Privacy policy
Last updated: 24 July 2026
This notice briefly explains what personal data JobGoblin uses, why, for how long and your rights under the GDPR.
1. Controller and contact
Controller: Peter Elias Nilsson, operating JobGoblin from Svartviksvägen 43, 619 31 Trosa, Sweden. support@jobgoblin.works
Use the contact above for questions or to exercise your data protection rights.
2. Data, purposes and legal bases
| Processing | Data | Legal basis | Retention |
|---|---|---|---|
| Account and service | Email, authentication, profile/CV, job adverts, applications, documents, interview answers and transcripts. | Contract or pre-contract steps (Article 6(1)(b)). | While the account is active; active copies are normally deleted within 30 days after a verified request. |
| AI features | Content needed for generation, translation, analysis or interview practice. | Contract (Article 6(1)(b)). | Results are stored in the account. OpenAI may normally retain abuse logs and certain API state for up to 30 days. |
| Payments | Plan, status, amount, currency and Stripe identifiers. We do not store full card details. | Contract and legal obligation (Article 6(1)(b) and (c)). | Abandoned checkout drafts: 30 days. Accounting records: 7 years. |
| Security and operations | IP/device information, logs, errors, feature usage, limits and entitlements. | Legitimate interests in a secure and reliable service (Article 6(1)(f)). | Operational logs normally 90 days; usage and security records normally no more than 24 months. |
| Support and privacy requests | Messages, contact and verification information. | Contract, legal obligation and legitimate interests (Article 6(1)(b), (c) and (f)). | As long as needed for the request, then only where legal duties or claims require it. |
| Autopilot and application sending | Job matches, selected documents, approval revisions, application answers, dispatch status and encrypted OAuth tokens. | Contract and actions you expressly request (Article 6(1)(b)). | While the account is active; OAuth tokens are deleted or made unusable when the connection is disconnected. |
Most data comes from you. Job information may also come from links you provide or public services such as JobTech. Required fields are identified in the service; without them the relevant feature cannot be provided.
3. AI and sensitive data
Relevant content is sent to OpenAI when you request an AI feature. During voice interviews, live audio is sent for transcription and responses; JobGoblin stores the transcript, not the audio recording. OpenAI states that API data is not used for model training by default.
AI outputs are drafts and JobGoblin does not make employment decisions. Autopilot may prepare applications automatically after your opt-in, but external sending always requires your separate approval of the locked application revision. Avoid special-category data, such as health, ethnicity, religion or political opinions, unless genuinely necessary.
4. Recipients and transfers outside the EEA
We share data only where needed with Supabase (database and authentication), Vercel (hosting, workflows, operational logs and web analytics), OpenAI (AI and voice), Stripe (payments), Resend (email digests), Google or Microsoft (only email sending you approve), selected employer application systems such as Recruitee, JobTech (job search) and unpkg (technical PDF resources). Stripe and the employer may act as independent controllers for their processing. We do not sell personal data.
Vercel Functions currently run in the United States, and other providers may also process data outside the EEA. Where required, a valid transfer mechanism is used, such as an adequacy decision, the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses. Contact us for information about the relevant safeguard.
5. Deletion and security
Request an export or account deletion at support@jobgoblin.works. Data required for accounting, security or legal claims is excluded until its retention period expires. Isolated backups are overwritten according to each provider's backup cycle.
We use encrypted connections, managed authentication, access controls, row-level security and restricted server credentials. No online service can guarantee complete security.
6. Your rights
Subject to the GDPR's limits, you may request access, correction, deletion, restriction and portability, and object to processing based on legitimate interests. You may withdraw consent where consent is used. We may need to verify your identity and normally respond within one month.
You may complain to the Swedish Authority for Privacy Protection (IMY) or the data protection authority where you live or work.
7. Children and changes
The service is intended for people aged 18 or older. We update this notice when the service, providers or rules change and will highlight material changes where appropriate.