Skip to content

Privacy Policy

Last updated: 14 August 2026

JobsMatch ("we", "us", "our") is an AI-powered job matching service for people looking for tech roles in Europe. This policy explains what personal data we collect, why we use it, who we share it with, and your rights under the EU General Data Protection Regulation (GDPR).

Early-stage notice — JobsMatch is operated as an independent project, not yet through a registered company. Features, pricing, and this policy may change. We will notify you of any material changes before they take effect.

Contact Information

Data controller: JobsMatch, an independent project operated from Europe.

Email: contact@jobsmatch.app

There is no registered legal entity yet. A company will be set up if the service becomes a commercial business. Until then, this email is the way to reach us for any privacy request. We aim to reply within 30 days.

Information We Collect

We collect only what we need to run the service. Some data lives on our servers; some stays only in your browser.

When you create an account

  • Email address, and a hashed password if you sign up with email (we never store the password in plain text).
  • If you sign in with Google, we receive only your email address from Google. We do not store your Google name or profile photo.
  • A display name, if you choose to add one in Settings.

When you upload a CV (PDF only)

  • The original PDF is read in memory and is not kept on our servers.
  • The extracted text is sent to our AI provider for that request, then discarded. We do not store the full CV text.
  • We do store a structured profile derived from the CV: skills, seniority, years of experience, languages, desired role, and location preferences.
  • We keep a scan history (up to the last 20 scans). Each scan includes your ATS score, layout metrics, a capped plain-text parse of what an ATS sees, and short quoted passages from the CV that support the content findings. Those quotes and the parse are personal data. They are included in a data export and are deleted when you delete your CV or your account.
  • A one-way hash of the extracted text, used only so that re-uploading the same file does not trigger a duplicate AI analysis.

When you build a profile by hand instead

  • Uploading a CV is optional. You can build the same profile by answering the steps at Build your profile, and everything in the section above then simply does not happen.
  • We store only the fields you filled in: area, target job title, seniority, years of experience, skills, spoken languages, remote and full-stack preferences, and up to three preferred locations. You see all of them on a summary screen before anything is saved.
  • No file is uploaded, no document text exists, nothing is sent to our AI provider, and no scan history is created — so there are no quoted passages and no plain-text parse to hold.
  • The ATS report is the one feature this path cannot give you: scoring how an applicant tracking system reads your CV requires the actual file.

Preferences and account status

  • Target role, optional salary preference, whether daily job-alert emails are on, and whether product emails (campaigns and research) are on.
  • Plan status (Starter, Pro, Career, or a grandfathered Lifetime grant), subscription dates, and a Stripe customer ID. We never see or store your card number.
  • A product-review survey, if you submit one: the answers you typed, when you sent it, and whether a complimentary Pro grant was applied. One review per account.

Data that stays in your browser only

  • Your login token, cached profile, optional profile photo, and — on Starter — saved jobs, the Kanban board, and Job Personas. Those Starter board items are not uploaded.
  • On Pro and Career, the board and Job Personas are stored on our servers so they follow you to a new laptop. Listing watches and in-app notifications are stored there too. Export and account deletion cover that copy. The photo stays in the browser.
  • Small measurement values (which page you arrived from, which option you picked, and which kind of public job pages you looked at). They contain no name, email, job title, or CV content.

Anonymous product analytics

  • Cookieless aggregate usage statistics via Vercel Analytics (no personal profiles, no cross-site tracking).
  • Anonymous funnel events on our own servers (for example, that someone started a scan). These are not tied to your account.
  • Optional reasons and a short comment when someone turns off the daily job email. These are not tied to the account.

You can browse job listings without an account. In that case we do not collect account or CV data.

How We Use Data

We use your data to:

  • Create and secure your account, and send the email that confirms your address.
  • Analyse your CV, show an ATS score and findings, and match you to relevant job listings. Matching is algorithmic (skill overlap and similar signals). It is not an AI deciding whether you should get a job.
  • Power optional AI tools you choose to use: CV rewrite, per-job CV tailoring, cover letters, and job summaries (TL;DR).
  • Send a daily job-alert digest by email. This is switched on by default when you create an account. You can turn it off at any time in Settings, or with the unsubscribe link in every digest.
  • Send product emails (campaigns, research surveys) when that preference is on. This is a separate list from the daily digest. You can turn it off in Settings or with the unsubscribe link in those emails.
  • Provide paid features if you buy them, manage your plan, and show invoices via Stripe.
  • Prevent abuse, keep the service secure, and improve matching and reliability.
  • Respond to your requests, including access, correction, and deletion.

We do not sell your personal data. We do not use it for advertising. We do not send your CV to employers. Applying for a job always happens on the employer's or job board's own website.

Legal bases (GDPR Art. 6)

  • Contract (Art. 6(1)(b)) — running your account, CV analysis, matching, and the AI tools you ask us to run.
  • Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, service improvement, the daily job-alert digest, and product emails (each with an easy opt-out).
  • Legal obligation (Art. 6(1)(c)) — keeping the payment references we need for tax or accounting if a paid transaction takes place.
  • Consent (Art. 6(1)(a)) — optional Google sign-in, and any future use that needs a separate yes.

