Privacy Policy
Plain language: what we store, what we never do, and how to delete your account.
What we collect
We collect your email address for authentication, your uploaded resume for parsing, and any profile information you enter. Job postings and generated resume drafts are stored in your account. We do not collect payment card details; those are handled entirely by Stripe.
What we do not do
We do not sell your data. We do not share it with third parties for advertising. We do not use your resume, job postings, or generated drafts to train our own AI models. We access models through OpenRouter, which routes inputs to underlying providers, and may use the OpenAI API fallback when the primary route is unavailable. Provider and endpoint policies can differ, including for retention and training, so we do not promise that every underlying provider handles inputs in the same way. We review those policies and use the least-retentive settings available to us.
Cookies and local storage
We use a small number of first-party, essential cookies to run the product: keeping you signed in, remembering an anonymous Quick Match session before you create an account, and carrying a referral code or redemption code through sign-in for a short time. These cookies are not readable by JavaScript, are not shared with any advertiser, and expire automatically (from 30 minutes up to 30 days depending on purpose). We do not use advertising or cross-site tracking cookies.
Analytics
We use PostHog to understand how the product is used: page views, feature usage, and session behaviour. PostHog operates in cookieless mode on this site. No personally identifiable information is sent to PostHog. You can opt out by enabling Do Not Track in your browser.
Third-party services
We use the following third-party services to operate Last Friday:
- Supabase: database and authentication. Your account data, resume, and job history are stored in Supabase.
- OpenRouter: AI gateway used to access models from providers such as Anthropic, OpenAI, and Google that generate your tailored drafts and cover letters. OpenRouter processes request metadata and routes the content to the selected endpoint. Its endpoint policies govern retention and training.
- OpenAI API fallback: fallback model provider used when a primary OpenRouter request cannot complete. Inputs are processed to generate the requested output under OpenAI's API terms and privacy documentation.
- Stripe: payment processing. We do not store your card details. Stripe's privacy policy governs payment data.
- PostHog: product analytics. Cookieless. No PII transmitted.
- Sentry: error monitoring, used to diagnose bugs. Configured not to send default personally identifying request data.
- Cloudflare Turnstile: bot protection on our free public tools. Cloudflare checks your browser and IP address to confirm you are not an automated script. It does not receive the resume or job text you submit.
Each provider has its own privacy policy.
Data retention
We retain your account data for as long as your account is active. You can request deletion at any time; see below.
Your data and deletion
You own the content you upload and generate. You can delete your account and all associated data (including your profile, resume, job history, and generated drafts) immediately and yourself from Settings → Danger zone. Deletion happens as soon as you confirm it; it does not require contacting us. If you would rather we do it for you, or you cannot access your account, email support@mylastfriday.com and we will action the request within 30 days and confirm by email when complete.
Access, correction, and complaints
You may request access or correction of personal information we hold about you, or ask how it has been used or disclosed by emailing support@mylastfriday.com. We may verify your identity before responding. If you have a privacy complaint, contact us first so we can investigate and respond.
We aim to respond to access requests within 30 calendar days. If a lawful extension is needed, we will explain the reason and expected response date. You may also complain to the Office of the Privacy Commissioner of Canada if you are not satisfied with our response.
Security incidents
We use access controls and security safeguards appropriate to the sensitivity of resume and profile information. If a security incident creates a risk of significant harm, we will assess it, keep records of every privacy breach, report to the Office of the Privacy Commissioner of Canada where required, and notify affected people as required by applicable law.
International processing
Our service providers may process information internationally, including in Canada, the United States, and other countries where their infrastructure or model endpoints operate. We use contractual and technical safeguards appropriate to the transfer and the sensitivity of the information.
Canadian users and service scope
Last Friday is operated by Christopher G. Pathinathan, an individual based in Toronto, Ontario, Canada, currently operating as an unregistered sole proprietor (not an incorporated company). We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Ontario's privacy laws. The service is not currently targeted to EEA users. If our geographic scope changes, we will review and update our privacy obligations before intentionally offering or marketing the service in that region. For privacy or business-identity questions, contact contact@mylastfriday.com.
Contact
Questions about this policy or your data? support@mylastfriday.com