Privacy

Your application data stays yours.

Motiavated processes the information needed to help you prepare job applications. You decide when the extension reads a page, review everything it prepares, and remain responsible for submitting the application.

Effective: July 18, 2026 · Last updated: July 24, 2026

Choose a quick explanation or read the complete policy. Both views describe the same privacy practices.

Scope and who we are

This policy applies to the Motiavated website, browser extension, Career Profile integration, and related services (together, “Motiavated”). Motiavated is the operator of these services. For privacy questions or requests, contact [email protected].

Data we collect and process

Account and identity data

Name, email address, account identifiers, and profile information you provide. We use Supabase authentication for sign-in and account sessions.

Authentication data

OAuth identifiers and session/access tokens needed to maintain your login. Motiavated does not receive or store your Google password or job-site passwords.

Professional and application data

Career Profile content; resumes, employment history, skills, education, achievements, and profile details; opportunities you save; application questions and answers; cover letters; generated resumes and other generated documents; and feedback or support messages you submit.

When you upload a resume or other Career Profile source document, we temporarily process the file to extract readable text. We do not retain the original uploaded binary after processing. We retain the extracted text and related metadata with your account so the Career Profile can search and use that source. You can delete the source and its extracted text from the Career Profile.

Website and job-page content

When you activate Motiavated or explicitly choose to prepare a page, the extension can process the page URL and title, job description, company and role information, application questions, form labels, supported form values, and other content relevant to that workflow. It does not continuously monitor unrelated browsing.

Usage, referral, and diagnostic data

This can include feature and generation/download events, basic technical or error information, analytics-consent status, and limited signup referral data. At registration, this may include supported UTM fields (source, medium, campaign, and content), the external referrer hostname only, landing path, and capture time. We do not retain the complete referrer URL, IP address, user-agent string, browser fingerprint, or a pre-signup persistent identifier. Optional product analytics are disabled until you opt in. Resume text, job descriptions, application answers, screenshots, form values, and full-page HTML are excluded from analytics.

Transaction data

When you buy credits, we process the purchased-credit amount, transaction identifiers, payment status, and billing/accounting records. Complete card details are handled by the payment provider and are not received or stored by Motiavated.

How we use data

We use data to create and manage accounts; authenticate users; understand which signup sources and campaigns are useful; parse pages you select; generate resumes, cover letters, and answers; save and organize application materials; maintain credit balances and process purchases; provide support; detect abuse, fraud, and security incidents; improve the product with opted-in, content-safe analytics; and comply with legal obligations.

We do not sell personal data or use it for personalized advertising, retargeting, determining creditworthiness, or lending.

Browser extension permissions and page access

The extension uses these permissions only to provide the job-application workflow you invoke:

  • activeTab and host permissions: make the packaged content script available on HTTP(S) pages so a job-application workflow can read relevant content or place reviewed values when you invoke it. The script reads page content in response to that workflow; it does not send page content merely because a page is visited.
  • identity: complete browser-based sign-in.
  • scripting: inject the packaged content script on supported web pages.
  • sidePanel: show the Motiavated workbench alongside a page.
  • storage: retain login/session and in-progress workspace state in the browser.
  • tabs: identify the active page, react to navigation for the requested workflow, and deliver reviewed content to the current tab.

Motiavated contains no remotely hosted executable code: executable extension code is packaged with the extension. Server and AI responses are handled as data and are not executed as code.

Chrome Web Store Limited Use

Motiavated’s use and transfer of information received through Chrome extension APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Information obtained through extension permissions is used only to provide or improve Motiavated’s user-facing job-application features. It is not sold, used for personalized advertising, or used to determine creditworthiness or for lending purposes.

Motiavated personnel do not manually read private application content except when you give explicit consent for support, when necessary to investigate security or abuse, when required by law, or when the data has been aggregated or de-identified.

Service providers and data transfers

Necessary processors may receive data needed to provide their services. We do not sell data or transfer it for advertising.

