Privacy Policy

Last updated: September 25, 2026

Your data, your controls. Wherever you live, you can download a copy of your data or delete your account yourself, in Settings → Privacy. We never send your resume to employers and we never sell your data. See Your Rights (Section 10) for the full list.

1. Who We Are

RemoteHunt ("Service", "we", "us") is operated by Egor Aizen, an individual based in Israel, who decides how your personal data is used and is responsible for it (the "controller"). You can reach us at privacy@remotehunt.app.

2. Data We Collect

Account

Your email address and, if you use one, a password — our sign-in provider, Supabase, stores it only as a hash. If you sign in with Google, Google shares your name, email address and profile picture with that provider.

Your resume and profile

The text of the resume you upload (we don't keep the file itself) and what we read from it: your name and contact details, work history, education, skills, languages and level. The preferences you set: target roles, country, level, languages, salary expectations and other job preferences. Your time zone, so that our emails arrive at a set hour of your own day.

What you do in RemoteHunt

Your matches, their scores and explanations; the jobs you view, save, dismiss or apply to, and the reasons you give; your notes and application stages; the cover letters and tailored resumes you generate; and your conversations with the AI coach.

Purchases

Creem, our Merchant of Record, takes the payment. From Creem we receive and keep the order number, the amount and currency, the dates of your pass, and whether it was withdrawn or refunded. We never see your card details.

Emails and messages

Which emails we sent you and, from our email provider, whether each one was delivered or bounced and — where tracking is on — whether it was opened or a link in it was clicked. When you write to one of our addresses, we keep the sender, subject and text of your message. When you use the chat on our site, we keep what you, our AI assistant and we write there, the page you wrote from, the type of browser and device, the email address you give us if you are not signed in (optional), and — if you are signed in — the link to your account. The AI assistant answers first, from the last few messages of the conversation and the price that applies to you; it cannot see or change your account. When it passes the conversation to a person, we email ourselves the conversation and reply to you within 2 days.

Technical and security data

When you sign in or download your data, we record the time, your IP address and your browser in a security log. When you delete your account, we erase the IP addresses and browsers from it and keep only your account id and the times. We also use the country your connection comes from, worked out from your IP address, to suggest your country when you set up your profile (you confirm or change it), to protect the Service from abuse, to set the price of the pass at checkout, and to know whether we must ask before keeping anything optional in your browser (Section 11). So that your price stays the same wherever you connect from, we keep with your account the country your price was set from and the country in your profile at that moment. When something breaks, error reports record technical details of the problem.

How you found us

When you arrive from a search engine, a link or a campaign, your browser can store the campaign markers that link carried (the standard utm_ parameters and any ad click id), the website you came from and the first page you opened. If your connection comes from the EU, the EEA, the UK or Switzerland, this happens only after you press “Accept” in our cookie banner; from anywhere else, unless you press “Reject” (Section 11). If you create an account, that record is saved once against your account so we can see which channels bring people to RemoteHunt. We never store the full address of the referring page for this purpose; the record expires after 90 days if you do not register, and it is deleted with your account.

3. What We Don't Ask For

  • Government ID numbers or identity documents
  • Payment card details (Creem, our Merchant of Record, handles payment)
  • Background checks or references

Please leave sensitive details — health, religion or beliefs, political views, trade union membership, sexual orientation, ethnic origin or a photo — out of the resume you upload. We don't need them, and our matching is not designed to use them.

No law requires you to give us personal data. Without an email address we can't create your account, and without a resume or profile we can't match jobs to you.

4. How We Use Your Data, and Why We May

  • To provide the Service — reading your resume; finding, scoring and explaining jobs; generating the documents you ask for; running your account and application tracker. Basis: our contract with you.
  • Emails about your search — a digest on days with new strong matches, and a few others (a welcome, your first match, reminders). You can turn them off at any time in Settings or with the link in any of them. Basis: our legitimate interest in helping your search; you can object at any time.
  • Service emails — confirming your address, and emails about a purchase, a withdrawal or a refund. Basis: our contract with you.
  • Payments and records — selling and managing the pass, and keeping purchase records. Basis: our contract with you, and tax and accounting law.
  • Security — protecting accounts, preventing abuse and fraud, and enforcing our Terms. Basis: our legitimate interest in a safe service.
  • Improving RemoteHunt — statistics without cookies, error reports, which channels bring people to us, what is done in the product, and short replays of the page when an error happens. Basis: our legitimate interest in improving the Service; for the optional statistics, in the EU, the EEA, the UK and Switzerland, your consent (Section 11).
  • Quality checks — when we change the matching, we re-run it on a small sample of real profiles and compare the results, so that a change doesn't make matching worse. Names and contact details (email address, phone number, profile links) are removed from the sample. It is kept in our private storage and used only for this. Basis: our legitimate interest in accurate matching.
  • Analytics cookies — only if you accept them (Section 11). Basis: your consent.
  • Answering you — replying to messages you send us. Basis: our legitimate interest, or our contract with you.

