Privacy Policy
Last updated: October 7, 2026
Scoutify finds jobs for you and applies to them on your behalf. That means we handle a lot of personal information, including some sensitive details. This policy explains, in plain language, what we collect, what we do with it, who else sees it, and how you can control it or delete it.
1. Who we are
Scoutify is run by Notify You, Inc., a US company doing business as Scoutify ("Scoutify", "we", "us"). This policy covers scoutify.com, the Scoutify web app at app.scoutify.com, our iOS, Android and desktop apps, and the emails we send (together, the "Service").
For anything privacy related, email us at support@scoutify.com. We are the party responsible for your personal information (the "controller", in GDPR terms).
2. The short version
- To apply to jobs for you, we collect your application profile: contact details, address, work authorization, education, work history, resume and answers to common application questions.
- We send that information to employers and their hiring systems when we apply for you. Once an employer has your application, it's theirs, under their own privacy policy.
- We use AI models from several providers (through OpenRouter and TypeSafe, and directly from OpenAI) to read resumes, fill in application forms, write resume text and sort recruiter emails. Your profile and emails are sent to those providers to do that work.
- We use analytics (including screen recordings of a small share of sessions), crash reporting, and Reddit ad measurement for sign-ups on our website and web app. Nothing from our iOS or Android apps is sent to Reddit.
- We don't sell your personal information for money. Our Reddit ad measurement may count as "sharing" under some US state laws. You can opt out on our Your Privacy Choices page, and we honor Global Privacy Control.
- You can delete your account yourself at any time. A few things survive deletion, and we list them in Section 9.
- You must be 18 or older to use Scoutify.
3. What we collect
Most of this comes from you. Some comes from the services you connect, from employers who email you, or from public sources you ask us to use.
Account information
- Your email address, your name, and how you signed in (email code, Google or Apple).
- Your plan, trial status, and account settings, including your email and notification preferences.
Your application profile
This is what we use to fill in job applications for you:
- Name, pronouns, email, phone number and mailing address. If you pay on the web, we may also copy the billing address you give our payment processor into your profile.
- Work authorization and whether you need visa sponsorship.
- Education, work history, skills, and links to your LinkedIn, GitHub or personal website.
- Your resumes (you can upload several) and the text we extract from them.
- Answers to application questions you give us, such as your start date, languages, nationality and citizenship, security clearance, test scores, date of birth, prior employment with a company, and short written answers about your work and motivations (which we also use to draft cover letters).
Voluntary self-identification (optional)
Many US employers ask applicants optional equal-opportunity questions. You can choose to give us answers about your race or ethnicity (including whether you are Hispanic or Latino), gender, disability status and veteran status. These are optional. Every question has a "Prefer not to say" option (that is, decline to answer), and choosing it never stops us from applying for you.
We use these answers only to fill in the same optional questions on employers' application forms. We don't use them to decide which jobs you see, and we don't use them for advertising. Because they are part of your profile, they are included in the information our AI providers see when they help fill in a form (see Section 6).
Employer portal accounts we create for you
Some employers (for example, companies that use Workday) require an account before you can apply. Where needed, we create that account in your name and store the login details, including the password, so we can finish and track the application and so you can sign in to it yourself. You can see these logins in the app.
Job preferences and search history
- The roles, locations, companies, seniority, salary range and other filters you set, and jobs you hide or mark as not interested.
- Searches you type (for example, "remote backend jobs in fintech"), jobs you view, save, or apply to, and whether auto-apply is on.
Purchases and subscriptions
Your plan, billing history, subscription status, and cancellation reasons if you share them. Payments are handled by Stripe on the web and by Apple or Google in the mobile apps. We never see or store your full card number.
Scoutify Mail and connected email accounts
- Your Scoutify email address. When we apply for you, we usually give the employer a Scoutify-provided address (it ends in @inboxhires.com) instead of your personal one. We receive and store the emails sent to that address, including attachments, so we can track your applications, show them in Scoutify Mail, forward them to you based on your email preferences, and pick up verification codes needed to finish applications. If you use Scoutify Mail to reply, forward or write emails, we store and send those too.
- Connected Gmail or Outlook. If you choose to connect your own inbox, we read job-application emails from it. Section 15 explains exactly what we access.
