Privacy Policy
A job search is sensitive, often the one thing you least want a current employer to hear about. This policy explains what job-boards.io ("we", "us") collects when you use the website, the app and the emails it sends (the "Service"), why, who else touches it, how long we keep it, and what you can do about it. It is written to be read, and it describes what the Service actually does.
1. Who we are
job-boards.io is the controller of the personal information described here: we decide why and how it is processed. This policy applies to everyone who uses the Service, signed in or not. It does not cover employers' career sites or the other sites a posting links to; when you follow a link to apply, that site's own privacy policy applies. The Terms of Service cover the rest of our agreement with you.
2. What we collect
2.1 When you search without an account
- The sentence you type. It is used to answer the search. The answer is held in our hosting provider's cache for 15 minutes, keyed by the sentence and not by you, so anyone typing the same words in that window gets the same answer. We also keep the first 200 characters of the sentence, with timings and result counts, in our search measurements for 30 days, recorded as an anonymous trial search and not linked to any person or device. The most common trial sentences of the week appear, without anything identifying who typed them, on our internal dashboard.
- A per-network counter. To stop the free search being abused, we count searches per network per day. The counter is keyed by a salted, one-way hash of your network address (for IPv6, of its /64 prefix), never the address itself, and is deleted after two days.
- Rate limits. Our hosting provider briefly tracks request rates per network address to throttle floods. That count is held by the provider, not written to our database.
- What stays in your browser. Your votes, the board you build, and your recent sentences are kept in your browser's storage, not on our servers, until you create an account (see section 3).
- Share links. If you copy a link to a search, the sentence is part of the link, so anyone you give it to can read it.
2.2 When you create and use an account
| What | Details |
|---|---|
| Account | Your email address; a password hash (never the password itself); whether your email is verified; your time zone, read from your browser so digests arrive at a sensible hour; when you signed up and last signed in; and counts of failed sign-ins used to lock out guessing. |
| Two-factor and passkeys | Your authenticator secret, encrypted; your recovery codes, stored only as hashes; and, for each passkey, its public key, identifier, and when it was added and last used. The private half of a passkey never leaves your device, which labels the passkey with your email address. |
| Google or Apple sign-in | If you use them: the provider's stable identifier for you, the email address it gave us, and when the link was made and last used. We ask Google only for your email address and a sign-in identifier, not your name, photo, contacts or anything else. Apple may give us a private relay address instead of your real one. |
| Sessions | For each signed-in device: a hash of the session token, when it was created and last active, the network address it signed in from, and a short description of the browser. You can review these and sign devices out from your account settings. |
| Your job search | Your boards and the jobs on them, with their statuses, notes, dates applied and followed up, and a history of each status change; your votes on search results; saved searches and what they found; alerts and the in-app and email notices they produced; your weekly application goal. |
| Searches | The sentence and filters of each search you run, used to answer it, and the first 200 characters kept with its timings in our search measurements for 30 days. |
| Feedback | The subject, message and page of anything you send through the feedback form, including a sentence you report as giving irrelevant results, and any company you ask us to add. |
| Email records | A copy of each alert email we send you (subject and body) and whether it was delivered, so the app can show you what was sent. |
2.3 Your resume and profile
Uploading a resume is optional. If you do, we keep the original file (PDF, Word, text or Markdown) with a thumbnail of its first page, the text read from it, and the profile we build from it: headline, summary, job titles, skills, years of experience, seniority, location, remote preference, salary floor, links, must-haves, deal-breakers, and any companies you list. You can edit any of it. Recording that you applied to a job also saves the headline and skills you had at that moment, so your application history shows what you applied with.
A resume usually carries your name, address and phone number, and can carry more. We do not need anything beyond your work history to find you jobs, so please leave out government identifiers, date of birth, health information, and similar details before uploading.
2.4 Collected automatically
- Request logs. Our hosting provider records technical details of requests (such as network address, time, page and browser) to operate and secure the Service. These logs are short lived.
- Error records. When something breaks, we record what failed and, if you were signed in, your account identifier, for 30 days.
- Usage counts. How many AI calls were made on your behalf each day and how large they were, so we can manage cost, kept for a year.
We do not use analytics or tracking scripts, fingerprinting, advertising identifiers, or third-party pixels, and we do not store your precise location.
3. Cookies and browser storage
We set three cookies, all first-party, all needed for sign-in to work, and none used for tracking or advertising. Because they are strictly necessary, we do not ask for consent to them and there is no cookie banner.
| Cookie | Purpose | Lasts |
|---|---|---|
jb_session |
Keeps you signed in. Holds a random token; we store only its hash. | 30 days, or 10 minutes while a two-factor sign-in is unfinished |
jb_oauth |
Protects a Google or Apple sign-in in progress from forgery. | 10 minutes |
jb_passkey |
Holds the one-time challenge for a passkey sign-in or registration. | 2 minutes |
Our hosting provider, Cloudflare, may set its own strictly necessary cookies to tell people from bots and to block attacks.
