JobVerdict

Privacy Policy

Last updated: July 2026

Plain-English note: this page describes what the product actually does — it was written against the code, not copied from a template. It has not been reviewed by a lawyer, and we make no claim here about compliance with any particular privacy law. If something on this page does not match what you observe, that is a bug: tell us and we will fix the code or the page.

What we collect

Your email address and password hash (for your account); the CV text and profile details you provide; the job descriptions you paste; and the evaluations, tailored CVs, and cover letters generated for you. We also keep minimal usage records (which features you ran, token counts) to enforce plan limits.

If you sign in with Google or LinkedIn, we receive only your name and email address from the provider — never your contacts, posts, or work history. We do not collect or store a profile picture. We do not access anything else on your Google or LinkedIn account.

Email we send

Two kinds. Account emails (password resets, payment confirmations) are always on. Product emails — a welcome note, an optional daily digest of new Job Radar matches, a heads-up before a Pro pass ends, and the occasional personal note if we spot a problem with your account — are capped at one per day, and every one carries a one-click unsubscribe link that stops all of them permanently. We never share your address, and we never send marketing on behalf of anyone else.

Job Radar

Job Radar matches you against a shared pool of publicly listed job postings that we collect from company career sites, public job boards, and recruitment agencies. We store only what those sources publish openly (title, company, location, link, short excerpt) and always link back to the original posting. Your Radar preferences (countries, keywords) are stored with your account. If you enable auto-prep, your CV is evaluated by our AI provider against top-matching postings automatically, under the same rules as manual evaluations. Job Radar never applies to a job on your behalf.

How it’s used

Your CV and job descriptions are sent to our AI provider (Anthropic) solely to generate your evaluations and documents. We do not sell your data, we do not use it to train models, and we do not share it with anyone except the processors needed to run the service (AI provider, hosting, payment provider). Product analytics are first-party only: we record which features are used in our own database to improve the service, and we use no third-party trackers, advertising pixels, or analytics scripts.

Payments

Card payments are processed by Ziina (licensed by the Central Bank of the UAE) on their hosted payment page; we never see or store your card details. We keep only the payment reference, amount, and status to activate your plan. Ziina’s privacy policy applies to the checkout itself.

Your controls

Two buttons on your account page, both self-service.

Export. Downloads a single JSON file containing your account record (email, plan, pass expiry, email preference, sign-in method, role, signup date), your profile and CV text, every evaluation with its receipts, tailored CVs, cover letters and outreach kits, your application status history, your Job Radar preferences and matches (with the postings they matched), your payment records, your connected sign-in accounts, your sign-in session dates, your feature-usage records, the first-party analytics events recorded for you, any email we queued or sent you, and any internal fault notes about your account. Credentials are deliberately excluded: your password hash, your session tokens, and any password-reset or email-verification tokens are never exported — putting a live credential in a downloadable file would be a self-inflicted breach. The file lists its own contents, so you can see exactly what is and is not in it. Limit: 5 downloads per day.

Deletion. Deleting your account removes, in one database transaction: the account row itself, your profile and CV, every evaluation and generated document, your application status history, your Radar preferences and matches, your payment records, your usage records, your connected sign-in accounts, all sign-in sessions, and any password-reset or email-verification tokens. It takes effect immediately and cannot be undone.

Two things are deliberately noterased, and we would rather say so than let you find out later. First, product-analytics events: we keep the row but strip your user identifier, your IP address and the event’s details blob from it, leaving only what the event was and when — so the aggregate count of “how many people ran an evaluation last Tuesday” survives with nothing attached to you. Second, an email we already sent you: the record that a message went out stays, with your address removed from it. Queued emails that were never sent are deleted outright. Internal fault notes about your account are deleted outright, and any other note that happened to mention your email address has that address scrubbed. After deletion, no remaining row carries your name, your email address, your account identifier, or your IP address.

Deletion is a one-way door and we do not keep a backup copy of your account for you. If you want your evaluations, export them first.

How long we keep things

  • Your account content — profile, CV, evaluations, documents, Radar matches, application history, usage and analytics records: kept until you delete your account. There is no automatic expiry, because a job search that spans two years is a normal job search.
  • Sign-in sessions — expire 30 days after sign-in. Expired sessions are deleted automatically by a routine that runs in the background.
  • Password-reset tokens — valid for 1 hour; email-verification tokens — valid for 24 hours. Both are stored hashed, are single-use, and are deleted automatically once expired.
  • Anonymised analytics events — kept indefinitely, with no identifier attached (see above).
  • Payment records held by Ziina — governed by Ziina’s own retention policy, not ours. Deleting your account removes our copy of the payment reference; it cannot remove theirs.
  • Anti-abuse records — if an IP address floods our password-reset or free ghost-check endpoints, we record a note about that address, not about an account. Those notes are not tied to any user and therefore are not removed when an account is deleted; they hold an IP address, a count, and a timestamp, and nothing else.
  • Job postings — the shared pool of publicly listed postings is not personal data and is not deleted with an account.

Contact

Questions or requests: FIRASFMOHAMMED@outlook.com