Your CV is sensitive. We treat it that way.

A job search touches some of your most personal data — your history, your contacts, your reasons for leaving. JobEmber is built so that data goes only where you allow it, is never used to train a model, and can be erased in one click.

Never used to train AI.

Your writing samples, voice profile, generated documents, feedback, and help-chat content are never used to train, fine-tune, or evaluate any model — ours or a provider's. Model providers are configured on no-training terms where offered.

PII replaced before a model sees it.

With PII redaction on, your name, email, phone, address, and target cities are swapped for placeholders before any prompt leaves for a provider. The real values stay in your account and are re-inserted only when you download a finished document.

Voice samples auto-deleted.

The samples you upload to build your writing voice are deleted the moment the voice profile is generated. The profile persists; the raw samples don't. A product commitment, in the Terms.

You choose which models see your documents.

Your tier decides which providers run your sensitive documents. Higher tiers keep sensitive work on no-training providers only.

TierProvidersSensitive ops (CV / CL / voice)
FreeGemini (free) + Ollama (local)Generation disabled — demo only
LowDeepSeek + GeminiMay be processed by providers that train on API data
Medium RecommendedAnthropic + DeepSeekAnthropic only (no training, no retention)
HighAnthropic onlyAnthropic — full pipeline, no DeepSeek, no Gemini

The exact processors, locations, and transfer mechanisms are listed on the Sub-processors page. Cost per tier is on the Pricing page.

Defenses you don't have to think about.

Prompt-injection defense.

Text from job postings, uploaded files, and forms is untrusted by design: it's wrapped, regex-screened, judged by a separate model, and schema-validated. A posting that tries to hijack an agent is dropped, logged, and skipped — the pipeline continues without it.

Isolated per account.

Every document, match, and template is scoped to your account. Agents run against your data only; one user's run can never read another's rows.

No hidden auto-apply.

JobEmber drafts and tracks. It never submits an application, sends a message, or contacts an employer on your behalf. You review, edit, and send every one yourself.

Your data, on your terms.

Full detail in the Privacy Policy. Security reports: [email protected]. Privacy questions: [email protected].