Using Scoutify in ChatGPT
You can search jobs and apply through the Scoutify app in ChatGPT. Searching works without an account. To apply, you connect a Scoutify account and approve access on a Scoutify page; you can remove the connection at any time in ChatGPT's settings, and deleting your Scoutify account ends it too.
- What we receive from ChatGPT: the searches and requests you ask ChatGPT to send to Scoutify, the resume file you attach and ask it to save, the application details you enter in the Scoutify form shown in ChatGPT, your time zone (so free daily applications reset at your midnight), and an identifier ChatGPT assigns to your ChatGPT account. We keep only a shortened one-way hash of that identifier, to apply daily limits per person.
- What ChatGPT receives from us: job results, your Scoutify email address and name, the status of your applications, and, when you open the form, your saved application details (contact details, address, work authorization and any equal-opportunity answers you gave). OpenAI handles your ChatGPT conversations under its own privacy policy.
- We use this information only to run the features you ask for, as described in this policy.
Messages and the leaderboard
If your plan includes the leaderboard, other users may see your anonymous handle and your application results (such as interview counts) there. If you send direct messages to other users, we store those messages and any attachments.
Device and technical information
- IP address, browser or device type, operating system, app version, and approximate location (city or region) that we or our analytics provider work out from your IP address. We don't collect precise GPS location.
- Device identifiers: a random ID our app creates on install, analytics and crash-reporting IDs, and push notification tokens.
- Server logs of requests to our service.
Usage analytics and session recordings
We record how people use Scoutify: screens and pages viewed, buttons and features used, errors, and events like signing up, applying or subscribing. On the web and in the apps, this is linked to your account and email address once you sign in.
We also record a small sample of sessions (about 2.5%) as screen recordings, so we can see where people get stuck. What gets hidden:
- In the web app, everything you type into forms is hidden, as are password and email fields and anything we've marked as sensitive. Other text shown on the page can be recorded.
- In the mobile apps, text you type and images are hidden. Other text shown on screen can be recorded, which can include things like your profile details, job details, email content or account details.
- If you arrive from one of our Reddit ads, we record your first 30 minutes on scoutify.com and in the web app regardless of the sample. In the web app, those recordings hide all text and images. On scoutify.com, they hide form fields.
Crash reports
When something breaks, our apps send crash reports and error details, including device type, app version, what the app was doing, and an installation ID.
Support and feedback
Messages you send us by email or through the feedback button, screenshots you attach, cancellation feedback, and survey answers.
LinkedIn profile data we look up for you
If you ask us to build a resume from your LinkedIn profile, we search the web for your public LinkedIn profile using the name and school or workplace you give us, and, once you confirm which profile is yours, we fetch its public contents (such as work history, education and skills) to create your resume.
4. How we use your information
- Applying to jobs for you. This is the core of Scoutify. We use your profile, resumes and answers to fill in and submit applications, including automatically in the background if your plan includes auto-apply. Section 5 has the details.
- Matching and alerts. We match new job postings to your preferences and send alerts by push notification, email or in the app.
- Resumes and cover letters. We read your resume to fill in your profile, pick the best resume for each job if you've uploaded several, build a resume from your LinkedIn profile if you ask, and draft cover letters.
- Tracking your applications. We read employer emails sent to your Scoutify address or connected inbox to update each application's status (for example, interview or rejection) and to get verification codes.
- Communicating with you. Account and security emails, application updates, receipts, product news, tips and offers. You can turn off marketing emails at any time (Section 10).
- Payments. Processing subscriptions, handling refunds and billing problems, and preventing payment fraud.
- Security and abuse prevention. Keeping accounts safe and stopping automated abuse. For example, we use Cloudflare Turnstile and Cloudflare's bot signals, and we limit free trials to one per device per day and a small number per network, using scrambled (hashed) versions of your device ID and IP network.
- Analytics and product improvement. Understanding how Scoutify is used, fixing bugs, and deciding what to build next.
- Advertising measurement. Measuring which of our Reddit ads lead to sign-ups and purchases on our website and web app (Section 7).
- Legal reasons. Complying with the law, enforcing our Terms, and handling disputes.
