← Back to app

Privacy Policy

Last updated: September 4, 2026

The short version: We collect only what is necessary to provide the service and the Chrome extension's single purpose. We do not sell your data, use it for advertising, or use your resume to train AI models. The extension does not collect employer passwords, one-time codes, CAPTCHA answers, signatures, or protected-trait answers, and it never submits an application. Your payment information is handled by Stripe, and we never see your full card number.

This Privacy Policy explains how 1stStep.ai ("we," "us," or "our"), operated from New Jersey, collects, uses, discloses, retains, and protects information when you use our platform at app.1ststep.ai or the 1stStep.ai Job Agent Chrome extension (together, the "Service").

1. Information We Collect

Category What We Collect Why
Account info First name, last name, email address To identify your account and verify your subscription status
Resume content Resume text, uploaded files, confirmed career facts, skills, education, employment history, achievements, and generated application documents To maintain your encrypted applicant vault and prepare materials you request
Job and application data Job title, employer, location, requisition identifier, job URL, job description, match assessment, application status, and fields you approve for an application To identify duplicate jobs, evaluate fit, prepare application materials, and support supervised form filling
Supported-page content On supported Greenhouse pages: the active page URL, job listing content, and the labels, types, options, and internal references of ordinary application fields To identify the exact job, show the user what can be filled, and return only approved values for that application
Device and security data IP address, browser request metadata, session and handoff identifiers, timestamps, rate-limit events, and security or error events To authenticate requests, prevent replay and abuse, preserve application state, and diagnose failures
Usage data Feature usage, security events, request counts, and content-free operational measurements To enforce plan and cost limits, prevent abuse, troubleshoot failures, and operate the service
Payment info Processed by Stripe — we only receive a subscription status confirmation To manage paid subscriptions

We do not ask the Chrome extension to collect or fill government IDs, Social Security numbers, health information, precise geolocation, employer passwords, passkeys, one-time codes, CAPTCHA answers, signatures, attestations, or answers about protected traits. The extension also excludes hidden fields, password fields, checkboxes, radio buttons, and final-submit controls from its approved-field workflow. Location preferences that you choose to save may be stored in your encrypted applicant vault.

2. How We Use Your Information

We use the information we collect to:

We do not use your resume, job descriptions, or personal information to train AI models, build advertising profiles, or sell to third parties.

3. How Your Data Is Processed

When you request resume tailoring, job matching, or an application package, the information needed for that request is sent over HTTPS to our Vercel serverless functions. An approved AI provider may process the minimum resume, profile, job-description, and instruction content needed to produce the requested output. We do not use that content to train our own models.

If you enable secure backup or use Job Agent features, confirmed profile facts, documents, job-search preferences, application workspace records, and consent records are stored server-side in tenant-partitioned encrypted records. Encryption keys remain in server-only production configuration. The Chrome extension does not keep a reusable copy of your applicant vault or resume documents.

When the extension is enabled and you visit a supported Greenhouse page, it automatically reads the active listing's URL, job title, company, location, and job description so it can recognize the job and show its user-facing controls. That detected listing is held in Chrome session storage. It is not sent to 1stStep.ai merely because you visited the page.

When you choose to start the supervised fill workflow, the extension sends app.1ststep.ai the exact page URL and a value-free description of eligible form fields, such as field labels, types, options, and internal references. The server authenticates the signed-in session, reverifies the public job, checks your approval and application session, and calculates a match assessment. If the application is eligible, the server returns only the confirmed values approved for those fields and, where applicable, the approved resume file for that exact application. The extension does not retain those returned candidate values or resume bytes as a reusable profile.

After filling, the extension reports which approved field keys succeeded or failed so the Service can preserve the checkpoint. It does not send the entered values back in that completion report and does not click the employer's final submit control. The user must review the employer page and decide whether to submit.

