Privacy policy
InternScout is an internship search tool made by a UMass Amherst student. Searching is free and needs no sign-in; AI features have a free monthly allowance, and optional paid plans raise it. This page explains what data it uses, where that data goes, and how to delete it.
The short version
- Searching needs no account.
- Your resume and other files are stored only in your browser and the extension. We never keep a copy of them.
- The profile your Deep Dive builds is saved to your InternScout account by default, encrypted, so it's there on your other devices. You can turn that off in the extension, which deletes our copy. Your demographic answers, saved logins and API keys are never saved to your account. Details below.
- You stay signed in on a device until you sign out. Your browser keeps a random sign-in code; our server keeps only a fingerprint of it.
- Stored is not the same as never sent. The Deep Dive and resume tailoring do send your resume and some other files to the AI, in the request itself. Details below.
- AI requests pass through our server to Google's paid Gemini API. We don't store them, and they aren't used to train AI.
- We keep a scrambled sign-in ID, when we first saw it, your monthly usage and cost counts, the states you picked, a fingerprint of each sign-in, your saved Deep Dive (encrypted, unless you turn saving off), your invite code and extra runs if you use invites, and, only if you subscribe, your plan and your Stripe IDs. The full list is below.
- If you sign up for the weekly email, your address and the fields you tick go to Buttondown, the service that sends it, not to our server. Buttondown also records the IP address you sign up from. Details below.
- We never see your password.
- You can delete it at any time. Delete my data also removes your saved Deep Dive and signs you out everywhere. The current month's counts stay until the month ends, and a few invite records (your hashed ID with a date or a count) stay after that, so deleting can't be used to reset a limit. Details below.
Searching listings
- You don't need an account or sign-in to search.
- The dashboard is a static page hosted on GitHub Pages. The listings are public job posts.
- Your saved statuses (like Interested or Applied), your filters and your profile are saved in your browser's local storage. Which listings you saved, and what you marked them, is never sent to us. If you arrive through a classmate's invite link, its invite code is kept there too, and is sent to us only when you sign in, to accept the invite. Delete my data clears it. If the extension is installed, the dashboard also hands it your profile, and the extension saves that with your Deep Dive (see below).
- When you sign in, the dashboard keeps your sign-in in local storage too: a random sign-in code, a short account ID, and your email address, only so it can show which account is signed in. It stays until you sign out, press Delete my data, or the sign-in ends.
- One thing does go: the list of states you picked. While you are signed in, the dashboard sends just those two-letter state codes (plus REMOTE, if you ticked it) to our Worker, stored against your scrambled sign-in ID. It is sent once per change, not per listing. The server accepts nothing else on that route, and the scanner only ever reads the totals per state, so it can fetch fuller listings where students are actually looking.
- GitHub hosts the page and may keep normal web server logs under its own policy. The dashboard also loads fonts and code libraries from public servers (such as Google Fonts).
- We count page visits with Cloudflare Web Analytics. It uses no cookies and doesn't identify you: it sees which page was loaded, the referring site, your browser type, a rough country and how fast the page loaded. We don't use ad trackers, and we set no cookies of our own.
Your profile and files
- Your resume, CV, transcript, cover letter and writing samples are stored on your device only. They live in browser storage (dashboard) or Chrome extension storage. We keep no copy of them, and they are never uploaded for safekeeping or backup.
- Your profile (majors, class year, work authorization, the facts and stories from your Deep Dive and your saved answers) is kept on your device too, and by default the extension also saves a copy to your InternScout account. What is saved and what never is: Your Deep Dive, saved to your account.
- Some of these files are sent to the AI when you run a feature that reads them. They go inside the request, through our Worker to Google's Gemini API, and are not stored at either end (see AI features). Which file goes depends on the feature and on the file's format:
- The Deep Dive reads your resume and CV to fill in your profile, and your cover letter and writing samples to learn your writing voice. A PDF is sent as the file itself. A Word or plain-text file is read on your device first and only the text it contains is sent, up to 60,000 characters.
- Tailoring your resume sends your resume when it is a PDF: the whole PDF goes, so the AI can transcribe its layout and the tailored copy can keep it. That reading is cached on your device and reused, so the file is sent once per resume, not once per application. If your resume is a Word file, the extension opens it locally and sends only the bullet text; that file never leaves your device.
- Your transcript is never sent to the AI. It is only ever attached to an employer's own form when their site asks for one.
- The extension can create accounts on employer application sites for you. It saves the sign-up email and those site passwords in extension storage on your device. The passwords are never sent to us or to the AI: the extension types them into the page itself, and the AI is only told to ask for one, never given it. The sign-up email address is included in each Auto-Apply request, because the AI has to know which address to register or sign in with.
- Chrome does not encrypt extension storage. Anyone who can use your computer account could read it.
