Privacy Policy
Last updated: September 17, 2026
Sift (sift-jobs.com) helps you discover internship postings and prepare job applications, with an optional browser extension that autofills forms you have already reviewed and approved. This policy covers the Sift web application, API, and browser extension together.
What we collect
We collect information you provide directly or authorize us to access to operate the service:
- Account credentials — your name and email address, managed through our authentication provider (Clerk).
- Candidate documents & professional history — uploaded resumes, cover letters, and academic transcripts (PDF or DOCX format), as well as structured education history, work experience, contact details (phone number, mailing address), work authorization (citizenship and visa sponsorship requirements), target preferences (desired roles, locations, salary expectations), and links to your professional profiles (LinkedIn, GitHub, or portfolio website).
- Supporting evidence links — public HTTPS URLs you choose to provide (such as your personal portfolio or GitHub profile/repository). Sift performs a bounded fetch of public page content to store a text snapshot, record source metadata, and extract candidate facts for your optional review.
- Watchlist & job preferences — companies, job boards, and catalog search parameters you track.
- Generated drafts & applications — tailored resume versions, proposed wording rewrites, and application records created for specific job postings.
- Extension operational data — an account-scoped authentication token, short-lived cached application packages (retained for up to 5 minutes), and local question-and-answer memory stored strictly on your device (see the extension section below).
- Slack integration data — if you opt in to Slack notifications: the specific channel and webhook URL you authorize us to post to.
Voluntary demographic & equal opportunity data
You may optionally provide voluntary self-identification data for standard Equal Employment Opportunity (EEO) categories:
- Race or ethnicity
- Disability status
- Veteran status
Providing this information is entirely optional. It does not affect internship discovery or match scoring. If provided, it is stored in your profile and used solely to populate voluntary self-identification fields in user-approved autofill packages for the browser extension. This information is never transmitted to Google Gemini or any third-party AI provider.
Why we collect it
We collect and process your information solely to deliver and improve Sift: matching your profile against internship openings, generating tailored draft application materials, autofilling fields you review and approve, and sending optional notification alerts. We do not sell your personal information, and we do not use your data for advertising or cross-context behavioral marketing.
Who we share it with
We work with trusted service providers (subprocessors) to run Sift, sharing only the data required to perform each function:
- Clerk — handles user authentication and session management; we never see or store your password.
- Supabase — provides hosted PostgreSQL database infrastructure (storing profile, application, preferences, and match data).
- Google (Gemini API) — provides generative AI capabilities across two distinct workflows:
- Resume extraction ("Extract with LLM"): When you choose this option on an uploaded resume, up to 12,000 characters of unparsed resume text is sent to Google's Gemini API to extract education history, degree level, GPA, and work experience entries.
- Resume tailoring: When generating a tailored draft for a specific posting, reviewed resume bullets, reviewed supporting facts, and job posting details (title, company, description, and required/preferred skills) are sent to Gemini to propose wording revisions.
Data is transmitted per-request over encrypted HTTPS. Sift configures requests using commercial API settings under which Google does not use customer API prompts or outputs to train foundation models. However, data transmitted through the API remains subject to Google's standard operational data processing, temporary caching, and abuse-monitoring practices under its API terms.
- Oracle Cloud Infrastructure (OCI) — hosts our application servers and encrypted object/file storage for uploaded and generated documents.
- Slack — receives notification payloads only if you explicitly authorize the Slack OAuth connection.
Beyond these operational subprocessors, we do not share your personal information with third parties except under narrow circumstances: (a) to comply with valid legal processes, applicable laws, or governmental requests; (b) to protect the security, integrity, and legal rights of Sift, our users, or the public; (c) to investigate or prevent fraud or system abuse; or (d) in connection with a corporate acquisition, merger, financing, or sale of company assets.
Data retention
Your active account information and profile data persist for as long as your account remains open. Operational retention rules for specific categories of data are as follows:
- Submitted applications: When an application is marked submitted (or transitions to an interview, rejection, or withdrawal after submission), its generated tailored resume file is retained for 90 days from the submission date. This ensures you can access and download the exact resume you submitted throughout active interview processes. After 90 days, the generated file is automatically and permanently purged by our cleanup worker.
- Unsubmitted applications: If an application is marked withdrawn or rejected before ever being submitted, its generated tailored resume file is purged immediately on the next automated cleanup cycle.
- Uploaded documents: Your original uploaded resumes, cover letters, and transcripts remain stored until you delete them in your dashboard, replace them with an updated file, or request account deletion.
- Supporting evidence snapshots & facts: Text snapshots of public portfolio or GitHub pages and candidate facts extracted from them persist for as long as the associated resume profile remains active. You can disable a supporting source or revoke individual facts in your dashboard at any time to prevent them from being used in application tailoring. Snapshots and extracted facts are permanently deleted when you delete the associated resume profile or request account deletion.
- Watchlists & search preferences: Your tracked companies, job board subscriptions, target roles, and location filters persist until you remove them from your dashboard or request account deletion.
Security & breach notification
We implement administrative, technical, and physical safeguards designed to protect your personal information, candidate documents, and voluntary demographic disclosures from unauthorized access, loss, or alteration. These measures include encrypted transmission (HTTPS/TLS) for data in transit, encrypted storage at rest for database records and file assets (via Supabase and Oracle Cloud Infrastructure), least-privilege operational access, and hashed authentication tokens for browser extension sessions.
