Privacy
We collect very little, and we designed the site that way on purpose.
Last updated
Your CV never leaves your device
When you use the CV matcher, your file is read inside your own browser. It is not uploaded, not stored, and never reaches our servers. What we receive is a short list of derived tags — skills, education level, years of experience, languages — and only when you ask for a match. We keep no copy of the file, so there is nothing for us to lose, leak, or hand over.
What we collect
If you create an account: your email address, and either a password or a link to your Google account, depending on how you chose to sign in. A password is stored only as a scrypt hash — we cannot read it, and neither can anyone who obtains the database. If you sign in with Google, Google tells us your address, that it has verified it, and the name and profile picture on that account; we store a reference to it so the same button works next time. You also get a username, which is a handle for support and nothing more: there is no directory and no way for one reader to look up another. We know how many sessions are open on your account and when each expires, and nothing else about them — no IP address and no browser is recorded against any sign-in. That is why your account page offers to sign out everywhere rather than showing you a list of devices: we genuinely cannot tell you which is which. If you save opportunities: the list of what you saved. If you ask for deadline reminders: that you asked, and how often. If you use the matcher and choose to save your profile: the derived tags described above. Nothing else is required to use the site. To slow down repeated failed sign-ins to an account, we keep a keyed fingerprint of the address that was tried and a count — not the address, not where it came from, and not the browser. The one place we do record a network address, roughly where it is, and the reported browser is a failed attempt on our own staff area. That is a security record at our own door, not something reading the site creates: ordinary visits are never recorded this way.
How long we keep it
A link to confirm your address or reset your password expires in one hour. A signed-in session expires on its own, and you can end every one of them at any time from your account page. The fingerprints behind the sign-in throttle are deleted as soon as their window lapses, so they do not accumulate into a record of who has ever signed in. Derived CV tags are deleted after 90 days without activity, and immediately if you did not ask us to save them. Saved opportunities are removed 30 days after their deadline. If an account is unused for 12 months we email you, and delete it 30 days later if you still have not signed in. Records of failed sign-in attempts on our staff area are deleted 30 days after the last one.
Cookies
We use a small number of cookies that are necessary for the site to work, such as keeping you signed in and remembering your language. Advertising cookies are only set if you agree to them, and you can change your answer at any time. Declining costs you nothing — the site works the same.
Who else handles your data
Cloudflare hosts the site, stores our database, and records technical errors so we can fix them. Resend sends our emails. If you choose to sign in with Google, Google handles that sign-in and knows you used it here — if you would rather they did not, use an email address and a password instead, which works exactly as well. When payments are available, Paddle will handle international cards and Flutterwave mobile money. Each of these receives only what it needs to do its job.
If you are in Rwanda
We process personal data under Law No. 058/2021 on the protection of personal data and privacy. You have the right to see what we hold about you, to correct it, to have it deleted, to object to how we use it, and to complain to the supervisory authority. Our registration reference will be published here once the operating entity is registered.
If you are in the EU or UK
You have equivalent rights under the GDPR: access, rectification, erasure, restriction, portability, and objection. You can complain to your national data protection authority.
How to exercise your rights
Most of it you can do yourself, without asking us and without waiting. Your account page shows everything we hold about you, lets you download it as a file, sign out every device, and delete the account outright. For anything that page does not cover, write to legal@seeajar.com from the email address on your account and tell us what you want. We will answer within 30 days. We will never charge you for this.