InternScout

Privacy policy

Last updated September 26, 2026

InternScout is an internship search tool made by a UMass Amherst student. Searching is free and needs no sign-in; AI features have a free monthly allowance, and optional paid plans raise it. This page explains what data it uses, where that data goes, and how to delete it.

The short version

  • Searching needs no account.
  • Your resume and other files are stored only in your browser and the extension. We never keep a copy of them.
  • The profile your Deep Dive builds is saved to your InternScout account by default, encrypted, so it's there on your other devices. You can turn that off in the extension, which deletes our copy. Your demographic answers, saved logins and API keys are never saved to your account. Details below.
  • You stay signed in on a device until you sign out. Your browser keeps a random sign-in code; our server keeps only a fingerprint of it.
  • Stored is not the same as never sent. The Deep Dive and resume tailoring do send your resume and some other files to the AI, in the request itself. Details below.
  • AI requests pass through our server to Google's paid Gemini API. We don't store them, and they aren't used to train AI.
  • We keep a scrambled sign-in ID, when we first saw it, your monthly usage and cost counts, the states you picked, a fingerprint of each sign-in, your saved Deep Dive (encrypted, unless you turn saving off), your invite code and extra runs if you use invites, and, only if you subscribe, your plan and your Stripe IDs. The full list is below.
  • If you sign up for the weekly email, your address and the fields you tick go to Buttondown, the service that sends it, not to our server. Buttondown also records the IP address you sign up from. Details below.
  • We never see your password.
  • You can delete it at any time. Delete my data also removes your saved Deep Dive and signs you out everywhere. The current month's counts stay until the month ends, and a few invite records (your hashed ID with a date or a count) stay after that, so deleting can't be used to reset a limit. Details below.

Searching listings

Your profile and files

Your Deep Dive, saved to your account

When you are signed in, the extension saves the profile your Deep Dive builds to your InternScout account, so it's there when you sign in on another computer or reinstall the extension. This is on by default.

AI features

Tailored resumes, the Deep Dive, Auto-Apply and short answers use AI. Here is what happens when you run one:

  1. The extension sends what the task needs to our server, a Cloudflare Worker. That is more than the questions alone, and it is not the same for every feature, so here is what each one sends. Two of them send your whole stored profile (your name, contact details, education, experience and the stories from your Deep Dive): Auto-Apply, which adds your writing voice, and the Deep Dive's interview step, which leaves out your voice and your saved answers. The rest each send only what their own bullet names below, which for one tailoring path is still most of your experience and education:
    • Auto-Apply sends your whole profile on every turn, and the sign-up email it uses for that site. On the first turn it also sends the posting: company, title, location, apply link and the first 5,000 characters of the description. Then, on each step, a snapshot of the application page: its web address and page title, the address of any form frame inside it, the headings, which step of the form you are on, whether a CAPTCHA is showing, any error messages the site is displaying, and every visible form field with its label, the question around it, what is currently in it, its options, whether it is required, its placeholder text, its length limit and its own error. It also sends the buttons on the page and a list of anything the extension has already filled in for you. When a page has fewer than four fields (a sign-in wall, an interstitial, a page that failed to load), it sends up to 2,500 characters of the page's visible text instead, so the AI can tell what it is looking at.
    • Tailored resumes send the job posting's title, company and the first 6,000 characters of its description, your career goal and your writing voice, and your resume: the whole PDF file if it is a PDF, or just its bullet text if it is a Word file. Your stored profile is not sent on this path, but the resume file is: a PDF goes whole, so whatever is printed on it (your name, your contact details, your education) goes with it, and a Word file is read here on your device and only its bullet text is sent. If you have no resume on file, the fixed template is built instead from your experience, projects, skills, education, career goal and voice; your name and contact details are printed onto it here on your device and never leave it.
    • The Deep Dive sends something different at each step. Read my resume sends your resume and CV files and nothing else; on a first run there is no profile yet, because that call is what fills it in. The interview sends your profile (all of it except your writing voice and your saved answers) along with the conversation so far. Analyze my writing sends your writing samples, your cover letter and up to 20,000 characters of your own interview replies. Finish & save stories sends the interview transcript plus the stories and goals you already have.
  2. The Worker checks your sign-in and your monthly allowance.
  3. It forwards the request to Google's paid Gemini API and passes the reply back to you.

Auto-Apply only reads a page while it is working on an application you started, in the tab it opened for that job. It does not watch your other tabs, and nothing is sent for a page you merely have open.

Using your own key (advanced). If you enter your own Anthropic or Google API key in the extension, requests go straight from your device to that company. They don't pass through our server, and that company's terms apply.

Sign-in

What we store

If you have never joined a paid plan, this is everything our server keeps about you. If you have, add the plan and billing records listed under If you join a paid plan.