The site also keeps some things in your browser's own storage, which never leaves your device unless noted:
| Key | What it holds |
|---|---|
trial_votes, trial_board, trial_prompt |
Your votes, board and last sentence from searching without an account. Sent to your account the first time you sign in, then removed from the browser. |
trial_recent |
Your last few trial sentences, shown as shortcuts. Never sent to us. |
trial_src |
The campaign tag of a link you arrived by, for this visit only. Sent with trial searches so we can count, in total, which links bring people in. |
theme |
Whether you chose the light or dark look. |
jb.searches.* |
Your recent searches in the app and their results, so they reopen instantly. |
jb.nav.*, jb.board, jb.homeflow.*,
jb.corequest.*, jb.logos.v1
|
Layout choices, the last board you opened, companies you asked us to add, and cached employer logos. |
Signing out does not clear this storage. On a shared computer, clear this site's data in your browser settings when you are done.
4. How we use it, and why we may
We use personal information only to provide the Service. Where the law asks for a legal basis (for example, the GDPR in the European Economic Area and the UK), these are ours:
| Purpose | Legal basis |
|---|---|
| Running your account and the features you use: searches, boards, tracking, saved searches, alerts, your profile and resume | Performing our contract with you |
| Sending email the account needs: verifying your address, password resets, and security notices such as a sign-in provider being connected or someone trying to sign up with your address | Performing our contract with you |
| Sending alert emails you turn on | Performing our contract with you, at your request; off at any time |
| Keeping accounts and the Service secure: sessions, lockouts, rate limits, the trial counter, detecting abuse | Our legitimate interest in a secure, available Service, and yours in a safe account |
| Improving the Service: search measurements, error records, usage counts, feedback, and widening the catalogue of employers when a search finds too few | Our legitimate interest in a Service that works and finds relevant jobs |
| Complying with the law and enforcing our terms | Legal obligation, and our legitimate interest in protecting the Service |
Where we rely on legitimate interests, we have weighed them against your rights, and you can object (see section 9). We do not use your information for advertising, we do not build profiles of you to sell, and we do not make decisions about you that have legal or similarly significant effects. The scores the Service shows are automated rankings of job postings against your own words, for you to use as you see fit.
5. AI processing
Reading your resume. When you upload a resume, its text (up to 20,000 characters) is sent to Anthropic's Claude models to fill in your profile. The file is read in your browser, and only its text goes to Anthropic.
Your job searches are never sent to Anthropic. When a search finds too few employers, we may ask Anthropic to find more employers in that field of work, such as "software engineering". That request names only the field: never your words, and never anything about you. Searches without an account never trigger it.
Anthropic processes this data as our service provider under its commercial terms, which do not allow it to train its models on it, and keeps it only for a limited period under its own retention policy. Ranking your search results does not use AI; it is a fixed formula that runs on our servers.
6. Who we share it with
We do not sell or rent personal information, and we do not share it with advertisers or data brokers. We share it only with the service providers below, which process it on our behalf and under our instructions, and only as much as each one needs:
| Provider | What it does | What it receives |
|---|---|---|
| Cloudflare | Hosting, database, caching, rate limiting, request logs, bot protection | Everything the Service stores, and the technical details of every request |
| Resend | Sending email | Your email address and the content of each email we send you |
| Anthropic | AI processing, as in section 5 | Resume text |
| Google, Apple | Sign-in, only if you choose it | That you are signing in to job-boards.io. They send us what is listed in section 2.2. |
| USAJOBS (U.S. Office of Personnel Management) | Federal job listings, for signed-in searches | Keywords taken from your search sentence, sent from our servers, with nothing about you |
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Employer logos are fetched by our servers, not your browser, and nothing about you is sent with them. When you open a posting, you go to the employer's own site, which sees only that you came from job-boards.io.
We may also disclose personal information:
- If the law requires it, such as a valid court order or subpoena. Where we are allowed to, we will tell you first so you can object.
- To protect the rights, safety or property of our users, the public or us, such as to investigate fraud or an attack.
- If job-boards.io is merged, acquired or sold, to the new owner, who must keep honouring this policy for the information we held. We will tell you before that happens.
Inside job-boards.io, access to the database is limited to the people who run the Service, and used only to operate, secure and support it. The internal dashboard shows account emails, sign-up and sign-in dates, activity counts, feedback, error records, and recent search sentences without the account that ran them. It does not show resumes, profiles, boards or notes.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account, two-factor, passkeys, Google or Apple connections, boards, jobs, notes, application history, saved searches, alerts, email records, profile, resumes and feedback | Until you delete them or your account. Votes are capped at your most recent 20,000. |
| Sessions, with their network address and browser description | Until you sign out, revoke them, or they expire after 30 days |
| Email verification and password reset links | 24 hours and 1 hour, then deleted |
| Search measurements, including the start of each sentence | 30 days |
| Error records | 30 days |
| Which postings an alert has already told you about | 60 days |
| Daily AI usage counts | 1 year |
| Trial per-network counter (hashed) | 2 days |
| Cached trial answers | 15 minutes |
| Browser storage | Until you clear it in your browser |
Expired items are removed by a job that runs every hour. Our providers keep their own operational records, such as request and email delivery logs, for limited periods set by their policies. We may keep information longer where the law requires it, or where it is needed to resolve a dispute or deal with abuse, and only for as long as that lasts.
