Controller: Veepo
Privacy Officer: Veepo (contact via support@veepo.app)
Privacy contact: support@veepo.app
Mailing address: Ajax, Ontario, Canada
Veepo (“Veepo,” “we,” “us,” or “our”), provides an AI-assisted job discovery, résumé creation, job matching, application preparation, and user-directed application submission service.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Veepo website, web application, iOS application, managed application inbox, and related services (collectively, the “Services”).
1. Important application notice
Veepo helps you find jobs and complete applications. You choose the jobs you want to pursue.
Double-tapping a job card or selecting Apply records your instruction for that job. If you have separately enabled and authorized Autopilot, Veepo may operate a cloud browser to complete and submit the selected application. If Autopilot is not enabled, Veepo prepares the application for review or asks for a further instruction before submission.
When an application is submitted, information from your profile, résumé, saved answers, and generated application materials is disclosed to the employer and its applicant tracking system (“ATS”). The employer and ATS then handle that information under their own privacy practices.
A submitted application may be irreversible. Disabling Autopilot or deleting your Veepo account does not recall information already delivered to an employer.
Veepo does not make hiring decisions for employers. Match scores and recommendations are tools for organizing your own job search.
2. Scope
This Policy applies to personal information handled by Veepo through the Services. It does not govern the independent practices of employers, recruiters, ATS providers, job-posting services, login providers, Apple, or websites linked from Veepo.
3. Information we collect
Account and authentication information
We may collect:
- email address and account identifier;
- protected authentication credentials;
- account creation, verification, login, and password-reset events;
- login method;
- consent and policy-acceptance records; and
- name, email, and provider identifier received through Google, Apple, or LinkedIn sign-in.
We do not receive your Google, Apple, or LinkedIn password.
Application profile information
You may provide:
- name, preferred name, and professional headline;
- personal email address, Veepo application email, and phone number;
- LinkedIn profile, portfolio, and website;
- country, province or state, city, postal code, and relocation preference;
- work authorization, sponsorship needs, and security-clearance status;
- skills, languages, salary expectations, notice period, and start date;
- preferred work arrangement;
- screening answers; and
- background- or reference-check willingness.
An employer's actual background-check authorization, certification, or electronic signature is separate from a profile preference saved in Veepo.
Résumé and professional information
When you upload, paste, build, edit, or generate a résumé or cover letter, we may process:
- uploaded files and extracted text;
- employment history, employers, titles, dates, and responsibilities;
- education, qualifications, and GPA;
- skills and proficiency levels;
- projects, certifications, publications, awards, courses, and volunteering;
- languages, strengths, hobbies, and custom sections;
- professional references and their contact information;
- formatting and template choices;
- generated résumé and cover-letter variants; and
- exported PDF files.
If you provide information about another person, such as a reference, you are responsible for having authority to provide it.
Job-search and matching information
We collect:
- target roles and locations;
- preferred work modes, employment types, and experience levels;
- salary floor and sponsorship preference;
- feed-sorting and filter choices;
- saved, skipped, viewed, and selected jobs;
- followed companies and collections;
- live-search queries; and
- interactions with job cards and match explanations.
We create inferences such as match scores, matched skills, potential gaps, relevant experience, inferred role families, recommended ordering, and AI-generated match explanations.
Application and Autopilot information
We may process:
- the selected job, employer, ATS, posting, and application URL;
- the résumé and cover letter used;
- application questions and answers;
- missing or uncertain information;
- application state, attempts, timestamps, and errors;
- submission evidence and employer confirmation;
- user handoffs and requests for attention;
- application status and status history; and
- the scope, version, acceptance, and withdrawal of Autopilot authorization.
A queued or applying status is not proof that the employer received the application.
Required self-identification profile information
To use Veepo's application service, you must complete the self-identification profile section, which includes information commonly requested in employer self-identification sections:
- gender;
- race or ethnicity;
- veteran status;
- disability status;
- work authorization;
- sponsorship requirements; and
- security-clearance status.
Veepo does not use saved race or ethnicity, gender, disability status, or veteran status to calculate job match scores, generate résumés, personalize the feed, or measure product analytics.
