Skip to main content
GOHUNT

PRIVACY POLICY

Last updated August 30, 2026

PLAIN-ENGLISH SUMMARY

GoHunt helps you discover jobs and submit applications. To do that we store the information you give us (resume content, profile details, login emails for job boards) and use it on your behalf to score postings, tailor resumes, and submit applications. We never sell your data and we don't share it with anyone outside the service providers we need to operate.

1. WHAT WE COLLECT

  • Account information: email address, password (hashed by Supabase Auth), authentication tokens.
  • Profile and resume data: name, phone number, location, country, citizenship, work authorization status, date of birth, gender, education, work history, projects, skills, portfolio links, and any text you enter into our onboarding wizard.
  • Resume files: PDFs/DOCX/TXT you upload, plus generated PDF resumes we produce, stored in private Supabase Storage buckets.
  • Job-portal credentials (only when you connect them): the email address (and, where required by the portal, a password) you use to sign into the job portal. Passwords are encrypted at rest with AES-256-GCM using a key held in our infrastructure secrets manager.
  • Generated application-site accounts: when an application site requires an account, our agent may create one for you using your email address and a generated password. These credentials are stored encrypted and are visible to you in Settings.
  • Profile photo (optional): if you upload one, it is stored privately and attached only to application forms that require a photo.
  • Email-provider access (only if you connect it): read-only access to your inbox, used to (a) automatically detect interview invitations and link them to your application history, and (b) retrieve one-time login codes some portals send during sign-in. We never send mail on your behalf.
  • Application activity: hunts you create, jobs scored, applications submitted, statuses, and per-application screening question answers (so we can reuse them on future applications).
  • Usage data: anonymized page-view analytics via Vercel Analytics. No third-party tracking pixels.

2. HOW WE USE IT

  • To score job postings against your profile (sent to OpenAI for structured scoring), tailor resumes (OpenAI for content adaptation; Typst for PDF rendering), and submit applications via our automated browser agent.
  • To detect interview invitations and follow-up emails in your inbox and surface them on your calendar.
  • To pre-fill known answers to repeated screener questions across applications.
  • To send transactional product emails: password resets, account updates, a notice when a hands-free application is queued (with a cancellation link), and a notice when an application is paused waiting on your answers. No marketing emails.

3. SUB-PROCESSORS — WHO PROCESSES YOUR DATA ON OUR BEHALF

We use a small set of trusted infrastructure providers (sub-processors) to operate the service, each under data processing terms consistent with this policy. Each provider only receives the data they need to perform their specific function:

  • Database, authentication, and file storage provider — holds your account, profile data, and uploaded resumes in private buckets with row-level access controls.
  • Application hosting and edge networking provider — serves the web application and routes requests.
  • Large language model provider — used for resume parsing, resume tailoring, and job scoring. Prompts include your profile and the job description. We do not opt into training-on-prompt programs.
  • Cloud compute provider — runs the browser- automation worker that submits applications on your behalf. Receives a short-lived signed URL to your tailored resume and profile fields scoped to the single application.
  • Email-provider OAuth issuer — only if you connect an email account. OAuth tokens are stored encrypted; read-only scope.
  • Transactional email relay — delivers the product emails described above. Receives your email address and the message content.
  • CAPTCHA-solving service — used only when an application site presents a CAPTCHA during an apply you authorized. Receives the CAPTCHA challenge from the page, not your personal data.

We do not sell, rent, or share your data with advertisers, data brokers, or any party outside the operational role above. A current list of named sub-processors, or a copy of our data processing agreement (DPA) terms, is available on request to agenticgenie@gmail.com.

4. DATA RETENTION AND DELETION

Your data is retained while your account is active. You can delete individual resumes, applications, hunts, and stories from the app at any time.

To delete everything, use Settings → Delete account. This is self-serve and takes effect immediately — there is no request to submit and no waiting period. It removes your account and every record attached to it: profile and career tracks, uploaded resumes and generated documents, applications and hunts, saved application answers, stored credentials, and synced email metadata. Files in storage are deleted alongside the database records rather than left behind.

If you have connected Gmail, we also revoke GoHunt’s access token with Google as part of the deletion, so the grant does not outlive the account.

Deletion is permanent and cannot be reversed. Job listings themselves are not personal data and remain in our shared listings pool; they contain nothing about you. We may retain a minimal record where the law requires it, such as evidence of OAuth disclosures.

5. YOUR RIGHTS

If you are in the EEA, UK, or California, you have the right to access, correct, export, or delete your personal data. Deletion you can exercise yourself at any time via Settings → Delete account; for access, correction or export, contact agenticgenie@gmail.com and we will fulfill the request within applicable legal timeframes. We rely on your consent for OAuth integrations and on legitimate interest for the operational data needed to run your account.

6. SECURITY

We store secrets (Naukri passwords, OAuth tokens) encrypted at rest. Service-to-service calls between our app and the application agent are signed with HMAC-SHA256 and verified with constant-time comparison. Database access is enforced by Supabase row-level security policies. No security model is perfect — if you discover a vulnerability, email agenticgenie@gmail.com and we will respond.

7. CHILDREN

GoHunt is not intended for users under 16. We do not knowingly collect data from anyone under 16.

8. CHANGES

We will update this page when material changes happen. The "Last updated" date at the top reflects the latest revision. Continued use after a change constitutes acceptance.

9. CONTACT

Questions or requests: agenticgenie@gmail.com.