- We have no copy of your files, your demographic answers or your saved logins. If you clear them, they're gone. Your profile can be restored from your account if you left saving on.
Your Deep Dive, saved to your account
When you are signed in, the extension saves the profile your Deep Dive builds to your InternScout account, so it's there when you sign in on another computer or reinstall the extension. This is on by default.
- What is saved: the profile the Deep Dive builds. That is the facts it collects about you (such as your name, contact details, address, work authorization and the other standard application questions), your education, experience, projects, skills and links, your stories and goals, your writing voice, and your answers to its questions. It also includes the profile you set on the dashboard (your majors, class year, graduation term, the kinds of roles, terms and states you picked, and your work authorization), and whether and when you finished the Deep Dive.
- What is never saved to your account: your resume, CV, transcript, cover letter, writing samples and any other file; your answers to the six demographic questions (gender, race, Hispanic or Latino, veteran status, disability and LGBTQ+); the logins and passwords the extension saved for employer sites; your own API keys; and your list of past application answers and jobs. These stay on your device. Our server also removes the demographic answers from anything it is sent, as a second check.
- Encrypted at rest. The saved profile is encrypted on our server with a key made for your account alone. It is stored against your scrambled sign-in ID, with the time it was last changed and its size. It is decrypted only to send it back to your own extension while you are signed in.
- It is not used for anything else: not for the AI (the extension sends the AI what each feature needs from the copy on your device, as described under AI features), not for ads, and not shared or sold.
- Turning it off: untick Save my Deep Dive to my account in the extension. It asks you to confirm, then deletes the copy on our server right away and stops saving. Your profile on the device is untouched.
- Delete my data (in the extension or on the dashboard) deletes the saved profile too, along with every sign-in, so every device is signed out.
AI features
Tailored resumes, the Deep Dive, Auto-Apply and short answers use AI. Here is what happens when you run one:
- The extension sends what the task needs to our server, a Cloudflare Worker. That is more than the questions alone, and it is not the same for every feature, so here is what each one sends. Two of them send your whole stored profile (your name, contact details, education, experience and the stories from your Deep Dive): Auto-Apply, which adds your writing voice, and the Deep Dive's interview step, which leaves out your voice and your saved answers. The rest each send only what their own bullet names below, which for one tailoring path is still most of your experience and education:
- Auto-Apply sends your whole profile on every turn, and the sign-up email it uses for that site. On the first turn it also sends the posting: company, title, location, apply link and the first 5,000 characters of the description. Then, on each step, a snapshot of the application page: its web address and page title, the address of any form frame inside it, the headings, which step of the form you are on, whether a CAPTCHA is showing, any error messages the site is displaying, and every visible form field with its label, the question around it, what is currently in it, its options, whether it is required, its placeholder text, its length limit and its own error. It also sends the buttons on the page and a list of anything the extension has already filled in for you. When a page has fewer than four fields (a sign-in wall, an interstitial, a page that failed to load), it sends up to 2,500 characters of the page's visible text instead, so the AI can tell what it is looking at.
- Tailored resumes send the job posting's title, company and the first 6,000 characters of its description, your career goal and your writing voice, and your resume: the whole PDF file if it is a PDF, or just its bullet text if it is a Word file. Your stored profile is not sent on this path, but the resume file is: a PDF goes whole, so whatever is printed on it (your name, your contact details, your education) goes with it, and a Word file is read here on your device and only its bullet text is sent. If you have no resume on file, the fixed template is built instead from your experience, projects, skills, education, career goal and voice; your name and contact details are printed onto it here on your device and never leave it.
- The Deep Dive sends something different at each step. Read my resume sends your resume and CV files and nothing else; on a first run there is no profile yet, because that call is what fills it in. The interview sends your profile (all of it except your writing voice and your saved answers) along with the conversation so far. Analyze my writing sends your writing samples, your cover letter and up to 20,000 characters of your own interview replies. Finish & save stories sends the interview transcript plus the stories and goals you already have.
- The Worker checks your sign-in and your monthly allowance.
- It forwards the request to Google's paid Gemini API and passes the reply back to you.
Auto-Apply only reads a page while it is working on an application you started, in the tab it opened for that job. It does not watch your other tabs, and nothing is sent for a page you merely have open.
- We don't store or log what you send or what the AI replies. The Worker only records that a task ran and how many tokens it used, so we can track cost.
- No training. We use Google's paid API. Under Google's terms for paid services, Google does not use your prompts or replies to improve its products. Google may keep them for a limited time to detect abuse, under its own terms.
- Cloudflare runs the Worker and handles the network connection under its own privacy policy.
Using your own key (advanced). If you enter your own Anthropic or Google API key in the extension, requests go straight from your device to that company. They don't pass through our server, and that company's terms apply.