5. How Matching Works (Automated Decisions)

RemoteHunt decides automatically which job postings to show you and in what order. Nobody reviews these results before you see them.

  • What it uses: your resume and profile — roles, level, country, languages, skills, experience, salary expectations and job preferences — and the jobs you like or dismiss.
  • Filters: a posting is hidden when we read that it cannot suit you — the employer hires only in countries you are not in, asks for a language you don't list, is for a different profession or level, pays well below your salary expectation, comes from a staffing agency, or looks like a scam or not a real vacancy. If you dismiss two jobs from the same company, we also hide its other jobs.
  • Score: of the remaining postings, the ones closest to your profile are scored from 0 to 100 by AI models — on role fit, work format, compensation, domain and company — with an explanation you can read on each job.
  • Effect: filtered postings don't appear in your feed, and the rest are ranked by score. This only affects what we show you: it doesn't stop you from applying anywhere, and nothing is sent to employers.
  • Your control: you can change the details the matching uses in your profile and Settings at any time, and you can ask for a person to review a result by writing to privacy@remotehunt.app.

6. AI Providers

To read resumes and job postings, score matches and write text, we send the data each task needs to AI models through OpenRouter (US), a service that passes our requests to model providers. OpenRouter does not store the content of requests by default, and with every request we instruct it to use only providers that, under their own terms, do not train their models on it.

  • Google (Gemini models) — our main models. They receive your resume text (with your contact details when they read your resume or write a tailored resume or cover letter), your profile, job postings, your conversations with the AI coach and your messages in the chat on our site (its AI assistant answers them first; see Section 2). Under the paid terms we use, Google does not use this data to train its models; it may keep it for up to 55 days to detect abuse.
  • OpenAI — turns your profile into numbers ("embeddings") that let us find the postings closest to it. OpenAI does not use data sent through its API to train its models.
  • Other models — when Gemini is unavailable, the AI coach can fall back to a model from Meta (Llama), served by a provider that OpenRouter selects under the rule above. It receives only what the coach needs — never your contact details — and that provider's own data policy applies.
  • TypeSafe (the Jev model) — a model that only rates how well a job fits you and writes no text. Since 24 September 2026 it takes part in scoring matches for a share of accounts: a job it rates a clear poor fit is not scored further and does not appear among your matches. For each job it rates, it receives the same summary of your profile and the job posting as our matching step — never your contact details — under the no-training rule above.

The free resume checker (/resume-checker) works without an account. The resume and job description text you paste or upload there is sent once, over this same OpenRouter path to Google (Gemini), to score that one pair and write the result you see on screen — nothing about it is written to our database or our logs, and nothing is saved once the answer comes back. Only the outcome (a score range and how long it took) is recorded, never the text.

7. Who Else Processes Your Data

We use these service providers, each only for the purpose shown:

  • Supabase — our database and sign-in (all the data in your account)
  • Railway — runs our servers and background jobs (all the data the Service processes)
  • Vercel — hosts the website (every request to the site, including the data you send through it) and runs our statistics without cookies: page views, loading speed and, under the rules in Section 11, product events
  • OpenRouter and the AI providers in Section 6 — AI processing
  • Resend — sends our emails and receives mail sent to our addresses (your email address and the content of emails)
  • ImprovMX — forwards mail sent to our addresses to our mailbox (the messages you send us)
  • Creem — our Merchant of Record for the pass: payment, tax and invoices (your name and email address, so its checkout is filled in for you, and your payment details, which Creem handles under its own privacy policy)
  • Sentry — error reports (technical details of an error, which can include data being processed when it happened, and — when you are signed in — your account id, never your email)
  • Telegram — instant notifications to us about purchases, withdrawals and messages to support (the email address of the account involved, the amount, and the first lines of a message); messages you send in the chat on our site reach us there in full, with the page you wrote from and your account's email address or the address you gave us, and our answers travel back through it
  • GitHub — stores our code, runs automated tests and keeps our backups (database backups; the quality-check sample in Section 4)
  • PostHog, Google Analytics, Microsoft Clarity — analytics, only if you accept analytics cookies (pages visited and actions taken)

We do NOT:

  • Sell, rent, or trade your personal data to third parties
  • Send your resume or profile to employers — when you apply, you do it on the employer's own site
  • Provide your data to recruiters or staffing agencies
  • Use your data for advertising or marketing by third parties

8. International Data Transfers

We are based in Israel, which the European Commission recognizes as providing adequate protection for personal data. Our servers and most of our providers are in the United States. Where personal data from the EU, EEA, UK or Switzerland goes to them, we rely on the safeguards they provide — the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

