Privacy Policy
Last updated July 2026
This policy explains what InstantFit collects, why, who we share it with, and the choices you have. It is written to be readable by a job-seeker while remaining precise about how your data is handled.
Who we are
InstantFit operates instantfit.net, a service that helps job-seekers find relevant job postings and prepare application documents. InstantFit is the data controller for the personal data described here. For any privacy question or request, contact us at privacy@instantfit.net.
What InstantFit does, and does not do
Understanding the service makes the rest of this policy clearer.
What InstantFit does
- Collects publicly available job postings from sources such as LinkedIn, with additional sources added over time, through a data-collection provider.
- Uses an AI model (Anthropic Claude) to score how well each posting matches your CV and criteria, and shows you the matches with a link to the original posting.
- On your explicit request, generates a tailored CV or cover letter for a specific job, based on the CV material you uploaded, which you then download and use yourself.
- Sends you email notifications about matches and account events, plus an optional daily digest you can switch on or off in Settings.
What InstantFit does not do
- It does not apply to jobs on your behalf, and does not submit anything to any job board or employer.
- It does not act on any third-party website as you, and never asks for or uses your login details for LinkedIn or any other source.
- It does not sell your personal data, and does not use it for advertising. Applying to a job is always your own action, taken outside InstantFit.
Non-affiliation. InstantFit is an independent service and is not affiliated with, endorsed by, or sponsored by LinkedIn or any other job source. LinkedIn is a trademark of LinkedIn Corporation. We reference job sources only to describe the public postings we surface for signed-in users, and we always link back to the original posting.
What we collect
We collect only what the service needs. All of it comes from you or is generated by the service for you. We do not buy data about you or enrich your profile from other sources.
Account data
Your email address and a hashed password (we never store your password in plain text); email-verification and password-reset tokens (stored only as cryptographic hashes); account settings such as your plan, trial and subscription timestamps, and email-digest preference; and, optionally, a link to your LinkedIn profile if you provide one as matching context (encrypted at rest).
CV and application materials
The CV text you upload or paste (the most sensitive data we hold, encrypted at rest and decrypted only to score a job or generate a document for you), and the tailored CVs and cover letters generated at your request (text and PDF files), stored so you can re-download them.
Job-search preferences
The search criteria you configure: keywords, location, job type, seniority, work mode, excluded words, score-band cutoffs, and scan schedule.
Job data and your activity
Copies of the public postings collected for your searches, the AI match score, its rationale and detected skill gaps, and your own activity on each match: manual score overrides, the application status you record, and any private notes you write.
Billing data
A customer identifier and subscription state from our payment processor, linked to your email. We never see or store your full card details. Those are entered directly with the payment processor on their hosted pages.
Technical data
A small number of essential cookies to keep you signed in and protect the sign-in form (a session cookie, plus a CSRF-protection cookie and a short-lived sign-in callback cookie set by our authentication library); your IP address, used transiently for security rate-limiting (these counters expire automatically); and server logs and error records that may reference your account identifier, used only to run and debug the service. Sensitive fields such as CV text are excluded from logs by design. We use no analytics or tracking scripts, advertising identifiers, or third-party tracking cookies.
Why we process your data
We process your data on the following bases:
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the service: run your searches, score postings against your CV, show matches, generate tailored documents on request | Account data, search preferences, CV text, job data | Performance of a contract |
| Send essential account email (verification, password reset, match notifications) | Email address, match metadata | Performance of a contract |
| Send the optional daily digest email | Email address, activity summary | Consent: opt-in, withdrawable any time in Settings |
| Process subscription payments and manage your plan | Billing data | Contract; legal obligation for tax/accounting records |
| Keep the service secure (login rate-limiting, session revocation, error monitoring) | Technical data | Legitimate interests |
Under Israeli law, we process your data for the purposes for which you registered, consistent with the purpose-limitation requirements of the Protection of Privacy Law, 5741-1981.
AI processing: what we send to Anthropic
Because AI is central to how InstantFit works, we want you to understand it before you upload a CV. To score a job, we send the posting's title and description together with your CV text to Anthropic (the AI provider behind Claude), and receive back a score, a short rationale, and a list of skill gaps. To generate a tailored CV or cover letter (only when you request one), we send the posting text and your CV text to Anthropic and receive the drafted document. If you provide LinkedIn profile context, it may be included in these requests too.