  • Authentication and database: Supabase Auth and the Motiavated PostgreSQL database stack provide authentication and account/application data storage.
  • AI: the configured generation stack can use OpenAI, Anthropic, and OpenRouter, depending on the model selected for a request. Relevant user-selected content is sent to the backend and applicable AI provider to generate the requested output.
  • Website measurement: Cloudflare Web Analytics provides aggregate traffic measurements.
  • Analytics: PostHog may receive consented, allow-listed product and technical events, including saved signup-source properties, only when analytics is configured and you opt in.
  • Error monitoring: Sentry may receive scrubbed server error information when error monitoring is configured.
  • Payments: Creem processes credit-purchase checkout and payment credentials.
  • Hosting and security: Motiavated uses application, proxy, and database infrastructure to provide the service and protect it.

These providers process only the data necessary for their services under their applicable terms and privacy commitments. Data may be processed in countries where Motiavated or its providers operate.

Optional analytics

Cloudflare Web Analytics provides aggregate measurements of website traffic. Its visits are approximate sessions, not exact unique people. We save one immutable first-touch signup-attribution record for an account: validated UTM source, medium, campaign, and content when supplied; otherwise an external referrer hostname or “direct”; plus landing path and capture time. Only the hostname is retained from a referrer, not its complete URL. This record is used to evaluate acquisition channels and is retained with the account unless deletion is requested or a longer retention period is necessary for legal, security, or accounting reasons.

PostHog product analytics are off until explicit opt-in. You can change the choice in Account settings. If enabled, PostHog may receive allow-listed feature usage, technical events, and saved signup-source properties—never intentionally application content, documents, job descriptions, form values, screenshots, or full-page HTML. Turning analytics off does not disable Cloudflare aggregate measurement or essential operational and security logging.

Connected Career Profile Builder

Connecting the Career Profile Builder is explicit. After connection, the builder can read the current Career Profile only for the authenticated account and only with the authorized scope. Saving a new Career Profile version requires your authorization; the GPT cannot select another user’s account. You can decline the connection or disconnect it in Account settings. Relevant Career Profile content may be processed by OpenAI through the connected GPT experience.

Payments

Creem handles payment credentials for credit purchases. Motiavated may receive transaction IDs, checkout/order status, amount, currency, purchased credits, and limited billing metadata. We do not store complete card numbers or security codes. Transaction records may be kept for accounting, fraud prevention, disputes, and legal obligations.

Data retention and deletion

We retain account, Career Profile, job, draft, document, support, usage, and transaction records for as long as needed to operate your account and the features you use. Account-owned application records are deleted with the account where applicable; credit and payment records may be retained where needed for accounting, fraud prevention, disputes, legal obligations, backups, or ledger integrity.

Uploaded Career Profile source documents are processed for text extraction, and the original uploaded binary is not retained after processing. Extracted text and related source metadata remain with your account until you delete the source or your account, subject to the exceptions below. Deleted source records are removed from the active service. Limited copies may persist temporarily in backups or records retained for security, legal, accounting, or dispute-resolution purposes.

You can delete or replace application materials in the product where controls are available, change analytics consent in Account settings, and disconnect the GPT there. To request account deletion or access, correction, or export of your data, contact [email protected]. Deletion may not be immediate where limited retained records are required; those records remain protected.

Data security, choices, and other terms

Security

We use reasonable technical and organizational safeguards, including authenticated access controls, token/password redaction in server logs, and scrubbed server error reporting. No method of transmission or storage is completely secure.

Your choices and rights

Subject to applicable law, you may request access, correction, export, or deletion of personal data; control analytics consent; and disconnect integrations. Use the contact channel above for a request.

Children’s privacy

Motiavated is not directed to children. If you believe a child has provided personal data to Motiavated, contact us so we can review the request.

Policy changes

We may update this policy as the product or legal requirements change. We will update the date above and, where appropriate, provide notice in the service or by email.

Contact

For privacy questions, account deletion, or other rights requests: [email protected].

Back to home