JobHunt Privacy Policy
1. Controller
The joint controllers of personal data (Art. 26 GDPR) are:
- Emil Grużalski, running a business under the name Emil Grużalski IT Services, address: ul. Warszawska 25 lok. 201, 85-058 Bydgoszcz, Poland, tax ID (NIP): 9532821831, REGON: 545828352,
- Kazimierz Daszkiewicz, running a business under the name Kazimierz Daszkiewicz, address: ul. Pytlasińskiego 16 lok. 13, 00-777 Warszawa, Poland, tax ID (NIP): 7393996275, REGON: 527800468
(together the “Controller”). The joint controllers determine together the purposes and means of processing data in the Service. The essence of their arrangement: they do not divide duties between them – each of them fully handles your requests, provides information about the processing, reports personal data breaches and deals with the supervisory authority. You can exercise your rights against each of them. Contact in data protection matters: [email protected].
2. What data we process
| Data | Source |
|---|---|
| E-mail address | you provide it when creating the Account and signing in; the Controller provides it when inviting you to the closed version of the Service or creating a test account for you |
| Password – only as a cryptographic hash (Argon2id), from which it cannot be read | you set it when creating the Account or changing the password; for a test account the Service generates it |
| Google account identifier | from Google, if you sign in with Google |
| Content you save: job offers, notes, tags, statuses and their history, dates | from you |
| Posts and votes on the ideas board | from you |
| Job pages sent by the browser extension, and the name and usage dates of the connected browser | from the JobHunt extension, when you use it |
| Date and version of the accepted Terms | from the sign-in process |
| Technical data: IP address, session information | from your browser |
| Invitation to the closed version of the Service: the e-mail address, the date of the invitation and who invited | from the Controller |
| Date of the last activity on the Account (to the hour) and of any block on the Account | from your use of the Service |
| Billing data (Paid Plan) | from you and from the payment provider – only once the Paid Plan is launched; at present the Service takes no payments and collects no such data |
3. Purposes and legal bases
- Providing the service – running the Account, signing in, storing your content, providing a copy of your data (Art. 6(1)(b) GDPR – contract).
- Legal obligations – tax and accounting for the Paid Plan, handling complaints (Art. 6(1)(c) GDPR).
- Security and abuse prevention – limits on sign-in attempts, requests and the amount of data per Account, checking that you are not a bot when signing in or creating the Account (Cloudflare Turnstile), checking that a new password does not appear in known data breaches, notifying you by e-mail when the password changes, detecting attacks, establishing and pursuing claims (Art. 6(1)(f) GDPR – the Controller's legitimate interest).
- Running the Service – aggregate usage statistics, handling reports and blocking Accounts that breach the Terms. For this, persons authorised by the Controller see the e-mail address, the dates the Account was created and last active, the sign-in method, the version of the accepted Terms and the number and size of saved offers – not their content, notes or history (Art. 6(1)(f) GDPR – the Controller's legitimate interest).
- Closed version of the Service and test accounts – while sign-up is by invitation only, we keep a list of invited e-mail addresses and check it at every sign-in and use of the Service; an invitation may concern a person who does not have an Account yet. The Controller may also create a test account, e.g. for a person reviewing the browser extension in an add-on store: the Service then generates a password, which the Controller passes on to that person, and that person accepts the Terms themselves at the first sign-in (Art. 6(1)(f) GDPR – the Controller's legitimate interest in opening and testing the Service gradually).
- Ideas board – publishing your posts and votes and letting you delete your own posts (Art. 6(1)(b) GDPR), and developing the Service based on the ideas submitted (Art. 6(1)(f) GDPR).
- Reminders by e-mail – if you turn them on in the Account menu → Reminders, at most once a week we send to your address a list of the applications that have had no update for a while (job title, company, number of days). You can turn them off at any time – in the settings or with the link in every such e-mail (Art. 6(1)(b) GDPR – a function of the service that you switch on yourself).
- Connecting an AI assistant – if you connect one (for example Claude) in the Account menu → AI assistant, then at your request we give it access to the data of your Account within the scope you choose: reading, or also adding and changing (never deleting). We record the connection (the assistant's name, the scope, the dates of use) until you disconnect it. The assistant's provider processes what the assistant reads under its own terms and your own agreement with it; it is not our processor and we do not control it (Art. 6(1)(b) GDPR – a function of the service that you switch on yourself).
- Proof of accepting the Terms – recording the version and date of acceptance (Art. 6(1)(b) and (f) GDPR).
Providing your e-mail address is voluntary, but an Account cannot be created without it. We do not make decisions about you based solely on automated processing, including profiling. We do not use your content for marketing and we do not sell data.
4. How long we keep data
- Account data and your content – until the Account is deleted. Deletion is immediate; in backups the data remains for at most 30 days (copies on the server – 7 days, encrypted copies kept outside the server – 30 days).
- Sign-in session – 30 days from last use, at most 90 days from signing in (you can sign out on all devices earlier in the Account menu); one-time links to set the password – up to 24 hours after they expire (they are valid for 60 minutes).
- Dates of reminder e-mails sent and the hashes of their turn-off links – 60 days.