DataWhy
Hashed sign-in IDTo tie your usage counts together without knowing who you are.
For each device you are signed in on: a fingerprint of its sign-in code (never the code itself), your hashed sign-in ID, your allowance tier, whether you used Google or Microsoft, and when the sign-in was made, last used and endsSo you stay signed in on that device. Deleted when you sign out there, after a year without use, or when you press Delete my data. At most 20 per account.
Unless you turn saving off: your Deep Dive profile, encrypted, with when it last changed and its size (what is in it and what is left out: see above)So your Deep Dive is there on your other devices. Deleted when you turn saving off or press Delete my data.
Monthly usage counts per AI task (for example, "3 tailored resumes in September"), with a random ID for each runTo enforce the monthly allowance.
One number per month: roughly what your AI use has cost us, in centsSo a single account can't use up the budget that pays for everyone's AI. It is removed when the month ends.
Short-term call counters (per minute and per day)To stop abuse.
The states you picked, and when you last changed themSo the scanner fetches fuller listings where students are looking. The scanner only gets totals per state, never who picked what. Picks stop counting after 90 days without activity.
If you press Delete my data: your hashed ID and the month you did it inSo the counts that have to survive until the month ends are swept automatically once it does. This marker is deleted with them.
The date our server first saw your account (for accounts from before invites started, the earliest month we have usage counts for, or when you first picked states or a plan)Only accounts in their first week can accept an invite. Kept after Delete my data, so deleting and signing in again can't make an account new again.
If you open Invite classmates: a random invite codeIt makes your invite link. The code says nothing about who you are.
If you join through an invite: that you did, when, and the inviter's hashed IDSo an account can accept only one invite. Kept after Delete my data, without the inviter's ID, so deleting and signing in again can't accept a second one.
If your invites earn you extra runs: how many invites have, in totalAn inviter is credited for at most 10 invites, ever. Kept after Delete my data (just your hashed ID and that number), so deleting and signing in again can't start the count over.
Extra AI runs from invites: how many you were given and how many you have usedThey are used after your monthly allowance and don't expire.

Separately from the table, we keep running totals of what AI costs the whole service: one for the month across the whole service, and one for the day's free-allowance share, so a single busy day can't empty the month's budget. Neither is tied to a person. Neither is linked to any account, and neither says anything about who used what.

Apart from what is inside your saved Deep Dive (which has your name and contact details in it, encrypted), we don't store names, emails, passwords, resumes, files, prompts or AI replies. We don't sell or share data, and we don't show ads.

If you sign up for the weekly email, Buttondown keeps your address, not our server. See If you sign up for the weekly email.

The paid plans are optional. Supporter is $5/month and Pro is $12/month; both raise your monthly AI allowance and nothing else. Search and the free AI allowance never need one.

If you sign up for the weekly email

The weekly email is optional. Search, your profile and everything else on InternScout work without it. You sign up with the form under the listings on the dashboard.

Delete your data

  1. On our server: sign in, then press Delete my data in the extension or on the dashboard. Your chosen states, your saved Deep Dive, every sign-in (so every device is signed out), your plan record, your invite code and extra runs, and everything from earlier months are removed right away. Three invite records stay, each just your hashed ID with a date or a number, because without them deleting and signing in again would get around the invite rules: the date we first saw your account (so it can't count as new again); if you joined through an invite, the record that you did, without the inviter's ID (so you can't accept a second one); and if your invites earned you extra runs, how many did (so the limit of 10 can't start over). This month's counts (your hashed ID and a few numbers, nothing else) stay until the month ends, because removing them on request would let anyone reset their limits by deleting and signing in again. They are then deleted automatically, within a day of the month ending.
  2. In your browser: clear site data for internscout.org (and for bpmcginley.github.io, the address InternScout used before September 2026, if you visited it then). In Chrome, click the icon left of the address bar, then Site settings, then Delete data. This removes your dashboard profile and saved statuses.
  3. In the extension: remove it at chrome://extensions. Chrome deletes its storage, including your files and saved site passwords. That doesn't reach the copy of your Deep Dive saved to your account: turn saving off or press Delete my data first.
  4. The weekly email: use the unsubscribe link in any of the emails. Delete my data can't reach it, because the address is kept by Buttondown, not by our server. To have it deleted from Buttondown's list as well, write to us at the address below.

We can only find your server rows through your sign-in, because we don't know who you are. If you can no longer sign in, your state picks stop counting after 90 days of no use and your sign-ins end after a year. A saved Deep Dive can only be reached through a sign-in to the same account, so delete it (or turn saving off) while you still can.

Chrome Web Store: limited use

The extension's use of data follows the Chrome Web Store User Data Policy, including the Limited Use requirements. In plain words:

Children

InternScout is built for college students. It isn't meant for anyone under 13. If you're under 18, a parent or guardian has to agree to the terms with you before you start a paid plan. If you believe a child under 13 has given us data, write to us at the address below and we'll delete it.

Changes

If this policy changes, we'll update the date at the top. Big changes will also get a notice on the dashboard.

Contact

InternScout is run by Bruce McGinley, an independent student project in Massachusetts, USA. Email brucepmcginley@gmail.com.

Questions, privacy requests or anything else: use the InternScout feedback form. It needs no account and only the person running InternScout reads it. Expect a reply within a few days; this is a one-student project, not a support desk.

For bugs you don't mind discussing in the open, you can also open a GitHub issue. Issues are public, so please don't put personal details in them.