You must provide a response for each required profile field and acknowledge employer-form reuse and AI-assisted processing. A supported "prefer not to answer" or decline selection is a completed response. The section itself is not skippable.
For employer-form reuse, Veepo routes each demographic field through a dedicated sensitive-field mapping path that receives only the relevant employer question, permitted options, and corresponding saved value. These values are excluded from general résumé tailoring, motivation-answer generation, general field-mapping prompts, matching, feed personalization, product analytics, and operational logs. When an employer offers a compatible option, Veepo preserves the saved answer exactly; an ambiguous mapping pauses for user review. Audit telemetry records the category and mapping version without recording the sensitive value.
Managed application inbox
Veepo may assign an address at veepo.email. We may process:
- inbox alias;
- sender, recipient, reply-to, CC, and BCC addresses;
- sender name, subject, snippets, and message bodies;
- attachments and attachment metadata;
- threads and timestamps;
- read, star, archive, report, and blocking choices;
- associated job; and
- rules- or AI-generated categories such as confirmation, assessment, interview, offer, or rejection.
Message categorization may be inaccurate.
Applicant credentials and browser context
When an employer requires an applicant account, Veepo may generate and store:
- username;
- encrypted generated password;
- associated employer or ATS;
- credential creation and reveal events; and
- last-revealed date.
A cloud-browser provider may separately retain employer cookies and login state in a persistent browser context.
Cloud-browser sessions and recordings
Autopilot uses a cloud-hosted browser. Veepo and its provider may process:
- employer pages visited;
- URLs and form content;
- information displayed or entered;
- session identifiers and timestamps;
- browser and network logs;
- employer cookies and login state;
- CAPTCHA challenge information;
- submission evidence; and
- troubleshooting events.
Autopilot records the cloud-browser session (replay video and screenshots) as a private evidence trail of the application it performed for you. Recordings can contain contact, résumé, screening, and application information. Replay access is restricted to authorized Veepo administrators and the cloud-browser provider as needed for submission verification, duplicate prevention, reliability, security, troubleshooting, and dispute investigation; users do not receive direct replay access. The application-details screen indicates when a session was recorded.
Recording is mandatory for every automatic cloud-browser application and cannot be disabled. If a recorded session cannot be created, Veepo fails closed to a manual handoff and does not run an unrecorded automatic application. Recordings are retained under the schedule in section 11 and, at our cloud-browser provider, under its own retention settings.
Company ratings
Signed-in users may rate a company's overall quality, culture, work-life balance, and career growth.
Veepo stores a rating in association with the contributor's account so it can be updated or deleted and to prevent duplicates. Other users receive only aggregated averages after a minimum participation threshold. They do not receive the contributor's identity or individual rating row.
Veepo currently collects numeric ratings, not public free-text company reviews. This Policy and the Terms must be updated before public text reviews are introduced.
Device, usage, and diagnostic information
We and our providers may process:
- IP address;
- browser, operating system, device type, and app version;
- account or analytics identifier;
- referring page and page paths;
- screens and features used;
- timestamps;
- coarse region inferred from network information;
- crash and error data;
- performance traces; and
- security and rate-limit events.
Our product analytics is configured to avoid automatic page-content capture and session replay, allowlist event properties, remove URL queries and fragments, respect browser Do Not Track, and avoid résumé text, application answers and employer messages. If you permit analytics, its identifier may be stored locally on your browser or device.
Our diagnostic tooling is configured to avoid default PII collection and remove user identity, cookies, headers, request bodies, query strings, and console breadcrumbs from captured events. Technical identifiers and diagnostic metadata may nevertheless constitute personal information.
Support and communications
We may collect support requests, feedback, surveys, correspondence, unsubscribe choices, complaints, privacy requests, and information needed to verify and answer them.
Information from job providers and employers
We collect public or licensed job information from employer career sites, ATS providers, and job-search providers. Current production-supported automatic application sources are Greenhouse and Lever. User-requested live search may send job-title, location, and filter queries to job-search providers such as JSearch and Adzuna.