- A connected AI assistant – until you disconnect it, and in any case at most 180 days from the connection (then it has to be connected again); authorization codes – 5 minutes.
- Password hash – until the password is changed or the Account is deleted.
- Invitation to the closed version of the Service – 7 days if you do not create an Account in that time; once you have created one – until the Account is deleted (the invitation is removed at most an hour after the Account is deleted, or, if 7 days have not yet passed since the invitation, an hour after they do). The Controller may remove it earlier, also at your request.
- Billing data – for the period required by tax law (as a rule 5 years from the end of the tax year).
- Data needed to pursue claims – until the limitation period expires.
5. Who processes data on our behalf
We use providers that process data on our behalf under data processing agreements:
| Provider | Role | Location |
|---|---|---|
| UW-TEAM.ORG Jakub Mrugalski (the Mikrus service) | server and database | Finland (Hetzner data centre in Helsinki) |
| Cloudflare, Inc. | connection to the Service (proxy, protection against attacks); bot check at sign-in and sign-up (Turnstile), when it is turned on | EU / USA – transfers to the USA under the EU-US Data Privacy Framework and standard contractual clauses |
| Cloudflare, Inc. (the R2 service) | storing encrypted database backups (without the key to read them) | EU (data kept in the EU jurisdiction of R2) |
| Resend, Inc. | sending e-mails with links to set the password, notices of password changes and reminders, if you turn them on | USA – transfers under the EU-US Data Privacy Framework and standard contractual clauses |
The Service takes no payments at present and uses no payment provider. Before the Paid Plan is launched we will add the payment provider to this list and tell you about it as described in section 11.
If you sign in with Google, Google Ireland Limited processes your data as a separate controller under its own privacy policy. Data may also be disclosed to public authorities when the law requires it.
Data is transferred outside the European Economic Area only on the basis of a European Commission adequacy decision (e.g. the EU-US Data Privacy Framework) or standard contractual clauses.
6. Job offer pages
When you add an offer by link, our server fetches that page from the portal – the portal then sees our server's address, not yours. When you paste a page source, we read it in your browser and save only the offer data you confirm.
6a. Browser extension
The JobHunt extension only acts when you click its icon. It then reads the content (HTML) of the page open in the active tab and recognises the offer on your computer. What reaches your account is the offer data you confirm with “Save to JobHunt”, or – if you choose “Review in JobHunt” – the whole page, for review in the Service. It does not read other tabs or your browsing history and does not run in the background. The page waits for your review in the Service and is deleted as soon as you save the offer or close the add dialog, and at the latest after 24 hours. To mark saved offers on every device, the extension fetches from the Service, every minute, cryptographic hashes (SHA-256) of the addresses of your saved offers – not the addresses or any other offer data – and keeps them in the browser. On job portals (listed in the extension) it sees the address of the open tab and compares its hash with them only locally; it does not read those pages without your click and does not send the addresses you visit. The extension is linked to your Account with a separate token that can only add offers, send pages and fetch those address hashes – with no access to the content of saved offers, notes or statuses; you can disconnect browsers in the Service (Account menu → “Browser extension”) or in the extension itself.
7. Ideas board
Posts on the ideas board are visible to all signed-in Users, but without any information about who wrote them – the Service shows neither the author nor the voters. In the database a post and a vote are linked to your Account: this lets you delete your own post, and deleting your Account also deletes your posts and votes. The Controller has technical access to this link and does not use it for any purpose other than running the Service and preventing abuse. Do not put personal data on the board.
8. Your rights
You have the right to: access your data, rectify it, erase it, restrict its processing, port it (download a copy of your data in JSON from the Account menu → “Download my data”; downloads are limited to a few per hour), object to processing based on legitimate interest, and lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa, Poland). You can delete your Account and all its data yourself in the Service (Account menu → “Delete account”).
9. Cookies and browser storage
The Service only uses cookies that are necessary for the service or that remember settings you ask for – these do not require consent:
__Host-session– keeps you signed in (up to 30 days from last use, at most 90 days),__Host-g_state,__Host-g_verifier– secure Google sign-in (10 minutes),lang– the chosen interface language, so sign-in pages and e-mails use the same language (1 year).
In browser storage (localStorage) we keep only your view settings: language, list or board view, collapsed columns and filter visibility. They are not sent to the server.
When the sign-in or sign-up form shows the Cloudflare Turnstile check, its script loads from Cloudflare's servers, and Cloudflare processes technical data about the browser and the connection (including the IP address) to tell people from bots.
We use no analytics or advertising cookies.
10. Security
The connection to the Service is encrypted (HTTPS). Each Account's data is separated from other accounts at the database level. Passwords are stored only as Argon2id hashes with a separate random salt for each – we do not know them and cannot read them. A new password is checked against the Have I Been Pwned breach list using k-anonymity: only the first 5 characters of the password's SHA-1 hash reach the service – never the password itself or your e-mail address. Links to set the password and session tokens are stored only as cryptographic hashes. Backups kept outside the server are encrypted before they leave it.
11. Changes to this policy
We will inform you of material changes by e-mail in advance. The current version is always available at this address.