5. How applying on your behalf works
When you apply to a job through Scoutify, or when auto-apply is on, software we run opens the employer's application page, fills in the form with the information in your profile, attaches a resume, answers the employer's questions, and submits it. With auto-apply, this happens without you approving each job: we apply to jobs that match your preferences, up to the limits of your plan. Auto-apply may switch on when you subscribe to a plan that includes it or finish your profile, and you can turn it off at any time in the app.
To answer questions that don't map directly to a profile field, we send the question, the job details and relevant parts of your profile to an AI model, which suggests an answer based on the information you've given us. If an employer's form requires a date of birth and you haven't given us one, we may enter an estimated date based on the year you finished your bachelor's degree.
Some employer sites are only reachable through a proxy network, so our application traffic may pass through our proxy provider using a connection located near the city in your profile. The connection is encrypted, so the proxy provider sees which site we visit, not what we submit. We also use a captcha-solving service, which receives only the page address and the captcha, never your personal information.
Please keep your profile accurate. What you give us is what employers receive.
8. How long we keep your information
- Account, profile, resumes, preferences and emails: for as long as your account exists. We don't automatically delete inactive accounts, so if you stop using Scoutify, delete your account (Section 9) or ask us to.
- Job match notifications and your personalized job feed: about 30 days.
- Free-trial abuse checks: the hashed device ID is kept for 24 hours, and the hashed network for up to 7 days.
- Scoutify Mail after you cancel: if you cancel your plan but keep your account, we keep receiving and storing mail sent to your Scoutify address so it's there if you come back. Delete your account to stop this.
- Payment records: as long as we need them for tax, accounting and legal reasons, even after your account is deleted.
- Backups and logs: copies of your information can remain in database backups and server logs after you delete it. Backups roll off over time, but some backup archives are kept longer so we can recover from a disaster. We don't restore deleted accounts from backups.
9. Deleting your account
You can delete your account and personal information at any time:
- In the app: go to Account, then Delete account.
- On the web: sign in at app.scoutify.com/account and choose Delete account.
- Without signing in: follow the steps at app.scoutify.com/delete-account.
- By email: write to support@scoutify.com from the email address on your account and ask us to delete it. We confirm it's your account, then delete it within 30 days.
If you subscribe through the App Store or Google Play, cancel that subscription first.Apple and Google bill you directly, and deleting your Scoutify account doesn't stop their billing. Web subscriptions paid through Stripe are cancelled automatically when you delete your account.
What deletion removes. Deletion happens right away. It removes your account, application profile, resumes, self-identification answers, stored employer portal logins, job preferences, saved and hidden jobs, notifications, your Scoutify Mail emails and attachments, direct messages, feedback and support tickets, and connected inbox access. Applications still waiting in the queue are deleted and never sent. An application that was already being submitted at that moment may still reach the employer.
We also cancel a web subscription and delete your customer record at Stripe, delete your sign-in identity at WorkOS, delete your in-app purchase records at RevenueCat, revoke our access to a connected Gmail account, and delete your analytics profile and its events in PostHog. Microsoft doesn't let us revoke Outlook access for you, so if you connected Outlook, also remove Scoutify at account.live.com/consent/Manage.
What we keep, and why:
- Applications already sent to employers. These are in the employers' hiring systems, and we can't delete them there; to remove them, contact the employer. Our own record of each one is anonymized: your answers, contact details, notes and screenshots are cleared, and we keep only the job, the employer's hiring system, the status, dates and cost, for aggregate counts that can't be tied to you.
- Payment records. Stripe keeps its record of your charges and invoices, and Apple and Google keep their own transaction records, under their policies and the law. We keep payment amounts and transaction IDs, with no link to you or your contact details, for tax and accounting.
- A hashed copy of your email address on our do-not-email list, so we never send you marketing email again. If you sign up again and verify the address, normal email resumes. A hash is a one-way scrambled value; we can't turn it back into your email address.
- A hashed copy of your email address with your sign-in provider's ID, so a sign-in token issued before deletion can't recreate the account.
- A hashed copy of your Scoutify email address (the @inboxhires.com one), so it's never given to anyone else and employer emails can't reach a stranger. Employers may still send mail to it, and that mail isn't forwarded.
