Your data

Privacy Notice

This notice explains in plain language what personal data KerjaKit handles, why we need it, who helps us process it, and the choices available to you. It is a notice, not a request for blanket consent.

Effective and legal version: 30 August 2026 (2026-08-30)

1. Who is responsible for your data

KerjaKit is operated by IIDEV STUDIO, a Malaysian sole proprietorship registered as 202603215168 (CA0426006-D), at No. 34, Jalan Beringin 10, Taman Rinting, 81750 Masai, Johor, Malaysia. The proprietor and data contact is Muhammad Isyraf Afifi bin Ismail. You can contact us at team.iidevstudio@gmail.com or +60 11-3350 6561.

This notice applies to the KerjaKit website, authenticated app, browser extension and related support channels. In this notice, “we”, “us” and “KerjaKit” refer to IIDEV STUDIO.

2. Personal data we collect and where it comes from

We receive data directly from you, from services you choose to connect, from your device and use of KerjaKit, and from public job sources. A résumé may incidentally contain sensitive information; please avoid including information that is not needed for your job search.

  • Account and identity data: email address, authentication method, Google account identifier and basic email/profile details when you use Google login, preferred name, language and account settings.
  • Career and workspace data: résumé and profile content, contact and employment history, skills, education, job postings, saved jobs, applications, Fit Checks, generated résumés and cover letters, interview preparation, answers, feedback, KerjaKit Chat messages and Job Radar preferences.
  • Commercial and support data: Power Action and Pro purchases, transaction and fulfilment status, refund history, support messages and deletion requests. We do not receive your full bank or e-wallet credentials.
  • Integration data: identifiers, connection status and tokens needed for optional Gmail sending, Telegram, WhatsApp or enabled job-source integrations, plus the content and destination you approve for an action.
  • Technical data: IP address, browser and device details, cookies, session and security events, error logs, feature usage, analytics events and masked session replay.
  • Public-source data: job advertisements, company information and public source URLs gathered from supported sources such as LinkedIn, JobStreet, Hiredly, Himalayas, Remotive, Threads or search results.

3. Required and optional information

An email address and authentication data are required to create and secure an account. A preferred name is required for the in-product experience, but remains separate from your résumé or legal identity. Career evidence and a job description are required when you ask KerjaKit to assess fit or generate career material. Payment and transaction data are required when you make a purchase.

Discovery survey answers, optional integrations, Job Radar preferences, feedback and most profile fields are optional until you use the related feature. If required information is not provided, we may be unable to create the account, secure it, process a purchase or provide the requested output. You can use core features without connecting Gmail, Telegram or WhatsApp.

4. Why we process personal data

We process personal data only for relevant business and product purposes.

  • Create, authenticate, protect and support your account; remember settings; prevent abuse; and respond to requests.
  • Turn your submitted evidence and job information into fit analysis, documents, interview preparation, chat assistance and Radar recommendations you request.
  • Process purchases, deliver Power Actions or Pro access, handle refunds, keep financial records and meet legal obligations.
  • Send transactional email and, only when you enable and approve it, carry out actions through connected services.
  • Measure reliability and product use, diagnose errors, improve KerjaKit and communicate material service, privacy or terms changes.
  • Protect users, our rights and the service, and comply with lawful requests and Malaysian law.

5. Google login and optional Gmail sending

Google login uses a dedicated OAuth client and only basic OpenID, email and profile scopes. It lets Supabase and KerjaKit confirm your identity and email. It does not grant Gmail access, and Google profile data is not treated as career evidence or copied into your résumé.

Optional Gmail sending uses a separate OAuth client and requests only gmail.send. If you connect it, the refresh token is stored encrypted and is used only to send a message after you approve its content and recipient. You may disconnect Gmail in KerjaKit and revoke access in your Google Account. Disconnecting does not erase transaction or security records we must retain.

6. AI-assisted processing

KerjaKit sends the relevant parts of your instructions, career evidence, job information and requested context to configured AI providers such as DeepSeek or OpenRouter to produce the feature you ask for. A preferred name may be supplied as conversational context, but it must not be treated as career evidence or a résumé or legal name.

AI outputs can be incomplete or wrong. You should review every output before using or sending it. We do not intentionally include your account email or Google identity in an AI prompt unless you put that information into the content being processed.

7. Service providers, disclosures and international transfers

We use service providers only to operate the relevant part of KerjaKit. They may process data outside Malaysia, including in the European Union, United States or other locations where they or their subprocessors operate. We use contractual, access-control and technical safeguards appropriate to the service and information involved.

  • Supabase for authentication, database and private file storage; Google Cloud and Google for infrastructure, login and optional Gmail; DeepSeek or OpenRouter for AI-assisted features.
  • PostHog EU for product analytics and masked session replay; Resend for transactional email; CHIP for Malaysian payment processing.
  • Brave Search and enabled job-source integrations for public job discovery; Telegram and Meta WhatsApp for optional user-enabled messaging or alerts.
  • Professional advisers, authorities, payment investigators or a successor to the business where disclosure is required, proportionate and lawful.

8. Analytics, cookies and session replay

We use essential cookies and similar storage for sessions, security, language and workflow state. PostHog EU helps us understand feature use and reliability. Inputs are masked, and sensitive career-content regions are blocked from session replay. We do not send email addresses, preferred names or raw career content as analytics event properties.

KerjaKit does not sell personal data or use it for third-party advertising. We do not currently provide an analytics opt-out control. You may restrict non-essential browser storage using browser settings, but doing so can affect product behaviour.

9. How long we keep data

We keep information only for the periods needed for the purposes above, subject to legal holds and mandatory records.

  • Account content: while the account is active, then deleted within 30 days after we verify a deletion request.
  • PostHog session replay: 30 days. Product analytics: 12 months.
  • Security logs and recoverable backups: up to 90 days. Deleted content may remain inaccessible in rotating backups until expiry.
  • Support correspondence: 2 years.
  • Financial and transaction records: 7 years, or longer where Malaysian law requires it. These records are restricted and retained even if an account is deleted.

10. How we protect data

Measures include encrypted transport, authenticated sessions, owner-only database controls, private storage, limited staff access, secret management, encrypted Gmail refresh tokens, hashed integration credentials, monitoring and recoverable backups. No online service can promise absolute security. Please use a strong password, protect your account and tell us promptly about suspected misuse.

11. Your choices and rights

Subject to Malaysian law, you may ask whether we hold your personal data, request access or correction, withdraw an optional permission, object or limit certain processing, disconnect an integration, or request account deletion. Some processing is necessary to perform the service or meet legal duties, so withdrawing it may prevent a feature from working.

For deletion, email team.iidevstudio@gmail.com from your registered account email. We will verify the request and complete deletion within 30 days. We revoke connected integrations, remove private files and account content, and retain only records that law requires. You may also contact the proprietor/data contact using the details in section 1. We may request information reasonably needed to verify identity.

12. Young users

KerjaKit is not for anyone under 16. Users aged 16 or 17 must have permission from a parent or legal guardian. A parent or guardian must authorize any paid purchase. If we learn that an under-16 user provided personal data, we will take reasonable steps to close the account and delete the data, subject to legal retention duties.

13. Changes and questions

We may update this notice as KerjaKit or the law changes. We will publish the new date and, for material changes affecting existing users, provide a prominent in-product notice. Questions, complaints and rights requests may be sent to team.iidevstudio@gmail.com, +60 11-3350 6561, or the registered address in section 1.