8. Deleting your account
You can delete your account from its settings with your password and a typed phrase. If you signed up with Google or Apple, set a password first through "Forgot your password?" so we can be sure it is you. Deletion is immediate and cannot be undone. It removes, in a single step, your account, sessions, Google or Apple connections, passkeys, two-factor secrets, boards, jobs, notes, application history, votes, saved searches, alerts, email records, profile, resumes and uploaded files, and feedback.
Three internal records outlive the account, with the link to you cut: search measurements lose your account identifier and the text of your searches; error records lose your account identifier; and AI usage counts are merged into an anonymous total. They then age out on the schedule above. Copies held by our providers (for example, an email already delivered, or a request log) are removed on their own schedules or on request. Browser storage stays on your device until you clear it.
9. Your rights
Wherever you live, you can ask us to:
- Access the personal information we hold about you, and get a copy.
- Correct anything inaccurate. Most of it you can edit in the app.
- Delete it. Deleting your account does this at once; you can also delete a resume, a board with its jobs, a saved search or an alert on its own.
- Port it: receive what you gave us in a structured, machine-readable format.
- Object to processing based on legitimate interests, or ask us to restrict it.
- Withdraw consent wherever we rely on it, without affecting what happened before.
To use any of these, email privacy@job-boards.io from the address on your account, so we can confirm the request is yours. We will reply within 30 days, and tell you if we need longer (up to the limit the law allows) and why. Requests are free. If you are in the EEA, the UK or Switzerland, you may also complain to your local data protection authority, though we would welcome the chance to put it right first.
10. California and other US states
If you live in California or another US state with a consumer privacy law, this section adds to the rest of the policy. In the last 12 months we have collected these categories of personal information, from you, your browser, and the sign-in provider you chose:
- Identifiers: email address, account and sign-in identifiers, network address.
- Professional or employment information: your resume, titles, skills, experience, salary floor, and the jobs you track and their status.
- Internet or other electronic activity: searches, votes, session and browser details.
- Sensitive personal information: the email and password you sign in with, and anything sensitive you choose to include in a resume. We use it only to provide the Service and keep it secure, as the law permits, and not to infer anything about you.
We use and disclose these for the purposes and to the service providers in sections 4 and 6, and keep them for the periods in section 7. We do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the last 12 months, including for anyone under 16. You have the right to know, access, correct and delete your personal information, and not to be discriminated against for using these rights. You may use an authorised agent, whom we will ask for proof of your permission. Make a request as described in section 9.
11. How we protect it
- Passwords are hashed with PBKDF2 and a per-user salt, plus a secret pepper that is not stored in the database.
- Only a hash of each session token is stored, so a copy of the database holds nothing that signs anyone in.
- Two-factor secrets are encrypted at rest; recovery codes are stored as hashes and shown once.
- All traffic is encrypted in transit. A strict content security policy lets only our own scripts run on our pages.
- Changing or resetting your password signs out every other device.
No system is perfectly secure. If a breach affects your personal information, we will tell you and the relevant authorities without undue delay, as the law requires. To report a vulnerability, email security@job-boards.io.
12. International transfers
We and our providers operate in the United States and other countries, and Cloudflare serves requests from a global network. Your information may therefore be processed outside the country you live in, including in countries whose data protection laws differ from yours. When information leaves the EEA, the UK or Switzerland, we rely on safeguards recognised by those jurisdictions, such as the European Commission's Standard Contractual Clauses or a provider's certification under the EU-US Data Privacy Framework.
13. Children
The Service is not for children. You must be at least 16 to use it, and we do not knowingly collect personal information from anyone younger. If you believe a child has given us personal information, contact us and we will delete it.
14. Do Not Track and Global Privacy Control
We do not track you across other sites and do not sell or share personal information for advertising, so there is nothing for these signals to switch off. We treat a Global Privacy Control signal as a valid request to opt out of sale and sharing all the same.
15. Changes to this policy
When the Service changes what it collects or how it uses it, this policy changes with it, and the date at the top moves. If a change is material, we will tell account holders by email or in the app before it takes effect. We will not use information we already hold in a materially different way without telling you first and, where the law requires, asking.
16. Contact
Questions about this policy or your data, and requests under section 9 or 10: privacy@job-boards.io. Security issues: security@job-boards.io.