Jobinko

How we handle your data

Privacy

Jobinko exists because a job search a candidate is hiding from their employer deserves to actually be hidden. Everything below is enforced in code, not promised in copy — the file references point at where.

Your résumé

Uploaded, parsed in memory, and deleted the moment parsing finishes. It is never written to storage and never logged. Only the fields you explicitly confirm on the next screen — current title, employer, years of experience, preferred role, skills, city, credential — are saved to your profile.

One thing you can choose to keep. If you use the ATS checker and press “keep this résumé”, the version you built here — the text you saw on screen, not the file you uploaded — is saved to your account so it can be scored against roles we index later. It is listed on your résumé page, you can delete any of it there, and deleting your account deletes all of it. Nothing is saved unless you press that button.

One third party sees the text. To read your skills and industry, which fixed patterns cannot do across arbitrary résumé layouts, we send the extracted text to Groq, the model provider we currently use for this. Your email address, phone number and profile links are stripped out before it leaves our server, and the file itself is never sent — only text. Everything the model returns is shown to you for confirmation before any of it is stored, and you can delete any of it. If we change provider, this sentence changes with it.

What that provider may do with it, taken from their own terms rather than from our summary of them. Groq is not permitted to use inputs or outputs to train or fine-tune any model unless we explicitly grant permission, and we have not. Inference requests are not retained by default, and we have additionally switched on Zero Data Retention on our account, which stops the troubleshooting and abuse-investigation logs that would otherwise be kept for up to 30 days. You keep the intellectual property in anything you send and anything returned.

One thing worth knowing plainly, because it is the part most likely to matter to you: that processing happens on servers in the United States, not in India. If that is not acceptable to you, use “Type it in instead” on the upload screen — nothing is sent anywhere, and the only thing you lose is the pre-filling.

Signing in

We ask for an email address to identify your account, nothing else. Signing in with Google reads only your email address to create or find your account — we never request, store, or display your name or photo from Google, and no other Google data is ever asked for.

What we never do

No employer is ever contacted. Nothing about your search is public or sold. No recruiter can find you here. We never accumulate a résumé corpus — the deletion above isn't a policy, it's the whole design.

A disqualifying role reaching your list is a defect, not a judgement call — every recommendation carries a one-tap “this shouldn't be here,” and reports are triaged as bugs, not feedback.

Who else sees anything

Supabase hosts the database and handles sign-in. PostHog measures product usage with session recording and autocapture both switched off. Sentry reports errors with session replay off and request bodies stripped before they ever reach a report, so résumé text can't end up in a crash log. None of these receive your résumé, and none of them are permitted to sell or share what they do receive.

Your control

Delete your account in one click from your profile, no email required. This removes your account and everything tied to it.

Last updated September 2026.