Privacy policy

Last updated: September 29, 2026

Highcard (highcard.app) is a browser extension and companion service that helps job seekers find and follow up with hiring managers and recruiters for jobs they're applying to. This page explains what we collect, why, and what we never do with it. The short version: we collect the minimum needed to run your account and your searches, we don't sell data, and we don't run ad trackers.

What we collect when you create an account

Payments

Payments are processed by Stripe. Your card number never touches our servers; we store only your plan and Stripe's reference IDs for your purchase. If you cancel, your subscription lapses, or a payment is refunded or disputed, Stripe tells us and your account returns to the free plan. Stripe's handling of your data is described in Stripe's privacy policy.

What the extension reads

The extension reads the job posting you have open, and nothing else. It runs on LinkedIn, Indeed (indeed.com, ca.indeed.com, uk.indeed.com) and a fixed list of recruiting sites employers use: Greenhouse, Lever, Ashby, Workable, SmartRecruiters, Workday and iCIMS. On those sites it reads only the job posting you have open. On any other page the panel stays closed and nothing is read or sent. It has no permission to read any other website.

What is sent to Highcard, and to whom

When you press Get Contacts, the details of that posting are sent to the Highcard backend, which runs the search. To do that, the relevant details (typically the company name and website, the job title and parts of the description) are passed to service providers acting on our behalf:

Your email address is not sent to the contact-data, search or AI providers.

Contact details of other people

A search result is business contact information about third parties, the hiring managers and recruiters at the company you're applying to: name, job title, employer, LinkedIn profile, location, and a work email address (either supplied by a data provider or inferred from the employer's email pattern). It comes from the professional-data providers above and from publicly visible professional profiles. We collect no special-category data and no personal (non-work) contact details.

If you are one of those people and want your details removed from Highcard's records, email info@highcard.app and we will delete them.

Your resume

If you upload a resume, the file stays in your browser's extension storage. It is sent to the Highcard backend for two purposes only: to extract its text, and to draft an intro email from it. The file is processed in memory and is not stored on our servers. The drafted email is cached briefly (see retention below) so that re-opening the same job doesn't re-run the AI. Your resume is never sent to the contact-data providers, and it is attached to an outgoing email only by your browser, when you send it.

Google user data

If you sign in with Google, we request only your email address and basic profile, used solely to create and sign in to your account. If you choose to connect Gmail for sending follow-up emails, we request the gmail.send permission and nothing more: it can only send messages, and it is used only to send the emails you write and approve. We cannot and do not read, store or analyze your inbox. Highcard's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect your data

This section describes the safeguards for the data above, including the sensitive Google user data (the Gmail permission and the emails you send).

Open tracking on the emails you send

Emails sent with tracking on contain an invisible 1×1 image hosted by us. When the recipient's mail client loads that image, we record that the email was opened. This is how the extension's activity feed can tell you an email was read.

Product usage data

To see which parts of Highcard help people and which get in the way, we record named product events. This covers the extension, our servers and highcard.app.

Cookies

We set one cookie: an HttpOnly, signed session cookie that keeps you logged in to your account. Logging out ends that session on our servers as well as in your browser. Page analytics on highcard.app keep their identifier in your browser's local storage, not in a cookie (see "Product usage data"). There are no advertising cookies and no cross-site tracking of any kind.

Who we share data with

Only the service providers listed above, plus PostHog for product usage data (see "Product usage data"), each processing data on our instructions to deliver part of the product. We never sell your data, we never share it for advertising, and we don't hand it to anyone else unless we're legally required to.

How long we keep things

Deleting your account

You can delete your account at any time from the account dashboard. You'll be asked for your password to confirm. Deleting removes your account record: your email, password hash, plan, usage count and every connected browser. Your address is taken out of our other records in the same step: the purchase row we keep for your payments stays as a payment reference with no address on it, any product feedback you sent keeps its text and date but no longer carries your address, and any pending account email is dropped. Data stored locally by the extension is removed by uninstalling it or clearing its storage. To have anything else erased, email info@highcard.app.

Backup copies made before you deleted are not rewritten, because editing a backup would defeat the point of having one. They expire on their own: our own daily copies within 14 days (we keep 14 of them), and our hosting provider's disk snapshots within 7 days. The one offline copy we take each month for disaster recovery is replaced by the next month's, so it is gone within about 60 days. After that we hold no copy of your account record. Payment records held by Stripe follow Stripe's own retention rules.

Changes and contact

If this policy changes materially, we'll update this page and the date above. Questions, removal or deletion requests: info@highcard.app.