Anthropic processes this data as our service provider to return the result. Under Anthropic's Commercial Terms of Service, data submitted through the paid API is not used to train Anthropic's models. Your CV is never shared with employers, job boards, or any other party. The AI provider receives it solely to compute your results.
International data transfers
Our servers are hosted with Hetzner in Helsinki, Finland (within the EU/EEA). Some of our providers, in particular Anthropic and Resend, are US-based; PayMe and iCount operate from Israel. Where personal data is transferred to them, we rely on the Standard Contractual Clauses incorporated into each provider's Data Processing Agreement as the transfer safeguard. For transfers governed by Israeli law, we rely on the Privacy Protection (Transfer of Data Abroad) Regulations, 5761-2001. Israel benefits from an EU adequacy decision, so data flows between our EU hosting and users in Israel do not require additional safeguards.
Retention, deletion, and backups
- While your account is active, we keep your data so the service can work. We do not auto-delete data from inactive accounts. It is kept until you ask us to delete it, or delete your account yourself.
- How much job history you can see depends on your plan (Free is a 7-day trial with a 7-day window; Pro sees a 30-day window). These are display limits only. The underlying data is retained, not destroyed, so upgrading restores it.
- You can delete your account and all associated data at any time, from Settings in the app or by emailing privacy@instantfit.net. Deletion permanently removes your account and everything tied to it (search profiles, uploaded CVs, matches and their AI scores, generated documents and their PDF files, notifications, and diagnostic error records), and deletes your customer record with our payment processor, which cancels any subscription. We complete requests within 30 days, and normally immediately for in-app deletions.
- We keep rotating encrypted-at-rest backups for disaster recovery on roughly a 7-daily / 4-weekly cycle. Data deleted from the live database may persist in backups for up to about 35 days before rotating out; we do not use backups for any other purpose.
- Our payment processor may retain certain transaction and invoice records after deletion where legally required (for example, for tax and accounting), independently of us.
Security
We take proportionate technical and organizational measures to protect your data:
- All traffic to instantfit.net is encrypted in transit (HTTPS/TLS).
- Passwords are stored only as bcrypt hashes; verification and reset tokens only as SHA-256 hashes.
- Your CV text and LinkedIn profile information are encrypted at rest with AES-256-GCM, with the key held separately from the database, so a database copy alone does not expose them.
- Resetting your password revokes existing sessions; login attempts are rate-limited to slow brute-force attacks. Sensitive fields are excluded from application logs by design.
No internet service can promise absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
Your rights
Under the GDPR (if it applies to you)
- Access the personal data we hold about you, and receive a copy;
- Rectify inaccurate data;
- Erase your data (the “right to be forgotten”); see Retention and deletion above;
- Restrict or object to processing based on legitimate interests;
- Data portability: receive the data you provided in a machine-readable format;
- Withdraw consent at any time where processing is based on consent (e.g. the digest email), without affecting prior processing;
- Lodge a complaint with a supervisory authority in your EU member state.
Under Israeli law
The Protection of Privacy Law, 5741-1981 (as amended, including Amendment 13) gives you, among others, the right to:
- Inspect the data held about you in our database;
- Request correction or deletion of data that is incorrect, incomplete, unclear, or outdated;
- Be removed from any direct-mailing list (our only recurring marketing-adjacent email is the opt-in digest, which you can disable in Settings at any time);
- Complain to the Israeli Privacy Protection Authority.
To exercise any right, email privacy@instantfit.net. We will verify your identity (normally via your account email) and respond within the timeframe the applicable law requires.
Children
InstantFit is a job-search tool for adults. The service is not directed at, and may not be used by, anyone under 18. We do not knowingly collect data from minors; if you believe a minor has created an account, contact us and we will delete it.
Third-party sites
Job postings link back to their original source (for example, a posting on LinkedIn). Once you follow such a link, that site's own terms and privacy policy govern. We have no control over, and no responsibility for, their processing. The same applies to our payment processor's hosted checkout and billing pages.
Changes to this policy
We may update this policy as the service evolves, for example when we add a new job source or sub-processor. We will post the updated version here with a new “Last updated” date and, for material changes, notify you by email before they take effect. Continued use of the service after a change takes effect means the updated policy applies.
Contact
Questions, requests, or complaints about privacy: privacy@instantfit.net.