Skip to main content

Privacy Policy

Last updated August 9, 2026

This policy explains what Remotera (“we”, “us”) collects, why, and what we do with it — across the Remotera website, the Remotera browser extension, and the Remotera Telegram bot. In plain terms: we store the job-search and job-application details you give us, and we use them to show you relevant roles and to fill out and submit applications on your behalf. We do not sell your data and we do not run ads.

Who this applies to

This policy covers the Remotera website, the Remotera browser extension, and the Remotera Telegram bot (collectively, the “Service”). Remotera is an independent, community-driven project, and is the data controller for the information described here; you can reach us at the address at the bottom of this page. Using the Service means you agree to this policy.

What we collect

We collect only what the Service needs to help you find and apply to jobs:

  • Account information. An email address, a display name, and — if you sign in with Google, GitHub, or Telegram — the profile details that provider returns to us (see “Signing in” below). We also store which sign-in methods are linked to your account and when you last signed in.
  • Applicant profile you provide. When you build your applicant profile we store what you enter: your name, contact details, home or mailing address, professional links (e.g. LinkedIn, GitHub, portfolio), your résumé, and the answers you save to common application questions (such as work authorization, notice period, salary expectation, and free-text responses). This is personally identifiable information that you knowingly give us so it can be reused across applications.
  • Search preferences and alerts. The filters you save, the roles and skills you follow, your eligibility country, and the alert rules you set up — including the Telegram account you link for delivery, if you link one.
  • Job-application form content. When you ask the extension to fill an application — or when you enable automatic applying — it reads the application form on the page you are applying through (the field labels and questions) so it can map your profile to the right fields. Where a question is new, the field text is sent to our backend to work out the appropriate answer from your profile. The extension reads a page only to find and fill an application form; it does not read or collect the content of other pages you browse.
  • Application records. When an application is filled or submitted, we keep a record of it — the job, the destination, the outcome, and the values that were entered — so you have a history of everything you applied to.
  • Content you post. Comments and reactions you leave on job postings and blog articles, stored with your display name. These are public — see “Content you post” in our Terms.
  • Product analytics. Which pages you open, which features you use, and the errors you hit, together with your account id, email address, and role once you are signed in. This is described in “Analytics and cookies” below.
  • Technical diagnostics. Error messages and stack traces from the website and the extension, so we can fix bugs.

We do not collect your passwords or login credentials for other services, health information, payment-card or financial data, your personal communications, your precise device location, or a history of the websites you browse.

Signing in

You can create an account with an email address and password, or through a third-party provider. When you use a provider, we receive only what that provider is asked to release for sign-in:

  • Google. Your name, email address, email-verified status, profile picture, and Google account id. We request only the basic profile and email scopes — we cannot read your Gmail, Drive, Calendar, Contacts, or any other Google data, and we never ask for that access.
  • GitHub. Your username, name, email address, avatar, and GitHub account id. We do not read your repositories.
  • Telegram. Your Telegram id, first/last name, username, and photo. Telegram does not release an email address, so we hold a placeholder address for the account.
  • Email and password. Your email address and a salted, hashed password — we never store the password itself.

When you sign in through a provider we store the access and refresh tokens that provider issues, encrypted at rest. They are used only to complete and maintain your sign-in, never to act on your behalf on that provider. Disconnecting a provider or deleting your account deletes them.

Analytics and cookies

We set a session cookie on .remotera.ai when you sign in. It is strictly necessary — without it the Service cannot tell that a request is yours — and it is removed when you sign out. Product analytics stores one more thing: an anonymous device id (ph_…_posthog) in a first-party cookie, localStorage and sessionStorage, so repeat visits from one browser count once. We do not use advertising or cross-site tracking cookies.

We use PostHog for product analytics and error tracking. It records page views, feature usage, and uncaught errors, and — once you are signed in — associates them with your account id, email address, and role, so that a bug report or a broken sign-in can be traced to a real session instead of guessed at. PostHog is a third-party processor and stores this data on servers in the United States.

Reject analytics in the cookie notice and we stop capturing immediately, delete the analytics id already stored in your browser, and store nothing on later visits. Analytics also does not load at all if you enable your browser's “Do Not Track” or an ad/tracker blocker that blocks PostHog. You can also ask us to delete your analytics history using the contact address below.

