← JobHunt

JobHunt Privacy Policy

Version: 2026-10-10 · effective from: 10 October 2026

Wersja polska – this is a translation; in case of any discrepancy the Polish version prevails.

1. Controller

The joint controllers of personal data (Art. 26 GDPR) are:

(together the “Controller”). The joint controllers determine together the purposes and means of processing data in the Service. The essence of their arrangement: they do not divide duties between them – each of them fully handles your requests, provides information about the processing, reports personal data breaches and deals with the supervisory authority. You can exercise your rights against each of them. Contact in data protection matters: [email protected].

2. What data we process

DataSource
E-mail addressyou provide it when creating the Account and signing in; the Controller provides it when inviting you to the closed version of the Service or creating a test account for you
Password – only as a cryptographic hash (Argon2id), from which it cannot be readyou set it when creating the Account or changing the password; for a test account the Service generates it
Google account identifierfrom Google, if you sign in with Google
Content you save: job offers, notes, tags, statuses and their history, datesfrom you
Posts and votes on the ideas boardfrom you
Job pages sent by the browser extension, and the name and usage dates of the connected browserfrom the JobHunt extension, when you use it
Date and version of the accepted Termsfrom the sign-in process
Technical data: IP address, session informationfrom your browser
Invitation to the closed version of the Service: the e-mail address, the date of the invitation and who invitedfrom the Controller
Date of the last activity on the Account (to the hour) and of any block on the Accountfrom your use of the Service
Billing data (Paid Plan)from you and from the payment provider – only once the Paid Plan is launched; at present the Service takes no payments and collects no such data

3. Purposes and legal bases

Providing your e-mail address is voluntary, but an Account cannot be created without it. We do not make decisions about you based solely on automated processing, including profiling. We do not use your content for marketing and we do not sell data.

4. How long we keep data

5. Who processes data on our behalf

We use providers that process data on our behalf under data processing agreements:

ProviderRoleLocation
UW-TEAM.ORG Jakub Mrugalski (the Mikrus service)server and databaseFinland (Hetzner data centre in Helsinki)
Cloudflare, Inc.connection to the Service (proxy, protection against attacks); bot check at sign-in and sign-up (Turnstile), when it is turned onEU / USA – transfers to the USA under the EU-US Data Privacy Framework and standard contractual clauses
Cloudflare, Inc. (the R2 service)storing encrypted database backups (without the key to read them)EU (data kept in the EU jurisdiction of R2)
Resend, Inc.sending e-mails with links to set the password, notices of password changes and reminders, if you turn them onUSA – transfers under the EU-US Data Privacy Framework and standard contractual clauses

The Service takes no payments at present and uses no payment provider. Before the Paid Plan is launched we will add the payment provider to this list and tell you about it as described in section 11.

If you sign in with Google, Google Ireland Limited processes your data as a separate controller under its own privacy policy. Data may also be disclosed to public authorities when the law requires it.

Data is transferred outside the European Economic Area only on the basis of a European Commission adequacy decision (e.g. the EU-US Data Privacy Framework) or standard contractual clauses.

6. Job offer pages

When you add an offer by link, our server fetches that page from the portal – the portal then sees our server's address, not yours. When you paste a page source, we read it in your browser and save only the offer data you confirm.

6a. Browser extension

The JobHunt extension only acts when you click its icon. It then reads the content (HTML) of the page open in the active tab and recognises the offer on your computer. What reaches your account is the offer data you confirm with “Save to JobHunt”, or – if you choose “Review in JobHunt” – the whole page, for review in the Service. It does not read other tabs or your browsing history and does not run in the background. The page waits for your review in the Service and is deleted as soon as you save the offer or close the add dialog, and at the latest after 24 hours. To mark saved offers on every device, the extension fetches from the Service, every minute, cryptographic hashes (SHA-256) of the addresses of your saved offers – not the addresses or any other offer data – and keeps them in the browser. On job portals (listed in the extension) it sees the address of the open tab and compares its hash with them only locally; it does not read those pages without your click and does not send the addresses you visit. The extension is linked to your Account with a separate token that can only add offers, send pages and fetch those address hashes – with no access to the content of saved offers, notes or statuses; you can disconnect browsers in the Service (Account menu → “Browser extension”) or in the extension itself.

7. Ideas board

Posts on the ideas board are visible to all signed-in Users, but without any information about who wrote them – the Service shows neither the author nor the voters. In the database a post and a vote are linked to your Account: this lets you delete your own post, and deleting your Account also deletes your posts and votes. The Controller has technical access to this link and does not use it for any purpose other than running the Service and preventing abuse. Do not put personal data on the board.

8. Your rights

You have the right to: access your data, rectify it, erase it, restrict its processing, port it (download a copy of your data in JSON from the Account menu → “Download my data”; downloads are limited to a few per hour), object to processing based on legitimate interest, and lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa, Poland). You can delete your Account and all its data yourself in the Service (Account menu → “Delete account”).

9. Cookies and browser storage

The Service only uses cookies that are necessary for the service or that remember settings you ask for – these do not require consent:

In browser storage (localStorage) we keep only your view settings: language, list or board view, collapsed columns and filter visibility. They are not sent to the server.

When the sign-in or sign-up form shows the Cloudflare Turnstile check, its script loads from Cloudflare's servers, and Cloudflare processes technical data about the browser and the connection (including the IP address) to tell people from bots.

We use no analytics or advertising cookies.

10. Security

The connection to the Service is encrypted (HTTPS). Each Account's data is separated from other accounts at the database level. Passwords are stored only as Argon2id hashes with a separate random salt for each – we do not know them and cannot read them. A new password is checked against the Have I Been Pwned breach list using k-anonymity: only the first 5 characters of the password's SHA-1 hash reach the service – never the password itself or your e-mail address. Links to set the password and session tokens are stored only as cryptographic hashes. Backups kept outside the server are encrypted before they leave it.

11. Changes to this policy

We will inform you of material changes by e-mail in advance. The current version is always available at this address.