Privacy policy
Last updated: September 29, 2026
Highcard (highcard.app) is a browser extension and companion service that helps job seekers find and follow up with hiring managers and recruiters for jobs they're applying to. This page explains what we collect, why, and what we never do with it. The short version: we collect the minimum needed to run your account and your searches, we don't sell data, and we don't run ad trackers.
What we collect when you create an account
- Your email address: used to sign you in, send account emails (activation, password reset), and identify your subscription.
- A password, if you use one: stored only as a salted bcrypt hash. We never see or store the password itself. If you sign in with Google, we receive your email address from Google and no password exists.
- Plan and usage data: your plan, a count of the contact searches you've run, and Stripe's reference IDs for your purchase, used to enforce plan limits and to keep your plan in step with your subscription.
- Security events: we log sign-ins, sign-in failures, password changes, connected browsers and plan changes so we can spot abuse. Those log lines identify your account by an internal ID and contain no email address, name or password.
Payments
Payments are processed by Stripe. Your card number never touches our servers; we store only your plan and Stripe's reference IDs for your purchase. If you cancel, your subscription lapses, or a payment is refunded or disputed, Stripe tells us and your account returns to the free plan. Stripe's handling of your data is described in Stripe's privacy policy.
What the extension reads
The extension reads the job posting you have open, and nothing else. It runs on LinkedIn, Indeed (indeed.com, ca.indeed.com, uk.indeed.com) and a fixed list of recruiting sites employers use: Greenhouse, Lever, Ashby, Workable, SmartRecruiters, Workday and iCIMS. On those sites it reads only the job posting you have open. On any other page the panel stays closed and nothing is read or sent. It has no permission to read any other website.
- The posting itself: job title, company, location, whether the role is remote/hybrid/on-site, the job description text, the job's own URL, the employer's company page on that site, and, on LinkedIn, the name and profile link of whoever posted the job. The description is truncated before it is sent.
- We do not read your browsing history, your other tabs, your bookmarks, or any page you haven't opened yourself. The extension has no history or tabs permission, and it never fetches pages in the background on other sites.
- Saved jobs, your notes and your contact lists live in your browser's own extension storage, on your machine. Uninstalling the extension or clearing its storage removes them.
What is sent to Highcard, and to whom
When you press Get Contacts, the details of that posting are sent to the Highcard backend, which runs the search. To do that, the relevant details (typically the company name and website, the job title and parts of the description) are passed to service providers acting on our behalf:
- Contact-data providers, to find the people at the hiring company and their business contact details (we use Apollo.io and AI Ark).
- A web-search and web-data provider, to work out the employer's real website, read the employer's public company page, and find public professional profiles (we use Serper, SerpApi, Bright Data, Apify and Wikidata).
- An AI provider, to read the job description and to draft the intro email you asked for (we use Anthropic's Claude). Your prompt and the text you sent are processed to produce the draft; they are not used to train the model.
- Stripe for payments. Resend for account emails (activation, password reset). Google for sign-in, and for sending your emails if you connect Gmail. Our hosting provider runs the servers.
Your email address is not sent to the contact-data, search or AI providers.
Contact details of other people
A search result is business contact information about third parties, the hiring managers and recruiters at the company you're applying to: name, job title, employer, LinkedIn profile, location, and a work email address (either supplied by a data provider or inferred from the employer's email pattern). It comes from the professional-data providers above and from publicly visible professional profiles. We collect no special-category data and no personal (non-work) contact details.
If you are one of those people and want your details removed from Highcard's records, email info@highcard.app and we will delete them.
Your resume
If you upload a resume, the file stays in your browser's extension storage. It is sent to the Highcard backend for two purposes only: to extract its text, and to draft an intro email from it. The file is processed in memory and is not stored on our servers. The drafted email is cached briefly (see retention below) so that re-opening the same job doesn't re-run the AI. Your resume is never sent to the contact-data providers, and it is attached to an outgoing email only by your browser, when you send it.
Google user data
If you sign in with Google, we request only your email address and basic profile, used solely to create and sign in to your account. If you choose to connect Gmail for sending follow-up emails, we request the gmail.send permission and nothing more: it can only send messages, and it is used only to send the emails you write and approve. We cannot and do not read, store or analyze your inbox. Highcard's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect your data
This section describes the safeguards for the data above, including the sensitive Google user data (the Gmail permission and the emails you send).
- Your Gmail permission stays on your device. The token Google issues when you connect Gmail is stored only in the extension's own storage in your browser. It is never sent to, or stored on, Highcard's servers. The extension uses it for one thing: calling Google's Gmail API over an encrypted connection to send the message you approved. Google expires it automatically after about an hour, and you can revoke it at any time in the extension ("Disconnect" or "Switch") or at myaccount.google.com/connections.
- The emails you send never pass through Highcard. The message is assembled inside the extension and goes straight from your browser to Google. Highcard's servers do not receive or store the body of any email. When open tracking is on, the server keeps only the recipient's name and address, the subject, the job it belongs to and the open events, for the period stated below.
- Encryption. Every connection between the extension, highcard.app, api.highcard.app and Google uses HTTPS (TLS). Our servers and their storage run on Render, whose disks are encrypted at rest.