Sign-in
- You sign in only to use AI features, to save your chosen states and to save your Deep Dive to your account. Search never needs it.
- You sign in with any Google or Microsoft account. You type your password on the provider's own page. We never see or receive your password.
- The provider gives back a short-lived token. The Worker checks it and does not save it. It reads the email in the token only to see whether it is a verified school (.edu) address, which gets a larger AI allowance. The email is never stored on our server.
- Staying signed in. The Worker then gives your browser or extension a random sign-in code, and that code is what signs you in from then on, so you stay signed in on that device until you sign out. Your device keeps the code, with your email address so it can show which account is signed in. Our server keeps only a fingerprint of the code (a one-way hash it can't be turned back into), your scrambled sign-in ID, your allowance tier, whether you used Google or Microsoft, and when the sign-in was made, last used and ends.
- A sign-in ends when you sign out, when you press Delete my data (which ends all of them), or after a year without being used. Each device or browser has its own, and we keep at most 20 per account, dropping the oldest.
- If our server can't start a sign-in like this, the dashboard falls back to keeping the provider's token for the current browser session only. It's gone when you close the browser or when it expires, about an hour later.
- From the token, the Worker makes a one-way hash: a scrambled code that can't be turned back into your name or email. We don't store your name or email.
What we store
If you have never joined a paid plan, this is everything our server keeps about you. If you have, add the plan and billing records listed under If you join a paid plan.
| Data | Why |
|---|---|
| Hashed sign-in ID | To tie your usage counts together without knowing who you are. |
| For each device you are signed in on: a fingerprint of its sign-in code (never the code itself), your hashed sign-in ID, your allowance tier, whether you used Google or Microsoft, and when the sign-in was made, last used and ends | So you stay signed in on that device. Deleted when you sign out there, after a year without use, or when you press Delete my data. At most 20 per account. |
| Unless you turn saving off: your Deep Dive profile, encrypted, with when it last changed and its size (what is in it and what is left out: see above) | So your Deep Dive is there on your other devices. Deleted when you turn saving off or press Delete my data. |
| Monthly usage counts per AI task (for example, "3 tailored resumes in September"), with a random ID for each run | To enforce the monthly allowance. |
| One number per month: roughly what your AI use has cost us, in cents | So a single account can't use up the budget that pays for everyone's AI. It is removed when the month ends. |
| Short-term call counters (per minute and per day) | To stop abuse. |
| The states you picked, and when you last changed them | So the scanner fetches fuller listings where students are looking. The scanner only gets totals per state, never who picked what. Picks stop counting after 90 days without activity. |
| If you press Delete my data: your hashed ID and the month you did it in | So the counts that have to survive until the month ends are swept automatically once it does. This marker is deleted with them. |
| The date our server first saw your account (for accounts from before invites started, the earliest month we have usage counts for, or when you first picked states or a plan) | Only accounts in their first week can accept an invite. Kept after Delete my data, so deleting and signing in again can't make an account new again. |
| If you open Invite classmates: a random invite code | It makes your invite link. The code says nothing about who you are. |
| If you join through an invite: that you did, when, and the inviter's hashed ID | So an account can accept only one invite. Kept after Delete my data, without the inviter's ID, so deleting and signing in again can't accept a second one. |
| If your invites earn you extra runs: how many invites have, in total | An inviter is credited for at most 10 invites, ever. Kept after Delete my data (just your hashed ID and that number), so deleting and signing in again can't start the count over. |
| Extra AI runs from invites: how many you were given and how many you have used | They are used after your monthly allowance and don't expire. |
Separately from the table, we keep running totals of what AI costs the whole service: one for the month across the whole service, and one for the day's free-allowance share, so a single busy day can't empty the month's budget. Neither is tied to a person. Neither is linked to any account, and neither says anything about who used what.
Apart from what is inside your saved Deep Dive (which has your name and contact details in it, encrypted), we don't store names, emails, passwords, resumes, files, prompts or AI replies. We don't sell or share data, and we don't show ads.
If you sign up for the weekly email, Buttondown keeps your address, not our server. See If you sign up for the weekly email.
If you join a paid plan
The paid plans are optional. Supporter is $5/month and Pro is $12/month; both raise your monthly AI allowance and nothing else. Search and the free AI allowance never need one.
- Stripe handles the payment, not us. Pressing Supporter or Pro sends you to Stripe's own checkout page. Your card number, billing name and billing email go to Stripe and are never sent to, or seen by, our server. Changing or cancelling happens on Stripe's own billing page too.
- All Stripe learns about you from us is your hashed ID, so a payment can be matched to an account without Stripe being told which student it is.
- Stripe is the seller of record for the paid plans, so its checkout also asks for your name and billing address to work out sales tax or VAT. That stays with Stripe; we are never sent it.
