Overview
Jobilly.ai (“Jobilly,” “we,” “us”) is an AI-powered career acceleration platform built for fresh graduates and postgraduate students. Our platform connects candidates with mentors, learning content, mock interviews, and managed job application support through a single integrated experience.
Because Jobilly handles resumes, career profiles, interview responses, application history, and in some cases sensitive employment-related information, we treat privacy as a core product requirement rather than a legal afterthought. This Privacy Policy describes, in detail, the categories of personal data we process, the purposes for which we use that data, the systems that store it, how access is restricted by role, and the rights available to you.
This policy applies to our public marketing website, candidate dashboard, employee and admin tools, institution portals, transactional emails, and any related services that link to this page.
Who this policy applies to
Jobilly serves four primary user types, and the data we collect depends on which experience you use. Free candidates register to access career advisory and free learning content; subscribed candidates additionally use mock interviews and our Job Application Service. Institution candidates access advisory, learning, and interviews through a partner university or employer subscription. Jobilly employees, mentors, managers, and admins access internal tools to support candidates, review applications, and operate the platform.
If you interact with Jobilly only as a website visitor without creating an account, we still collect limited technical data such as browser information and pages viewed, as described below. If you are an institution administrator, we also process data needed to manage your organization’s subscription, roster, and reporting.
Account and identity data
When you create an account, we collect your email address, name (including first and last name where provided), and authentication credentials. You may sign up with email and password or through OAuth providers such as Google. Supabase Auth manages authentication on our behalf and issues secure session tokens used to keep you signed in.
We assign each user an internal user identifier and, where applicable, a member ID used across the platform. For employees and admins, we may enable multi-factor authentication and record whether MFA is enabled on the account. We store your account role (for example free candidate, subscribed candidate, employee, admin, manager, institution admin, or institution candidate), which determines which features and data you can access.
We record when your account was created and may log sign-in events, password reset requests, and security-related account changes. We do not store your raw password in readable form; credentials are handled by our authentication provider using industry-standard hashing and security practices.
Profile and career data
Your candidate profile holds the career information you provide and that we use to personalize services. This may include education level, graduation college, graduation year, specialization or branch, skills, technology interests, career goals, desired job search role, years of experience, work experience descriptions, gender where you choose to provide it, LinkedIn profile URL, and resume files uploaded to Supabase Storage.
Resume files are stored in encrypted object storage and linked to your profile by URL. When you use our Job Application Service, mentors and assigned recruiters may use your resume and profile data to tailor applications, draft cover letters, and match you with relevant roles. Your profile also records subscription status, the Jobilly employee assigned to support you (if any), and timestamps showing when profile information was last updated.
If you complete a career advisory intake form, we collect additional details such as phone number (including country code), preferred technologies, career path interests, and any other fields you submit through that workflow. This information helps mentors prepare for advisory sessions and recommend learning paths.
Career advisory and Growth School data
When you book or attend a career advisory session, we store session metadata including scheduled date and time, assigned mentor, session status, meeting link, mentor notes, and any recommended learning path linked to the session. Calendar integrations may receive enough information to schedule the meeting, such as your name, email, and session time.
Growth School collects learning progress data as you move through paths, modules, and lessons. We record which lessons you have started or completed, watch percentage for video lessons, quiz attempts including your answers and scores, pass or fail outcomes, and sandbox coding challenge submissions including the code you write and automated test results. Quiz and lesson content may use vector embeddings stored in our database to power similarity search and personalized evaluation, but these embeddings are derived from content and questions rather than raw personal identifiers.
We cache AI-generated lesson videos and scripts so that content can be served efficiently to many users. Your individual progress records are tied to your user account and are not shared with other candidates except in aggregated institution reporting where applicable.
Mock interview and voice data
Mock interviews may use voice or text interaction with AI-powered interviewers configured with company-specific personas. Before any voice-based session, we present an explicit consent screen explaining that the session involves voice processing and describing what we retain.
