Privacy Policy
Last updated: September 8, 2026
Controller
Nenad Franjic, reachable at info@job-badger.com — see the Imprint for full details.
What information we collect
When you use the free tools on this site, we collect what you submit: a job posting URL, your email address, and career details you provide (current role, years of experience, optional name, optional salary expectation, optional work-location preference, optional LinkedIn URL, and the career text you provide — typed, pasted (e.g. from your LinkedIn profile), or extracted from a CV you upload). Uploaded CV files are parsed in memory and never stored; only the extracted text you can see and edit is processed. There is no account.
When you reserve a spot for the premium service, we collect the posting URL, your email, and any optional note you add.
Technical data: our infrastructure processes your IP address to protect the service against abuse (rate limiting) and in short-lived server logs. Generated letters and request details are stored under the retention policy below. Hashed email/IP quota keys enforce limits; hashes are pseudonymous, not anonymous.
Where you came from: when you submit a form, we record any campaign tag in the page's address (a utm_source-style parameter) and the domain that referred you — for example reddit.com, never the full referring address. This tells us which channels actually help people, and it is stored only alongside your submission. We use no advertising pixels and no third-party tracking of any kind, and nothing is stored on your device for this.
Your finished letters are also kept in your own browser(session storage) so a page refresh doesn't lose them; that copy includes your unfinished profile, posting and search drafts. It is local to that browser tab; closing the tab normally clears it, though browsers may restore tabs. Use “Clear profile and results” to remove the preparation draft explicitly.
How we use your information
- To generate the application materials you requested
- To find and show you matching job postings
- To notify you about your reservation when the premium service opens
- To operate and improve the service
We do not sell, rent, or share your personal information with third parties for their marketing purposes. No newsletter is sent unless you separately ask for one.
Legal basis for processing (GDPR Art. 6)
If you are located in the European Economic Area, we process your data under:
- Performance of a contract / pre-contractual steps — processing your fit-check, application-prep, or job-search request to deliver the result you asked for.
- Consent — you actively accept this policy and the terms before application generation. CV AI review has its own explicit consent checkbox. Upload extraction itself uses no AI. Optional marketing messages require a separate choice; you can withdraw it by contacting us.
- Legitimate interest — retaining submissions to operate the service, enforce fair-use limits, prevent abuse, and (with your reservation) contact you when the paid service opens.
AI processing of your data
To generate your application materials, the career details you submit (including text extracted from an uploaded CV) and the job posting text are sent, after your explicit confirmation, to an AI model provider — currently OpenAI(United States). We may route requests through Vercel's AI Gateway and may add other model providers (such as Anthropic) in the future; this policy will be updated when that happens. API data at these providers is not used to train their models under their API terms. The model is instructed to use only the facts you provide and never to invent achievements, numbers, or employers — still, review any AI-generated draft before you send it; you decide what to submit and where.
Job searches are different: when we query job boards and aggregators on your behalf, we send only your search keywords and location— never your name, email, CV text, or any other personal detail. One exception: your keywords may be machine-translated into the search location's language by the same AI provider to find local-language postings.
Data storage and security
Submissions are stored in a Postgres database (Neon, via Vercel's Marketplace, currently hosted in the United States under EU Standard Contractual Clauses; a migration to an EU region is planned). New submissions do not copy CVs or drafts into application logs or founder notification emails. Those notifications carry only the anonymous counters described below — country, role family, experience band and similar — and never your email address, name, CV text, generated letter, exact salary or the job link. An email service (Resend) delivers requested reports, reservation notices and the founder's sign-in codes. Connections use TLS encryption in transit.
Retention — what we delete and what we keep. An automated job is scheduled daily. Submission content becomes eligible for deletion after 7 days and is removed on the next successful run: the career text or CV you provided, the letters and analyses we generated for you, your name, your salary expectations, and the search terms held against your submission. This removes content from the live submissions table. Provider logs, database backups and reports delivered by email have separate retention; the seven-day rule does not control those copies. (The separate anonymous tally of searched job titles described below is not part of your submission and is not linked to you.)
What we keep beyond that point is deliberately minimal: your email address and, if you gave one, your LinkedIn URL — so we can reach you and recognise a returning user; plus the job-posting link and a marker of whether a letter was a revision, which is only what the free daily limits and the one-free-revision rule need in order to work. Your salary expectation and work-location preference are used only to produce the anonymous counters below — they are never written into a letter — and the values themselves are deleted with the rest of your submission after seven days. We retain consent choices and their version/source, attribution tags, and token-usage metadata. The founder's sign-in codes are hashed, expire after ten minutes and are cleaned up by the daily job. Administrator sessions expire after eight hours; quota keys expire according to their limit window, while a per-job revision marker is retained to enforce the one-revision rule. We also keep aggregate daily counts (how many searches and letters, from which country and channel) that are not linked to any person and cannot be traced back to you.
If you ask a free tool to email you its result we send that one report and keep your email address together with your choice about future emails, so we can recognise you if you come back. That send is transactional: you asked for it, so it needs no marketing consent. Hearing from us again is a separate, unticked box you have to choose, and we do not add you to anything by default. The report itself is not stored — it is your own text and we have no reason to keep it, though the delivered copy naturally exists with the email provider and in your inbox. Reply “delete me” to any email and the address goes.
One addition to those counts: we keep a tally of the job titles people search for— the words themselves, such as “paid media specialist”, with a count of how often they were searched. This is what tells us which job titles mean the same thing, so a search for one finds postings advertised under the other. It is stored as a plain tally, never attached to your submission, your email or your IP address, and a search containing anything that could identify someone (an email address, a phone number, a link, a postcode) is not recorded at all rather than recorded in a cleaned-up form. Your location is not stored alongside it.
You can ask us to delete your email and LinkedIn URL at any time — a plain email is enough, and we will do it.
Third-party services
We use the following services, each with its own privacy policy:
- Vercel — website hosting and privacy-friendly, cookieless visitor analytics (aggregate page counts; no cross-site tracking, no persistent identifiers)
- Neon — database storage (US region, SCCs; EU migration planned)
- Resend — email delivery
- OpenAI (or another configured AI provider, possibly routed via Vercel AI Gateway) — generating application drafts and translating search keywords
- Public job boards and aggregators (e.g. EURES, national employment services, company career APIs) — queried with your search keywords and location only
International transfers
Some providers above process data in the United States (Vercel, Neon, OpenAI). These transfers rely on EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. We plan to move primary data storage to an EU region.
Children
The service is intended for people of working age and is not directed at children under 16. We do not knowingly collect data from children.
California residents (CCPA/CPRA)
We do not sell or share personal information as defined by the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. California residents have the rights to know, delete, and correct — exercise them via the contact below.
Cookies
The public tools use no advertising or analytics cookies. Visitor statistics are collected without persistent visitor identifiers. The founder dashboard uses an essential, HTTP-only session cookie after administrator sign-in; it expires after eight hours. Browser session storage keeps form drafts as described above.
Your rights
You have the right to access, correct, delete, restrict, or port your data, and to object to its processing (GDPR Art. 15–21), as well as the right to lodge a complaint with a supervisory authority. A plain email is enough — contact info@job-badger.com.