Privacy Policy
Olive Independent Study, Inc.
Last Updated: August 10, 2026
See also: Terms of Service
Table of Contents
- Introduction
- Scope of This Policy
- Eligibility and Children's Privacy
- Definitions
- Categories of Information We Collect
- How We Collect Information
- AI and Automated Processing
- Purposes for Processing Personal Information
- Sharing of Personal Information
- Cookies, Local Storage, and Tracking Technologies
- Data Retention
- Security Practices
- Your Privacy Rights
- Accessing, Updating, or Deleting Your Information
- Third-Party Websites and Links
- Organizational and Educational Institution Integrations
- De-Identified and Aggregated Information
- California-Specific Disclosures (CCPA / CPRA)
- Data Storage, Transfers, and International Users
- Data Breach Notification
- Changes to This Privacy Policy
- Contact Information
- Chrome Web Store Compliance
1. Introduction
This Privacy Policy ("Policy") describes how Olive Independent Study, Inc. ("Company," "we," "us," "our") collects, uses, discloses, maintains, and protects information related to individuals who use, access, or interact with the Olive platform (the "Service").
By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with this Policy, you should not access or use the Service.
This Policy is intended to be comprehensive and to cover current and reasonably anticipated future processing activities, including AI-assisted features, analytics, and integrations with third-party systems. Some descriptions may refer to features or integrations that are not yet generally available but are included to support legal completeness as the Service evolves.
2. Scope of This Policy
This Policy applies to information collected through the Service, including:
- Websites and web applications operated by Olive Independent Study, Inc.
- Mobile applications published by Olive Independent Study, Inc., including the Olive Jobs apps for iOS and Android
- Browser extensions published by Olive Independent Study, Inc., including the Olive Auto-Apply Chrome extension
- AI-powered tools, resume processors, interview simulators, and chat systems
- Communication channels and account systems, including the Olive Discord bot
- Data received from educational institutions or authorized organizational partners
- Device, browser, and usage information collected automatically
This Policy does not apply to:
- Any third-party websites, platforms, or applications linked to the Service
- Data collected independently by universities, employers, or job boards
- Employee or contractor data processed by Olive Independent Study, Inc.
3. Eligibility and Children's Privacy
The Service is intended for adults who are at least 18 years old. By using the Service, you represent that you meet this age requirement and have the legal capacity to enter into binding agreements.
We do not knowingly collect personal information from individuals under 18 years of age. If we become aware that a minor under 18 has submitted personal information through the Service, we will take reasonable steps to delete such information as soon as practicable. If you believe that a minor has provided personal information in violation of this Policy, please contact us at [email protected].
If you access the Service through a university or other educational institution, that institution may have its own policies governing eligibility, student participation, and data handling practices. This Policy governs only the processing activities performed by Olive Independent Study, Inc. through the Service. For more details about institutional integrations, see Section 16 below.
4. Definitions
For the purposes of this Policy, the following terms have the meanings set forth below:
"Account" means a unique profile created to access the Service.
"Personal Information" means any information that identifies, relates to, describes, or can reasonably be associated with an individual. This includes identifiers, professional data, usage data, and AI-processed information.
"Service" refers to the job readiness, career development, AI-powered tools, web interfaces, and accompanying technologies offered by Olive.
"User Content" includes resumes, text inputs, uploads, recordings, chat messages, and any other data submitted by users.
"De-identified Information" means information that cannot reasonably be used to infer the identity of an individual.
"Aggregated Information" means information combined with other data, rendering personal identification impossible.
5. Categories of Information We Collect
We collect information from or about you in the following broad categories. Not all categories may apply to all users, and certain categories are included for purposes of future-proofing the Service.
A. Identity and Contact Information
- Full name
- Email address
- Authentication identifiers (e.g., tokens issued by login providers)
- Profile photo or avatar (if applicable)
- User account identifiers
- Organization or institution affiliation (if any)
B. Professional and Job-Related Information
- Resume content and uploaded documents
- Career summary and skills
- Work and academic history
- Certifications, achievements, and project data
- Professional preferences and career interests
- Job search filters and saved roles
- AI-generated embeddings or structured data derived from your profile
C. Usage, System, and Device Data
- Browser type and version
- Device type and operating system
- IP address, and the approximate location (country, region, and city) our hosting provider derives from it
- Device location coordinates, only on our website, and only when you use a "use my location" control and grant your browser's location permission (see Section 5.F)
- Session identifiers, timestamps, and log data
- Referrer URLs and interaction patterns
- Crash reports and diagnostic information
D. Communication and Interaction Data
- AI chat messages and voice interactions
- Interview transcripts and recordings
- User-initiated support messages
- Content generated during onboarding, mock interviews, or job matching
E. Organization-Provided Information
If your university, educational institution, or organization partners with us, they may provide:
- School or organization identifiers
- User roster or enrollment confirmations
- Program or cohort information
- Usage insights or aggregated engagement data
F. Sensitive Information
We do not intentionally collect or process:
- Protected health information ("PHI") as defined under HIPAA
- Government-issued identification numbers (e.g., SSN, passport)
- Financial account numbers or credit card data
- Educational records protected under FERPA, unless voluntarily submitted through resume uploads or user input, or provided to us by an educational institution as described in Section 16
- Biometric identifiers used for identification
Two categories of sensitive information we DO collect are described below. Neither is sold, shared with advertising partners, or used for any purpose beyond the one described.