We do not store raw voice recordings by default. During a live session, audio may be streamed to speech-to-text and text-to-speech providers for real-time transcription and interviewer responses, but those streams are processed for the session rather than archived as audio files. After the session, we may store the interview transcript, structured scorecard, company and role context, round type, and AI-generated feedback to help you review performance and track improvement over time.
You may also submit post-interview feedback describing real questions you encountered elsewhere, difficulty, and outcome notes. This feedback helps enrich our interview question database and improve future sessions. You can request deletion of interview transcripts associated with your account, subject to legal and operational retention limits described below.
Job Application Service data
Subscribed candidates using the Job Application Service provide data used to search for roles and submit applications on their behalf. This includes your active subscription plan, start and end dates, assigned recruiter, subscription status, and a separate application profile containing job search preferences such as preferred locations, salary expectations, and remote work preference.
Certain application profile fields are considered sensitive because they may relate to visa status, disability, or similar employment-related attributes. These fields are encrypted before being written to the database and are visible only to the recruiter assigned to your account, not to other candidates or unauthorized staff. Every access to sensitive application data by Jobilly employees is intended to be logged in our audit system.
For each job we apply to on your behalf, we store the company name, role title, job posting URL, application date, current status (such as queued, applied, interviewing, rejected, or offered), tailored resume file URL, and cover letter text. Employees may also run job discovery workflows that store scraped job listings linked to your account, including job description text and relevance scores, along with records of which listings were selected for application.
Recruiter messages between you and your assigned Jobilly employee are stored with sender role, message content, and timestamp so that application support remains documented and auditable.
Institution and partner data
Partner universities and employers may subscribe to Jobilly for cohorts of students or employees. Institution records include organization name, branding assets such as logo URL and primary color, subdomain configuration, subscription plan, and designated institution admin users.
When you join through an institution, we link your user account to that institution and record enrollment date. Institution administrators may view progress and usage reports for candidates in their program, such as lesson completion, interview activity, and advisory participation, as authorized by the institution agreement. Institution admins do not receive access to sensitive application profile fields unless explicitly permitted by product configuration and law.
Payment and billing data
Individual subscriptions and institution billing are processed through Stripe. When you subscribe, Stripe collects payment card details and billing address directly; Jobilly receives subscription identifiers, payment status, plan type, and billing period information needed to activate and maintain your access. We do not store full payment card numbers on our servers.
We retain records of your subscription history, invoices where applicable, and correspondence related to billing disputes or refunds for as long as needed for accounting, tax, and legal compliance.
Usage, device, and analytics data
When you use Jobilly, we automatically collect technical and usage information to operate, secure, and improve the platform. This includes pages and features accessed, clicks and navigation paths, approximate geographic location derived from IP address, browser type and version, device type, operating system, referral source, and timestamps of activity.
We use privacy-conscious product analytics (such as PostHog) to understand funnels like free-to-paid conversion, lesson completion rates, and interview completion rates. Analytics are configured to minimize unnecessary personal identification and to support product decisions rather than third-party advertising profiles.
Server logs, error reports, and performance metrics may include request URLs, response times, error stack traces, and anonymized or pseudonymous identifiers tied to your session. Error monitoring tools such as Sentry help us detect and fix bugs quickly. Structured logs in systems like Axiom or Better Stack support security investigations and operational troubleshooting.
Communications and support data
If you contact us through our contact form, support email, or in-product messaging, we retain the content of your message along with your name, email, phone number if provided, and any attachments needed to resolve your request. Transactional emails sent through providers such as Resend include delivery metadata and may record open or click events where enabled.
We send service-related emails such as account verification, password reset, session invitations, application status updates, and security alerts. You cannot opt out of essential transactional messages while maintaining an active account, but you may opt out of non-essential marketing communications where offered.
