Privacy Policy
How JobEmbed collects, uses, and protects your personal data.
Effective date: 11 August 2026 · Last updated: 18 August 2026
What changed on 11 August 2026: reading a CV you upload is now switched ON. Our Article 28 terms with OpenAI, the only processor that receives CV text, are in place and include zero retention of what we send. §4, §5, §6 and §7 are updated from "built but not yet switched on" to what the service actually does. Nothing else about the handling changed: we still take four things per position, we still never store the file, and CV text still never reaches Langfuse.
Earlier, on 10 August 2026: the app's compute moved into the EU — the serverless functions that render JobEmbed now run in Frankfurt, where previously they ran in the United States while only the entry point was European. JobEmbed also began holding your work history — the employer, period, company description and achievements for each position. That notice also removed two providers it had named but did not use: Plausible Cloud (no analytics of any kind runs on the site) and n8n (retired on 5 August 2026 when the pipeline moved onto scheduled jobs).
1. About this notice
This Privacy Policy explains what personal data JobEmbed collects, why we collect it, how long we keep it, who we share it with, and the rights you have over your data. It applies to everyone who visits jobembed.co or uses our service.
If you don't want to read the whole document, the short version is: we collect the email address you sign up with, the search profiles you create, which jobs you save, and — if you give it to us — your work history. We use this to match jobs to you and to send you account-related email. If you upload a CV we read four things out of the file and throw the file away. We don't sell your data. You can delete your account at any time, which removes your data from our database — a profile picture you uploaded is deleted separately on request (see §9).
2. Data controller
The service is operated by:
Roman Kliukin, trading as JobEmbed, registered as a sole proprietor ("Преузетник") in the Republic of Serbia.
- Registered address: Kraljice Natalije 42, stan 5A, 11000 Beograd, Serbia
- Matični broj (registration number): 68164214
- ПИБ (tax ID): 115183888
For any matter related to your personal data or this Privacy Policy, contact: privacy@jobembed.co.
3. EU representative
JobEmbed is in the process of designating a representative within the European Union under Article 27 of the GDPR. The representative will be appointed within 30 days of public launch. We will update this section with the representative's name, address, and contact details once appointed.
In the meantime, data subjects in the EU can reach us directly at privacy@jobembed.co.
4. Personal data we collect
Provided by you
- Email address (when you sign up).
- Optional sign-in identity if you use Google OAuth (your Google email, name, and profile picture).
- Search profile content you create: free-text query (e.g. "Senior Product Manager"), selected countries, work-mode preferences (remote / hybrid / on-site), language requirements, and how recent a posting must be.
- Facts about you that you use as filters, where you choose to supply them: your years of experience, whether you hold a degree, and the languages you speak with your proficiency in each. These describe you rather than the job, and we hold them so we can filter results for you.
- Work history, if you choose to provide it: for each position you held, the employer, the period you worked there, a description of the company where you supply one, and your achievements. You can type these in yourself, or upload a CV in PDF and have us read them out of it.
- We never keep the file. An uploaded PDF exists only for the seconds it takes to read the text; it is not written to storage, not written to a temporary file, and not retained in any column. There is nothing to delete afterwards because there is nothing to delete.
- Those four things are all we take from the file. We do not extract your name, address, phone number, date of birth, photograph, education, skills list, languages or interests from a CV, even where the document contains them. This is a limit on what we read out, not a step that removes it afterwards. (Some of the same facts — degree, languages, years of experience — you may separately type in yourself as filters; see above.)
- You can edit or delete any position at any time, and deleting your account removes all of them.
- Action data: which jobs you save.
- Profile picture, if you upload one or if it arrives with your Google sign-in. It is held in a publicly-readable bucket: anyone who has the URL can open the image, and it is not protected by your login.
- Settings: your language preference.
- Waiting-list details, if you join the waiting list from our home page without creating an account: your email address and, optionally, the role you are looking for, in your own words. We use these only to invite you when we open access.
- Payment data if you subscribe. Subscriptions are not yet available. When they launch, card details will be entered on the payment provider's own hosted checkout page. We never receive or store a full card number — only the last four digits, a customer ID, and your subscription status.
Generated automatically
- Account metadata: account ID, trial-expiry timestamp, subscription status, email-deliverability status.
