Skip to content
Compare Jobs Privacy Terms

PUBLIC INFORMATION / PRIVACY

Privacy Policy

This policy describes the information the current Scan.Careers website, account service, and Chrome extension process, what is stored, and what remains on your device.

Effective September 13, 2026

1. Scope

Scan.Careers is operated by ProTron LLC, doing business as SkillDoc.ai.

This policy applies to the Scan.Careers website, Scan.Careers account service, and Scan.Careers Chrome extension. It reflects the product as it operates on the effective date. Scan.Careers is an evidence-oriented job-comparison tool, not a recruiting service or employer.

2. Information we collect

Google sign-in and account identity

When you choose Google sign-in, Scan.Careers receives and stores your Google account subject identifier, verified email address, a bounded display name, and, when available, a bounded HTTPS Google-hosted profile-image URL. The Google subject identifier—not email alone—is used to resolve your Google identity. Scan.Careers does not request access to Gmail, Google Drive, contacts, calendars, or other Google services.

Sessions

Scan.Careers issues a random, opaque session token to your browser. The service stores a SHA-256 hash of that token, along with session identifiers, creation and expiration times, last-seen time, and revocation state.

Optional SkillDoc connection

You may explicitly connect your Scan.Careers account to a SkillDoc account. Scan.Careers stores a local account link so SkillDoc can remain the canonical identity, entitlement, and credit authority for that connected account. When connected, Scan.Careers may check your SkillDoc entitlement and request credit consumption or restoration. Linking is explicit, and Scan.Careers does not merge accounts by email alone.

Career information you explicitly save

Signing in does not automatically upload pre-existing Chrome-extension data. If you explicitly choose to save local data to your account, the service can store a structured career profile, bounded confirmed or proposed evidence records, and bounded saved-scan records. These records can include role and work preferences, evidence text and review state, job identity details, canonical requirements, corrections, decisions, and actions.

Usage and first-party analytics

The service records bounded successful-analysis accounting, including a usage category, provider and model labels, quantity, and timestamp. First-party website analytics store only an allowlisted event name and timestamp. Those analytics rows contain no account identifier, custom metadata, pasted job text, or AI-provider content.

3. Job comparison processing

When you request a website comparison, the pasted job descriptions are sent to the Scan.Careers Worker and processed to produce the requested comparison. They are not durably stored in the production Scan.Careers D1 database. The website may retain the validated derived comparison in your browser until you clear it; pasted descriptions remain only in the active page memory and form state.

For a connected SkillDoc account, after a successful comparison Scan.Careers may send SkillDoc a bounded completion summary containing the source type, finding count, and up to ten selected skill labels. Scan.Careers does not send pasted job descriptions to SkillDoc through its entitlement, credit, or activity requests.

The Chrome extension can keep bounded profile, evidence, settings, and saved-scan information in local Chrome storage. Local browser or extension information is separate from optional cloud account data.

4. AI processing

Scan.Careers uses Google Gemini, a service provided by Google, to analyze job-related information and return structured analysis. For a website comparison, the pasted job descriptions are included in the request sent to Gemini. Scan.Careers validates and bounds provider output before presenting it. Google operates Gemini independently; this policy does not make claims about Google's separate retention, model-training, or other data practices. Review Google's applicable terms and privacy information for those practices.

5. Information we do not durably store in D1

  • Google access tokens or refresh tokens.
  • OAuth authorization codes after the authentication request that consumes them.
  • Plaintext Scan.Careers session or handoff tokens.
  • Server-side Google, Gemini, or SkillDoc service credentials in browser-accessible storage.
  • Full pasted multi-job description collections.
  • Raw Gemini prompts or raw Gemini responses.
  • Raw or derived multi-job comparison data.
  • Raw résumé files or raw imported résumé text.
  • Google profile-image binaries, Gmail, Drive, contacts, or other unnecessary Google profile data.

Bounded structured information derived from user-reviewed career evidence may be stored locally, and may be stored in the cloud only after explicit save or sync.

6. Cloud save, restore, and deletion

Cloud save and restore are explicit actions. The current sync process compares data and reports conflicts instead of silently overwriting divergent records.

The authenticated Scan.Careers account-deletion control deletes the cloud user record and cascades removal of linked Google identity records, sessions, handoffs, the local SkillDoc account link, cloud career profile, cloud evidence, cloud saved scans, and linked usage records. The old session then becomes invalid.

Deleting a Scan.Careers account does not delete the connected SkillDoc account or records controlled by SkillDoc, such as its credit ledger or ecosystem activity. Those records are governed by SkillDoc's own controls and policies.

Deleting a cloud account does not delete local Chrome-extension or browser data. Local data remains on the device until you use the product's local deletion controls or clear the relevant browser or extension storage. Metadata-free analytics events have no account identifier and cannot be linked back to an account for account deletion.

7. Service providers

  • Cloudflare provides website hosting, Worker execution, and D1 database infrastructure.
  • Google provides account authentication.
  • Google Gemini provides AI processing for requested analyses.
  • SkillDoc provides connected-account identity, entitlement, credit, and bounded activity services when you explicitly link an account.

No marketing-email service is currently implemented. A verified Google email address is used as an account and authentication identifier; Google sign-in does not subscribe you to a newsletter or establish marketing consent.

8. Browser storage and functional cookies

The website uses browser storage for your Scan.Careers session token and, when applicable, a validated derived comparison. The account service also uses short-lived functional cookies during Google authentication and optional SkillDoc connection flows. These authentication cookies are not used for advertising.

9. Security

Current safeguards include HTTPS transport, server-side secrets, random opaque sessions, hashed server-side session representations, expiring and single-use OAuth state and handoff records, exact origin and return-URL controls, bounded request fields, and user-scoped database access. No system can guarantee absolute security.

10. Your choices and requests

You can choose whether to sign in, whether to save eligible local data to the cloud, whether to restore cloud data, and whether to delete your cloud account. You can also clear the locally saved website comparison or use the extension's local privacy controls.

For privacy or support requests, contact support@scan.careers.

11. Policy updates

This policy may be updated as Scan.Careers changes. Material changes will be reflected by updating this page and its effective date. The revised policy applies when posted, subject to applicable law.

SCAN.CAREERS / 2026
How It Works Guides FAQ Privacy Terms
Evidence first. No hiring probability claims.