Back to home

Privacy notice

JobFinderOS · beta · August 2026

This notice explains what we collect when you use JobFinderOS, who processes it on our behalf, where it goes, how long we keep it, and the export and deletion rights built into the app. It is shown at the points where we collect your data, and lives at /privacy permanently.

01Who is responsible

JobFinderOS is a production-grade job-search platform built and operated by the JobFinderOS team, the data controller for everything described here.

Contact: anthony@flutterhive.dev — for anything about your data you can also sign in and use the in-app account tools in Settings → Your data. No data protection officer has been appointed.

02What we collect

  • Your account — email address and password (hashed). No name is required to register.
  • Your CV — the file you upload (PDF or Word), and the text the system extracts from it.
  • Your profile — the setup you choose (country, region, towns, languages, job titles) plus the name, email and phone the AI reads out of your CV, which you can correct.
  • Matches, drafts and applications — the scores and decisions on jobs we show you, the tailored CV and cover letter drafted for each, and a record of applications you approved and sent.
  • Site analytics — Google Analytics cookies measuring which pages and features are used, so we can see what to improve. Analytics loads only after you accept it in the consent banner — decline and no analytics script runs at all. Google processes this measurement data, which can involve transfers outside the EU.

03Why we process it

Everything above is processed to run the service you signed up for: hunting job boards on your settings, scoring jobs against your CV, drafting applications for your approval, and sending the ones you approve. That processing is necessary to perform that service. We do not sell your data, run advertising on it, or build profiles for anything outside the app.

04Who else processes your data

These processors act on our instructions only:

  • Z.ai — AI provider · outside the EU

    To score jobs against your CV, suggest search titles, tailor your CV and cover letter, and fact-check those drafts, parts of your CV text and the job ad are sent to Z.ai's API (api.z.ai). Z.ai processes this outside the EU. Each call is logged with the endpoint and model it used (no CV text in the log) so the transfer is auditable.

    Beta: during the current beta phase, AI processing runs on Z.ai. We are migrating AI processing to an EU-hosted endpoint of the same models, planned to be in place by the end of the beta phase — this notice will be updated when that change lands.

  • Supabase — database and file storage · EU (eu-west-1, Frankfurt)

    All account data and the CV file itself live in Supabase (Postgres and a private storage bucket) in the EU, Frankfurt region.

  • Render — application hosting · EU (Frankfurt)

    The API and the twice-daily hunt jobs run on Render in Frankfurt, in the same region as the database.

  • Your own Gmail — application emails · optional, you connect it

    Email applications are sent from your own Gmail account, which you connect under Settings — they carry your address, never ours. Sending runs through Google's infrastructure. During the beta rollout of this feature, email sending is briefly offline; browser and manual apply are available throughout.

  • Resend — onboarding emails · EU (eu-west-1, Ireland)

    When you sign up we send a short series of onboarding emails (about six, one per day) explaining each part of the platform. Your email address is stored with our email provider, Resend, for this purpose. Every email has an unsubscribe link — using it stops the series and nothing else about your account. Deleting your account removes the contact entirely.

  • Only if you turn them on

    Error tracking (Sentry, an EU-region project when enabled) may receive error reports. Connecting your Gmail under Settings uses Composio as the integration layer — that link is created only if you click Connect.

05Transfers outside the EU

The processing outside the EU that our setup verifies is the CV text and job-ad text sent to Z.ai for matching, tailoring and fact-checking, as described above. Your stored account data and CV file remain in the EU (Frankfurt). Applications you send go out from your own Gmail account and are delivered by Google and the employer's mail system, whose locations are outside our control — and once delivered, we cannot recall an application you have approved and sent.

The Z.ai transfer above applies during the beta phase: we are moving AI processing to an EU-hosted endpoint of the same models, planned to be live by the end of beta, after which CV and job-ad text no longer leave the EU for AI processing.

06How long we keep it

  • Job ads — kept only while they are plausibly still open; we do not build an archive of postings.
  • Everything personal — your account, CV, profile, matches, drafts, applications and processing logs — is kept until you delete your account. Deleting it removes all of it, permanently.

07Your rights

Export. In Settings → Your data you can download what we hold about you — your account details, profile, matches, drafts (including each tailored CV and cover letter) and applications (including the subject, body and recipient address of every application you sent) — as a JSON file.

Erasure. The same screen deletes your account and all personal data with it: your profile, the CV file itself, every match, draft and application, your AI usage logs, and the account. Two honest limits: job postings stay (they are shared scraped data, not personal to you), and a Composio integration you connected is left orphaned on Composio's side rather than disconnected.

You also have the rights to access, rectify and object to processing, and to lodge a complaint with a supervisory authority. Use the contact in section 01 for any of these.

08Security

Your password is stored hashed, sign-in uses per-account tokens, and every query for profiles, matches, drafts and applications is scoped to your account. The CV storage bucket is private — files are not publicly reachable.

JobFinderOS is in beta. If this notice and what the app actually does ever disagree, treat that as a bug: the in-app export and deletion in Settings always operate on the real data.