Demographic information, only when you volunteer it: race, gender, veteran status, disability status, LGBTQ+ identification, Hispanic/Latino status, and sexual orientation, provided through the Olive Auto-Apply browser extension for the sole purpose of auto-filling equal opportunity employer (EEO/EEOC) questions on job application forms. To do that, these answers may be sent to our AI provider so it can match the right answer to a form field — see Sections 5.G and 7.B for the full disclosure.
Device location, only when you ask for it and grant permission: job search is location-based, so our website offers "use my location" controls in the search filters, in your job preferences, and in the Olive assistant. If you use one, your browser asks you for permission and, if you grant it, returns your device's location coordinates. We use those coordinates to fill in your search location and to find jobs near you, and we send them to Google's Geocoding API to convert them into a place name (see Section 7.B). The resulting location may be saved as part of your search filters or job preferences. We do not track your location in the background, and we do not collect location coordinates unless you use one of these controls and grant permission — you can decline and type a city instead, or revoke the permission in your browser settings at any time. Our mobile apps do not request device location at all; you type a location instead.
Any other personal or sensitive information intentionally submitted by the user (including in free-form text or resume uploads) is processed in accordance with this Policy.
G. Data Collected by the Olive Auto-Apply Browser Extension
The Olive Auto-Apply browser extension collects and processes the following categories of data to provide its job application autofill functionality:
- Profile data — name, email address, phone number, education history, and work experience, synced from your Olive account
- Resumes and cover letters — uploaded or generated documents used to fill application forms and sent to the Olive backend for tailoring
- Default application answers — work authorization status, sponsorship requirements, salary expectations, and available start date, saved to your Olive account and synced to the extension
- Voluntary demographic information — race, gender, veteran status, disability status, LGBTQ+ identification, Hispanic/Latino status, and sexual orientation — saved to your Olive account, synced to the extension, and used only to auto-fill equal opportunity employer (EEO/EEOC) questions on job application forms. Where the extension cannot match a form field on its own, these saved answers are included in the request we send to our AI provider so it can select the right answer for that field — see Section 7.B
- Job application metadata — URLs, job titles, company names, and applicant tracking system (ATS) types for applications you interact with
- Form field structure — field labels and page structure from job application forms, sent to the Olive backend and on to our AI provider to generate answers matched to each field
- Fill history — a local record of your last 20 autofill attempts, including the URL, ATS type, timestamp, and success rate, stored only on your device
- Fill feedback — optional user-submitted ratings, field counts, issues encountered, and comments, sent to the Olive backend to improve autofill accuracy
- Authentication tokens — tokens issued when you sign in to the extension with Google, Microsoft, or LinkedIn, or with an emailed one-time code, stored locally in browser storage and refreshed automatically
What the extension does not collect:
- Browsing history or activity on websites other than supported job application pages
- Form data from pages that are not job application forms
- Keystrokes, mouse movements, or screen content
- Cookies from websites you visit
Where the extension runs. The extension's manifest declares no host_permissions, so installing it grants no blanket or open-ended access to the web. The install prompt is not empty, though. Your browser asks you to approve two things: the fixed set of pages the extension is hard-coded to run on — the 56 match patterns enumerated in its manifest — and the tabs permission it uses to tell which page you are currently on, which Chrome describes to you as reading your browsing history. Nothing beyond that is granted at install. As the list above says, we do not collect your browsing history; the extension uses that permission only to know whether the tab you are on is a supported job application page. Of the 56 patterns, most are applicant tracking system domains that exist only to host job applications (Greenhouse, Workday, Lever, Ashby, iCIMS, SmartRecruiters, and similar). The remainder are employer or consumer career sites, and those are mostly scoped to the job or careers area rather than the whole domain — LinkedIn, for example, is matched only on linkedin.com/jobs/ pages, not the feed, messaging, or profiles.
If you are on a job application page that is not on that list, you can click "Scan this page" in the extension's side panel. Your browser — not the extension — then asks you to approve that one site, and the extension reads the page only if you choose Allow. Two things are worth being precise about: that approval covers the whole site, not just the page you were on, and it persists until you revoke it in your browser's extension settings, so on a later visit to a site you already approved the extension activates without asking again. The extension never asks for site access on its own, and it does not run on any site that is neither in its manifest list nor approved by you. You can review and revoke these per-site approvals at any time from your browser's extension permissions screen.
On every site where it does run, the extension reads only the job posting and the application form. It does not read or transmit your general browsing.
