GAF-J

Privacy Policy

Effective 4 September 2026 · Contact: admin@gaf-j.com

GAF-J exists to handle your work history carefully. This policy says what we collect, where it lives, who sees it, and how you get rid of it. It covers the free app, the site gaf-j.com, and the hosted service at app.gaf-j.com.

1. The free app: nothing leaves your computer

The free app stores everything in one database file on your own computer. It does not phone home, has no analytics, and sends nothing to us. When you ask it for a document, it builds a packet from the records you confirmed and hands it to the AI you connected (a chat you paste into, Claude Desktop, or a provider key you hold). That traffic goes from your computer to your provider under your provider's terms; we are not in the path and never see it.

2. The website

gaf-j.com is static pages served by GitHub Pages. We run no analytics, no cookies, and no trackers on it. GitHub's servers see the ordinary request logs any web host sees (your IP address, the page requested, your browser type) under GitHub's privacy statement. Your theme choice (light or dark) is kept in your own browser's storage and never sent anywhere.

3. The hosted service: what we store

When you sign in at app.gaf-j.com we create an account and store, in a folder that belongs to that account only:

Each account's data is stored separately from every other account's and encrypted at rest on the hosting provider's disks. There is no query in the service that reads across accounts. We do not use your data to train any model, do not sell it, do not share it with employers, recruiters, or advertisers, and do not read it except to fix a problem you asked us to fix, with your permission.

4. The AI model

On the hosted service, when you ask for a document, the app builds a packet containing only the parts of your confirmed record relevant to that document plus the posting or interview it is for, and sends it to an AI model run by Anthropic through our relay. The relay stores neither the packet nor the reply; its log holds the operation name, token counts, timing, and a hash. Anthropic processes the packet under its commercial terms, which do not permit training on it. The reply comes back to your account as your document.

5. Payments

Credits are bought through Stripe. Stripe collects your card details and billing information directly under Stripe's privacy policy; we receive only a confirmation that a purchase completed, the package bought, and Stripe's ids for it. We never see or store your card number.

6. Retention and deletion

7. Your rights

You can see, export, correct, and delete your data yourself from inside the app at any time, without asking us. For anything the app cannot do, or to ask what we hold about you, write to admin@gaf-j.com from the email on your account; we answer within thirty days. If you are in the European Economic Area, the United Kingdom, or California, the rights those laws give you (access, correction, deletion, portability, objection, and the right not to be discriminated against for exercising them) apply and are honored the same way.

8. Security

Sign-in is by Google only; we hold no passwords. Sessions are server-side and expire. All traffic is over HTTPS. The service refuses requests from other origins, stores no provider keys for hosted accounts, and runs the AI through named operations only. If we ever learn of a breach affecting your data we will tell you by email without undue delay.

9. Children

GAF-J is for people looking for work and is not directed at anyone under 16. We do not knowingly collect data from children; if you believe a child has created an account, write to us and we will delete it.

10. Changes

If this policy changes in a way that matters to you, we say so on the site and in the app before the change takes effect. The effective date at the top is the date of the current version.