Your Jobs

Privacy Policy

Last updated 18 September 2026

1. Who is responsible for your data

The controller of the personal data described here is [YOUR NAME — or e.g. “the operator of this private preview”] — an individual, because this is a private preview rather than a company. Being a small project does not put it outside data-protection law: if it holds your CV, someone is responsible for it, and that is who this page names.

This policy covers the job-search dashboard and the emails it sends. It does not cover an employer’s website or a job board you reach through a link from the Service — those have their own policies.

Privacy questions and requests: [CONTACT EMAIL].

2. What we collect

We hold the following, most of which you or an administrator provide directly:

  • Account details — your display name, login name, home country, and the email address an administrator records for you.
  • Profile and CV — names, contact details, work history, education, skills, and any other content you add or import.
  • Photograph — if you upload a headshot. See section 7: this is stored so that it is publicly reachable by its link.
  • Preferences — the locations, working arrangements, role families, languages, and salary range you target, and your interface language.
  • Activity — roles you save, apply to, hide or rate; CV drafts; and your conversations with the in-app assistant.
  • Plan emails — the address they are sent to and a record of what was sent and when.
  • Waitlist — if you ask for access before you have an account, we receive your email address and the name on that Google account, through Google sign-in. Using Google is deliberate rather than convenient: it means the address is one you have proved you control, so nobody can put someone else’s address on the list. We keep it only to decide on and respond to your request; see section 9 for how long.
  • Waitlist, if you try to sign in without an account — signing in with Google when no account matches that address puts the address on the waitlist and sends one acknowledgement email, rather than refusing you with nowhere to go. No account is created and you are not signed in; it is a request, not access. It is the same verified-by-Google address as above, kept and removed on the same terms, and an address that has already been declined is not added again.
  • Technical records — sign-in events and a log of actions taken in the app, kept for security and support.
  • How you use it — for each sign-in: when it happened, whether it was a password or Google, the approximate location our host derives from your connection (country, region, city, timezone) and whether the device looked like a phone, tablet or computer. We do not store your IP address, and we do not store the full browser identifier. Separately, we count how often each page is opened, per day — totals, not a list of what you personally opened.
  • What you do in the app — that you opened a role, read its full description, searched (including the words you typed, kept short), changed a filter, or clicked through to an employer. We record the action and which role it concerned, never the contents: no CV text, no job description, no assistant conversation. We also record when something appears broken — repeated clicks on something that isn’t clickable, and errors thrown in your browser — because those are otherwise invisible and are how the product gets fixed. This is what a beta is for, and it is first-party: nothing is shared with anyone, and nothing follows you to another site.

We do not ask for special-category data (such as health, ethnicity, or trade-union membership) and you should not include it in your profile or in chat messages.

3. If you sign in with Google

If you use “Continue with Google”, Google tells us your email address, whether it is verified, your name, and your profile picture, together with a stable account identifier. We use the email address to match you to the account an administrator created, and we store the identifier so that signing in again still finds you if you change your Google address. We do not receive your Google password, and we do not access your Gmail mailbox, Drive, contacts, or calendar.

If your profile has no name or photo yet, we use the ones on your Google account to fill the gap, so you do not start with an empty page. We only ever fill a blank: a name or a photo you have set yourself is never replaced by your Google one, however many times you sign in.

If you prefer not to use Google, you can sign in with the login name and password an administrator gives you instead. You can also ask us to unlink Google from your account.

The same applies if you use Google to join the waitlist before you have an account. No account is created and no session is issued at that point; we record the verified address so an administrator can decide on your request, and email you once to confirm it was received.

Google API Services User Data Policy. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to sign you in and to maintain your account. We do not use it for advertising, we do not sell it, and we do not transfer it to others except as needed to run the Service as described in this policy.

4. Why we use it, and our legal bases

Under the UK/EU GDPR, we rely on the following bases:

  • To provide the Service you asked for (contract) — running your account, ranking roles, generating drafts, and sending the plan email you switched on.
  • To keep it secure and working (legitimate interests) — preventing unauthorised access, diagnosing faults, and keeping records of what happened.
  • To meet our obligations (legal obligation) — for example, responding to a lawful request.
  • With your consent — where we ask for it specifically. You may withdraw consent at any time, without affecting what we did beforehand.