While we maintain rigorous safeguards, no method of transmission over the internet or electronic storage is completely secure. In the event of a confirmed security incident affecting the confidentiality or integrity of your personal information, we will notify affected users and relevant regulatory authorities in accordance with applicable data breach notification laws.
International data transfers
Sift operates and hosts its services primarily in the United States using cloud infrastructure provided by Oracle Cloud Infrastructure, Supabase, Google, and Clerk. If you access Sift from outside the United States (including from the European Economic Area, United Kingdom, or Switzerland), your personal information will be transferred to, stored, and processed in the United States.
Where required by applicable data protection laws (such as the EU or UK GDPR), cross-border transfers are conducted pursuant to recognized legal transfer mechanisms, including European Commission-approved Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or relevant adequacy decisions, supported by subprocessor contractual commitments.
Cookies & tracking
Sift uses only functional session cookies provided by Clerk to maintain secure authentication. Sift does not run third-party analytics trackers, advertising trackers, or tracking pixels.
The browser extension
The Sift extension autofills application forms on job posting websites using details you have reviewed and approved in your dashboard. The extension never submits an application on your behalf — you review every populated field and click submit yourself.
- URL verification: When you browse supported ATS platforms (such as Greenhouse, Lever, Ashby, or Workday) or pages detected as application forms, the extension sends the current page URL to
api.sift-jobs.com/extension-handoffto determine whether an approved application package exists for that role. Sift uses these URLs solely to identify matching application packages and does not use this mechanism to build a general browsing history. Standard web infrastructure access logs may transiently log HTTP request URLs and query parameters for security, diagnostics, and operational performance. - Account token: Your extension token is stored in your browser's local extension storage (
chrome.storage.local) to authenticate requests toapi.sift-jobs.com. It is never transmitted to any other domain. - Approved package cache: Approved application packages fetched from Sift are cached locally in your browser for up to 5 minutes, after which they expire automatically and are cleared from local storage.
- Local Q&A memory ("Learn as you apply"): When you answer custom open-ended questions on job application forms (such as "Why do you want to work here?"), the extension saves your responses in
chrome.storage.localnamespaced to your user account. This enables the extension to suggest or autofill your previous answers when you encounter similar questions in future applications. These answers are stored strictly on your local device and are never sent to Sift's servers or any third party.
Your controls & account deletion
- Extension access revocation: You can revoke the browser extension's access immediately from your dashboard under Preferences → Extension access → Revoke.
- Clearing local extension data: Signing out of the extension, switching accounts, or uninstalling the extension clears your cached packages, extension tokens, and local Q&A memory from your browser.
- Document management: You can delete or replace your uploaded resumes, cover letters, and transcripts directly in your dashboard at any time.
- Supporting evidence controls: You can disable any supporting source or revoke individual extracted facts in your Evidence dashboard at any time to exclude them from application tailoring. Deleting a resume profile permanently removes all supporting sources, snapshots, and extracted facts associated with that profile.
- Account deletion: To delete your account and associated personal information, contact [email protected]. Upon verification of your request, Sift will delete or de-identify your account, profile, voluntary EEO disclosures, uploaded documents, generated drafts and resumes, match history, watchlist subscriptions, supporting evidence snapshots/facts, and server-side extension tokens from active databases and file storage. Please note that residual copies may persist temporarily in secure system backups until overwritten in accordance with standard backup retention cycles, and server logs or transaction records may be retained as permitted or required by law, security, fraud prevention, or regulatory compliance.
- Local device storage note: Server-side account deletion removes your data from Sift's servers and invalidates your extension tokens, but cannot remotely delete local data stored in
chrome.storage.localon disconnected client devices. To remove local extension data, sign out of or uninstall the browser extension.
Privacy rights & state disclosures
Depending on where you reside, you may have legal rights under applicable privacy laws regarding access to, correction of, deletion of, or obtaining a portable copy of your personal data. To exercise any such rights, please contact us at [email protected].
Notice for California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides specific privacy rights:
- No sale or sharing of personal data: Sift does not "sell" your personal information and does not "share" your personal information for cross-context behavioral advertising.
- Categories of personal information collected: In the preceding 12 months, Sift has collected the following categories: Identifiers (name, email, IP address, extension tokens); Professional or employment-related information (resumes, cover letters, transcripts, work experience); Education information (institutions, degrees, GPA, graduation dates); Protected classifications (voluntary EEO race/ethnicity, disability, veteran status, only if voluntarily provided); Internet or network activity (interactions with application forms via the extension, URLs of visited job application pages); and Geolocation/location preferences (city, state, country, preferred job locations).
- Business purpose disclosures: We disclose the categories above to our subprocessors (Clerk, Supabase, Google Gemini API, Oracle Cloud Infrastructure, Slack) strictly for the operational business purposes described in "Who we share it with."
- Your rights: You have the right to request access to personal information collected, the right to request deletion of your personal information, the right to correct inaccurate information, and the right not to receive discriminatory treatment for exercising your privacy rights. You may submit requests by emailing [email protected].
Children's privacy
Sift is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact [email protected].
Changes to this policy
If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page.
Contact
For questions regarding this policy or to submit a data request, email [email protected].