6. How We Collect Information
We collect information through one or more of the following methods:
A. Information You Provide Directly
- Creating an account
- Uploading a resume or other files
- Completing forms, surveys, assessments, or profile fields
- Participating in interviews or using voice-based tools
- Engaging with AI chat, coaching, or recommendation features
- Configuring default answers and demographic preferences in the Olive Auto-Apply browser extension
- Submitting support tickets or contacting customer service
B. Automatic Collection Through the Service
- Cookies, local storage, and session tokens
- Browser and device metadata
- Interaction data (clicks, page views, time on page)
- Error logs, crash events, and system diagnostics
- AI tool usage history and interaction timestamps
- Form field labels and page structure extracted by the Olive Auto-Apply browser extension on supported job application pages
C. Sign-In Methods and OAuth Authentication
The Service offers several ways to sign in, and the information we receive depends on which one you use:
- A third-party account. On the website and in the Olive Auto-Apply browser extension you can sign in with Google, Microsoft, or LinkedIn; in the Olive Jobs mobile apps you can additionally sign in with Apple. We receive limited profile information from that provider — your name and email address, your profile photo if available, and the account identifiers used for authentication. We do not access your contacts, calendar, files, or any other account data beyond what is needed for authentication. Your use of these third-party login services is also governed by their own privacy policies.
- An emailed one-time code. You give us an email address, we email you a short-lived six-digit code, and entering the correct code signs you in. No third-party login provider is involved; we receive only the email address you supply.
- Guest browsing. So that you can search jobs and try the Service before creating an account, we automatically create an anonymous guest account for your browser or device. A guest account has no name or email address attached — only an internal identifier — and the activity recorded under it (searches, saved jobs, chats) carries over if you later sign in with one of the methods above and convert it into a full account.
If you sign in with Apple, we exchange Apple's one-time authorization code for a token that lets us revoke Olive's Sign in with Apple grant when you delete your account. We store that token encrypted and use it for no other purpose.
D. Information from Third Parties
We may receive information from:
- Authentication providers
- Educational institutions or organizational partners
- Job boards or integrated job search tools
- Analytics and service infrastructure partners
7. AI and Automated Processing
A. AI-Enabled Features
The Service includes AI-enabled and automated features, such as resume analysis and tailoring, interview simulations, chat-based and voice-based coaching, and job recommendations. When you use these features, your inputs (including resumes, prompts, interview answers, voice audio, chat messages, and other content) are processed by machine learning systems to generate outputs and suggestions.
B. Third-Party AI Providers and the Data We Share With Them
To deliver these features, we share certain Personal Information with third-party AI providers that process it on our behalf:
- OpenAI powers our real-time voice conversations, chat-based coaching, interview simulations, resume analysis and tailoring, and job-matching assistance. When you use these features, we (or, for live voice sessions, your device directly) send OpenAI the relevant inputs — which may include your resume and profile content, job descriptions you are working with, your interview answers, chat messages, your voice audio during voice sessions, and, when you use the Olive Auto-Apply browser extension, the field labels and structure of the application form together with your saved default answers. That last case is worth calling out: when the extension encounters a form field it cannot fill from your saved answers on its own, it asks OpenAI to work out the right answer, and the request includes your saved defaults — which, if you have provided them, include your demographic answers (see Sections 5.F and 5.G) along with your phone number and address. During an in-app voice session, audio streams directly from your device to OpenAI's real-time service so the assistant can hear and respond, which means OpenAI receives your device's IP address for that session.
- Google (including Google Cloud, Vertex AI, and Google Maps Platform) powers resume and profile understanding, semantic job matching and embeddings, content generation for resume tailoring and evaluation, and location lookup. We send Google the relevant inputs for these features — which may include your resume and profile content, job descriptions, search queries, the text you type into a location box, and location coordinates you choose or share from your device.
These providers act as our service providers (processors): they are permitted to use your information only to provide the requested service to Olive, and not for their own independent purposes. Under our agreements with them, OpenAI and Google are contractually required to protect your Personal Information with safeguards at least as protective as those described in this Policy (including this Policy's confidentiality, security, and data-retention commitments), to restrict access to authorized personnel, and not to use your Personal Information to train their own foundation models except as needed to provide the service to Olive. Both providers process data in the United States.
We also rely on additional service providers to host the Service, deliver your traffic to it, send email, look up locations, and transcribe stored audio. Each of those providers, and what each one receives, is listed in Section 9.A. Where we rely on such providers, they act as service providers to us and are permitted to use your information only to provide services to the Company, subject to contractual confidentiality and security obligations. The specific providers we use may change over time; please refer to the most current version of this Policy for an up-to-date list.
C. Your Choices and Consent
In our iOS and Android mobile apps, the first time you use a feature that would send your information to a third-party AI provider, we present an in-product disclosure that explains, in plain language, what data will be shared (such as your resume content, interview answers, chat messages, and voice audio), who it will be shared with (OpenAI and Google), and how it is protected — and we ask you to agree before any data is shared. If you do not agree, that feature will not send your data to the provider and will not run.
When you use AI features through other parts of the Service, your use of those features reflects your agreement to the sharing described in this Section 7.
You can choose not to use AI features at any time. You can also request deletion of your data as described in Sections 11 and 14, including by contacting us at [email protected].
