Privacy
Last updated: July 13, 2026
Klepify is a Chrome extension and web service that helps job seekers detect job postings, score their fit, and generate tailored resumes. This policy explains what we collect, why, and what we don't.
1. What we collect
To make Klepify work, we collect:
- Account email — for sign-in and account recovery.
- Resume content you upload — your name, contact info, work history, skills, and education. Stored on encrypted infrastructure (TLS in transit, encryption at the storage layer), accessible only to your account via Postgres row-level security.
- Job posting content from pages you activate Klepify on — the page's text content, URL, and detected fields (title, company, salary, etc.). Used to populate your view and a shared swarm cache that helps other users skip re-processing the same URL.
- Application history — the tailored resumes you generate, with their associated job context, so you can re-open and re-download them.
- Usage metadata — counts of API calls per user (for rate limiting and billing), error logs (without resume content), and Stripe customer/subscription IDs for paid users.
- Application profile — the details needed to complete job applications: name, contact info, home/current address, professional links, and work-authorization answers. Only if you choose to provide them, this also includes demographic self-identification (EEO: gender, race, veteran, disability status) and salary expectations. These sensitive fields default to "decline to answer" / "prefer not to say," are entirely optional, and you can view, change, or delete them at any time.
- Answers you enter on application forms — when Klepify fills an application and you complete or correct a field, we save that answer to your application profile so future applications can be pre-filled. You control this data and can edit or delete it.
- Recruiter email — only if you enable the email proxy (a paid feature): messages sent to the per-application addresses we provision on
jobs.klepify.com, stored so we can track and forward them. See section 5.
2. What we never collect
- Content of any tab where Klepify is not actively running.
- Browsing history, cookies, passwords, or saved autofill data from your browser.
- Credit card numbers — these are handled exclusively by Stripe; we receive only the customer ID.
- Page content from chrome://, about://, file://, or extension URLs.
3. How we use it
Resume content and job posting content are sent to Google's Gemini API to extract structured data and generate tailored resume text. Google's terms forbid them from using API request content to train their models. If you enable the email proxy, recruiter email is additionally processed by Brevo, our email sub-processor (see section 5). We do not share, sell, or rent your data to recruiters, employers, ad networks, or any third party.
Applying on your behalf. When you explicitly ask Klepify to apply to a specific job, the extension fills out that job's application form in your own browser and, on your confirmation, submits it — attaching your tailored resume. The resume and the information you provided are sent to that employer's application system, exactly as if you had filled the form and clicked submit yourself. Klepify never applies to a job without your explicit, per-application request, and shows you what will be submitted on your first applications.
4. Sharing — the swarm cache
Job posting metadata (title, company, description, freshness signals) is shared across the Klepify user base. When you visit a job posting we've already seen, you get an instant cached result instead of waiting for another extraction. Your resume, application history, and match scores are never shared with other users.
5. Email proxy (Pro feature)
If you enable Klepify's email proxy (a paid feature), Klepify provisions a unique address for each job application on our jobs.klepify.com subdomain (e.g. apply-<token>@jobs.klepify.com) and uses it as the contact email on that application. This lets recruiter replies and one-time verification codes route to your Klepify tracker instead of your personal inbox.
When the proxy is enabled, we receive, store, and forward the recruiter emails sent to your proxy addresses — including subjects, message bodies, and any one-time verification codes — so we can match them to the right application, update its status, and forward a copy to your account email. You can also reply to recruiters through the proxy; those replies are sent from your proxy address and stored alongside the thread. One-time verification codes are single-use and discarded shortly after they are delivered to you.
Inbound and outbound proxy email is processed by Brevo (Sendinblue GmbH), our email sub-processor, before it reaches or leaves Klepify. We do not request or require access to your Gmail, Outlook, or any personal mailbox to operate the proxy — it works entirely through the addresses we provision. We never share proxy email content with recruiters' other tools, ad networks, or any party beyond the sub-processor needed to deliver it.
6. Retention & deletion
You can delete your account at any time from the Klepify side panel. Deletion removes your profile, resume content, application history, usage records, and — if you used the email proxy — your proxy addresses and all stored recruiter mail. Job posting metadata you contributed to the swarm cache remains anonymized (it cannot be linked back to your account).
7. Security
We follow industry-standard practices: TLS 1.2+ on all traffic, database row-level security, hashed authentication tokens, signed Stripe webhooks. No system is perfectly secure; if you suspect a breach, email security@klepify.com immediately.
8. GDPR / CCPA
If you reside in the EU, UK, or California, you have the right to access, correct, or delete your data, and to object to processing. Email support@klepify.com with "data request" in the subject and we'll respond within 30 days.
9. Cookies & analytics
The Klepify website uses Google Analytics 4 (measurement ID G-5J14JBW20J) to understand aggregate, anonymized traffic — which pages people visit and where they arrive from — so we can improve the site. It sets first-party _ga cookies and, like all GA4 properties, truncates visitor IP addresses before storage. We do not use it for advertising or remarketing, we don't sell data, and we run no ad-network or social tracking pixels. You can opt out any time with Google's opt-out browser add-on or by blocking analytics in your browser.
The Klepify extension runs no analytics at all — no tracking, no third-party scripts. It stores only an authentication token and your current job context in chrome.storage.local, all local to your machine.
10. Changes to this policy
If we make material changes, we'll email registered users at least 30 days before the change takes effect. The "Last updated" timestamp above is the source of truth.
11. Contact
Questions about privacy: support@klepify.com. Security: security@klepify.com.