. We will update this policy and our sub-processors list to reflect material changes.
6. AI processing & your content
Jobby uses third-party AI models (currently Anthropic's Claude) to power several features. By using these features you acknowledge and consent to your content being processed by these AI services:
- Resume parsing — your uploaded resume text is sent to the AI model to extract structured profile data (skills, experience, salary expectations).
- Job description parsing — uploaded job descriptions are sent to the AI model to extract structured job data.
- Match scoring — your profile data and job data are sent to the AI model to calculate compatibility scores and match reasons.
- Report cards (Power Play) — interview transcripts may be sent to the AI model to generate post-interview evaluations.
- AI co-pilot (Power Play) — interview context may be sent to the AI model to provide real-time assistance.
What we send: only the specific content needed for each feature (e.g. resume text, job description text, profile fields). We do not send your email address, password, payment details, or unrelated personal data to AI models.
AI provider data use: under our agreement with Anthropic, your data sent via their API is not used to train their models. However, Anthropic may retain inputs temporarily for abuse monitoring and safety purposes per their own policies. We encourage you to review Anthropic's Privacy Policy for full details.
Accuracy disclaimer: AI-generated outputs (including parsed profiles, match scores, report cards, and co-pilot suggestions) are provided for informational and convenience purposes only. They may be inaccurate, incomplete, biased, or misleading. Jobby does not warrant the accuracy or reliability of any AI-generated content. You should not rely on AI outputs as the sole basis for hiring, employment, or any other consequential decisions. Jobby disclaims all liability for losses or damages arising from reliance on AI-generated content.
You may choose not to use AI-powered features (e.g. by manually entering profile data instead of uploading a resume), though some core functionality such as match scoring relies on AI processing.
7. Data retention
We retain data according to the following schedule:
| Data type | Retention period |
|---|---|
| Account and profile data | Until account deletion + 30-day grace period |
| Interview recordings & transcripts | Until recording expiry (set by Daily.co), then automatically purged |
| Landing page analytics events | 90 days, then automatically deleted |
| Profile view records | 90 days, then automatically deleted |
| Read notifications | 90 days, then automatically deleted |
| Billing records | As required by tax/accounting law (typically 7 years) |
| Consent records | Duration of account + legal retention requirements |
You may delete your account at any time from your Privacy Settings. Upon deletion, your personal data is anonymised immediately and permanently purged after a 30-day grace period (in case you change your mind). During the grace period you may contact us to restore your account.
8. Cookies
We use three categories of cookies: necessary (authentication, consent preferences), analytics (anonymous usage data via Vercel Analytics), and support (Intercom live chat). Analytics and support cookies are only loaded with your explicit consent.
We respect the Global Privacy Control (GPC) signal. If your browser sends GPC, optional cookies are disabled by default.
For full details on each cookie, see our Cookie Policy.
9. Your rights
Depending on your jurisdiction, you may have the following rights:
GDPR & UK GDPR rights (EEA/UK residents)
- Access (Art. 15) — request a copy of your personal data.
- Rectification (Art. 16) — correct inaccurate data.
- Erasure (Art. 17) — request deletion of your data (“right to be forgotten”).
- Restriction (Art. 18) — limit how we process your data.
- Portability (Art. 20) — receive your data in a structured, machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interest.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Lodge a complaint — with your local supervisory authority.
Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- Right to know — request what personal information we collect, use, and disclose.
- Right to delete — request deletion of your personal information.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale/sharing — we do not sell your personal information as defined by CCPA. You can exercise this right at any time via your Privacy Settings (“Do Not Sell/Share My Information”).
- Right to non-discrimination — we will not discriminate against you for exercising your CCPA rights.
Categories of personal information collected: identifiers (name, email), professional information (job title, skills, resume), internet activity (usage data, IP address), commercial information (subscription plan, billing status).
Other US state privacy laws
If you reside in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), or other states with consumer privacy laws, you have similar rights to access, delete, correct, and opt out. Contact us at hi@jobby.dev to exercise these rights.
How to exercise your rights
- Self-serve: use your Privacy Settings to export your data, delete your account, manage cookie preferences, opt out of marketing emails, and toggle “Do Not Sell/Share”.
- Email: contact hi@jobby.dev for any privacy request. We will verify your identity and respond within 30 days (GDPR) or 45 days (CCPA).
10. International data transfers
Jobby is based in the United States. If you are located in the EEA, UK, or another jurisdiction with data transfer restrictions, your personal data will be transferred to and processed in the United States.
We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Agreement (IDTA), and other appropriate safeguards to ensure your data is protected in accordance with applicable law. Details of our sub-processors and their locations are available on our Sub-processors page.
11. Children's privacy
Jobby is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at hi@jobby.dev and we will delete it promptly.
12. Security
We implement technical and organisational measures to protect your data, including encryption in transit (TLS 1.2+), encryption at rest (AES-256), row-level security policies, rate limiting, PII scrubbing in error monitoring, and regular security reviews. No system is perfectly secure — we cannot guarantee absolute security.
13. Changes to this policy
We may update this policy from time to time. We will notify registered users by email of any material changes at least 14 days before they take effect. Material changes include new data collection categories, new purposes of processing, changes to sub-processors, or changes to your rights. Continued use of Jobby after the effective date constitutes acceptance of the updated policy.
14. Contact
For any privacy-related questions, data protection inquiries, or to exercise your rights, contact us at hi@jobby.dev.