Security

Security at iNeedAutoJob

We never store your job-site passwords, your data is encrypted and yours, and nothing is ever submitted without your approval.

No stored job-site passwords

Applies run in your own logged-in browser — we never store your job-board passwords. Your resume is encrypted at rest with AES-256-GCM.

You approve everything

Nothing is submitted automatically. Every application is a click you make.

Honest by design

When something fails, you get the exact reason — no silent drops.

Last updated: July 16, 2026

This page describes the concrete practices we use to protect your account and your data on iNeedAutoJob. We focus on describing what we actually do — not on badges we haven’t earned.

Encryption

Sensitive data you provide — such as your resume and profile — is encrypted at rest using AES-256-GCM, an authenticated encryption standard with a random initialization vector per secret, and is never stored in plain text. Traffic between your browser and the app travels over HTTPS/TLS, so data is protected in transit as well as at rest.

How job-site sign-in is handled

We never store your job-site passwords. Applications on JobStreet, Indeed, and LinkedIn happen inside your own already-signed-in browser session — the extension never sees or transmits your password, and there are no stored job-board credentials for us to hold or leak. You stay signed in on each site as you normally would; you can disable or remove the extension at any time.

Your session, your IP

JobStreet, Indeed, and LinkedIn require applications to be filed from your own logged-in session. The optional browser extension acts within that session to complete forms you’ve approved — using your login, your session, and your IP. It runs only while enabled, works on your behalf, and can be disabled or removed whenever you like.

You’re always in control

The engine drafts and queues applications, but it never submits anything on its own. Every application requires your explicit approval, individually or in bulk. If a job can’t be applied to, the queue reports the exact reason so you’re never left guessing — we practice honest failure reporting rather than silent drops.

Access & data handling

  • Access to production data is limited to what’s needed to operate and support the Service.
  • We don’t sell your personal data, and we share it only with the providers that help run the product (see below).
  • Your data belongs to you — export it (on Pro) or request deletion at any time.

Infrastructure & sub-processors

We rely on a small set of trusted providers to run the Service, and share only what each needs:

  • Supabase — database and authentication.
  • Google Gemini — AI text generation.
  • Vercel — application hosting.
  • Resend — transactional email (e.g. sign-in codes).
  • Our payment provider — Pro subscription billing.

Resume handling

We read the text of the resume PDF you upload so the AI can tailor applications accurately. Uploading a new PDF replaces the old one; an ordinary save never wipes it. ATS-optimized versions are generated as copies — your original is never overwritten.

Report a security issue

Found a vulnerability or have a concern? We appreciate responsible disclosure. Email support@ineedautojob.com and we’ll respond promptly.

Security — iNeedAutoJob