commuter
privacy policy

Your resume is the product's input, not its product.

0pon, LLC (Washington, DC) · last updated 2026-09-01

1. What we collect

2. How we use it

Solely to operate the Service for you: parse your resume into the fact source, search compliant job sources, score matches against your gates, generate tailored documents, and bill your plan. We do not sell your personal data, use it for advertising, or use your resume or documents to train AI models.

3. Who touches your data (sub-processors)

Fonts are self-hosted; pages make no requests to Google or any font CDN.

4. Cookies

One essential authentication cookie keeps you signed in. A pseudonymous analytics identifier is stored in your browser and sent to PostHog through commuter.dev; no third-party analytics script runs on the page. One first-party cookie (cm_land, 30 days) records how you first arrived: the address of the page you landed on, the site that linked you here, and the time. We use it to learn which communities bring people to Commuter; it holds no name, email, or anything from your resume, and it is read only when you join the waitlist or sign up. There are no advertising trackers or third-party advertising cookies.

4a. The autofill browser extension (optional)

If you install the Commuter autofill extension, it runs only when you click it on a job application page at a supported applicant-tracking site, and it does two things: it fetches your own profile (name, contact details, work history, education, skills) and the CV and cover letter Commuter rendered for that exact posting, and it fills the form fields it can answer from that material. It never invents an answer: a field your profile cannot fill is left blank and highlighted. It never submits an application; you do. It sends nothing to anyone but Commuter, and it sends Commuter nothing but the posting URL, so we can find your documents for it. It authenticates with a personal token you generate in Settings, stored only in your browser; generating a new one replaces the old one, and revoking it disables the extension at once. We log the calls (which endpoint, when, which account) for abuse control, not their contents, and we never read, store, or see the application form itself. When you click Fill, the extension also reports to our analytics (PostHog, routed through commuter.dev, as in section 4) that a fill started, completed, or failed, with the name of the applicant-tracking system and counts of fields filled and left, tied to your Commuter account. Never the posting, a field value, or page content. On Professional and Scale plans, Fill also sends the text of the application questions the form left blank, together with your fact source and the posting, to our model provider (Anthropic, under our API agreement, not used to train their models) so Commuter can draft answers from your own facts; the drafts are shown to you in the form before you submit anything, each call is recorded against your monthly assistant budget, and the questions and answers are kept with your tailored documents so you can see exactly what was asked and answered.

5. Where it lives and how long

Your live data is stored on infrastructure we control, isolated per account. We keep it while your account is active. Accounts inactive for 12 months are deleted after an email notice. Waitlist emails are kept until launch outreach completes or you ask us to remove yours. Encrypted disaster-recovery archives expire within 30 days; deletion tombstones prevent an older archive from restoring a deleted account during that window.

One thing survives deletion. To stop a deleted account from being re-created to reset a free trial, we keep a small anti-abuse record: hashed forms of the identifiers on the account (pseudonymized, not anonymous) - email address, phone digits, and name - plus a similarity fingerprint of the resume that cannot be turned back into its text. This record holds no resume, documents, job pool, or billing data. It lets us recognize the same hashed identifier if it is submitted again and flag a substantially similar resume; it is not used for anything else and is not shared. We keep it unless and until we stop running the free-trial abuse check.

6. Deletion and your rights

Delete your account yourself from Settings: one click immediately removes everything associated with it, including your live resume, derived profile, generated documents, job pool, sign-in email, and billing record - everything except the anti-abuse record described in section 5. Encrypted backup copies age out within 30 days and cannot be restored as a live account because the restore process reapplies a non-identifying deletion tombstone. Your generated documents can be exported before you go. Deletion is a real, tested operation, not a manual promise, and you can also email mike@0pon.com to have it done for you. We honor access and deletion requests for everyone regardless of jurisdiction.

Where we operate. The Service is operated from and directed to the United States. We do not currently accept signups from the United Kingdom, the European Union, the wider EEA, or Switzerland, and requests from those regions are refused at the door rather than accepted and stored, because we would rather turn someone away than hold their resume under terms that do not properly cover them. If you reached us from one of those regions and believe we hold data about you, email mike@0pon.com and we will find and delete it.

7. Security

All access is authenticated; every user's data is isolated from every other user's, and that isolation is covered by automated tests and independent adversarial review. Data moves over TLS everywhere, including between our edge and backend over an encrypted private network (Tailscale).

8. Children

Commuter is for adults seeking employment and is not directed to anyone under 18.

9. Changes and contact

Changes are posted here with an updated date. Questions: mike@0pon.com, 0pon, LLC, Washington, DC.