D. Accuracy and Human Oversight
AI-generated content may contain inaccuracies or reflect limitations of the underlying models. Outputs are intended to support, not replace, your own judgment. You remain responsible for reviewing and deciding how to use any AI-generated suggestions or content.
The Service does not make automated decisions that produce legal or similarly significant effects without human review. AI-generated job application answers are presented as editable suggestions — you may review, modify, or delete any AI-generated content before submitting an application.
Automated Form Actions (Browser Extension)
The Olive Auto-Apply browser extension fills job application form fields from your profile and saved answers. It does not automatically accept consent checkboxes or legal agreements — such as privacy policy acceptance, terms of service, arbitration provisions, or background check authorization — and it does not submit applications on your behalf. You review the filled application, complete any consent or legal acknowledgments yourself, make any changes, and submit it. You remain solely responsible for the content of any application you submit and for any terms or conditions you accept. You can cancel an in-progress autofill at any time.
8. Purposes for Processing Personal Information
We may use Personal Information for a wide range of operational, analytical, and compliance-related purposes. These purposes include, but are not limited to, the following:
A. Providing and Maintaining the Service
- User authentication and account creation
- Operating AI-driven tools such as resume parsing and interview simulation
- Processing and analyzing resumes, documents, and user inputs
- Generating tailored job recommendations
- Supporting job search and application workflows
B. Improving, Developing, and Enhancing the Service
We analyze usage data and user interactions to:
- Enhance feature performance and reliability
- Develop new features and tools
- Improve AI accuracy and training, including by using de-identified or aggregated information
- Monitor system integrity and security
C. Communicating with You
- Sending administrative notices
- Responding to support inquiries
- Providing onboarding guidance
- Sending optional service updates or informational messages (unless you opt out)
D. Security, Fraud Prevention, and Compliance
- Detecting unauthorized access or misuse
- Monitoring system integrity
- Complying with legal obligations or requests
- Enforcing our Terms of Service and investigating potential violations
E. Organizational and Academic Partner Functions
If you access the Service through a participating university or institution:
- We may provide aggregated engagement metrics to administrators
- We may verify enrollment or institutional affiliation
- We may support institution-specific job-matching frameworks
F. De-Identified and Aggregated Data Uses
We may create and use de-identified and aggregated data for analytics, system improvement, trend analysis, and other research-related purposes. This data does not identify individual users and may be shared with institutions, partners, or publicly in research reports.
9. Sharing of Personal Information
We may share Personal Information under the circumstances described below. We do not exchange Personal Information for money. However, as described in Section 10, we use third-party advertising technologies — both in your browser and server-to-server from our own servers — that share limited information with advertising partners for conversion measurement and retargeting. Under California and other state privacy laws, this "sharing" for cross-context behavioral advertising may be treated as a "sale" or "share" even though we receive no money for it. You can opt out of this sharing at any time — see Section 10.C and Section 18.
A. Service Providers and Vendors
We use third-party providers to support the Service. The list below groups them by function and describes what each one receives.
Hosting, infrastructure, and content delivery
- Vercel hosts the Olive website and the API that the website, the mobile apps, and the browser extension all call. Every request you make to the Service passes through Vercel, so it processes your IP address, your browser and device information, and the contents of your requests.
- Cloudflare provides DNS, TLS termination, and security filtering in front of
olive.jobsand our backend services, including the servers that answer job searches. It sits between you and our origin servers and therefore processes your IP address, your browser and device information, the URLs you request, and the contents of your requests. Cloudflare operates a global network, so your request may pass through a Cloudflare location outside the United States on its way to our servers. - Google Cloud Platform runs our backend services, databases, and file storage. Resumes and other uploads, chats, transcripts, voice recordings, and profile data are stored in Google Cloud in the United States.
Authentication
- Firebase Authentication (Google) issues and verifies your sign-in credentials. Your browser or device contacts it directly, so it receives your IP address along with your identity information.
- Google, Microsoft, LinkedIn, and — in the mobile apps — Apple act as sign-in providers when you choose to sign in with one of them. See Section 6.C.
Location and maps
- Google Maps Platform provides location lookup. When you type into a location box, the text you type is sent to Google's Places Autocomplete service to produce suggestions. When you drop a pin on the map or use a "use my location" control, the coordinates are sent to Google's Geocoding API to be turned into a place name. Both are restricted to place-level results (city, postal code, region, country) — never street addresses. These requests are made by our servers, so Google receives our server's address rather than yours.
- OpenFreeMap serves the background map tiles for the map-based radius picker on the website. Those tiles are requested by your browser directly from OpenFreeMap, so it receives your IP address, your browser information, and the map area and zoom level you are viewing — which indicates the area you are searching around. Our mobile apps do not use it.
Analytics
- Google Analytics 4, via Firebase Analytics, on the website only — see Section 10.A. Our mobile apps contain no analytics SDK.
AI processing and model inference
- OpenAI and Google (Vertex AI / Gemini) — see Section 7.B for exactly what each one receives.
