Privacy Policy

Last updated: July 14, 2026

Who we are

Wilbo (wilbo.ai) is an AI job-application assistant. This policy covers the wilbo.ai website and the Wilbo browser extension.

What we collect

Account data. When you sign in with Google we store your Google account id, email address, display name, and profile picture.

Application data. The information you add so Wilbo can apply for you — for example your contact details, work history, resume, and answers to screening questions.

Job page content. While Wilbo fills out an application on indeed.com, the extension reads the content of that page (the job posting and the application form's fields and questions) and sends it to our servers so we can determine the right answers. The extension only ever reads indeed.com pages. It does not read other websites, and it does not collect your browsing history.

Pairing credentials. When you connect the extension to your account, we issue it a device token. We store a hashed copy to recognize your extension. You can disconnect a paired extension from your dashboard at any time, which revokes the token.

Wilbomail data. If you claim a Wilbomail address or connect application-code forwarding, we process the email needed to provide that service, including message headers, body, and attachments. We also keep alias, thread-routing, delivery, and verification-challenge records. Gmail forwarding confirmation is reduced to the code or link metadata needed to complete setup.

Usage data. We keep basic aggregate statistics (for example, how many people visited, signed up, or connected the extension, and the campaign or site that referred them). These are stored as counters, not individual browsing records.

What we do with it

We use this data for one purpose: operating Wilbo — matching jobs to your profile, filling out and submitting applications you approve, and showing you a record of what was sent. Application data is shared with the employer or job platform only as part of an application you asked for.

We do not sell your data. We do not share it with third parties except the service providers that host Wilbo. We do not use it for advertising, creditworthiness, or lending purposes, or for any purpose unrelated to running Wilbo.

AI processing & redaction

Wilbo reads job postings, tailors applications, and condenses your instructions using large AI models that run on upstream compute providers. We take steps to protect your privacy before your text reaches that compute: personal identifiers we hold (such as your name and email address) are replaced with anonymous placeholders like [PRIVATE FULL NAME #1], and email addresses and phone numbers found in free text are masked the same way. The upstream models work with the placeholders; the real values are restored on our own infrastructure after the response comes back.

Redaction is a safeguard, not an absolute guarantee — free text can contain personal details in forms we do not recognize. Don't put anything in your notes you wouldn't want processed.

Wilbomail forwarded email

If you claim a Wilbomail address, email sent to it passes through our infrastructure on its way to your inbox, and ordinary replies can pass back through the same service so the recipient sees your Wilbomail address. Bounded raw-message recovery copies expire automatically after 60 days. Routing, delivery, and application records may be retained with your account as described below.

Wilbomail is a forwarding service. It does not sign in to your Gmail account, request Gmail OAuth scopes, or use the Gmail API to read your inbox. If you choose the optional Gmail application-code method, you create a narrow forwarding rule in Gmail and Wilbo receives only the messages Gmail sends to the dedicated intake address.

During an application you asked Wilbo to complete, an authenticated one-time verification message may be matched to that active application, and its code may be used to continue the same session. A successfully consumed code message is deleted rather than forwarded; a released or expired challenge forwards the held message normally. See Email codes for job applications.

Google Calendar RSVP controls are separate from the Wilbomail email relay. If you use them, Google sends the response under the Google account currently signed in, and the organizer may see that account's email address. See Calendar invitations & Wilbomail. For a plain-language description of the relay and its limits, read how Wilbomail works.

Retention & deletion

We keep your data while your account is active. You can delete your account yourself, at any time, from your Account Settings page — after you confirm with a code we email you, your profiles, resumes, application history, extension tokens, billing details, and account record are permanently removed and any subscription is cancelled. If you'd rather not use the self-serve option, email us instead and we'll do it for you. Disconnecting the extension revokes its access immediately.

Contact

Questions or deletion requests: support@wilbo.ai