- Credentials are stored as hashes, not values. Passwords are stored as salted bcrypt hashes. The credential that links your browser to your account, and the tokens used to verify or reset an account, are stored as hashes too; the extension itself holds only a short-lived access token that expires after fifteen minutes. Secrets such as API keys live in the server's protected configuration, never in the code or the extension.
- Access control. Every request to the Highcard service must carry a valid token for a signed-in account, and each account can only reach its own data. Access to the production systems is limited to the operator. Server logs never contain names, email addresses, tokens or profile links; a person is referred to by an opaque reference only.
- Retention and deletion. Data is kept only for the periods listed under "How long we keep things" and is purged automatically after that. You can delete your account, and everything tied to it, from your account page at any time.
- If something goes wrong. If we learn of a security incident affecting your data, we will notify affected users by email without undue delay and describe what happened and what we are doing about it.
Open tracking on the emails you send
Emails sent with tracking on contain an invisible 1×1 image hosted by us. When the recipient's mail client loads that image, we record that the email was opened. This is how the extension's activity feed can tell you an email was read.
- What we store per tracked email: who you sent it to (name, email address, job title and LinkedIn profile as shown in the extension), the subject, which job it was about, when you sent it, how many times it has been opened, when it was first and last opened, and for each open the time and the recipient's browser/mail-client identification string (their user agent, truncated). We do not store the recipient's IP address and we do not attempt to locate them.
- You can turn it off: the Email Tracking switch in the extension's Email tab. It is on by default. With it off, no tracking image is added and no tracking record is created at all.
- It is not proof of reading. Apple Mail's privacy protection and many corporate mail scanners fetch images automatically, which registers as an open; recipients who block images register nothing.
- Recipients are not profiled, and this data is never used for advertising or shared with anyone.
Product usage data
To see which parts of Highcard help people and which get in the way, we record named product events. This covers the extension, our servers and highcard.app.
- What an event holds: its name (for example a search run, contacts shown, an email address looked up, a draft generated, an email sent or opened, a setting changed), when it happened, the job board it happened on, counts such as how many contacts were found, and a one-way hashed reference to the job posting. Each event is tied to your account's internal ID.
- What it never holds: the job text, the names or addresses of the people found, the content of your emails, your resume, or the web addresses you visit. There are no keystrokes and no mouse tracking in the extension.
- Who processes it: PostHog Inc., hosted in the US or the EU depending on how our project is configured. Events are kept for 12 months.
- You can turn it off: the Share anonymous usage data switch in the extension's Settings. With it off, the extension sends no usage events at all.
- On highcard.app we use cookieless page analytics (your browser's local storage, not a cookie) and session replay, a recording of how pages are used so we can fix confusing ones. Every form field is masked in those recordings, as is your email address on the account pages, so what you type is never captured.
Cookies
We set one cookie: an HttpOnly, signed session cookie that keeps you logged in to your account. Logging out ends that session on our servers as well as in your browser. Page analytics on highcard.app keep their identifier in your browser's local storage, not in a cookie (see "Product usage data"). There are no advertising cookies and no cross-site tracking of any kind.
Who we share data with
Only the service providers listed above, plus PostHog for product usage data (see "Product usage data"), each processing data on our instructions to deliver part of the product. We never sell your data, we never share it for advertising, and we don't hand it to anyone else unless we're legally required to.
How long we keep things
- Your account (email, password hash, plan, usage count): until you delete it.
- Contact records found by a search: up to 60 days, then re-checked or dropped.
- A job's search results: reused for 7 days, after which the search runs again from scratch, and deleted within 30 days. These results are cached per job posting rather than per person, so a cached result for the same posting may also answer someone else's search for it. They contain the job and the business contacts found for it, nothing about you.
- A drafted intro email: kept for up to 7 days (deleted within 30) so reopening the Email tab does not write it again. It is stored under your account and is never served to anyone else. Your resume file itself is not stored on our servers.
- Which website belongs to which employer: up to 30 days.
- Email tracking records: up to 180 days after sending, then deleted.
- Product usage events: up to 12 months, then deleted by PostHog.
- Data in your browser (saved jobs, contacts, resume, settings): until you remove it or uninstall the extension.
Deleting your account
You can delete your account at any time from the account dashboard. You'll be asked for your password to confirm. Deleting removes your account record: your email, password hash, plan, usage count and every connected browser. Your address is taken out of our other records in the same step: the purchase row we keep for your payments stays as a payment reference with no address on it, any product feedback you sent keeps its text and date but no longer carries your address, and any pending account email is dropped. Data stored locally by the extension is removed by uninstalling it or clearing its storage. To have anything else erased, email info@highcard.app.
Backup copies made before you deleted are not rewritten, because editing a backup would defeat the point of having one. They expire on their own: our own daily copies within 14 days (we keep 14 of them), and our hosting provider's disk snapshots within 7 days. The one offline copy we take each month for disaster recovery is replaced by the next month's, so it is gone within about 60 days. After that we hold no copy of your account record. Payment records held by Stripe follow Stripe's own retention rules.
Changes and contact
If this policy changes materially, we'll update this page and the date above. Questions, removal or deletion requests: info@highcard.app.