4. Third-Party Services

We work with the following third-party providers who may process your data:

Provider Purpose Data Shared
Approved AI providers, including OpenAI and Anthropic Resume tailoring, application documents, and other user-requested AI processing The minimum resume, profile, job-description, and instruction content needed for the requested output.
Stripe Payment processing Email address, payment card details. Subject to Stripe's Privacy Policy.
Vercel Hosting and serverless infrastructure Standard server request logs (IP, timestamp, route). Subject to Vercel's Privacy Policy.
Upstash Encrypted account records, opaque sessions, rate limits, and short-lived workflow coordination Encrypted tenant data and pseudonymous operational keys. Upstash does not receive employer passwords, OTPs, or CAPTCHA answers.
GoHighLevel (GHL) CRM — customer account records for paid subscribers Name and email upon subscription. Subject to GoHighLevel's Privacy Policy.
Resend Account verification and transactional email Email address and the minimum delivery metadata needed to send and suppress transactional messages.
Google Chrome and Chrome Web Store Extension distribution, updates, and browser APIs used for local extension operation Google may process installation, update, crash, security, and browser telemetry under your Chrome settings and Google's own privacy terms. We do not provide Google with your applicant vault or approved application values.

Public applicant-tracking services such as Greenhouse may be queried to verify a public job listing. When you direct the extension to fill an employer form, the approved values are written into that employer-controlled page and therefore become visible to the employer site's systems. The extension does not press the final submit control. We do not allow our service providers to use your data for our advertising or to sell it on our behalf.

5. Data Retention

Encrypted applicant-vault records, consent records, preferences, and schedules may be retained for up to 365 days after their most recent use. Application runs, generated-document objects, notifications, and related workflow records generally expire within 30 to 90 days. Content-free operational and spend measurements generally expire within 8 days, and signed extension handoff tokens expire within minutes.

The extension keeps the currently detected job in Chrome session storage for the browser session. A captured job awaiting delivery to the app is designed to be short-lived and removed after acknowledged delivery or expiry; because browser cleanup runs when the extension is active, an expired entry may remain locally until the next cleanup event, until you clear extension data, or until you uninstall the extension. Approved candidate values and resume bytes returned for a fill are used transiently and are not saved by the extension as a reusable profile.

Revoking an individual saved fact prevents its future use but may retain its prior encrypted version until the containing vault expires or the account is deleted. An account-deletion request removes the active tenant records and private objects controlled by 1stStep, subject to provider processing time and records that must be retained for security, payment, tax, dispute, or other legal obligations. Some payment and email-suppression records are maintained by the applicable provider under its own retention requirements.

6. Your Privacy Rights

Depending on where you reside, you may have the following rights regarding your personal data. To exercise any of these rights, email us at support@1ststep.ai. We will respond within 45 days; if we need more time, we will notify you and may extend the response period by an additional 45 days.

Right to Know / Access Request a copy of the personal data we hold about you and how it is used.
Right to Correct Request correction of inaccurate personal data we maintain about you.
Right to Delete Request deletion of your personal data, subject to legal retention obligations.
Right to Data Portability Receive a copy of your data in a portable, machine-readable format.
Right to Opt-Out We do not sell personal data or use it for targeted advertising. There is nothing to opt out of.
Right to Non-Discrimination We will not deny service, charge different prices, or treat you differently for exercising any of these rights.

New Jersey residents have rights under the New Jersey Data Privacy Act (N.J.S.A. 56:8-166.1 et seq., effective January 15, 2025), including the rights listed above. If we deny your request, you may submit an appeal by emailing support@1ststep.ai with the subject line "Privacy Rights Appeal." We will respond to appeals within 60 days and will provide a written explanation of our decision. If your appeal is denied, you may contact the New Jersey Division of Consumer Affairs at njconsumeraffairs.gov.

California residents have rights under the California Consumer Privacy Act (CCPA), including the rights listed above. We will respond to verifiable consumer requests within 45 days.

