Privacy policy
What we collect, and why.
Effective September 28, 2026. Covers the GradLaunch website (gradlaunch.ca) and the GradLaunch Chrome extension.
- We collect what's needed to rate jobs against your profile, tailor your resume, and show you your job search on your dashboard. Nothing else.
- We don't sell your data, show ads, or use analytics or tracking tools.
- The extension reads only the job posting you have open, and an application form only when you click Autofill on it. It doesn't read your LinkedIn messages, feed, connections or other pages, and it never submits an application.
- Using the extension with your own AI key and without signing in keeps your data in your browser. Only the AI provider you pick receives it, when you ask for a rating or a tailored resume.
- You can delete your data at any time. See Deleting your data.
Contents
- Who we are
- The Chrome extension
- The website
- How we use data
- Who processes it
- What we never do
- How long we keep it
- Deleting your data
- Security
- Your rights
- Children
- Changes and contact
1. Who we are
GradLaunch ("we", "us") runs gradlaunch.ca and the GradLaunch Chrome extension, which helps you decide which jobs are worth applying to and tailors your resume for them. Questions about this policy go to hello@gradlaunch.ca.
2. The Chrome extension
What it reads on web pages
- The job posting you have open on LinkedIn: its title, company, location, description, and whether LinkedIn shows that you've already applied ("Applied 3 days ago").
- Job titles already on screen in LinkedIn's results list, to show a match badge beside each one. This is read and scored inside your browser and never sent anywhere.
- On other job sites, only when you click the extension's icon on a posting: the text of that page, to read the job from it.
- Application forms, only when you click Autofill in the panel on that page: the form's questions, their options, and which fields are already filled, plus the page's title and opening text to tell which job it's for. Autofill needs Chrome's permission to run on job sites, which it asks for the first time you use it. When filling, it may open the form's sections, add work-history and education entries, and upload your resume (built from your profile or tailored resume) to the form's resume field. It never submits a form.
- On gradlaunch.ca, it receives the sign-in token the website hands it when you connect your account.
It does not read LinkedIn messages, your feed, profiles, connections, or any page you don't have open. It doesn't fetch job pages in the background, and it doesn't record your browsing history.
What it stores in your browser
In Chrome's extension storage, on your computer: your resume profile, your settings (including your own AI key, if you add one), recent fit ratings, tailored resumes, suggested searches, and an activity record per job you open: its title, company, location and link, when you opened it, its fit rating, whether you tailored a resume, and whether you applied. If you use Autofill, also your saved answers to application questions: the answers you write or confirm, the bullet points you wrote them from, and answers you choose to remember for questions like work authorization, salary expectations or voluntary self-identification. Saved answers stay in your browser; they are not synced to your account.
When Autofill uses the AI (for questions your profile and saved answers don't settle, or to write an answer from your bullet points), the request contains those questions, your profile, the saved answers that look relevant, your bullet points and the start of the page's text. It goes to the AI provider the same way as a fit rating (below). Answers to work authorization, sponsorship, salary and self-identification questions are never guessed by the AI: they come only from you.
If you use your own AI key and don't sign in
Nothing is sent to GradLaunch. When you import a resume, rate a job, tailor a resume or ask for search ideas, that request goes straight from your browser to the AI provider you chose (Anthropic or Google Gemini) with your key. It contains your profile and the job's text. That provider's own privacy policy applies to it.
If you sign in to GradLaunch
- Your profile syncs with your GradLaunch account, so it's the same on the website and in the extension.
- Your activity (the per-job record described above) and your tailored resumes sync to your account, to build your dashboard, match log, applications list and resume downloads on gradlaunch.ca. Activity recorded before you signed in is sent when you first sign in.
- AI requests (the prompt with your profile and the job's text, and a resume PDF when you import one) go to our server, which sends them to Google's Gemini API and returns the result. We don't store these prompts; we keep a count of requests for your plan's limits.