- Modal runs a GPU speech-transcription service that we use to produce transcripts from voice-session audio already stored in our systems. When it is used, the audio clip is sent to Modal and a transcript is returned. This is triggered internally by our team for quality review, not by anything you do in the product.
- Mailgun sends our transactional and digest email and receives email sent to our support address. It processes your email address and name, the contents of the messages we send you (including the job listings in a digest) and the messages you send us, and delivery telemetry such as whether a message was delivered or opened.
Communication platforms
- Discord, if you choose to link a Discord account and use the Olive Discord bot. Discord carries the messages and voice audio you exchange with the bot on its platform, and we store the link between your Discord account and your Olive account.
Telephony — currently disabled
- Twilio supplies the phone numbers and call handling for the optional phone-interview feature. That feature is turned off in production: an incoming call is answered only with a message saying the feature is unavailable and is then ended, so no interview audio is captured and no recordings are produced. We have kept the Twilio account and phone numbers so the feature can be switched back on. If it is, Twilio will again process the number you call from, the call audio, and any recording of the call, and we will update this Policy to describe it as active.
Fonts
- Google Fonts. Our mobile apps load one typeface from Google's font service at runtime, so Google receives your device's IP address and browser/device information when that request is made. The email we send you also references typefaces from that same service: if your mail app is set to load remote content, it will fetch them when you open the message, and Google will receive your IP address and mail-client information at that moment. Most mail apps block remote content until you allow it. The website does not do this — its fonts are downloaded when we build the site and are served from our own domain.
These providers may have access to Personal Information only as necessary to perform services on our behalf and are bound by contractual obligations to maintain confidentiality and security. For the specific AI providers we use (OpenAI and Google), the categories of data we share with each, the protections they are contractually required to maintain, and the consent we obtain from you before sharing, see Section 7 (AI and Automated Processing). Advertising partners are covered separately in Section 10.A.
A.1. Infrastructure We Operate Ourselves
Not every component of the Service is a third-party product. Our job search index — the searchable copy of job postings, the search queries run against it, and the mathematical representations (embeddings) derived from resumes and job descriptions — runs on Elasticsearch software that we operate ourselves, on a private virtual machine inside our own Google Cloud project. It is not a hosted or managed search service and there is no vendor on the other side of it: the software's publisher receives no data from it, the machine accepts no direct connections from the public internet, and access is controlled solely by us. For the purposes of this Policy it is our own infrastructure, and the underlying computing and storage are covered by the Google Cloud Platform entry above.
A.2. Images Loaded from Employer Websites
Job listings display the employer's logo. We serve most logos from our own storage, but where we hold only a link to an image hosted elsewhere, your browser loads that image directly from the site hosting it — so that site receives your IP address and browser information. We do not send those sites any account information about you.
B. Educational or Organizational Partners
If you access the Service through a participating institution:
- We may share aggregated or de-identified engagement metrics to help institutions evaluate program effectiveness
- Limited user-level information may be shared if explicitly authorized or required to deliver institution-specific features
C. Legal, Regulatory, and Compliance Disclosures
We may disclose Personal Information if required to:
- Comply with applicable laws or regulatory obligations
- Respond to lawful governmental or judicial requests
- Protect the rights, safety, or property of the Company or users
- Prevent fraud, abuse, or unauthorized use of the Service
D. With Your Consent
We may share Personal Information for any other purpose disclosed to you at the time of collection if you consent to such sharing.
10. Cookies, Local Storage, and Tracking Technologies
We use cookies, browser local storage, and similar technologies to operate the Service, remember your preferences, understand how the Service is used, and measure the effectiveness of our advertising. Some of these technologies are third-party advertising pixels and cookies that "share" limited information for cross-context behavioral advertising, as described in Section 10.A below. Under California and other state privacy laws this sharing may be treated as a "sale" or "share" even though we receive no money for it, and you can opt out at any time as described in Section 10.C.
A. Categories of Technologies We Use
- Strictly Necessary — CSRF and PKCE state for third-party sign-in (e.g., LinkedIn OAuth), the cookie that records your advertising choice so we can honor it before any pixel loads, and other security-critical state. These are required for the Service to function and are not subject to opt-out. Your signed-in session itself is not held in a cookie: Firebase Authentication keeps it in your browser's or device's local storage, and the app authenticates each request to our servers with a short-lived Firebase ID token sent in an
Authorizationheader. - Functional — User-interface preferences (theme), search filters, onboarding progress, referral-source attribution, and other state stored in browser cookies,
localStorage, orsessionStorageto provide a continuous experience across visits. - Analytics — On our website we use Google Analytics 4 (via Firebase Analytics) to understand aggregate product usage (which features are used, where users encounter friction). It is a first-party implementation — the measurement code is part of our own application rather than a third-party tag — but the resulting events are processed by Google as our analytics provider. We have configured this implementation to avoid the use of Google Signals and cross-site advertising integrations. Our mobile apps contain no analytics SDK.