Employer messages may provide application confirmation, interview, offer, rejection, and status information.
4. How we use information
We use personal information to:
- create, authenticate, and secure accounts;
- provide password recovery and login services;
- build, parse, edit, tailor, format, and export résumés;
- draft and verify cover letters and application content;
- calculate and explain job matches;
- personalize and filter the job feed;
- save job-search choices;
- prepare and submit applications selected by users;
- populate forms and upload selected documents;
- identify missing or uncertain application questions;
- create applicant accounts and manage credentials;
- receive, classify, forward, and display employer communications;
- track applications and prevent duplicate submissions;
- aggregate company ratings;
- send security, application, and support messages;
- send optional match digests only with valid marketing consent;
- understand product use and improve reliability where you permit optional analytics;
- detect abuse, fraud, and security incidents;
- enforce our Terms; and
- comply with legal obligations.
5. AI and automated processing
Veepo uses artificial intelligence for résumé parsing, résumé and cover-letter tailoring, mapping ambiguous application fields to known answers, limited application drafting, optional match deep dives, and inbox categorization.
Depending on the feature, AI requests pass through Vercel AI Gateway to providers including Google Gemini and Anthropic Claude. AI processing is inherent to these features. General field mapping sends application fields and non-sensitive saved answers needed for that task. Demographic values are excluded from general AI prompts and are processed only through the isolated sensitive-field path described in section 3.
Veepo currently requests the gateway's no-prompt-training option where supported. We do not promise that a provider never retains or uses information unless that promise has been verified against the current provider plan, contract and complete processing chain.
AI may misread information or generate an inaccurate result. You can edit your profile and résumés, change preferences, disregard matches, and review information requiring your attention.
Veepo's normal match algorithm considers target roles, professional experience, relevant fields, skills, seniority, work mode, location, salary, employment type, sponsorship preference, and posting recency. Saved self-identification information is excluded.
Match scores are not sent to employers and do not make employment decisions. Veepo does not submit a job solely because it has a high score; you must select that job.
6. Employer-specific controls
Some applications require employer privacy notices, terms, certifications, electronic signatures, background-check authorization, demographic consent, or other legally significant choices.
In Review mode (Autopilot off), Veepo pauses and requests your action when separate assent is required. When Autopilot is on, you authorize Veepo to make these employer-facing legal choices in your name as part of submitting the application (accepting employer terms, privacy notices, and acknowledgements; agreeing to certifications; authorizing a background-type check; and providing an electronic signature), as described and enumerated in the Terms of Use (Limited electronic agency) and on the Autopilot Authorization screen. Enabling Autopilot does not authorize unrelated employer marketing.
7. How we disclose information
Employers and ATS providers
At your instruction, Veepo discloses the information needed for the selected application to the employer and its ATS. These recipients generally determine their own subsequent uses and retention.
Service providers
Current provider categories include:
- Supabase for authentication, database, and storage;
- Vercel for hosting, server functions, and AI Gateway;
- Google Gemini and Anthropic Claude for configured AI functions;
- Browserbase for cloud-browser sessions, session recordings, logs, and persistent contexts;
- Resend for product email and the managed inbox;
- PostHog for optional restricted analytics;
- Sentry for diagnostics;
- CapSolver and NopeCHA for CAPTCHA processing where permitted;
- Google, Apple, and LinkedIn for optional authentication;
- JSearch and Adzuna for requested live search; and
- Greenhouse, Lever, employers, and other ATS recipients for applications.
We disclose only information reasonably necessary for the relevant service. We contractually require service providers that process personal information for us to provide protections appropriate to that information and applicable law.
Legal and safety disclosures
We may disclose information to comply with law or lawful process, protect users or others, investigate abuse or security incidents, enforce our Terms, or establish and defend legal claims.
Business transactions
Information may be disclosed in connection with a merger, financing, acquisition, restructuring, or asset sale, subject to appropriate confidentiality and applicable law.
With consent
We may disclose information for another purpose when you give valid consent.
8. No sale or behavioural advertising
Veepo does not sell personal information, disclose it to data brokers, use it for third-party advertising, or track users across unaffiliated apps or websites for targeted advertising.