Signing out in the extension's Settings stops all syncing and cancels that browser's sign-in on our server.
3. The website
- Account: when you sign in with Google, we receive your name, email address, profile photo and a Google account ID. We don't receive your Google password or access to your Gmail, Drive or other Google data.
- Profile and resume: the details you enter or import from your resume (name, contact details, education, experience, skills, the jobs you're looking for), plus resume templates you upload.
- Job tools (under More tools): the searches you run, the jobs they return, their scores, and the tailored resumes and cover letters you create there.
- Applications you track, and your plan and usage counts.
- Payments: handled by Stripe. We store your Stripe customer ID and subscription status, never your card details.
- Emails: if you turn on the daily digest, we email you new matches. If you send feedback, we receive your message and email address.
The website uses no analytics, advertising or tracking cookies. It keeps a few settings in your browser's local storage (for example, the page you last opened) and Google sign-in keeps you signed in.
4. How we use data
Only to provide GradLaunch to you:
- rating how well a job fits your profile, and estimating its salary;
- tailoring your resume to a job, using only experience in your profile;
- showing your dashboard: jobs checked, estimated hours saved, applications, good matches you haven't applied to, and your tailored resumes;
- running your plan: limits, billing and support;
- keeping the service working and secure, and answering your feedback.
5. Who processes it
These companies process data on our behalf, only to provide the service:
| Service | What for | What it receives |
|---|---|---|
| Google Firebase and Cloud Firestore | Sign-in and our database | Your account and everything stored in it |
| Google Gemini API | AI for fit ratings, tailoring and resume import | Your profile, job text, resume files you import |
| Anthropic | AI, only if you add your own Anthropic key | Sent from your browser with your key, as above |
| Railway | Hosts our API server | Requests to our API |
| Vercel | Hosts the website | Standard web requests for the site's pages |
| Stripe | Payments | Your email and payment details (entered on Stripe) |
| Resend | Sending email | Your email address and the email's content |
| Apify | The job search under More tools | Your search terms, not your profile |
We may disclose data if the law requires it, or to a successor if GradLaunch is sold or merged, under this policy.
6. What we never do
The use of information received from the GradLaunch extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. In particular, we don't:
- sell or rent your data, or share it with data brokers;
- use it for advertising, or to decide creditworthiness or lending;
- use it for anything unrelated to helping you with your job search;
- let people read it, except with your permission (for example, to answer your support request), for security, or where the law requires it.
7. How long we keep it
We keep your account data while you have an account. Data in the extension stays in your browser until you delete it or remove the extension. When you ask us to delete your account, we delete it within 30 days; copies in backups are overwritten on their normal cycle.
8. Deleting your data
- In the extension: Settings → Delete everything erases all of its data in your browser. Removing the extension also erases it.
- Single jobs: remove any job from Matches on the website.
- Disconnect the extension: sign out in the extension's Settings.
- Your whole account: email hello@gradlaunch.ca from the address you sign in with, and we'll delete your account and everything in it.
9. Security
All connections use HTTPS. The extension's sign-in token is stored on our server only as a one-way hash, and you can cancel it at any time by signing out. Your own AI key, if you add one, never leaves your browser except to go to that AI provider. No system is perfectly secure, but we take reasonable steps to protect your data.
10. Your rights
You can see and edit your profile at any time on the website or in the extension. You can ask us for a copy of your data, to correct it, or to delete it, by emailing hello@gradlaunch.ca. Depending on where you live (for example, under Canada's PIPEDA or the EU/UK GDPR) you may have further rights, including to complain to your data protection authority.
11. Children
GradLaunch is for job seekers and isn't directed at children under 16. We don't knowingly collect data from them. If you believe a child has given us data, contact us and we'll delete it.
12. Changes and contact
If we change this policy, we'll update the date at the top. If a change affects how we use data you've already given us, we'll tell you before it applies. Contact: hello@gradlaunch.ca.