How we use your information
We use account and identity data to authenticate you, enforce role-based access across candidate, employee, admin, and institution experiences, and protect accounts from unauthorized access. Profile and career data power personalization including job recommendations, learning path suggestions, resume tailoring, and mentor preparation for advisory sessions.
Learning and interview data enable us to track your progress, generate feedback, improve question banks, and measure whether our content helps candidates prepare for real hiring processes. Job Application Service data is used exclusively to discover relevant roles, prepare application materials, submit applications with your authorization, and communicate status updates between you and your assigned recruiter.
Usage and analytics data help us understand which features deliver value, detect abuse or automated scraping, maintain rate limits, diagnose latency issues (especially for voice interviews where we target sub-two-second response times), and plan infrastructure capacity. We also process data where necessary to comply with applicable law, respond to valid legal requests, enforce our Terms of Service, and protect the safety and rights of Jobilly, our users, and the public.
AI and automated processing
Jobilly uses artificial intelligence throughout the platform. Large language models such as Anthropic Claude may generate learning content, evaluate quiz answers, produce interview feedback, tailor resumes and cover letters, and score job relevance. Embedding models convert text into vector representations stored in PostgreSQL with pgvector to power retrieval-augmented generation for lessons, quizzes, and interview questions.
Voice interviews may invoke streaming speech-to-text (such as Deepgram), streaming text-to-speech (such as ElevenLabs), and real-time audio transport (such as WebRTC via Daily.co). Video lessons may be generated through services such as HeyGen and cached for reuse. Code sandbox challenges may execute in isolated environments such as Judge0 on separate worker infrastructure so that candidate code never runs on the main application server.
Automated processing may produce scores, rankings, or suggestions that influence what jobs, lessons, or interview questions you see. These outputs are assistive rather than determinative — mentors and recruiters review important decisions, and you should verify AI-generated content before relying on it for employment or legal decisions. You may contact us to learn more about how automated processing affects your account.
Legal bases for processing
Where the General Data Protection Regulation (GDPR) or similar laws apply, we process personal data on one or more of the following bases. We process data necessary to perform our contract with you — for example, operating your account, delivering subscribed services, and submitting job applications you authorize. We process data based on legitimate interests where those interests are not overridden by your rights, including platform security, fraud prevention, product improvement, and internal reporting.
We rely on consent where required by law, such as before voice-based mock interviews or certain optional marketing communications. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. We also process data when necessary to comply with legal obligations, such as tax record retention or responses to lawful government requests.
How we share information
Jobilly does not sell your personal information to data brokers or advertisers. We share data only with service providers that help us deliver the platform, under contracts that require confidentiality and appropriate security measures.
Infrastructure providers include Supabase (managed PostgreSQL database, authentication, and file storage), Vercel (frontend hosting), Railway or Fly.io (background workers for scraping, interview processing, and video callbacks), Cloudflare (CDN, WAF, and bot protection), and Upstash Redis (caching and rate limiting). AI and media providers include Anthropic, OpenAI (embeddings), Deepgram, ElevenLabs, Daily.co, HeyGen, and Apify (employee-triggered job scraping). Operational tools include Stripe (payments), Resend (email), Cal.com (scheduling), Sentry (error monitoring), Axiom or Better Stack (logs and uptime), PostHog (analytics), and Doppler or Infisical (secrets management).
Assigned Jobilly mentors, recruiters, and admins may access your data when needed to perform services you request, subject to role restrictions and audit logging. Partner institutions receive reporting on enrolled candidates as described in their agreement. We may disclose information if required by law, court order, or governmental authority, or when we believe disclosure is necessary to protect rights, safety, or property. If Jobilly is involved in a merger, acquisition, or sale of assets, your data may transfer to the successor entity subject to continued protection consistent with this policy.
Security and data protection
Our security model follows defence in depth so that no single layer failure exposes user data. At the edge, Cloudflare provides WAF rules to block common attacks, rate limiting, bot mitigation, and DDoS protection. All traffic uses TLS 1.3 encryption in transit with HSTS enforced.
