Last updated 18 September 2026
The controller of the personal data described here is [YOUR NAME — or e.g. “the operator of this private preview”] — an individual, because this is a private preview rather than a company. Being a small project does not put it outside data-protection law: if it holds your CV, someone is responsible for it, and that is who this page names.
This policy covers the job-search dashboard and the emails it sends. It does not cover an employer’s website or a job board you reach through a link from the Service — those have their own policies.
Privacy questions and requests: [CONTACT EMAIL].
We hold the following, most of which you or an administrator provide directly:
We do not ask for special-category data (such as health, ethnicity, or trade-union membership) and you should not include it in your profile or in chat messages.
If you use “Continue with Google”, Google tells us your email address, whether it is verified, your name, and your profile picture, together with a stable account identifier. We use the email address to match you to the account an administrator created, and we store the identifier so that signing in again still finds you if you change your Google address. We do not receive your Google password, and we do not access your Gmail mailbox, Drive, contacts, or calendar.
If your profile has no name or photo yet, we use the ones on your Google account to fill the gap, so you do not start with an empty page. We only ever fill a blank: a name or a photo you have set yourself is never replaced by your Google one, however many times you sign in.
If you prefer not to use Google, you can sign in with the login name and password an administrator gives you instead. You can also ask us to unlink Google from your account.
The same applies if you use Google to join the waitlist before you have an account. No account is created and no session is issued at that point; we record the verified address so an administrator can decide on your request, and email you once to confirm it was received.
Google API Services User Data Policy. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to sign you in and to maintain your account. We do not use it for advertising, we do not sell it, and we do not transfer it to others except as needed to run the Service as described in this policy.
Under the UK/EU GDPR, we rely on the following bases:
Ranking, fit scores, role summaries, and drafted CV text are produced automatically, and features that analyse your profile or an imported LinkedIn export send that text to a large-language-model provider. Drafted text can be inaccurate and should always be reviewed by you before you use it. Scores are suggestions you are free to ignore, and we do not make solely automated decisions that produce legal effects or similarly significantly affect you.
We do not sell your personal data and we do not use it for advertising. We share it only with service providers who process it on our instructions:
We may also disclose data where the law requires it, or to establish or defend legal claims, or as part of a reorganisation of the business — in which case we will tell you.
If you upload a photograph, it is stored in a location that anyone holding its link can open, without signing in. That is what lets the image load in your profile and in emails. Treat it as public: please do not upload a photo you would not want shared, and ask us if you would like it removed.
The database and file storage are hosted by Supabase in Japan (AWS ap-northeast-1), and some providers listed above operate in the United States and elsewhere. Your data may therefore be stored or processed outside your own country.
Because this is a personal project rather than a company, no formal transfer agreement has been put in place with legal advice. That is stated plainly rather than papered over with wording that would suggest otherwise. If it matters to you — for example if you would be using this for a regulated purpose — please do not use the Service, or ask first and you will be told exactly where your data sits.
Account, profile, and activity data are kept while your account is open. The session cookie lasts seven days, and the short-lived Google sign-in cookie lasts ten minutes.
If you ask for your account to be deleted, it will be. Deletion is a manual process at present — there is no automatic routine that runs on a schedule — so please ask, and it will be actioned promptly rather than instantly. Anything that has to be kept to meet a legal obligation or resolve a dispute will be kept, and you will be told what and why. Plan-email records and security logs are kept for as long as they are needed for those purposes. Backups are overwritten on a rolling basis.
A waitlist entry is kept until it is decided — invited or declined — and then only as a record of that decision, so we can tell you what happened rather than losing track of your request. Ask us and it will be removed.
Sign-in records are kept while your account is open, because “where did that sign-in come from” is only answerable with history. Page-view totals carry no per-person trail and are kept in aggregate. Both go when your account does.
Data is encrypted in transit, database access is restricted to our servers using privileged credentials that are never sent to your browser, and sessions are carried in signed, HTTP-only cookies so they cannot be forged or read by scripts. No system is perfectly secure, but if a breach affects you we will tell you and the relevant authority as the law requires.
You can ask us to:
Write to [CONTACT EMAIL]. This is a small project rather than a company with a support team, so requests are handled as promptly as possible rather than to a contractual deadline. These rights are not absolute — some data must be kept, and you will be told if that applies. If you are unhappy with the response you may complain to the data-protection authority in your country.
We use a small number of cookies, all of them needed to run the Service or to remember a preference — none of them for advertising, and none of them shared with anyone else. The Cookie Policy lists each one.
We do measure how the Service is used — sign-ins and page-view totals, described in section 2. That is done by our own server against your account, not by cookies, not by a third-party analytics product, and not by anything that follows you to other websites.
The Service is for people aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child has used it, contact us and we will delete the account.
We may update this policy as the Service or the law changes. The revision date above will change, and we will notify material changes in the Service. It applies from the date shown.
[YOUR NAME — or e.g. “the operator of this private preview”] — [CONTACT EMAIL]. Your Jobs is the name shown on the sign-in screen; the Service is branded after the person signed in.