JobPivot

Privacy Policy

Last updated: June 19, 2026

Draft — not legal advice. This is a good-faith description of how JobPivot works today. Have it reviewed by counsel before relying on it for your jurisdiction.

JobPivot is a privacy-first job-search tool. We built it so you can keep your entire search in one place without your data being sold, profiled for ads, or shared with employers. This policy explains what we collect, why, and the control you have over it.

Information we collect

We only collect what the product needs to work:

  • Account details — your email address, an optional display name, and (for password accounts) a securely hashed password. If you sign in with Google, we receive your email and name from Google.
  • Content you create — the jobs, companies, contacts, interviews, follow-up reminders, notes, and resume files you add. This is yours; we treat it as confidential.
  • Resume files — the documents you upload, stored as files (not in our main database) and reachable only through short-lived, signed links scoped to your account.
  • Minimal technical data — standard server logs needed to operate and secure the service. We do not run third-party advertising or analytics trackers.

How we use it

We use your information solely to provide JobPivot: to authenticate you, store and display your job search, send the transactional and (optional) reminder emails you ask for, and keep the service secure. We do not sell your data, and we do not use your job-search content to train models or build advertising profiles.

The app includes a “recruiter visibility” preference that is off by default and currently inert — it records a choice for a future opt-in feature and shares nothing with anyone today.

Service providers (sub-processors)

We rely on a small number of vendors to run the service, each processing data only on our behalf:

  • Railway — application hosting and our PostgreSQL database.
  • Cloudflare R2 — storage for your uploaded resume files.
  • Resend — delivery of transactional emails (verification, reminders).
  • Google — only if you choose “Sign in with Google” for authentication.

Cookies

We use only first-party cookies, and no advertising or cross-site tracking cookies:

  • An essential session cookie that keeps you signed in. It is HTTP-only and sent only over HTTPS in production.
  • A small preference cookie that remembers your chosen jobs view (table vs. board).

Your rights and controls

  • Export — download everything we store about you as a single file, anytime, from Settings.
  • Delete — delete your account from Settings. This permanently removes your data, including your resume files from storage. Deletion cannot be undone.
  • Email preferences — turn reminder emails off (or back on) from Settings. We'll still send essential account emails such as verification.

Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA (access, correction, portability, erasure). The export and delete tools above cover the core of these; contact us for anything else.

Data retention

We keep your data for as long as your account exists. When you delete your account, we remove your records and resume files. Routine backups and security logs may persist for a short period before being rotated out.

Security

Passwords are stored only as salted bcrypt hashes; email-verification tokens are stored hashed, never in plain text. Traffic is served over HTTPS, and resume files are accessed only through expiring signed links. No system is perfectly secure, but we aim to follow sensible, current practices.

Children

JobPivot is intended for adults in the workforce and is not directed at children under 16. We do not knowingly collect data from children.

Changes

We may update this policy as the product evolves. We'll revise the “last updated” date above and, for material changes, take reasonable steps to let you know.

Contact

Questions about your privacy? Email us at [email protected].