Workybara ("we") is a registered California business. This policy describes what we
collect when you use workybara.ai, why we collect it, who processes it, and the
choices you have. The short version: your data is used to match you with jobs, it is
never sold, and you can ask for a copy or deletion of everything at any time.
What we collect
- Account data. Your email address and a password, managed through
our authentication provider. If you only join the waitlist on the homepage, we
store just your email address.
- Resume and profile data. If you upload a resume (PDF, DOCX, or
TXT), we store the original file, the text extracted from it, and the structured
profile built from that text: skills, work experience, accomplishments, and any
contact details or links the resume contains. If you edit your profile, we store
your edits.
- Derived matching data. We convert your profile into numerical
representations (embeddings) used to rank jobs for you. These are stored on
infrastructure we operate and are keyed to your account, not your name.
- Usage analytics. We record product events such as page views and
feature usage through PostHog, and traffic on our public pages through Google
Analytics (which, like the Meta Pixel, does not load on signed-in pages).
Analytics are tied to a random account identifier, not your email. We do not use
session recording, and we configure analytics to strip personal information from
event data.
- Security data. Login and signup pages use Cloudflare Turnstile to
block automated abuse, which processes your IP address and browser signals to make
that decision.
- Ad measurement data. Our public pages (the homepage and
informational pages like this one) load the Meta Pixel, which lets us measure
whether our ads on Meta platforms (such as Facebook and Instagram) lead to
signups. Meta receives standard web signals from those visits (the public pages
viewed, your IP address, and browser information) and sets a cookie. The pixel
does not load on signed-in pages, and we never send Meta your resume, profile,
matching data, or job search activity. Meta's use of this data is described in Meta's privacy policy.
What we use it for
We use your data to run the product: authenticate you, build your profile, rank jobs
for you, fix problems, and understand which features work. We rely on your consent
for processing your resume (you choose to upload it) and on our legitimate interest
in operating and securing the service for the rest. We do not sell your data, we do
not share it with employers unless you take an action that does so, we do not use
your resume or profile data for advertising, and we do not use your data to train
third-party AI models. Advertising measurement is limited to the Meta Pixel described
above.
Who processes it
Workybara runs on infrastructure and services that process data on our behalf:
- Supabase - database, authentication, and file storage (your
account, profile, and uploaded resume files).
- Amazon Web Services - hosting for the application and our
matching infrastructure, plus AI models (via AWS Bedrock) that parse resume text
into structured profiles and analyze job fit.
- OpenAI - AI models used for parts of skill extraction and
profile suggestions. Text you provide may be sent to OpenAI's API for those
features; OpenAI's API terms prohibit training on this data.
- PostHog - product analytics, as described above.
- Google - Google Analytics for site traffic analytics.
- Cloudflare - Turnstile abuse protection on auth pages.
- Meta - the Meta Pixel for ad measurement, as described above.
All processing happens in the United States. If you use Workybara from outside the
US, your data is transferred to and processed in the US.
Cookies and local storage
We use cookies to keep you signed in (authentication session), analytics cookies set
by PostHog and Google Analytics, and an ad measurement cookie set by the Meta Pixel
(described in "What we collect"). The app also uses your browser's
local storage to cache things like your job matches and filters on your own device so
pages load faster; you can clear this at any time through your browser.
How long we keep it
Your account, profile, and uploaded resumes are kept while your account exists so the
product keeps working for you. When you replace your resume, the previous file is no
longer used for matching. When your account is deleted, we delete your account data,
profile, resumes, and derived matching data.
Your rights
You can access and edit your profile in the app at any time. By emailing contact@workybara.ai from your account email address you can also request: a copy of your data, correction,
or deletion of your account and everything associated with it. Deletion requests are
currently handled directly by us rather than by a self-serve button; we complete them
within 30 days and confirm by email. Depending on where you live (for example the EU
or California) some of these are statutory rights; we honor them for everyone
regardless of location.
Changes and contact
If this policy changes materially, we will update the date above and note the change
on this page. Questions or requests: contact@workybara.ai, Workybara, California, USA.