JobCraftsMan is an AI job-search tool I build and run myself. Your CV, cover letters, and interview answers are personal — often sensitive — so this page explains exactly what JobCraftsMan collects, how it's used, and what control you have. It's written to be readable in a few minutes, not to satisfy a lawyer.
1. Who runs JobCraftsMan
JobCraftsMan is operated by Gökhan Arlı, an independent developer. The best way to reach me is the contact page — I read every message.
There is no shared database with any other product. Anything you share with JobCraftsMan stays with the service.
2. What data JobCraftsMan collects
When you sign up
- Email address — used to log you in and send transactional email (verification, password reset).
- Name — displayed in the UI; you can change it anytime.
- Password — stored as a one-way bcrypt hash. I cannot see your password and cannot recover it.
When you use JobCraftsMan
- Your profile — the experience, education, skills, and target role you enter to feed the tools.
- Your content — the CVs and cover letters you build, the job descriptions you paste, and your interview answers and feedback. Saved so you can come back to them.
- Subscription state — which tier you're on and your credit balance. Payment details (card last-4, billing country) are held by Stripe — never by JobCraftsMan.
Automatically
- Server logs — IP address, user agent, request paths, and response codes. Retained a short period for debugging and abuse prevention.
- Authentication session — when you log in, an auth token is stored in your browser so you don't have to sign in on every visit.
3. What JobCraftsMan does not collect
- No tracking cookies. No Google Analytics. No advertising pixels.
- No advertising IDs. JobCraftsMan doesn't run ads.
- No location data beyond the rough geographic implication of your IP address.
- No microphone, camera, or contact-list access.
4. How your data is used
- To provide the service: log you in, build CVs and cover letters, run interviews and feedback, and score your CV against a job description.
- To send transactional email (verification, password reset, security and billing notices). You can opt out of product emails in settings; transactional email is required for the account to function.
- To enforce credit limits and prevent abuse (rate limiting, fraud detection).
- To debug errors and improve the product. Errors are sent to a monitoring service without your personal content attached.
Your profile, CVs, cover letters, and interview data are never sold, rented, or shared with advertisers, and they are never used to train AI models — yours or anyone else's.
5. Third-party services JobCraftsMan uses
JobCraftsMan is built on a small set of trusted vendors (sub-processors). Each receives only the minimum data needed to do its job.
- Anthropic — provides the AI (Claude) that writes interview questions and feedback, cover letters, and CV suggestions. Receives the profile, CV, cover-letter, or job-description content needed for the request you make. Under Anthropic's Commercial Terms, API inputs and outputs are not used to train models.
- Stripe — processes payments for the Eager plan. Receives only the payment details you enter directly into Stripe's form. JobCraftsMan never sees your card number.
- Cloud hosting — reputable infrastructure providers host the application, database, and stored documents. Data at rest is encrypted.
- Email delivery — a transactional email provider sends account email (verification, password reset, billing). It receives your email address and the message contents.
- Error monitoring — captures error reports with sensitive parameters (passwords, tokens) scrubbed, tagged with an anonymized user ID rather than your name or email.
6. Your rights
Under GDPR (and similar laws in the UK, California, and elsewhere) you have the right to:
- Access a copy of your data — use the Export button in Settings, or ask via the contact page.
- Correct your name, profile, and preferences — directly in the app.
- Delete your account and all associated data — use the Delete account button in Settings, or ask via the contact page.
- Object to specific uses of your data — ask via the contact page; I'll resolve within 30 days.
- Lodge a complaint with your local data protection authority if I haven't responded to a reasonable request.
When you delete your account, your data is soft-deleted immediately (no longer accessible to you or anyone else) and permanently purged within 30 days.
7. How long data is kept
- Account, profile, and content — until you delete them or your account.
- Server logs — a short retention window for debugging and abuse prevention.
- Soft-deleted accounts — purged within 30 days.
- Backups — rotated within 30 days, so a deletion fully propagates within that window.
8. Security
JobCraftsMan uses standard production practices: HTTPS-only (TLS 1.2+), passwords hashed with bcrypt, scoped auth tokens, security-header and content-security policies, and a rate limiter against brute-force and abuse. Stored data is encrypted at rest.
That said, no service is unhackable. If a breach affects your data, I'll notify you by email without undue delay after discovery.
9. Age
JobCraftsMan is intended for adults entering or moving through the workforce. It is not directed at children under 16. If you believe a child under 16 has created an account, contact me and I'll delete it.
10. Changes to this policy
If I make material changes, I'll update the "Last updated" date at the top and email everyone with an active account. Trivial fixes (typos, broken links) won't trigger a notification.
11. Contact
Questions, deletion requests, or anything else — reach me through the contact page. I read every message personally.