Disclosing an application to an employer at your direction is part of the Service you requested and is not a sale.
9. Web storage and iOS technologies
The web Service uses essential authentication and preference cookies or local storage for security, onboarding state and interface preferences. Optional analytics storage is not activated until you permit it where required by our chosen high-water consent standard.
The iOS application may process:
- résumé files deliberately selected by you;
- app and operating-system version and diagnostic information;
- Sign in with Apple identifiers;
- local settings and secure authentication tokens; and
- an APNs token if push notifications are offered and enabled.
Veepo does not intend to use IDFA, cross-app tracking, or advertising SDKs.
10. Consent and controls
Veepo provides:
- a required Terms acceptance and 18+ confirmation at account creation;
- a linked Privacy Notice;
- a separate, versioned Autopilot authorization (off by default);
- job-specific Apply instructions;
- required completion of each self-identification profile field, with "prefer not to answer" or an equivalent decline response accepted as completion;
- a required acknowledgment for employer-form reuse and AI-assisted sensitive-field mapping;
- direct user action for employer-specific legal controls in Review mode (under Autopilot these are accepted on your behalf per your authorization);
- a separate unchecked marketing opt-in;
- rating update and deletion controls;
- mobile system-permission controls; and
- withdrawal of future Autopilot authority.
Marketing email and product analytics are independent optional choices that default off and may be withdrawn in Settings. Browser recording is mandatory for automatic applications and has no user-facing opt-out. Veepo will continue evaluating additional privacy controls as the Service evolves, without promising that a particular control will be introduced.
Withdrawal affects future processing. It does not invalidate prior lawful processing or recall an application already delivered to an employer.
Autopilot is off by default. Disabling it stops new applications from being enqueued or automatically submitted, but cannot reverse a submitted application or one already in progress.
11. Retention
Veepo retains information only as long as necessary for the stated purpose, legal compliance, security, disputes, and enforcement.
Veepo applies the following retention periods:
| Information | Retention |
|---|---|
| Account, profile, résumé and user-controlled application records | While the account is active; erase or de-identify from active systems within 30 days after verified deletion |
| Original and generated documents | While retained by the user; active-system deletion within 30 days after document/account deletion |
| Managed inbox messages and attachments | While the account is active or a shorter user-selected period; active-system deletion within 30 days after deletion |
| Generated credentials and browser contexts | Until disconnected or account deletion; controlled-provider deletion within 7 days |
| Browser session recordings | 7 days; documented troubleshooting hold no longer than 30 days |
| Browser and network logs | 7–30 days, minimized and redacted |
| Identifiable product analytics | 12 months, then deleted or aggregated |
| Error and diagnostic events | 30–90 days, according to the configured vendor plan |
| Support and privacy requests | 2 years after closure unless a dispute requires longer |
| Consent, contract and application-instruction evidence | Up to 6 years after account closure |
| Breach records | At least 2 years as required by Canadian law |
| Company ratings | Delete with the rating or account and recompute live aggregates without it |
| Backups | Encrypted rolling backups overwritten within a documented 35–60 day maximum |
Employers and ATS providers determine their own retention of submitted applications.
12. Account deletion
You may initiate account deletion from Settings in the web and iOS applications.
Veepo deletes information under its direct control according to its deletion workflow and retention schedule. Before removing your account and its database records, Veepo purges the files it stores for you (generated and original résumés and cover letters, and managed-inbox attachments), your persistent cloud-browser context, and your product-analytics profile. The database removal then cascades your profile data, saved jobs, application records not legally retained, company ratings, managed-inbox copies, and generated credentials. Limited information may remain temporarily in rolling backups or be retained where required for security, law, fraud prevention, or legal claims.
Two limits are inherent and disclosed: our cloud-browser provider retains session recordings under its own retention settings (there is no per-session delete, so a recording is removed by that retention schedule rather than on individual request), and Sign in with Apple is not yet offered, so there is no Apple token to revoke. Each purge step is best-effort: a temporary vendor failure is logged and does not stop your account from being deleted.
