Trust & Security

The honest version.

You're letting an agent read your resume and submit applications on your behalf. That's a lot of trust. Here's exactly what we do with your data, what we don't, and how you stay in control.

What we collect

Just enough to do the job — nothing else. Specifically:

  • Your resume. You send it once on WhatsApp; we use it to tailor each application.
  • The chat history between you and the JobSwitch number on WhatsApp.
  • The roles we've surfaced to you and how you responded (YES, NO, edits).
  • The applications the agent has drafted or submitted on your behalf, with timestamps.

We don't collect your other WhatsApp chats, your contacts, your social graph, your location, or your device info beyond what WhatsApp Cloud API sends us with each message.

Where it lives

On servers we operate ourselves in India, behind a Postgres database that's encrypted at rest. The database is not exposed to the public internet — it's reachable only from inside our private Docker network.

Backups are encrypted and rotated. We don't replicate your data to third parties for "analytics" or any other purpose.

Who sees it

The shortest version: only the people who must.

  • The agent — automated systems that read your resume to draft applications. No human reads your resume in the normal flow.
  • You — every draft is shown to you on WhatsApp before anything is submitted.
  • The companies you apply to — only what's in the application itself. Same resume, cover letter, and form fields you'd submit yourself.
  • The JobSwitch team — only when you ask for help, when something breaks and we need to debug it, or when we're legally compelled. Access is logged.

Your data is never sold, never shared with recruiters without your knowledge, and never used to train models that aren't ours.

What the agent will never do without you

JobSwitch is built around human-in-the-loop. Concretely, the agent will never:

  • Submit an application without your explicit YES.
  • Change facts on your resume. It rephrases and reorders; it doesn't fabricate.
  • Apply to a role you've told it to skip.
  • Share your resume or chat history with anyone outside the JobSwitch team.
  • Send messages on WhatsApp to anyone other than you.

Auto-apply for high-confidence matches is opt-in only, off by default, and limited to roles you've pre-approved by company and role-type.

How to delete your data

Send the message forget me to JobSwitch on WhatsApp. We delete your resume, chat history, and application records within 24 hours.

No forms, no email chain, no "are you sure?" loops. If you want a copy of your data before you delete it, ask — we'll send it to you.

Security practices

  • WhatsApp webhook signatures are validated with HMAC-SHA256 on every inbound message. We drop anything that doesn't match.
  • Internal service tokens protect every machine-to-machine endpoint. No public APIs handle your data.
  • Postgres is bound to localhost (in development) or only reachable inside our Docker network (in production). No host ports exposed.
  • Secrets are never committed to source control. Production secrets live in environment variables on the server.
  • HTTPS-only, secure cookies, SSL redirect in production.

We're a small team and don't pretend to be SOC 2 today. We'll get there. What we promise now is that the basic stuff — the stuff that actually keeps your data safe — is done carefully.

Want the formal version?

See our Privacy Policy for the legal terms, Data Processing Addendum for the GDPR-style processor terms, and Terms of Service for the rest. If you have a specific concern that isn't covered, message us on contact.

The last job hunt you'll ever run.

Send one message. Let JobSwitch do the rest.

Free during beta. Available now in India.