- Advertising — We use third-party advertising technologies to measure the effectiveness of our advertising and to show relevant ads. Today this includes the Reddit pixel, and we may add Meta and Google advertising pixels in the future. When these are active, we share limited information with these partners for conversion measurement and retargeting: the pages (URLs) you visit on the Service, your IP address, your browser/device information (user-agent), and a pseudonymous internal account identifier. We do not share your name, email address, resume content, or other sensitive personal information with advertising partners, we do not enable "automatic advanced matching" (which would scrape email addresses and phone numbers off the page), and advertising pixels are suppressed on sensitive pages — including health-adjacent pages and any page dealing with demographics, EEO questions, immigration status, national origin, religion, or reentry and recovery programs. Under California and other state privacy laws this "sharing" for cross-context behavioral advertising may be treated as a "sale" or "share" even though we receive no money for it. You can opt out at any time — see Section 10.C below.
- Server-side advertising measurement (Conversions API) — Ad blockers and browser privacy protections frequently prevent the browser pixel from reporting a conversion. To measure our advertising accurately, we also send a server-to-server copy of a limited set of conversion events directly from our servers to Reddit's Conversions API. Today this applies to a single event: creating an Olive account. The message we send contains the event name and time, a random one-time event identifier used so Reddit can recognize it as the same conversion the browser pixel reported and count it once, a pseudonymous internal account identifier, and your IP address and browser user-agent as they appeared on that request. It does not contain your name, email address, phone number, resume content, or the page you were on. This transmission is subject to exactly the same opt-out as the pixels, and the opt-out is enforced on our server rather than only in your browser: if you have opted out, or your request carries a Global Privacy Control signal, the server-side message is never sent. If we cannot confirm your choice, we suppress the send.
B. Managing Cookies and Similar Technologies
You may use your browser settings to block or delete cookies and clear local storage at any time. Doing so will interrupt core features: blocking the strictly necessary cookies prevents third-party sign-in from completing, and clearing your browser's local storage signs you out, because that is where your session is kept.
C. Your Advertising Choices and Universal Opt-Out
You can opt out of the advertising "sharing" described above at any time, in either of two ways:
- Use the "Your Privacy Choices" link in our website footer, including on our homepage; or
- Toggle off the Advertising controls in your Privacy & Security settings.
We recognize and honor the Global Privacy Control (GPC) browser signal as a valid opt-out preference signal for all U.S. visitors, regardless of the state in which they reside. If your browser or browser extension is configured to send a GPC signal, we treat you as opted out of advertising sharing automatically and disable advertising pixels and analytics event collection for your session — no separate action is required. You can verify GPC is enabled at globalprivacycontrol.org.
D. Do-Not-Track Signals
Because no uniform industry standard exists for interpreting the legacy Do-Not-Track (DNT) header, we do not act on DNT specifically. We treat the Global Privacy Control signal (described above) as the operative universal opt-out, consistent with current California Attorney General enforcement guidance.
11. Data Retention
We retain Personal Information for as long as reasonably necessary to fulfill the purposes outlined in this Policy, including:
- Providing and improving the Service
- Maintaining account activity and records
- Complying with legal, regulatory, or contractual obligations
- Resolving disputes or enforcing agreements
Retention periods may vary depending on the nature of the information. For example:
- Resume uploads, job preferences, interview transcripts, and AI interactions are retained while your account is active.
- When you delete your account yourself, we delete your sign-in credentials and promptly remove or replace the information on your account record that directly identifies you — including your name, email address, profile photo, phone number, external profile links, saved location preferences, device records, and demographic answers. The rest of the account record (preferences, activity, and similar signals) is retained under an internal account identifier rather than your name or email address, which we have removed from it, and may be retained indefinitely for analytics, service improvement, and research as described in this Policy.
- Content you uploaded or generated — resume files and other uploads, generated documents, chat and interview transcripts, and voice recordings — is not automatically purged when you delete your account, and those files still contain whatever personal information you put into them. You may request a full erasure of that content through our support channels; full erasures are reviewed and carried out by an administrator.
- If you submitted an application to an employer through the Service, that employer's record of your application — including the name, contact details, and documents you supplied with it — is the employer's record of a candidate and is not removed when you delete your Olive account.
- Voice recordings are retained for service and model improvement only where you have given an explicit opt-in; otherwise they are removed when you request a full erasure.
- System logs and diagnostic information may be retained for security or operational purposes.
- Backups may store certain information for a limited period after deletion for disaster recovery.
Browser Extension Data Retention
- Local extension data (stored in chrome.storage) — including default answers, demographic preferences, fill history, and authentication tokens — is deleted when the extension is uninstalled or the user signs out.
- Backend data (profile, application history, fill feedback) — retained while your account is active. When you delete your account, directly identifying information is removed or anonymized; de-identified data may be retained as described in the "Data Retention" section above. A full erasure may be requested through our support channels.
- Fill history — stored locally only, limited to the last 20 entries, and overwritten automatically as new entries are added.
When retention is no longer necessary, we will delete, anonymize, or de-identify the data, unless we are legally required to retain it.