- Hashed device and network identifiers that limit free trials. They expire within 7 days.
- An anonymous deletion log entry recording when the deletion happened and what was removed, with nothing that identifies you.
- Copies in internal team tools. Copies of feedback or purchase notices that were posted to our internal Slack or Discord channels (Section 6) may remain there.
- Backups and logs, as described in Section 8.
10. Your choices
- Profile: view and edit your profile, resumes and self-identification answers in the app at any time. You can change any self-identification answer to "Prefer not to say".
- Auto-apply: turn it on or off in the app.
- Marketing emails: use the unsubscribe link in any marketing email, or change your email preferences in your account settings. Marketing emails are on by default. We'll still send you account, security and billing emails.
- Push notifications: turn them off in your device settings.
- Connected inbox: disconnect Gmail or Outlook in your account settings, or from your Google Account permissions or Microsoft account.
- Analytics: there is no in-app switch to turn off analytics, session recordings or crash reports today. On the web, you can block analytics with your browser's privacy settings or an extension. You can also ask us to delete the analytics data linked to your account.
- Reddit ad measurement: turn on "Do not sell or share my personal information" in your account settings on the web or in the Account screen of the mobile app, or see Section 11 for the other ways to opt out.
11. Your privacy rights
Wherever you live, you can ask us to give you a copy of your personal information (in a portable format if you want), correct it, or delete it. Email support@scoutify.comfrom your account email address. We'll confirm the request comes from you, and we'll respond within 30 days, or sooner where the law requires. We won't treat you differently for using your rights. If someone else (an "authorized agent") makes a request for you, we'll ask for proof that you authorized them.
If you are in the European Economic Area, the UK or Switzerland
Under the GDPR and similar laws, you also have the right to object to our use of your information, to ask us to restrict it, to withdraw consent at any time, and to complain to your local data protection authority. The legal bases we rely on are:
- Contract: to provide the Service you signed up for, including applying to jobs for you, matching, alerts, Scoutify Mail and payments.
- Consent: for your optional self-identification answers (race or ethnicity, disability, and similar), which you give by choosing to fill them in, and for connecting your inbox. You can withdraw consent by changing your answers to "Prefer not to say", disconnecting your inbox, or deleting your account.
- Legitimate interests: for security and abuse prevention, analytics and product improvement, ad measurement, and marketing emails to our users. You can object to these at any time.
- Legal obligation: for tax, accounting and legal requests.
If you live in California or another US state with a privacy law
Laws such as the California Consumer Privacy Act give you the right to know what personal information we collect, use and disclose, and to access, correct and delete it. In the past 12 months we have collected the categories described in Section 3: identifiers (like your name, email, IP address and device IDs), customer records, characteristics of protected classifications (your optional self-identification answers), commercial information (purchases), internet and app activity, approximate location, professional and education information, the contents of emails, and inferences about the jobs you'd be a good fit for.
Some of this is "sensitive personal information": your optional self-identification answers, the contents of your Scoutify Mail and connected inbox, and the employer portal logins we create for you. We use it only to provide the Service you asked for, not to infer things about you.
We disclose these categories to the service providers and employers described in Section 6. We don't sell personal information for money. Our Reddit ad measurement (identifiers and internet activity) may count as "sharing" for cross-context behavioral advertising or as "targeted advertising". To opt out, use any of these:
- Global Privacy Control. If your browser or extension sends a GPC signal, we treat it as an opt-out automatically: we don't load the Reddit Pixel, and when you sign up or sign in on the web with GPC on, we record the opt-out on your account.
- Your Privacy Choices. Opt out in your browser at scoutify.com/privacy-choices. It's saved in a cookie, so repeat it in each browser you use.
- Account settings. In the web app or the mobile app, open Account and turn on "Do not sell or share my personal information". It's saved on your account, so it covers all our apps.
- By email, without signing in. Enter your email address at scoutify.com/privacy-choices and we'll email you a confirmation link, valid for 7 days. When you click it, we opt out every Scoutify account that uses that address, and we keep a hashed copy of the address so an account you create with it later starts opted out. If the form doesn't work for you, email support@scoutify.com with the subject "Do not sell or share my personal information".