7. Cookies and Local Storage

1stStep.ai uses a secure, HTTP-only session cookie for signed-in access and may use browser localStorage or sessionStorage for device-local workflow state. Information is transmitted to our servers when you request cloud backup, matching, tailoring, extension handoff, application preparation, export, deletion, or another server-backed feature.

The Chrome extension uses Chrome session storage for the currently detected job and Chrome local storage for a short-lived captured-job handoff. The extension authenticates server requests through the open app.1ststep.ai tab and its HTTP-only session cookie; it does not read or store that cookie, a bearer token, passwords, complete applicant-vault records, or reusable resume documents. Stripe may set cookies for fraud prevention and payment processing.

8. Chrome Extension

Single purpose. The extension's single purpose is to help a signed-in user review a supported Greenhouse job, understand its match assessment, and fill ordinary application fields with values the user has already confirmed. It is not a general browsing monitor, job-board scraper, credential manager, or autonomous application-submission tool.

Complete functional outline. The extension:

Permissions used.

PermissionHow the extension uses it
Supported site accessRuns only on app.1ststep.ai and the specifically declared Greenhouse hosts needed to detect jobs and support the supervised workflow.
activeTabReads the active supported tab when the user invokes an extension action.
tabsFinds an open 1stStep.ai tab, opens or focuses the correct 1stStep.ai workflow, and communicates with the same-origin authentication bridge.
storageKeeps the currently detected job, short-lived capture records, and limited operational state described in Sections 5 and 7.
sidePanelAllows Chrome to present the extension's Job Agent interface alongside a supported page where that interface is available.

When it operates. The extension is limited to app.1ststep.ai and supported Greenhouse pages. On a supported page it detects the current job locally so it can present relevant controls. Website content is transmitted to 1stStep.ai only when needed for a user-facing action that you initiate, such as opening the job in 1stStep.ai or starting the supervised fill workflow.

What it does not do. The extension does not collect general browsing history, run on unrelated sites, execute remotely hosted code, bypass employer security controls, answer consequential questions, sell data, use data for personalized advertising or credit decisions, or automatically submit applications.

Limited Use. 1stStep.ai's use and transfer of information received through the Chrome extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use extension data only to provide or improve the disclosed single purpose and related security, reliability, and support operations. We do not transfer it to advertising platforms, data brokers, or information resellers. We do not permit people to read user-specific extension data unless you explicitly authorize access for support, access is necessary to investigate abuse or a security incident, access is required by law, or the data has been aggregated and anonymized for lawful internal operations.

Your controls. You can stop page access by disabling or uninstalling the extension, clear local extension data through Chrome, and request access to or deletion of server-side personal data by contacting us as described below. Uninstalling the extension does not automatically delete records stored in your 1stStep.ai account.

9. Data Security & Breach Notification

We use HTTPS for data in transit, authenticated encryption for protected server-side records, tenant-scoped access controls, revocable sessions, bounded access tokens, rate limits, and server-only provider credentials. Passwords, OTPs, CAPTCHA answers, and full payment card numbers are not stored by 1stStep. However, no method of internet transmission or electronic storage is 100% secure, and we cannot guarantee absolute security.

In the event of a security breach affecting your personal data, we will notify affected New Jersey residents as required under the New Jersey Identity Theft Prevention Act (N.J.S.A. 56:8-163). Notification will be made in the most expedient time possible and without unreasonable delay, and no later than 30 days after we discover the breach, unless a law enforcement agency determines that notification would impede a criminal investigation.

10. Children's Privacy

1stStep.ai is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has submitted personal information to us, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. For significant changes, we will make reasonable efforts to notify you by email or through a notice in the app at least 30 days before the changes take effect. Continued use of the service after changes are posted constitutes your acceptance of the updated policy.

Questions or requests about your data?
Email us at support@1ststep.ai. We take privacy seriously and will respond promptly. For New Jersey privacy rights matters, you may also contact the New Jersey Division of Consumer Affairs at njconsumeraffairs.gov.