12. Security Practices
We implement a combination of administrative, technical, and physical safeguards designed to protect Personal Information from loss, unauthorized access, misuse, alteration, or destruction. These security measures may include:
- Encryption of data in transit using SSL/TLS
- Access controls and authentication mechanisms
- Monitoring for unusual activity or unauthorized access attempts
- Secure cloud infrastructure protected by industry-standard safeguards
- Routine backups and disaster recovery systems
- Vendor and partner security due diligence
Despite these efforts, no method of electronic transmission or storage is completely secure. You use the Service at your own risk. We encourage users to follow best practices for account security, including safeguarding login credentials.
13. Your Privacy Rights
Depending on the jurisdiction in which you reside (such as California), you may have specific rights regarding your Personal Information. These rights may include, where applicable:
- Right to Know: Request disclosure of categories and specific pieces of Personal Information collected about you.
- Right to Access: Obtain a copy of your Personal Information.
- Right to Delete: Request deletion of Personal Information, subject to legal and operational exceptions.
- Right to Correct: Request correction of inaccurate Personal Information.
- Right to Opt Out of Sale/Sharing: You have the right to opt out of the "sale" or "sharing" of your Personal Information for cross-context behavioral advertising. We do not exchange Personal Information for money, but our use of third-party advertising technologies may constitute a "sale" or "share" under state law. You can opt out as described in Section 10.C.
- Right to Non-Discrimination: We will not deny services or provide differing levels of service based solely on your exercise of your rights.
To submit a privacy request, contact us at [email protected]. We may require verification of your identity before fulfilling requests.
14. Accessing, Updating, or Deleting Your Information
You may be able to access, modify, or delete certain Personal Information directly within your account settings. If this is not possible, you may submit a request through our support channels.
We offer two levels of deletion:
- Self-service account deletion. When you delete your account from your settings, we delete your sign-in credentials so you can no longer sign in, and we promptly remove or replace the information on your account record that directly identifies you — including your name, email address, profile photo, phone number, external profile links, saved location preferences, device records, and demographic answers. If you signed in with Apple, we also revoke Olive's Sign in with Apple grant. The rest of the account record is then held under an internal account identifier rather than your name or email address, which we have removed from it, and we may retain that information indefinitely for analytics, service improvement, model improvement, and research, as described in the "Data Retention" section. Step-by-step instructions are on our Delete Your Account page.
- Full erasure on request. Self-service deletion does not itself purge the content you uploaded or generated — resume files, uploaded documents, interview transcripts, and voice recordings are retained, and still contain whatever personal information you put into them. You may request complete removal of that content by contacting us through our support channels. Verified full-erasure requests are reviewed and carried out by an administrator.
- Voice recordings. Where you have given an explicit, separate opt-in, your voice interactions may be used and retained to improve voice features and quality. You can decline at any time, and voice recordings are removed when you request a full erasure.
- Backups may retain information temporarily for disaster recovery.
15. Third-Party Websites and Links
The Service may include links to third-party websites, platforms, or tools. We do not endorse or control third-party practices, and we are not responsible for the privacy, security, or content of such third-party services. Your interactions with those parties are governed by their own terms and privacy policies. We encourage you to review the privacy policies of any third-party service you visit.
16. Organizational and Educational Institution Integrations
Certain users may access the Service through a university, employer, or other organizational program. When the Service is made available through such partnerships, the following additional terms apply:
A. Information We May Share with Organizational Partners
Where you access the Service through an organizational program, we may provide administrators of that organization with:
- Aggregated participation, usage, and engagement statistics
- Individual member reporting, including your name, the email address associated with your account, your most recent activity date, counts of your resumes, saved jobs, practice interviews, and evaluations, and your practice interview and evaluation scores
We do not provide organizational partners with the content of your resumes, your conversations with Olive, or your practice interview transcripts, except where you expressly authorize it or where a specific institution-provided program feature makes it available and that feature is disclosed to you.
B. FERPA and Education Records
We are not the custodian of official academic records. FERPA-protected information that you submit yourself (for example, a GPA listed in a resume) is processed solely as user-submitted content, governed by this Policy and not by the Family Educational Rights and Privacy Act ("FERPA").
Separately, an educational institution may designate us as a "school official" with a legitimate educational interest and provide us with education records about you (for example, course enrollment). Where it does, we handle those records under that institution's direction, use them only for the purposes the institution authorizes, and do not redisclose them except as permitted by FERPA or required by law. Educational institutions remain responsible for compliance with their own FERPA obligations and privacy practices.
17. De-Identified and Aggregated Information
We may convert Personal Information into de-identified or aggregated data by removing or obscuring identifiers. We may use or disclose such information for:
- Research, analytics, and reporting
- Service optimization and performance insights
- Trend analysis and usage analytics
- Internal business purposes
- Sharing with educational institutions or partners in aggregate form
This information cannot reasonably be used to identify an individual.
18. California-Specific Disclosures (CCPA / CPRA)
If you are a resident of California, the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA") provide specific rights regarding your Personal Information. This section supplements the information elsewhere in this Policy.