What the extension accesses on your device

The browser extension requests only the access it needs to detect and fill application forms, and it acts only when you start a fill or turn on automatic applying:

  • Access to job sites you apply on. Job applications live on thousands of employer and applicant-tracking sites that can’t be listed in advance, so the extension needs broad site access to locate the form on whatever page you’re applying through. It uses this only to detect and fill application forms.
  • Your Remotera sign-in state. The extension reads its own Remotera session cookie to know whether you are signed in. It does not read cookies for other websites.
  • Tabs, side panel, and on-page controls. To open a posting, show its own side-panel interface, and let you start a fill from the page or a right-click menu.
  • Local storage on your device. Your settings and your local apply/review queue are stored on your own device.

How we use your data

We use the information above only to:

  • fill out and (when you choose) submit job applications for you;
  • reuse your saved answers across applications so you don’t retype them;
  • rank and filter job postings against your profile and preferences;
  • send the job alerts and account emails you asked for;
  • keep your history of applications and their outcomes;
  • operate, secure, debug, and improve the Service.

We do not use your data for advertising, we do not sell it, and we do not use it to determine creditworthiness or for lending. We do not use your profile or your application content to train AI models.

When data leaves our systems

Your data is stored in our own database on our own servers. We share it only in these limited ways:

  • To submit your applications. When you apply to a job, the values you approved are entered into that employer’s or applicant-tracking system’s application form — that is the point of the Service.
  • To generate answers. To work out answers to application questions and to tailor a résumé, some text (the application’s question and the relevant parts of your profile) is processed by our third-party AI provider, currently OpenAI. It is used only to produce your answer.
  • Product analytics. Usage and error events go to PostHog, as described above.
  • Email delivery. Account emails (verification, password reset, notifications) are delivered by Resend, which receives your email address and the message.
  • Telegram delivery. If you link Telegram for job alerts, the alert messages are delivered to you through Telegram.
  • Infrastructure. We use standard hosting and infrastructure providers to run the Service.

We do not sell or rent your personal data, and we do not transfer it to third parties for purposes unrelated to the Service. If the Service is ever transferred to another operator, we will say so here before your data moves.

Where your data is stored

Our database and application servers are hosted in the European Union. Some of the processors listed above — our AI provider, our analytics provider, and our email provider — operate in the United States, so using the Service involves transferring some of your data there. We only send those processors what each of them needs for the task described above.

Why we are allowed to process your data

If you are in the EEA or the UK, our legal bases are:

  • Performance of a contract. Your account, profile, applications, and alerts exist because you asked us to provide them.
  • Legitimate interests. Keeping the Service secure, debugging it, and understanding how it is used, balanced against your privacy.
  • Consent. Where we ask for it explicitly — for example before an application is submitted on your behalf. You can withdraw consent at any time.

Your rights over your data

Wherever you live, you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct anything that is wrong — most of it you can edit yourself in your profile;
  • delete your account and the personal data attached to it;
  • export your data in a machine-readable form;
  • stop a particular use, including product analytics;
  • withdraw a consent you previously gave.

Write to the address at the bottom of this page and we will act on it. We will not charge you or make you justify the request. If you are in the EEA or the UK and you think we have handled your data badly, you also have the right to complain to your national data-protection authority.

Data retention and deletion

We keep your profile, answers, and application history for as long as your account is active. Delete your account and we delete that data, except where we are required to keep something by law. Job postings themselves are public information and are not personal to you — they stay in the catalogue after you leave.

Security

Access to the Service requires you to be signed in, requests carrying your data are transmitted over encrypted connections, passwords are stored hashed, and third-party sign-in tokens are encrypted at rest. No system is perfectly secure, but we take reasonable measures to protect your information.

Children

Remotera is intended for adults in the workforce and is not directed to children. We do not knowingly collect data from anyone under 16.

Changes to this policy

We may update this policy as the Service evolves. When we do, we will revise the “last updated” date above, and material changes will be reflected here.

Contact

Questions about this policy or your data? Email us at support@remotera.ai.

Terms of Service