Privacy
Last updated 31 August 2026
Just So applies for jobs on your behalf. To do that it holds a lot of what makes you you: your CV, your history, the way you write, and an application record under your own name. This page says exactly what is held, what is done with it, and who else ever sees it.
The service is run privately by its owner and is at pilot stage, used by a small number of testers. If anything below is unclear, write to [email protected].
What is held
Your account. Your email address, a hash of your password (never the password itself), and when you signed in. If you sign in with Google we receive your Google account identifier, your email address and your name from Google, and nothing else. The sign-in asks for openid email profile and no Gmail scope, so signing in with Google gives this service no access to your mail.
What you give it to apply with. The documents you upload (a CV, a LinkedIn export, diplomas, references, a personality test, anything else) and the details you fill in: your name, pronouns, date of birth, address, email address and phone number, and, only where you choose to answer them, the equal-opportunity questions employers ask (gender, ethnicity, disability status, veteran status). The answers you give on your profile are held with them. This is the material every CV and cover letter is written from, and it is the most personal thing here.
What the service produces for you. The positions found, the fit assessment of each, the CV and cover letter written for each one, and the record of each application: which position, when it was attempted, and what happened.
Your mailbox connection, if you make one. It is optional and can be skipped. What is stored is the credential itself, a Gmail app password or an OAuth refresh token for a connection made that way, encrypted with the key held outside the database.
Portal accounts. Where you turn the permission on, accounts created in your name on job portals, and the passwords issued for them. The password is kept rather than discarded so that you are not locked out of an account created on your behalf.
What your browser reports about your device. Timezone, languages, screen size, processor count and the platform your browser names, read when you sign in. The browser that fills in employer forms for you presents your own timezone and language rather than the server's, which is the only thing this is used for.
Operational records. Diagnostic events about runs and requests, and one row for every application attempt.
What your mail is read for
The mailbox connection is read-only, and that is enforced in code twice over: the mailbox is opened with IMAP's EXAMINE rather than SELECT, and every fetch is a BODY.PEEK. Nothing can be sent, deleted, moved, marked as read or changed in any way.
It is read for three things and no others:
- a verification code or a sign-in link a portal mails in the middle of an application, so the application can carry on instead of stopping;
- a reply from the employer after an application, so you can be told whether it arrived;
- at the moment you connect, proving the mailbox can actually be read before the credential is stored.
Your mailbox is not searched generally. Every read is bounded to sender domains derived from the job being applied to and to a time window around the application, and a message is only opened at all if Gmail's own authentication result says it genuinely came from the sender it claims. A verification code and a sign-in link are never written into any record. What was asked for, and which senders were refused, is logged, never the answer.
Your AI subscription
Your profile and your documents are written by your own Claude or ChatGPT subscription rather than by an account of ours. You sign in to that provider through the provider's own flow, and the credential stays in a directory that provider's own program owns. It is never collected, read, stored or passed on by this service; what is kept is the label and plan the provider itself reports, so your Profile tab can show you which subscription is connected.
Your profile material and the job postings are sent to that provider as part of every run, and what they do with it is governed by their terms and their privacy policy rather than by this one.
Applying on your behalf
When you press Apply, a browser opens, fills in the employer's form from your profile, attaches the CV and cover letter you approved, and submits the application under your name. The employer receives what any applicant would send them, and what happens after that is between you and the employer.
Nothing is submitted until you press Apply, unless you turn on Auto apply, which applies as soon as the documents are generated. It is off until you turn it on.
Cookies
A session cookie, set when you sign in, so that pages know it is you. Beside it a second cookie holding no secret, which lets the sign-in page tell a browser stuck on an old cookie apart from a first-time visitor. There is no analytics, no advertising and no third-party tracking of any kind on this site.
Who else sees any of it
None of it is sold, rented, or shared for advertising, profiling or any other purpose. There is no analytics provider, no ad network and no data broker in this service.
Four things outside this server receive anything at all, and only these:
- the employer you applied to, and the job portal in between, receiving your application;
- your own AI provider, Anthropic or OpenAI, receiving your profile material and the job postings, through your own subscription;
- Google, if you connect a Gmail mailbox or sign in with Google;
- Cloudflare Email Service, which sends the verification and password-reset mails and so receives your address and the text of that mail.
The service runs on hardware its owner operates.
How long it is kept
Your account, profile, documents and applications are kept until you ask for them to go. Diagnostic events are deleted after ninety days, and the working files a run leaves behind after thirty.
The record of which positions have been applied to is kept. Whether a position has already been applied to is the question this whole service is built around, and losing that record risks applying twice to one employer under your name.
What you can decide
- The mailbox connection is optional, skippable, and can be disconnected.
- Creating portal accounts is a permission that is off until you turn it on.
- Auto apply is off until you turn it on.
- To get a copy of what is held about you, to correct it, or to have your account and everything in it deleted, write to [email protected]. There is no self-serve delete yet, so it is done by hand, and you will get an answer.
Security, honestly
Passwords are stored hashed. Mailbox credentials are stored encrypted with a key held outside the database. Each account's files live in a directory of their own, and a run is given access to that one directory rather than to the server.
No service is perfectly secure, and this one is a pilot run by one person rather than a company with a security team. That is worth holding in mind when deciding what to upload.
Changes
If any of this changes in a way that matters, the page will say so and the date at the top will move. Continuing to use the service after that is how the change is accepted.
Getting in touch
[email protected], for anything on this page or anything not on it.