Privacy Policy
Last updated: September 27, 2026
1. Information We Collect
Account Information
When you create an account, we collect your name and email address through Firebase Authentication (Google OAuth or email/password sign-in).
Profile Data
You provide resume text, work experiences, skills, projects, and certifications. This data is stored in your user profile to power job matching and resume optimization.
Job Data
Jobs you manually add or import are stored alongside AI-generated analyses, match scores, and keyword extractions.
Match Previews Without an Account
On the job posting checker you can paste resume text to preview your match for one job before signing up. We send that text and the job description to our AI provider (Google Gemini) once to calculate the score, then discard it. We do not store the resume text or the job link, and we do not write either to our logs.
Usage Data
We track which features you use (analyses, resume rewrites, cover letters, automated applications) for subscription billing and service improvement.
2. How We Use Your Information
- Provide AI-powered job matching, keyword extraction, and match scoring
- Generate optimized resumes and cover letters tailored to specific roles
- Store your profile for consistent matching across sessions
- Track token usage for subscription billing and tier enforcement
- Improve matching algorithms and service quality
3. Data Storage and Security
Your data is stored securely in Google Firestore with encryption at rest and in transit. User profiles, job data, analyses, and billing records are kept in your personal Firestore document and subcollections.
Some data is also stored locally in your browser via localStorage (Zustand store persistence), including your profile, settings, job list, and cached analysis results. API keys you provide are stored exclusively in your browser and are never sent to our servers.
4. Third-Party Services
Cursu integrates with the following third-party services:
- Google Gemini — Your resume text and job descriptions are sent to Google Gemini for AI analysis, resume optimization, and cover letter generation. Data is processed per Google's API terms and is not used to train their models.
- Firebase (Google Cloud) — Authentication, database storage, and cloud functions for background processing.
- Stripe — Payment processing for subscriptions. We do not store your credit card details; Stripe handles all payment data directly.
- Sentry — Error tracking in production to identify and fix bugs. Personal data is automatically redacted from error reports.
5. Cursu Autofill Browser Extension
Cursu Autofill is an optional Chrome extension. It fills job application forms on supported job boards with details you already confirmed in Cursu. It is separate from the Cursu website, it is not required to use Cursu, and it does nothing until you start an application from Cursu. This section describes exactly what it does with your data.
What it reads
On the job board domains listed below, and nowhere else, the extension reads the application form: field names, labels, input types, the options a dropdown offers, and whether a field already holds a value, so that it never overwrites something you or the site already entered. It reads the form, not the page around it. It does not read your other tabs, your browsing history, or any site that is not listed below.
The job board domains are boards.greenhouse.io, job-boards.greenhouse.io, boards.eu.greenhouse.io, job-boards.eu.greenhouse.io, jobs.lever.co, jobs.eu.lever.co, and jobs.ashbyhq.com. A second, smaller script runs on the Cursu app itself; its only job is to hand the extension the job you clicked Apply on and a short-lived sign-in token. It reads nothing else on the page.
What it writes
It writes the contact details you confirmed in Cursu — first and last name, email, phone, location, and your profile links such as LinkedIn, GitHub, or a personal site — into the form fields it matched to them with high confidence, and it attaches the tailored resume you approved for that job. Where it is not confident, it leaves the field untouched and lists it under "Needs you" in a panel it shows on the page. It never submits an application and never clicks a Next or Continue button. You review what was filled and submit the form yourself.
What it stores
Two things, both in browser session storage, which is cleared when you close the browser and is never written to disk or synced between your devices:
- A short-lived Cursu sign-in token. It is also cleared when you sign out of Cursu, and it expires on its own about an hour after it is issued.
- The job id and application URL for a tab the extension opened on your behalf. This entry expires on its own and is removed when that tab closes.
Nothing else. Your profile, your resume, and the values it fills are not kept by the extension: they are requested from Cursu for one application and discarded.
What leaves your browser
After a fill, the extension sends Cursu one reliability report about that run: which job board it was and the job board hostname, how long the run took, how many fields were found, matched, filled, skipped, and failed, the reasons fields were skipped, which matching strategies were used, which standard fields were filled by name (for example "email"), whether you edited a filled field afterwards, whether the resume attached, and the version numbers of the rules that ran. This is what tells us a job board has changed its form.
A field it did not recognize is reported as a one-way hash of its label plus a word count. That is enough to see the same unrecognized question recurring, and not enough to read the question back.
The report never contains the value of any field, the text of any label, placeholder, or dropdown option, the job id, the employer, your resume or its filename, the page address beyond the job board hostname, or the text of any error. Nothing you type is transmitted to us by the extension.
What it never does
- It never answers demographic, EEO, race, gender, disability, or veteran questions; work authorization or visa sponsorship questions; criminal history questions; government identifier fields such as a Social Security or national insurance number; salary or compensation questions; availability or start date questions; "how did you hear about us" questions; or consent and attestation fields. It detects these and deliberately leaves them blank for you.
- It never ticks a checkbox or selects a radio button on your behalf.
- It never writes a free-text response, such as a cover letter box or a "why do you want to work here" question.
- It never fills a hidden, disabled, or read-only field, and it never fills the invisible decoy fields some job boards use to catch automated form filling.
- It never submits an application.
- It never reads, runs on, or asks for permission to any website outside the domains listed above.
- It never sells or shares your data, never uses it for advertising, and sends no data to any third party. The only places your details go are the form in front of you and the Cursu servers described above.
A note about other extensions and scripts
The Cursu site hands the extension a sign-in token when you start an application. Any script running on the Cursu site can ask for one the same way, and so can another browser extension you have granted access to the Cursu site, because an extension with access to a page can run scripts on it. This is a property of the browser rather than something Cursu Autofill can prevent, and it is true of every site you sign in to. Only install browser extensions you trust.
Removing it
Uninstalling the extension from your browser removes everything it stored. Signing out of Cursu clears its token. Cursu works without the extension.
Limited Use
Cursu Autofill's use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:
- We use the data the extension handles only to provide and improve the autofill feature you asked for.
- We do not transfer it to others except as necessary to provide that feature, to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We never use it for advertising, and we never sell it.
- No human reads it, except with your explicit consent, to investigate abuse or a security incident, or where the law requires it.
6. Cookies and Local Storage
Cursu uses browser localStorage (not cookies) to persist your application state, including:
- User profile, settings, and onboarding status
- Scraped job data and cached AI analyses (24-hour staleness window)
- Firebase authentication session tokens
7. Data Retention
- Account and profile data — Retained until you delete your account.
- Token usage events — Server-side audit logs retained for 90 days.
- AI analyses — Cached locally with a 24-hour staleness window; server-side copies retained with your account.
- Billing records — Retained for 13 months per standard accounting requirements.
8. Data Sharing
We do not sell, rent, or share your personal data with employers, recruiters, or data brokers. Your job search activity remains private. Data is only shared with the third-party service providers listed above, strictly for the purpose of delivering the service.
9. Your Rights
- Access: You can view and export all your data at any time through your profile settings.
- Correction: You can update your profile, resume, and other information at any time.
- Deletion: You can delete your account and all associated data. Contact us if you need assistance with complete data removal.
- Portability: Your resume and profile data can be exported in standard formats.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notice. Continued use of Cursu after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or your data, contact us at support@cursu.ai.