9. How Long We Keep Data

  • Your account and everything in it (resume, profile, matches, documents, coach conversations, notes): until you delete your account — then it is deleted from our live database at once
  • Backups: up to 90 days, then overwritten
  • Security log (sign-ins, data downloads, deletions: account id and time, and — until you delete your account — IP address and browser): up to 2 years
  • Records of purchases and refunds (order number, amount, dates): up to 7 years, for tax and accounting. Creem, as the seller, keeps its own records
  • A refund we still owe you (the order number and dates, and for a resume pack the amount — not your account id, email or country): if you delete your account before we have refunded you, we keep this until the refund is made, so it is not forgotten, and then delete it
  • Messages you send us: up to 2 years
  • Usage statistics: kept without your account id after you delete your account
  • Chrome extension records (install id and version, and — once you sign in through it — the link to your account and your browser's token hash): see Section 12
  • Server logs (which can include IP addresses) and error reports: up to 90 days
  • The quality-check sample (Section 4; profiles with names and contact details removed): until we replace the sample; to have your profile removed from it sooner, write to privacy@remotehunt.app

10. Your Rights

Wherever you live, you can use these rights — the ones the EU General Data Protection Regulation (GDPR) and Israel's Privacy Protection Law give. Most of them work directly from Settings → Privacy:

  • Get a copy of your data — the “Download my data” button gives you everything tied to your account as a JSON file you can take to another service: your profile and preferences, the text of the resumes and notes you gave us and the earlier versions of your profile, your matches and their scores, the jobs you saved, dismissed or applied to and your notes on them, the documents you generated, your conversations with the AI coach, the emails we sent you and what our email provider reported about them, your messages to us, your purchases and payment attempts, the security log of your account, how you found us, and the browsers you connected the Chrome extension from. Backups, server logs, error reports, the records Creem keeps as the seller and the quality-check sample (Section 4) are not in the file — write to us for those.
  • Correct your data — in your profile and Settings.
  • Delete your account — the “Delete my account” button deletes your account and its data at once (Section 9 lists what stays, and for how long).
  • Object or restrict — turn off our emails with the link in any of them or in Settings, and ask us to stop or limit any other use of your data.
  • Withdraw consent — press “Cookie settings” at the bottom of this page, our home page or our blog, and choose “Reject” (Section 11).
  • Ask a person to review an automated matching result (Section 5).
  • Complain to a data protection authority — in the EU, EEA or UK, the one where you live; in Israel, the Privacy Protection Authority.

For anything else, or to delete an account you can no longer sign in to, write to privacy@remotehunt.app. We reply within 30 days, and we may ask you to confirm the request from your account's email address.

11. Cookies and Browser Storage

Some data is kept in your browser. What is needed to run the Service is kept without asking. For everything optional, the rule depends on where your connection comes from, worked out from your IP address: from the EU, the EEA, the UK or Switzerland, nothing optional is stored or sent until you press “Accept” in our cookie banner; from anywhere else, the optional statistics below run unless you press “Reject”. The analytics cookies wait for “Accept” wherever you are.

  • Needed to run the Service — sign-in cookies (set by Supabase); a cookie that remembers whether your account has an active pass (up to 120 days); a cookie that remembers your plan for five minutes, so that every page does not have to look it up again; your cookie choice; a cookie, set only for connections from outside the EU, the EEA, the UK and Switzerland, that records that the optional statistics may run before you answer (until you close your browser); the preferences and drafts you enter; and, if you drop a resume on our home page before signing up, the file itself for up to 3 hours, so that it is ready once your account exists. Signing out or deleting your account removes all of this from the browser, except your cookie choice, the cookie about where your connection comes from (our servers set it again on every page) and whether you have already seen our languages prompt.
  • The chat on our site — if you are signed in, nothing: the conversation belongs to your account. If you are not, a random code that lets your browser find your conversation again; it is kept in the browser only when the optional storage below is allowed (from the EU, the EEA, the UK or Switzerland, after “Accept”), otherwise only while the tab is open; pressing “Reject” or signing out deletes it.
  • Statistics without cookies, for every visitor — Vercel Web Analytics and Speed Insights count page views and measure loading speed, Sentry reports errors (technical details of what broke), and we count visits to our public pages ourselves (which kind of page, and nothing else). None of these stores anything in your browser or profiles individual visitors.
  • How you found us (optional) — the campaign markers described in Section 2, for up to 90 days.
  • Product events and visit counting (optional) — what is done in the product, for example starting to sign up, opening a job or pressing Apply, sent to Vercel Web Analytics without cookies, with the page it happened on but never with a file name or an email address; and markers in the open tab that keep a reload from counting as a second visit, or an offer we showed you from counting twice.
  • Error replays (optional) — when an error happens, Sentry can keep a short replay of the page with all text and inputs hidden (in about one case in ten); while the tab is open, a session marker stays in your browser.
  • Analytics cookies, only with your consent — PostHog, Google Analytics and Microsoft Clarity measure how the product is used, including session replays with sensitive fields masked. None of them loads unless you press “Accept” in our cookie banner.

