Privacy Policy
Last updated: September 20, 2026
Elafate ("we", "us") is a job-search workspace: it builds a career plan from your answers, tracks your applications, tailors resumes, and can fill job applications for you through our browser extension. Doing that requires handling career and identity information that matters. This policy says exactly what we collect, what we do with it, who touches it, and what you can ask of us.
Questions or requests about your data: admin@elafate.com.
What we collect
- Account details: your name and email address, provided through our sign-in provider (WorkOS) when you create an account.
- Onboarding and profile answers: your target role, career status, experience, skills self-ratings, priorities, work authorization status, location preferences, compensation floor, time availability, and any free text you add.
- Resume and application content: resumes you upload or generate, cover letters, notes, and the jobs and applications you track.
- Conversations: your messages with the AI coach.
- Autofill profile: if you use the browser extension, contact details, address, work history, education, and answers you choose to store, including optional demographic (EEO) answers.
- Billing status: your subscription state and a Stripe customer reference. Your card number never touches our servers; payment details go directly to Stripe.
- Technical and usage data: server logs (request metadata, IP address) kept for security and debugging, and product-analytics events (pages you open, features you use) collected through PostHog and tied to your account so we can see what works and what doesn't.
- Session replay: once you are signed in, PostHog also records how you move through the app (the pages and layout you see, where you click and scroll, and how long requests take) so we can find what is slow or broken. What you type and the text on the screen are masked in your browser before anything is sent, so a replay shows the shape of the page rather than your resume, your messages or your answers. Visitors who are not signed in are never recorded.
How we use it
We use your information for one purpose: running Elafate for you. That means building and pacing your plan, matching roles to your profile, tailoring resumes, filling applications you initiate, answering your questions, processing your subscription, and keeping the service secure. We do not sell your personal information, we do not share it with advertisers, and we do not use it to train AI models.
AI processing: what is and is not sent
Parts of the product are powered by large language models. When you complete onboarding, chat with the coach, tailor a resume, or use autofill on a new form, relevant content (your answers, resume text, messages, and the labels of form fields being filled) is sent to a model through our inference provider, OpenRouter, which routes it to the model operator (currently Moonshot AI) to generate the result. Web research runs through our search provider (Tavily).
Two hard lines we build around: demographic (EEO) answers are never sent to any AI model (they are used only to fill the specific form fields you initiate, from values you stored); and the extension never writes free-text answers for you and never submits an application. Submission is always your act.
Who processes data for us
We use a small set of service providers, each only for the purpose listed: WorkOS (sign-in and authentication), Stripe (payments and subscription billing), Render (application hosting and database, United States), Cloudflare (website hosting and delivery), OpenRouter (AI inference routing) and the model operators it routes to (currently Moonshot AI), Tavily (web search for research features), and PostHog (product analytics, how the product is used). We use no advertising networks and no cross-site ad trackers.
The browser extension
The extension reads the structure of job-application pages you open it on, in order to plan and fill fields from your stored profile. It sends field labels and page context, together with your stored profile values, to our servers to plan the fill. It acts only on pages where you invoke it, never ticks legal-consent checkboxes, and never clicks submit. What you send to a job board is what you reviewed and submitted yourself.
Retention and deletion
We keep your data while your account is active so the product keeps working. You can delete your account yourself at any time from Settings › Account. We email a confirmation code first to check it is really you. Deletion is immediate and cannot be undone: it erases your workspaces, plan, resumes, applications, notes and conversations, ends every signed-in session, cancels any active subscription, and deletes your identity at WorkOS. You can also email admin@elafate.com from your account address and we will do it for you.
Three things outlive a deletion, and these are all of them. Invoices and payment records stay with Stripe, which we must keep for legal and accounting reasons. Any product feedback you sent us — a bug report or an idea — is kept so we can still act on it, with your identity removed from it. And we keep a dated record that an account was deleted, which holds no name, email or address.
Your rights
Depending on where you live (including under GDPR and US state privacy laws), you may have rights to access, correct, delete, or export your personal information, and to object to or restrict some processing. Deletion is self-serve and immediate, in Settings › Account. Exercise any of the others by emailing admin@elafate.com. We honor these requests for everyone, regardless of jurisdiction, and will respond within 30 days. We never discriminate against you for exercising them.
Cookies and local storage
We use no advertising or cross-site tracking cookies. One first-party cookie keeps you signed in; it is strictly necessary, and scripts on the page cannot read it. Your browser's local storage holds interface preferences (like theme), and PostHog keeps an identifier in a first-party cookie and local storage that ties your product-analytics events together on this site.
Security
All traffic is encrypted in transit (TLS). Access tokens are short-lived and verified cryptographically; extension tokens are stored only as one-way hashes, never in plain text. No system is perfectly secure, but we treat career and identity data as sensitive by default. The EEO and consent rules above are examples of that posture built into the product itself.
Children
Elafate is for adults looking for work. You must be 18 or older to use it, and it is not directed at children. We do not knowingly collect personal information from anyone under 18, and never from children under 13; if we learn that we have, we delete it. If you believe a child has given us information, email admin@elafate.com.
Changes
If we change this policy in a way that matters (new data, new providers, new uses), we will update this page and its date, and for significant changes we will tell you in the product or by email.