CV processing and AI

When you upload a CV or use an AI tool, the relevant text (CV extract, your profile fields, and, where needed, the job description and your display name) is sent to OpenAI, which processes it to complete that request. Under OpenAI's API terms, API data is not used to train their models. OpenAI may keep it briefly for abuse monitoring, then delete it.

AI output (scores, rewrites, cover letters, summaries) is for your information only. Job match scores are estimates. None of this is a hiring decision, a credit decision, or any other automated decision with legal or similarly significant effects on you (GDPR Art. 22).

Data Sharing & Sub-processors

We share personal data only with the providers that help us run the service, and only as needed for that purpose. Job boards that supply listings do not receive your account or CV data.

  • OpenAI, L.L.C. (USA) — AI processing for CV analysis, content findings, rewrites, cover letters, job summaries, and job-listing classification. Receives the text needed for the request.
  • Stripe, Inc. (USA) — payment processing. Stripe handles card details under its own privacy policy and acts as an independent controller for payment data. We store only your Stripe customer ID and plan status.
  • Google LLC (USA) — optional sign-in. If you choose Google, we receive your email address.
  • Vercel Inc. (USA) — hosts the website and provides cookieless aggregate analytics.
  • Railway Corp. (USA) — hosts the API and the PostgreSQL database where account, profile, and scan data are stored.
  • Resend (USA) — sends transactional email (account confirmation), the daily job-alert digest, and product emails. Receives your email address and the email content.

These providers process data under their own terms and, where they act as processors, under appropriate data-processing terms. Some are in the United States. Transfers rely on Standard Contractual Clauses (SCCs) or another mechanism approved by the European Commission, as set out in each provider's documentation.

How long we keep data

  • Account, profile, and preferences: until you delete your account or ask us to erase them.
  • CV scan history, including quoted passages: last 20 scans, or sooner if you delete your CV or your account. The original PDF and the full extracted text are not stored.
  • Browser-only data: until you clear it in your browser, log out (auth keys), or switch account. Deleting your account on the server does not automatically wipe your browser storage.
  • Payment records: held by Stripe as an independent controller for the period required by law. We do not keep card details or a full invoice archive of our own.

User Rights (Access, Correction, Deletion)

If you are in the EU/EEA you have the following rights:

  • Access (Art. 15) — get a copy of the personal data we hold. Use Export in Settings → General → Privacy & data.
  • Correction (Art. 16) — fix inaccurate data in Settings → Profile, or email us.
  • Deletion (Art. 17) — delete your CV from the dashboard, or delete your whole account in Settings → General → Privacy & data. That removes your account, profile, and scan history from our servers and cancels an active Stripe subscription.
  • Restriction (Art. 18) — ask us to limit how we use your data while a concern is being resolved.
  • Portability (Art. 20) — receive your data as a JSON file via the same Export button.
  • Objection (Art. 21) — object to processing based on legitimate interests, including the daily job-alert emails and product emails (turn them off in Settings or via the unsubscribe link in that email).
  • Automated decisions (Art. 22) — our tools rank listings and generate drafts for you; they do not make legally binding decisions about you.

Export covers server-side data (account, profile, scans). On Pro and Career it also includes the cloud board, personas, listing watches, and notifications. It does not include browser-only items such as your photo, or the Starter board and personas that never left your device.

To use any of these rights, use the in-app controls or email contact@jobsmatch.app. We aim to respond within 30 days. You can also lodge a complaint with the data protection authority in your country of residence. A list of EU authorities is at edpb.europa.eu.

Cookies and local storage

JobsMatch does not use tracking or advertising cookies, and does not follow you across other websites. We store data in your browser's local storage, not in first-party cookies.

Strictly necessary. Login token, CV profile cache, saved jobs, Kanban, personas, and settings. Without these the app cannot stay signed in or keep your work between visits.

Measurement. Small values (jm_funnel_entry, jm_goal, and jm_hero_intent) record which page you arrived from, which option you picked when we asked what you were looking for, and whether you searched, opened listings, or tried to apply. They are not strictly necessary. They contain no name, email, job title, or CV content, and they are cleared once you have used the product.

If you sign in with Google, Google may set its own cookies as part of its sign-in service, under Google's privacy policy.

You can clear browser storage from your browser settings, and delete server-side data from Settings.

Data Security

Passwords are stored as salted hashes, never in plain text. Traffic uses HTTPS. Database access is limited to the services that need it. Card payments go to Stripe and do not pass through our servers.

No method of transmission or storage is perfectly secure. If a personal data breach is likely to risk your rights and freedoms, we will notify the competent authority within 72 hours and, where the law requires it, affected users without undue delay.

Changes to this policy

We may update this Privacy Policy. The "Last updated" date at the top will change. We will give reasonable advance notice of material changes in the app. If a change introduces a new purpose for processing your personal data, we will ask for your agreement where the law requires it.