Once you opt out, we stop including your account in the information our servers send to Reddit. In a browser that is opted out, we also don't load the Reddit Pixel or keep the Reddit click ID, and we turn off Google's advertising features in Google Analytics. If we deny a request, you can appeal by replying to our answer.
12. Security
We use encryption in transit (HTTPS) for our apps and services, encrypt the sign-in tokens we store for connected inboxes, limit who on our team can access personal information, and use bot and abuse protection. No system is perfectly secure, though, and we can't guarantee that information will never be accessed without permission. If we learn of a breach that affects you, we'll tell you as the law requires.
13. Where your data is processed
Scoutify is based in the United States, and our main servers and database are in the US. Our service providers process information in the US and in other countries, including through Cloudflare's global network. As explained in Section 6, some of the companies that run AI models for us are in China. If you use Scoutify from outside the US, your information will be transferred to, and processed in, countries whose data protection laws may differ from yours. Where the law requires, we rely on safeguards for these transfers, such as the European Commission's Standard Contractual Clauses in our providers' data processing terms.
14. Age requirement
You must be at least 18 years old to use Scoutify, as our Terms also say. We don't knowingly collect personal information from anyone under 18. If you believe someone under 18 has given us information, email support@scoutify.comand we'll delete it.
15. Gmail and Outlook connections
Connecting your own inbox ("Bring Your Own Email") is optional. It lets Scoutify track applications that use your real email address, pick up verification codes, and let you reply from your own address.
What we ask for:
- Gmail: permission to read your email (
gmail.readonly), send email as you (gmail.send), and organize your email (gmail.modify). Connections made before these were added may only have read access. - Outlook: permission to read your email (
Mail.Read), send email as you (Mail.Send), read your basic profile (User.Read), and stay connected (offline_access).
What we do with that access:
- We search your inbox only for messages from applicant tracking systems, from interview scheduling and assessment services (such as Calendly or HackerRank), and from companies you've applied to through Scoutify, starting from around when you began applying. We don't list or download the rest of your inbox.
- We store the matching messages, link them to the right application, and update its status. To sort them (for example, interview invite or rejection), we send the message content to our AI providers (Section 6).
- We send email as you only when you reply to or write an email in Scoutify.
- We archive application confirmations and similar messages only if you turn on auto-archive.
What we don't do:
- We don't use your email data to train AI models.
- We don't sell your email data or use it for advertising.
- We don't share it except with the service providers that help us deliver these features, as described above, or when the law requires.
- People at Scoutify don't read your emails, except a small number of authorized engineers when needed to fix a problem you report, for security, or to comply with the law.
Limited Use: Scoutify's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting: you can disconnect at any time in your Scoutify account settings, from your Google Account permissions page, or from your Microsoft account's app permissions at account.live.com/consent/Manage. We stop accessing your inbox once it's disconnected. Microsoft doesn't let us revoke Outlook access for you, so if you disconnect Outlook in Scoutify, also remove Scoutify there. Emails we already stored stay with your account until you delete your account. Deleting a message in Scoutify Mail moves it to the Deleted folder, where you can still restore it. Email support@scoutify.com if you want stored emails deleted sooner.
16. Scoutify's LinkedIn Page
This section is about our own company Page on LinkedIn, not about your LinkedIn profile (for that, see "LinkedIn profile data we look up for you" in Section 3). We publish job listings and other posts to Scoutify's LinkedIn Page, either through LinkedIn's own tools for Page admins or through Buffer (buffer.com/privacy), a scheduling tool that LinkedIn approves.
- We receive access tokens that let us post to our own Page, and we keep them in encrypted secret storage. A Page admin can revoke them at any time in LinkedIn.
- We read engagement numbers (impressions, clicks, likes) for our own posts so we can improve what we post.
- We don't collect profile data or connections of LinkedIn members who view or engage with our posts, and we don't use LinkedIn data for advertising or AI model training.
- On a Page admin's request, we delete LinkedIn-derived data within 10 days.
17. Changes to this policy
We'll update this policy when our practices change, and change the "Last updated" date at the top. If a change is significant, we'll tell you by email or in the app before it takes effect.
18. Contact us
Notify You, Inc. (doing business as Scoutify)
Email: support@scoutify.com