Legal
Privacy Policy
Last updated 8 August 2026
This page explains what Pilou collects, why, and how you can control it. If anything here is unclear, email benjaminlarger.bl@gmail.com.
What we collect
- Account details: your email address and password (stored as a salted hash, never in plain text)
- Profile data you provide: work history, education, skills, links, and preferences used to fill applications and tailor documents
- Uploaded files: your CV/resume and any files you attach for autofill
- Job search and application data: postings you view, jobs you track, and the status of each application
- Usage data needed to run the product: LLM call metadata for cost tracking, and basic error logs
- Extension page data: when you use the browser extension, the structure of the job application form on the page you're viewing (field labels and types) and, on a job posting, its visible description text
How we use it
Your profile data is sent to our LLM provider only to generate a fill plan, a tailored resume, or a cover letter for a specific job posting you chose to act on. It is not used to train any model, and it is not sold or shared with advertisers.
The browser extension
The extension can read the pages you visit so it can detect job postings and application forms. That detection runs entirely on your device, with nothing sent anywhere. Data only leaves your device when you actively trigger a fill or ask for a tailored document: at that point, the form's structure, the job posting text, and your profile are sent to our LLM provider to generate the result. The extension never captures a screenshot automatically; any image you attach, for example to a bug report, is a file you chose yourself.
What Pilou never does
Pilou never invents an answer to a required field it can't verify from your profile. Any genuinely unknown value is flagged for you to answer, never guessed. Pilou never clicks Submit on a form: every application still goes out with your final review.
Data retention and deletion
Your profile, documents, and application history are kept for as long as your account is active. Email us to request an export or deletion of your data, and we'll act on it within a reasonable time.
Audience measurement
We count page views with Umami, a privacy-first analytics tool. It sets no cookie, does not store your IP address, and cannot follow you from one site to another, so there is no consent banner to click here. What it records stays aggregate: how many people opened a page, which site sent them, roughly which country and which kind of device. None of it is tied to your account, and none of it identifies you. If your browser sends a Do Not Track signal, nothing is recorded at all.
Third parties
We use a small number of service providers to run Pilou: our LLM provider (Google's Gemini API, to generate fill plans and tailored documents), our hosting provider (Railway), our transactional email provider (Resend, for account verification and beta invites), and our analytics provider (Umami Cloud, to count page views). Each only receives the data needed to perform its function. We do not sell your data to anyone.
Your choices
You can edit or delete your profile data at any time from the app, and you can request full account deletion by emailing us.
Questions about your data? Contact benjaminlarger.bl@gmail.com. See also our Terms of Use and Support page.