At the application layer, every input is validated (for example with Zod schemas), outputs are encoded to reduce cross-site scripting risk, CSRF protections are applied, and security headers including Content Security Policy are set. Authentication uses Supabase Auth with secure session tokens; employees and admins may use multi-factor authentication.
Authorization is enforced at the database level through Row-Level Security policies in PostgreSQL, meaning a candidate cannot read another candidate’s rows even if application code contains a bug. Sensitive application fields are encrypted before storage. Secrets and API keys live in a dedicated secrets manager and are injected at runtime — never committed to source code.
Employee access to candidate profiles and sensitive fields is logged in an audit_log table recording the actor, action, target, timestamp, and IP address where available. Dependencies are scanned automatically in CI, and candidate code runs in isolated sandbox environments separate from production networks.
Data retention
We retain personal data for as long as your account is active and as needed to provide the services you use. Profile information, resumes, learning progress, interview transcripts, application history, and recruiter messages remain available while your account exists unless you request deletion of specific items or your entire account.
If you delete your account or request erasure, we will delete or anonymize personal data within a reasonable period, except where retention is required for legal, tax, accounting, or dispute resolution purposes. Backup systems may retain deleted data for a limited window before backups rotate and overwrite.
Security logs, audit records, and aggregated analytics may be kept longer in de-identified or pseudonymized form to maintain platform integrity and comply with security obligations. Subscription and payment records may be retained for the period required by financial regulations.
Your rights and choices
Depending on your location, you may have the right to access a copy of the personal data we hold about you, correct inaccurate or incomplete information through your profile settings or by contacting us, delete your account and associated data subject to legal exceptions, export your data in a portable machine-readable format where technically feasible, restrict or object to certain processing, withdraw consent for consent-based processing, and lodge a complaint with your local data protection supervisory authority.
Jobilly provides GDPR-style data export and deletion capabilities designed into the platform architecture. To submit a request, email privacy@jobilly.ai or use jobilly.ai/contact. We may need to verify your identity before fulfilling requests. We will respond within the timeframe required by applicable law, typically within thirty days for GDPR requests.
You can update much of your profile and career data directly in the candidate dashboard. You may cancel subscriptions through your account or Stripe customer portal where available. Institution candidates should contact their institution admin for program-specific questions in addition to Jobilly.
International data transfers
Jobilly is operated from the United States and uses service providers that may process data in the United States, European Union, and other countries. When we transfer personal data across borders, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, supplementary measures where required, and vendor assessments for security and privacy practices.
If you access Jobilly from outside the United States, you acknowledge that your data may be processed in jurisdictions with different data protection laws than your country of residence, but we apply consistent protections described in this policy regardless of processing location.
Cookies and similar technologies
We use cookies and similar storage technologies to maintain your authenticated session, remember preferences, protect against cross-site request forgery, and measure product usage. Essential cookies are required for the platform to function; analytics cookies help us understand feature adoption and may be configurable depending on your jurisdiction.
You can control cookies through your browser settings, but disabling essential session cookies will prevent you from staying signed in. We do not use cookies for third-party advertising networks.
Children
Jobilly is designed for graduates and adult learners, not children. We do not knowingly collect personal information from anyone under 16 years of age. If you believe a child has provided us personal data, please contact privacy@jobilly.ai and we will take steps to delete that information promptly.
Changes to this policy
We may update this Privacy Policy as our services, data practices, or legal requirements change. When we make material changes, we will post the updated policy on this page with a revised effective date and, where appropriate, notify you by email or through an in-product notice. We encourage you to review this page periodically.
Contact us
For privacy questions, data access requests, deletion requests, or concerns about how your information is handled, contact Jobilly.ai — Privacy at privacy@jobilly.ai or through jobilly.ai/contact. We take all privacy inquiries seriously and will work with you to resolve them.