A. Categories of Information Collected
Within the last 12 months, we may have collected information in the following categories defined under the CCPA:
- Identifiers (e.g., name, email address, device identifiers)
- Personal information categories defined in state law
- Commercial and professional information (resume data, job preferences)
- Internet or network activity (usage data)
- Geolocation data (approximate, derived from IP address; precise device coordinates only where you use a "use my location" control and grant permission)
- Sensory data (voice recordings if submitted)
- Inferences drawn from user activity
B. "Sale" and "Sharing" of Personal Information
We do not exchange Personal Information for money. However, we use third-party advertising technologies — currently the Reddit pixel and Reddit's server-side Conversions API (and we may add Meta and Google in the future) — that share limited information with advertising partners for conversion measurement and retargeting: the pages (URLs) you visit on the Service, your IP address, your browser/device information, and a pseudonymous internal account identifier. Some of this is sent from your browser and some is sent server-to-server from our servers; both are described in Section 10.A and both are subject to the same opt-out. Under California and other state privacy laws, this "sharing" for cross-context behavioral advertising may be treated as a "sale" or "share" even though we receive no money for it. We do not "sell" or "share" sensitive personal information for advertising, and we suppress advertising pixels on sensitive pages. The categories of Personal Information "shared" in this manner are identifiers and internet or network activity, as described above. You can opt out of this sharing at any time — see Section 18.C below.
C. CCPA/CPRA Rights Summary
California residents have the following rights, subject to certain limitations:
- The right to know what Personal Information is collected
- The right to request deletion of Personal Information
- The right to correct inaccurate information
- The right to access collected information
- The right to opt out of the "sale" or "sharing" of Personal Information for cross-context behavioral advertising. To exercise this right, use the "Your Privacy Choices" link in our website footer, including on our homepage, or toggle off the Advertising controls in your Privacy & Security settings. (California law permits either a "Do Not Sell or Share My Personal Information" link or an alternative opt-out link; we use the latter.) If your browser sends a Global Privacy Control (GPC) signal, we treat you as opted out automatically (see Section 10.C).
- The right to limit the use of sensitive personal information (we do not use or disclose sensitive personal information for advertising or any purpose requiring this right)
- The right to non-discrimination
D. Exercising Your Rights
To submit a request under CCPA/CPRA, contact us at [email protected]. We may require identity verification before fulfilling requests.
E. Global Privacy Control
We recognize and honor the Global Privacy Control (GPC) browser signal as a valid universal opt-out preference signal, including for the "sale" or "sharing" of Personal Information for cross-context behavioral advertising as well as analytics collection. When GPC is enabled in your browser, we treat you as opted out automatically and no separate request is required. See Section 10.C for details.
19. Data Storage, Transfers, and International Users
The Service is operated from within the United States, and our servers, databases, and file storage are located in the United States. By using the Service, you understand and acknowledge that your Personal Information may be stored, processed, or transferred within the United States. Our content-delivery and security provider operates a global network, so an individual request from you may pass through one of its locations outside the United States on its way to our servers before being handled and stored in the United States.
The Service is designed and intended primarily for users located in the United States. While users outside the United States may access the Service, they do so at their own risk and are responsible for ensuring that their use complies with local law.
By using the Service, international users consent to the transfer, processing, and storage of their Personal Information in the United States, where privacy laws may differ from those in their jurisdiction.
20. Data Breach Notification
In the event of a data breach involving Personal Information, we will follow applicable legal requirements for notification. Depending on the nature of the breach, this may include:
- User notification via email or in-app alert
- Notification to relevant governmental authorities
- Implementation of corrective and preventive measures
We will take reasonable steps to mitigate harm and prevent future unauthorized access.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When changes are made, we will update the "Last updated" date at the top of this page. In the event of material changes, we may also provide notice through:
- Email notification
- In-app or website banners
- Account notifications
Your continued use of the Service following updates indicates your acceptance of the revised Policy.
22. Contact Information
If you have questions regarding this Privacy Policy, or if you wish to submit a privacy request, contact us at:
Olive Independent Study, Inc. ATTN: Privacy Office 770 Juniper Street, Suite 2011 Atlanta, GA 30308 Email: [email protected]
23. Chrome Web Store Compliance
The Olive Auto-Apply Chrome extension's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data collected by the Olive Auto-Apply extension is:
- Used only to provide and improve the extension's single purpose of autofilling job applications
- Not transferred to third parties except as necessary to provide the autofill service (e.g., sending form field structure and your saved answers to the Olive backend, and on to our AI provider, so an answer can be matched to each field)
- Not used for advertising, sold to data brokers, or transferred to any information reseller
- Not used to determine creditworthiness or for lending purposes
- Not read by humans except with your explicit consent, for security purposes (e.g., investigating abuse), or to comply with applicable laws
The extension transmits data exclusively over HTTPS and requires you to sign in — with Google, Microsoft, or LinkedIn OAuth, or with a one-time code emailed to you. All API communication with the Olive backend uses encrypted connections and bearer token authentication.