Privacy Policy
This page says exactly what StillHiring keeps about you and what it does with it. It was written against the code that runs this site, not copied from a template, so where the product does something by hand — reviewing a payment, re-checking a listing — it says so.
- The short version
- What we store
- What we do not store
- Why
- Who else touches it
- AI processing
- Cookies & local storage
- Retention
- Your data, your calls
- Security
- Rules we set ourselves
The short version
You give us a resume and an email address. We turn the resume into a structured profile so we can grade jobs against it, and we keep the profile, your saved jobs, your application tracking and your payment records for as long as you keep the account. We do not sell your data, we do not send it to recruiters, and we do not run advertising or third-party analytics on this site. Deleting your account from the account page erases the account and the data on it. Any remaining question goes to the contact page.
What we store
Everything below is what the database actually holds for an account. Job listings themselves are also stored, but those are public postings from employers' own pages and boards — they are not your personal data.
- Account. Your email address, a display name, and either a bcrypt password hash or the link to the Google account you signed in with. Your plan, cycle, period end date, grace window and scan balance live on the same row.
- Your profile. The structured result of parsing your resume: skills, the experience lines that evidence each skill, roles, target locations, work modes, seniority, industries, projects, work history, education, certifications, salary expectations, notice period, and the companies or technologies you have excluded.
- Your activity. Jobs you saved, jobs you are tracking (with the status you set, your notes, dates, the stage history, and the application material you applied with), and interview preparation notes and mock-interview runs.
- Your browser registrations. If you turn on alerts, the push endpoint and its cryptographic keys, so a message can reach that browser.
- Payment records. One row per order: our reference, what you bought, the amount, how it was paid for, the UTR you reported or the payment provider’s own payment id, its review status and timestamps, and the email address you paid from.
- Messages you send us. What you write on the contact page, the email address you give or the account you were signed into, the topic, an order reference if you quoted one, and whether a person has handled it. No IP address and no browser fingerprint is kept with it. It is part of your data export and it is deleted with your account.
- Counters. How many metered actions your account used in each calendar month. This is what makes an allowance real instead of an honour system.
The profile fields exist because the matching does: an evidence grade has to be able to point at the experience line behind it, which means the line has to be stored.
What we do not store
- The resume file itself. An upload is read into memory, parsed, and dropped. The document is never written to storage and there is no download of it later.
- Raw resume text. What is kept is the parsed, structured profile — not a stored copy of your document as prose. Where a screen needs the text again, it re-derives it.
- Card or bank credentials. There is no card form on this site. Where a payment runs through our payment provider, the card or net-banking details go to that provider’s own page and never through our servers; we keep only its reference for the payment. A UTR is a transaction reference you volunteer; it identifies a payment, not an account we can charge.
- Anything you do off-site. We link out to employers and boards. Once you click through, their policy applies and ours stops.
One honest exception: when you track an application, the tailored material you applied with — the resume draft, summary and bullets the Application Copilot assembled for that listing — is stored against that application, so you can see what you actually sent. That text is generated from your stored profile, and it is deleted with the account.
Why we hold it
To run the four things the product promises: find listings, re-check them, explain the fit, and help you apply. Each category of data maps to one of those. Payment records exist because a payment is not verifiable from your word alone — it has to be confirmed against the provider’s own record of it, or, on the direct-UPI path, against the bank credit by a person — and because you are entitled to a receipt. Usage counters exist because a monthly allowance cannot be enforced without them. Nothing is collected for a purpose you did not ask for.
AI processing
Three features can use a language model through OpenRouter: enriching a resume parse, discovering jobs, and drafting application material. Every one of them is off unless the operator has set the matching environment flag to on and supplied an API key — RESUME_AI, JOBS_AI and COPILOT_AI. When a flag is off, that feature runs on deterministic rules only and no text of yours is sent to a model.
When a flag is on, what goes out is the minimum that feature needs: the extracted resume text for a scan, your profile signals for a search, the fact pack assembled from your own data for a draft. The model is told to output only what the input supports, and a guard rejects any skill or claim it cannot trace back to your resume — the model can reorder and phrase, not invent. AI output is never stored as a fact about you or about an employer, and the same live-URL check gates an AI-found listing as any other.
Retention
- Your account data is kept while the account exists, and no longer.
- Deleting the account erases the profile, saved jobs, tracked applications and their material, interview notes, usage counters, push registrations and payment rows tied to it.
- A confirmed-gone job listing is hard-deleted from our database a day after we mark it expired; we do not archive postings we can no longer see.
- Background-run logs, which contain counts and error text rather than personal data, are pruned automatically after 30 days.
- Platform-level request logs sit with the hosting provider for that provider's own retention window. They record request metadata and account identifiers, and they are not a customer database we query.
Your data, your calls
Whatever you are entitled to where you live, this is what you get here, and how to ask for it:
- See it and fix it. Your profile, saved jobs, tracker and wallet are all on screen and editable. Corrections are yours to make, immediately.
- Get a copy. Everything we hold on your account is already visible to you — profile, saved jobs, tracked applications, wallet and order history — and the account page will hand it to you as a downloadable file — every row we hold, including your application notes and interview material — without asking us first. If you cannot reach that button, ask in writing and we will send the same thing.
- Delete it. The account page deletes your account and everything stored on it, in place. There is no retention period after that and no copy kept back for marketing.
- Object or ask a question. Data requests, including requests from someone who believes a listing we hold should not be held, go through /contact. Please write from the email address on your account so we can be sure the request is yours; a request about somebody else's account is refused unless they have asked us themselves.
We answer within a reasonable period and we will not charge you for asking.
Security
The site is HTTPS-only with strict transport security. Passwords are stored as bcrypt hashes and never in plain text; a sign-in attempt costs the same whether or not the address exists. Changing your own password, or having one reset by an administrator after you have proven the address, invalidates every session that account already had, so a cookie stolen before the change stops working with it rather than at its natural expiry. We never ask for a password in a message, and a reset hands over a freshly generated one once, in reply to a ticket, for you to replace immediately. Session and CSRF cookies are httpOnly. Outbound fetches are constrained so the crawler cannot be pointed at internal infrastructure. Request rates are limited per account and per network — including the contact form. Administrative access is granted by a stored role flag that is only ever set for an approved, Google-verified address — not by a guessed email string. Payments are reviewed by a human against the bank statement before they are considered settled.
None of that is a guarantee. No service connected to the internet can promise that a determined attacker will fail, and we would rather tell you what we do than claim a certainty we cannot sell you.
Rules we set ourselves
- No selling, renting or reselling of your data to recruiters, employers or brokers.
- No fabricated data. A listing we cannot confirm is labelled uncertain; a score we cannot compute is left blank; an estimate is marked as one. Illustrative examples on marketing pages are labelled as examples.
- No dark patterns around money: a plan is bought with a payment you make on purpose, and nothing renews by itself.
- The service is built for working professionals and is not directed at children; we do not knowingly hold data from anyone under 16.
If this policy changes, the date at the top changes with it and the new text is what governs from that date. Material changes to what we collect are pointed out on this page rather than buried.
Last updated: 25 September 2026. Governing law: India. See also the terms of service and how to reach us.