Account deletion cannot:
- recall a submitted application;
- delete an employer's or ATS provider's copy;
- close every employer applicant account;
- erase an employer's required hiring record; or
- recall an already delivered email.
13. International processing
Veepo is based in Canada. Providers may process information in Canada, the United States, and other countries. Foreign information may be subject to local laws and lawful government access.
The EEA and the UK are within our service territory, so the EU GDPR and UK GDPR apply. Before Veepo offers the Service in the EEA or UK, we will identify the lawful basis for each processing purpose, put transfer mechanisms (such as standard contractual clauses) in place, complete the required transfer assessments, and appoint EEA and UK representatives. Until then, Veepo is not offered to residents of those regions.
14. Security
Veepo uses safeguards designed for the sensitivity of the information, including encrypted transport, authentication, row-level database controls, private storage, application-level encryption for generated passwords, rate limits, restricted administrative access, analytics allowlists, diagnostic scrubbing, and secret redaction.
No storage or transmission system is completely secure, and we cannot guarantee absolute security.
15. Privacy rights
Depending on where you live, you may have rights to:
- access information;
- learn how it is used and disclosed;
- correct inaccurate information;
- obtain a portable copy;
- delete information;
- withdraw consent;
- object to or restrict processing;
- opt out of sale, sharing, or targeted advertising;
- limit certain sensitive-information uses;
- appeal a denied request; and
- complain to a regulator.
Requests may be submitted through support@veepo.app. Veepo may verify identity and will respond within applicable legal periods. We will not discriminate against you for exercising a privacy right.
16. Regional notices
Canada
Veepo is accountable under applicable Canadian private-sector privacy laws. You may request access or correction and may withdraw consent subject to legal and contractual limits.
Complaints may be directed first to the Veepo Privacy Officer and then to the Office of the Privacy Commissioner of Canada or the applicable provincial authority.
Quebec
Quebec is within our service territory. Quebec's Law 25 applies, including its rules on consent, automated decision-making, data portability, and cross-border transfers, and Quebec's language law requires French-language versions of these documents and the interface. Before Veepo operates in Quebec, French-language versions of the Terms and this Policy and the interface, the Law 25 automated-decision disclosure for Autopilot, distinct sensitive-information consent, the portability and related workflows, and the required privacy impact assessments must be in place. Until then, Veepo is not offered to Quebec residents.
Veepo's matching function recommends jobs to users. It does not make an employer's hiring decision.
California and other U.S. states
Categories collected may include identifiers, contact records, professional and education information, internet activity, service interactions, communications, sensitive information, diagnostics, and inferences.
Veepo does not sell or share personal information for cross-context behavioural advertising and offers no financial incentive for personal information.
Applicable access, correction, deletion, portability, opt-out, limitation, and appeal rights may be exercised through support@veepo.app.
EEA, UK, and Switzerland
Where applicable, processing may rely on:
- contract for account, résumé, matching, inbox, and selected-application functionality;
- consent for sensitive information, optional marketing, and non-essential analytics;
- legitimate interests for proportionate security, diagnostics, and improvement; and
- legal obligation or legal claims.
Veepo does not use match scores to make decisions producing legal or similarly significant effects.
Controller: Veepo
Data Protection Officer: Not appointed; reassessed against the GDPR Article 37 thresholds before EEA/UK launch.
EU representative: To be appointed before Veepo offers the Service in the EEA (GDPR Article 27).
UK representative: To be appointed before Veepo offers the Service in the UK (UK GDPR Article 27).
17. Children
The Services are intended for users aged 18 or older. Veepo does not knowingly collect personal information from anyone under 18. If we learn that someone under 18 created an account, we will take reasonable steps to delete it. The 18-or-older requirement applies consistently across the Terms, account signup, and our app-store listings.
18. Changes
We may update this Policy as the Services or law change. We will post the new effective date and provide additional notice or seek new consent where required for a material change.
19. Contact
Veepo
Attention: Privacy Officer
Email: support@veepo.app
Mail: Ajax, Ontario, Canada
Privacy requests: support@veepo.app