5. Automated analysis and AI

Ranking, fit scores, role summaries, and drafted CV text are produced automatically, and features that analyse your profile or an imported LinkedIn export send that text to a large-language-model provider. Drafted text can be inaccurate and should always be reviewed by you before you use it. Scores are suggestions you are free to ignore, and we do not make solely automated decisions that produce legal effects or similarly significantly affect you.

6. Who we share it with

We do not sell your personal data and we do not use it for advertising. We share it only with service providers who process it on our instructions:

  • Supabase — database, authentication storage, and file storage. Your data is held in their AWS ap-northeast-1 (Tokyo) region.
  • Google — sign-in via OpenID Connect, and the Gmail API used to send your plan emails.
  • Our large-language-model provider — receives the profile, CV, or job text needed to produce an analysis or draft. Which provider is used is set by the operator.
  • Job-board APIs (such as Adzuna, Jooble, Reed, and Careerjet) — we fetch public job advertisements from them. We send them search terms such as a job title and location; we do not send your profile or identity.
  • A search API — used to check whether a role also appears on LinkedIn. It receives the role’s job title and employer, not your personal data.
  • Our hosting provider — serves the application on our behalf.

We may also disclose data where the law requires it, or to establish or defend legal claims, or as part of a reorganisation of the business — in which case we will tell you.

7. Your headshot is publicly reachable

If you upload a photograph, it is stored in a location that anyone holding its link can open, without signing in. That is what lets the image load in your profile and in emails. Treat it as public: please do not upload a photo you would not want shared, and ask us if you would like it removed.

8. Sending data outside your country

The database and file storage are hosted by Supabase in Japan (AWS ap-northeast-1), and some providers listed above operate in the United States and elsewhere. Your data may therefore be stored or processed outside your own country.

Because this is a personal project rather than a company, no formal transfer agreement has been put in place with legal advice. That is stated plainly rather than papered over with wording that would suggest otherwise. If it matters to you — for example if you would be using this for a regulated purpose — please do not use the Service, or ask first and you will be told exactly where your data sits.

9. How long we keep it

Account, profile, and activity data are kept while your account is open. The session cookie lasts seven days, and the short-lived Google sign-in cookie lasts ten minutes.

If you ask for your account to be deleted, it will be. Deletion is a manual process at present — there is no automatic routine that runs on a schedule — so please ask, and it will be actioned promptly rather than instantly. Anything that has to be kept to meet a legal obligation or resolve a dispute will be kept, and you will be told what and why. Plan-email records and security logs are kept for as long as they are needed for those purposes. Backups are overwritten on a rolling basis.

A waitlist entry is kept until it is decided — invited or declined — and then only as a record of that decision, so we can tell you what happened rather than losing track of your request. Ask us and it will be removed.

Sign-in records are kept while your account is open, because “where did that sign-in come from” is only answerable with history. Page-view totals carry no per-person trail and are kept in aggregate. Both go when your account does.

10. Keeping it safe

Data is encrypted in transit, database access is restricted to our servers using privileged credentials that are never sent to your browser, and sessions are carried in signed, HTTP-only cookies so they cannot be forged or read by scripts. No system is perfectly secure, but if a breach affects you we will tell you and the relevant authority as the law requires.

11. Your rights

You can ask us to:

  • give you a copy of your personal data, and tell you how we use it;
  • correct anything inaccurate;
  • delete your data, or restrict what we do with it;
  • provide your data in a portable, machine-readable format;
  • object to processing based on our legitimate interests;
  • withdraw consent you have given.

Write to [CONTACT EMAIL]. This is a small project rather than a company with a support team, so requests are handled as promptly as possible rather than to a contractual deadline. These rights are not absolute — some data must be kept, and you will be told if that applies. If you are unhappy with the response you may complain to the data-protection authority in your country.

12. Cookies

We use a small number of cookies, all of them needed to run the Service or to remember a preference — none of them for advertising, and none of them shared with anyone else. The Cookie Policy lists each one.

We do measure how the Service is used — sign-ins and page-view totals, described in section 2. That is done by our own server against your account, not by cookies, not by a third-party analytics product, and not by anything that follows you to other websites.

13. Children

The Service is for people aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child has used it, contact us and we will delete the account.

14. Changes to this policy

We may update this policy as the Service or the law changes. The revision date above will change, and we will notify material changes in the Service. It applies from the date shown.

15. Contact

[YOUR NAME — or e.g. “the operator of this private preview”][CONTACT EMAIL]. Your Jobs is the name shown on the sign-in screen; the Service is branded after the person signed in.