Your resume is the product's input, not its product.
1. What we collect
- Account data: the email address you use to join the waitlist or sign in.
- Resume content: the resume text you provide. This is the core personal data you give us and typically contains your name, contact details, work history, and education.
- Derived profile: a structured fact source we generate from your resume (skills, roles, dates) plus the search preferences you set (target roles, compensation floor, remote policy, locations).
- Activity data: jobs matched to you, rankings, application pipeline states, and postings you clip.
- Generated documents: the tailored resumes and cover letters we produce for you.
- Billing data: your subscription tier and status. Card numbers never touch our servers; Stripe holds them.
- Usage analytics: which pages and features you use, collected via PostHog through our own domain. No advertising trackers, ever.
- Operational logs: standard request metadata (timestamps, coarse status).
2. How we use it
Solely to operate the Service for you: parse your resume into the fact source, search compliant job sources, score matches against your gates, generate tailored documents, and bill your plan. We do not sell your personal data, use it for advertising, or use your resume or documents to train AI models.
3. Who touches your data (sub-processors)
- Anthropic (Claude API): receives job-posting text and your resume-derived content to parse, score, and draft. Per Anthropic's API terms, API inputs are not used for model training.
- Stripe: payment processing. Your card is entered on Stripe's pages and stored by Stripe, never by us.
- Resend: sends transactional email (sign-in links, account notices) to the address you registered.
- Vercel: hosts the web application and serves your access-gated pages.
- Amazon Web Services (AWS, US East): runs the servers that store your profile, resume, and job matches, and that generate your tailored documents. Storage is encrypted at rest and backed up daily to AWS S3.
- PostHog (US cloud): product analytics as described above.
- Job sources (freehire, RemoteOK, Remotive, The Muse, public applicant-tracking pages such as Greenhouse, Lever and Ashby, and, when used for a given search, USAJOBS and Adzuna): we send them keyword and geography queries only - never your name, email, or resume.
Fonts are self-hosted; pages make no requests to Google or any font CDN.
4. Cookies
One essential authentication cookie keeps you signed in. A pseudonymous analytics identifier is stored in your browser and sent to PostHog through commuter.dev; no third-party analytics script runs on the page. One first-party cookie (cm_land, 30 days) records how you first arrived: the address of the page you landed on, the site that linked you here, and the time. We use it to learn which communities bring people to Commuter; it holds no name, email, or anything from your resume, and it is read only when you join the waitlist or sign up. There are no advertising trackers or third-party advertising cookies.
4a. The autofill browser extension (optional)
If you install the Commuter autofill extension, it runs only when you click it on a job application page at a supported applicant-tracking site, and it does two things: it fetches your own profile (name, contact details, work history, education, skills) and the CV and cover letter Commuter rendered for that exact posting, and it fills the form fields it can answer from that material. It never invents an answer: a field your profile cannot fill is left blank and highlighted. It never submits an application; you do. It sends nothing to anyone but Commuter, and it sends Commuter nothing but the posting URL, so we can find your documents for it. It authenticates with a personal token you generate in Settings, stored only in your browser; generating a new one replaces the old one, and revoking it disables the extension at once. We log the calls (which endpoint, when, which account) for abuse control, not their contents, and we never read, store, or see the application form itself. When you click Fill, the extension also reports to our analytics (PostHog, routed through commuter.dev, as in section 4) that a fill started, completed, or failed, with the name of the applicant-tracking system and counts of fields filled and left, tied to your Commuter account. Never the posting, a field value, or page content. On Professional and Scale plans, Fill also sends the text of the application questions the form left blank, together with your fact source and the posting, to our model provider (Anthropic, under our API agreement, not used to train their models) so Commuter can draft answers from your own facts; the drafts are shown to you in the form before you submit anything, each call is recorded against your monthly assistant budget, and the questions and answers are kept with your tailored documents so you can see exactly what was asked and answered.
5. Where it lives and how long
Your live data is stored on infrastructure we control, isolated per account. We keep it while your account is active. Accounts inactive for 12 months are deleted after an email notice. Waitlist emails are kept until launch outreach completes or you ask us to remove yours. Encrypted disaster-recovery archives expire within 30 days; deletion tombstones prevent an older archive from restoring a deleted account during that window.
One thing survives deletion. To stop a deleted account from being re-created to reset a free trial, we keep a small anti-abuse record: hashed forms of the identifiers on the account (pseudonymized, not anonymous) - email address, phone digits, and name - plus a similarity fingerprint of the resume that cannot be turned back into its text. This record holds no resume, documents, job pool, or billing data. It lets us recognize the same hashed identifier if it is submitted again and flag a substantially similar resume; it is not used for anything else and is not shared. We keep it unless and until we stop running the free-trial abuse check.
6. Deletion and your rights
Delete your account yourself from Settings: one click immediately removes everything associated with it, including your live resume, derived profile, generated documents, job pool, sign-in email, and billing record - everything except the anti-abuse record described in section 5. Encrypted backup copies age out within 30 days and cannot be restored as a live account because the restore process reapplies a non-identifying deletion tombstone. Your generated documents can be exported before you go. Deletion is a real, tested operation, not a manual promise, and you can also email mike@0pon.com to have it done for you. We honor access and deletion requests for everyone regardless of jurisdiction.
Where we operate. The Service is operated from and directed to the United States. We do not currently accept signups from the United Kingdom, the European Union, the wider EEA, or Switzerland, and requests from those regions are refused at the door rather than accepted and stored, because we would rather turn someone away than hold their resume under terms that do not properly cover them. If you reached us from one of those regions and believe we hold data about you, email mike@0pon.com and we will find and delete it.
7. Security
All access is authenticated; every user's data is isolated from every other user's, and that isolation is covered by automated tests and independent adversarial review. Data moves over TLS everywhere, including between our edge and backend over an encrypted private network (Tailscale).
8. Children
Commuter is for adults seeking employment and is not directed to anyone under 18.
9. Changes and contact
Changes are posted here with an updated date. Questions: mike@0pon.com, 0pon, LLC, Washington, DC.