You can change your answer at any time with “Cookie settings” at the bottom of this page, our home page or our blog. “Reject” stops the optional statistics and deletes the “How you found us” record from your browser; a record already saved against your account stays until you delete the account.

We don't use advertising cookies or retargeting pixels.

12. The RemoteHunt Chrome Extension

The RemoteHunt extension for Google Chrome helps you judge a job posting and apply to it on the page you are already on. It runs only on the job boards and application sites it names (for example LinkedIn, Indeed, Himalayas, Greenhouse, Lever and Ashby) and on remotehunt.app. It never submits an application: it can fill in a form, and you press the site's own button to send it.

What it reads

On a job page: the posting's title, company, location, description and address. On the application forms of the seven application sites it supports (Greenhouse, Lever, Ashby, Workable, SmartRecruiters, Recruitee and Teamtailor): the form, and only when you press “Fill with RemoteHunt”; and, after you have opened a form there, the address and text of the page that follows, to tell that your application went through. On any other page, only when you press “Check this page” in the extension's window: that one page, read the same way as a job page. Nothing else on the pages you visit.

What it sends to us, and when

  • Once a day — a random install id created by the extension, its version, and a fingerprint (a hash) of a secret that never leaves your browser. No account data.
  • Country check, when you open a job page — the posting's text and address, the country you chose and the install id, so that we can tell you whether the employer hires where you live. No account data, and no AI model is involved.
  • Fit score, when you ask for it — without an account, the resume text kept in the extension and the posting's text; the resume file itself is sent once, when you add it, only to turn it into text. When you are signed in, your RemoteHunt profile is used instead. Either way the text goes to an AI model over the path in Section 6 (OpenRouter to Google Gemini, with the same no-training rule).
  • Only when you have signed in through the extension — saving a job to your Hunt, marking it applied when the extension sees the application site's own confirmation, fetching your contact details and resume file to fill in a form, and asking whether the job on the page is already in your RemoteHunt feed (the page's address only).
  • Your resume, once, only if you choose — when you connect the extension to a new account, the connect page asks whether to use the resume you added in the extension. Only if you press “Use it” does the extension send that file (or text) to your account, where it is kept like a resume you upload on the website, until you remove it or delete your account.
  • A few first-time steps — for example that the extension opened its panel or checked a fit for the first time, each once, with the install id only, so that we can count how many people reach each step. No page content and no account data.
  • On a Himalayas posting — the posting's address and the employer's own application link, if the page shows one. We keep that link only after our own server has opened it and confirmed it is the same job.

Your IP address is used, briefly, to limit how often the free checks can be run, as on the rest of the Service.

What it keeps in your browser

The country you chose; the resume text and file you added, if any; the details you type into “My details” (name, email, phone, city, LinkedIn); the install id and its secret; and, once you sign in, the extension's own sign-in token. “Remove resume” deletes the resume, and removing the extension deletes everything it kept.

What we keep on our side

For each install: the install id, its version, when it was first and last seen, the fingerprint of its secret and — once you sign in through it — the link to your account. For each signed-in browser: a hash of its token (never the token itself), when it was created and last used, and whether it was disconnected. Counts of how often each feature is used, per day, without any id, and for each first-time step, the install ids that reached it (kept for up to 40 days). We keep nothing of the resume or job text you check without an account: it is read to answer you and dropped. When you are signed in, a fit score is kept for 7 days so the same job is not scored twice, and the jobs you save or mark applied become part of your Hunt, like any job you save on the website.

How long, and how to stop it

An install record carries no personal data until you sign in through it, and it stays while the extension may still report from it. To disconnect a browser, use Settings → Privacy → Connected browsers, or remove the extension. When it is installed it opens a welcome page on remotehunt.app, and when it is removed Chrome opens a short page there; neither asks for or keeps anything. Deleting your account deletes every extension token and unlinks your installs from it; “Download my data” includes both.

13. Children

The Service is not intended for anyone under 18. We do not knowingly collect data from minors.

14. Security

  • All data travels over encrypted connections (HTTPS/TLS)
  • Our database provider encrypts the data it stores
  • Passwords are stored only as hashes, by our sign-in provider
  • Only we, through protected accounts, have access to the data behind the Service
  • Backups are kept in private storage for up to 90 days

No system is 100% secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.

15. Changes to This Policy

We may update this policy. We will post the new version here with its date and, for important changes, tell you by email or in the Service before they take effect.

16. Contact

For privacy questions: privacy@remotehunt.app (or contact@remotehunt.app).