Last updated 30 September 2026
Privacy Policy
We collect only what's needed to run your job search, protect it, and never sell it or use it to train AI. This page says what we keep, why, who helps us run Jobcreo, how long we keep it and what you can ask of us.
1. Who we are
Jobcreo is run by Laud Zion Cascalla, a Software, Cloud & Automations Engineer based in the United Arab Emirates. He decides how your personal data is used (the “controller”). “We” and “us” on this page mean him, running Jobcreo.
Questions or requests about your data: support@jobcreo.com, or the Contact page.
2. What we collect
- Your account: your name, email address and password (stored only as a secure hash by our sign-in provider), and your profile picture if you sign in with Google. If you turn on two-factor sign-in, the authenticator it uses.
- Your job search: the applications, companies, interviews, contacts, notes and skills you add, the jobs you save, and your answers to the welcome questions (the roles and places you’re looking for).
- Your CV: the text of a CV you upload, kept as your original, plus any versions you tailor to a job, so you can edit and download them. The uploaded file itself isn’t kept.
- Job searches: what you search for in Find jobs and what it found.
- AI answers about a job: the latest scam check, skill gaps, interview prep and follow-up draft for each application, kept with it so they’re there next time.
- Interview practice: your answers are sent to our AI provider to be scored during the session. When you answer out loud, the audio is turned into text and is not kept.
- Payments and credits: the credit packs you buy (the pack, price, currency, date and Stripe’s receipt link), your credits and what used them, and your customer and payment IDs from Stripe. We never see or store your card number.
- Student discount: the school email you verify and when it was verified.
- Google Calendar: if you connect it, the access tokens needed to add and update your interviews, stored encrypted.
- Messages to us: what you send through Help & support, Rate Jobcreo, the coach’s thumbs up or down, or the Contact page (your name, email, what best describes you, such as a freelancer or an employer, and your message). A support request also includes the page you were on, your credits left and your device type, to help us fix problems.
- Security and activity records: when you sign in and were last active, your IP address and browser for sign-ins and security events (password or two-factor changes, account closure), and the credits you’ve spent each day.
We don’t use advertising or analytics trackers. See the Cookie Policy for the few cookies Jobcreo needs to work.
3. Why we use it
- To run Jobcreo for you (our agreement with you): your board, job searches, coaching, CV tailoring, calendar sync and reminder emails.
- To take payments and prevent abuse (our agreement with you, and our legitimate interest in stopping people making extra accounts for more free credits).
- To keep Jobcreo and your account secure (legitimate interest, and legal obligations): rate limits, bot checks on public forms, the security log, and spotting suspicious activity.
- To answer you and improve Jobcreo (legitimate interest): support requests, feedback and contact messages.
- To send emails you asked for: sign-in and security emails, receipts, interview reminders and, if you turn it on, the daily jobs email. You can turn reminders and the jobs email off in Settings.
We never sell your data, never show you ads, and never use what you write to train AI models.
4. Who helps us run Jobcreo
These companies process data for us, only to provide their part of Jobcreo and under their own security and privacy commitments. Each gets only what its job needs.
- Supabase: our database and sign-in. Stores your account and workspace.
- Vercel: hosts the website and app.
- OpenAI: the AI features (reading job posts, scam checks, coaching, CV tailoring, skill gaps), the coach’s standard voice and turning your spoken answers into text. Receives the text each request needs, such as a job post or your CV.
- ElevenLabs: the coach’s premium voice, for practice sessions that use it. Receives the text the coach says.
- SerpApi (Google Jobs) and public job boards: job searches. Receive the job titles and places you search for, never your name or email.
- Mapbox (or Photon, by OpenStreetMap): suggests places as you type a location.
- Stripe: payments. Handles your card details directly; Jobcreo never sees them.
- Google: sign in with Google, and Google Calendar if you connect it.
- Resend: sends Jobcreo’s emails. Zoho Mail hosts our support inbox.
- Upstash: counts requests for rate limits (keyed by IP address or account, kept briefly).
- Cloudflare Turnstile: checks that a person, not a bot, is filling in public forms such as sign-up and Contact.
We may also share data if the law requires it, or to protect Jobcreo’s users or the public from fraud or harm. If Jobcreo is ever transferred to a business (for example once it’s registered as a company), your data moves with it under this policy, and we’ll tell you first.
5. Where your data is processed
These services run on servers in several countries, including the United States and the European Union, so your data may be processed outside the country you live in. We only use providers that protect it with encryption and contractual safeguards, as the UAE, Philippine and EU privacy laws require.
6. How we protect it
- Everything is encrypted in transit (HTTPS) and at rest.
- Each account's data is kept apart in the database itself (row-level security), so no other account can read it.
- Calendar tokens are encrypted again before they're stored, with a key only our servers hold.
- Two-factor sign-in with an authenticator app, which you can turn on in Settings → Security.
- Jobcreo has one administrator account, protected by two-factor sign-in. It can see account details and usage, and can update your name, email or password when you ask, or suspend an account that breaks the terms. Sensitive admin actions need a fresh two-factor code, and every admin action is recorded.
7. How long we keep it
- Your account and workspace: while your account is open.
- Job searches and their results: 30 days (jobs you save stay until you remove them).
- Closing your account (Settings → Security) deletes your account, profile and workspace straight away. Any credits left are lost, and Jobcreo shows how many before you confirm.
- After an account is closed we keep only: a short record that it was closed (the email address, the date and a reason if you gave one); support requests and feedback, no longer linked to your account; and security records for up to 12 months.
- Messages from the Contact page: until we've dealt with them, and deleted on request.
- Payment records: Stripe keeps its own records of payments for as long as financial laws require.
8. Your rights
Depending on where you live, including under the EU and UK GDPR, the UAE’s Personal Data Protection Law and the Philippines’ Data Privacy Act, you can ask us to:
- show you the personal data we hold about you, and give you a copy;
- correct anything that's wrong (most of it you can edit yourself in Settings);
- delete it (you can close your account yourself at any time);
- limit or object to how we use it, or withdraw a consent you gave;
- send your data to you in a common format, to take elsewhere.
Email support@jobcreo.com and we’ll answer within 30 days. If you’re not happy with our answer, you can complain to your data protection regulator, such as the UAE Data Office, the Philippines’ National Privacy Commission or the authority in your EU country.
9. Age
Jobcreo is for people aged 18 or over. We don’t knowingly collect data from anyone younger; if you think we have, tell us and we’ll delete it.
10. Changes to this policy
When we change this policy we update the date at the top. If a change affects how we use your data in a significant way, we tell you in the app or by email before it takes effect.
11. Contact
Laud Zion Cascalla, running Jobcreo: support@jobcreo.com.