- What we keep: your hashed ID, which plan you are on and whether it is active, the Stripe customer and subscription IDs, the date it is paid through, and the IDs of payment events we've already processed (so a repeated message can't charge or credit you twice).
- Stripe processes payments under its own privacy policy.
- While a subscription is live, Delete my data is refused with a message asking you to cancel first, so nothing keeps billing a card for an account that no longer exists here. Cancel on Stripe's billing page, then delete.
If you sign up for the weekly email
The weekly email is optional. Search, your profile and everything else on InternScout work without it. You sign up with the form under the listings on the dashboard.
- What it contains: the internships InternScout found in the past week, grouped by field: the fields with the most new roles that week, each with a few postings and a link to the rest. For now everyone gets the same email. The fields you tick are saved with your subscription so it can be matched to them later.
- How often: once a week. Buttondown first sends one confirmation email, and nothing else arrives until you click its link.
- Buttondown holds your address, not us. The form sends your email address, and the fields you ticked, straight from your browser to Buttondown, the service that sends the email. They never pass through or get stored on InternScout's servers, which is why the What we store table above has no row for them. Buttondown keeps them under its own privacy policy.
- The person running InternScout can see the subscriber list in Buttondown's dashboard: your address, the fields you ticked, whether you have confirmed, and what Buttondown records when you sign up: the IP address you signed up from, a rough location worked out from it, and the page the form was on. Open and click tracking is switched off for this email. The list is used only to send this email, is never sold or shared, and is not copied anywhere else.
- Signing up again with other fields adds them to the ones you had; it doesn't remove any. To drop a field, write to us, or unsubscribe and sign up again.
- Unsubscribing: every email has an unsubscribe link at the bottom, and it stops the emails. To have your address deleted from Buttondown's list as well, write to us at the address under Contact below.
Delete your data
- On our server: sign in, then press Delete my data in the extension or on the dashboard. Your chosen states, your saved Deep Dive, every sign-in (so every device is signed out), your plan record, your invite code and extra runs, and everything from earlier months are removed right away. Three invite records stay, each just your hashed ID with a date or a number, because without them deleting and signing in again would get around the invite rules: the date we first saw your account (so it can't count as new again); if you joined through an invite, the record that you did, without the inviter's ID (so you can't accept a second one); and if your invites earned you extra runs, how many did (so the limit of 10 can't start over). This month's counts (your hashed ID and a few numbers, nothing else) stay until the month ends, because removing them on request would let anyone reset their limits by deleting and signing in again. They are then deleted automatically, within a day of the month ending.
- In your browser: clear site data for
internscout.org(and forbpmcginley.github.io, the address InternScout used before September 2026, if you visited it then). In Chrome, click the icon left of the address bar, then Site settings, then Delete data. This removes your dashboard profile and saved statuses. - In the extension: remove it at
chrome://extensions. Chrome deletes its storage, including your files and saved site passwords. That doesn't reach the copy of your Deep Dive saved to your account: turn saving off or press Delete my data first. - The weekly email: use the unsubscribe link in any of the emails. Delete my data can't reach it, because the address is kept by Buttondown, not by our server. To have it deleted from Buttondown's list as well, write to us at the address below.
We can only find your server rows through your sign-in, because we don't know who you are. If you can no longer sign in, your state picks stop counting after 90 days of no use and your sign-ins end after a year. A saved Deep Dive can only be reached through a sign-in to the same account, so delete it (or turn saving off) while you still can.
Chrome Web Store: limited use
The extension's use of data follows the Chrome Web Store User Data Policy, including the Limited Use requirements. In plain words:
- Data is used only for the extension's single purpose: helping you fill out internship applications, plus the AI help that goes with it.
- Data is only sent where that purpose needs it (to Google's Gemini API through our Worker, and your Deep Dive profile to your own InternScout account unless you turn that off), or where the law requires.
- Data is never sold.
- Data is never used for ads, including personalized ads.
- Data is never used to decide credit, lending or anything like it.
- No person reads your data, unless you give clear permission (for example, you paste it into a bug report), it's needed for security, or the law requires it.
Children
InternScout is built for college students. It isn't meant for anyone under 13. If you're under 18, a parent or guardian has to agree to the terms with you before you start a paid plan. If you believe a child under 13 has given us data, write to us at the address below and we'll delete it.
Changes
If this policy changes, we'll update the date at the top. Big changes will also get a notice on the dashboard.
Contact
InternScout is run by Bruce McGinley, an independent student project in Massachusetts, USA. Email brucepmcginley@gmail.com.
Questions, privacy requests or anything else: use the InternScout feedback form. It needs no account and only the person running InternScout reads it. Expect a reply within a few days; this is a one-student project, not a support desk.
For bugs you don't mind discussing in the open, you can also open a GitHub issue. Issues are public, so please don't put personal details in them.