- Sign-in session records: IP address, browser user-agent, and timestamps for each sign-in. Kept for abuse prevention and security for as long as the session record exists — see §9, which says plainly that we do not currently expire them on a schedule.
- Pipeline logs: when a scrape is triggered on your behalf, the system records a
pipeline_runsrow tying the scrape snapshot to your account.
Not collected
- We don't keep your CV file. We read your work history out of it and discard the document — see §4 above for exactly which four things we take and what we leave behind.
- We don't collect your job-application content. JobEmbed surfaces matches; you apply on LinkedIn or wherever the posting points, and we never see what you send them.
- We don't track you across other websites.
- We don't use behavioural advertising cookies or third-party trackers.
- We don't run web analytics of any kind. No pageview counter, no session recording, no heatmaps.
5. Lawful bases for processing (GDPR Article 6)
| Activity | Lawful basis |
|---|---|
| Creating and operating your account | Contract (Article 6(1)(b)) |
| Sending account, security, and billing email | Contract / Legal obligation (Article 6(1)(b) / (c)) |
| Matching jobs to your search profile | Contract (Article 6(1)(b)) |
| Storing the work history you enter, and matching jobs against it | Contract (Article 6(1)(b)) |
| Reading your work history out of a CV you upload | Contract (Article 6(1)(b)) — you ask us to do it by uploading the file, and it is how the service you signed up for works |
| Holding your waiting-list email and the role you typed | Consent (Article 6(1)(a)) — you submit the form yourself, and can withdraw at any time |
| Anti-fraud, security logs, account lockout | Legitimate interest (Article 6(1)(f)) |
| Optional product email (digests, re-engagement — not active in v1) | Consent (Article 6(1)(a)) |
6. How we use it
- Show you jobs that match your search profile.
- Send authentication, password-reset, and billing email.
- Detect and prevent abuse (rate-limited signups, bounced-email handling).
- Calculate aggregate operational metrics (active accounts, conversion funnel, cost per user) — no individual profiling for marketing.
We do not use your data to train AI models.
Where AI is involved, and where it isn't. Two different things use a language model, and they are worth telling apart:
- Job and company descriptions — public text from the postings themselves. No JobEmbed user is identifiable in it. These calls are recorded in Langfuse (§7) for quality and cost monitoring.
- Reading a CV you upload — this one is your personal data. The text is sent to OpenAI to extract the four things listed in §4. OpenAI does not retain it and does not train on it, under the Article 28 terms in §7; we do not retain it either. These calls are deliberately not recorded in Langfuse, so no part of your work history reaches our observability provider. That is a property of the code, not a setting we remember to switch off.
Job matching itself is not done by a language model — it is ordinary filtering over the fields you chose.
7. Third-party processors
The service relies on the providers below. Each processes specific data on our instructions under a Data Processing Agreement or equivalent contractual terms. Our Article 28 terms with OpenAI — the only processor that receives CV text — are in place, and include zero retention of the content we send. Langfuse receives no CV data at all: those calls are excluded in code, not by configuration.
| Provider | Purpose | Data shared | Hosting region |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Email, account metadata, search profiles, saved jobs, work history, profile picture, billing records | EU (Ireland) |
| Vercel | Hosting for the web app | IP address, user-agent (request logs), and everything the app renders for you | EU (Frankfurt) — both the edge location that receives your request and the functions that render the app |
| LemonSqueezy (Merchant of Record — issues invoices in its name, collects + remits VAT, processes refunds) | Payment processing, subscription, VAT compliance | Email, payment method, billing address, subscription history | EU / US (Stripe sub-processor) |
| Bright Data | LinkedIn job-listing data collection | Search queries (no personal data) sent as scrape inputs. The webhook returns the employer's own published posting text, which sometimes carries the contact details — including a named work email address — of the person advertising the role. We neither add to that text nor strip it | Global |
| Resend | Transactional email delivery | Email address, message body | EU / US |
| Google (Google Ireland Ltd. / Google LLC) | Optional "Sign in with Google" | Your Google email address, name and profile picture, and your IP address at the moment of sign-in | EU / US (EU–US Data Privacy Framework) |
| OpenAI | (a) classifying public job- and company-description text; (b) reading the work history out of a CV you upload | For (a): public posting text only, no user identifiers. For (b): the text of your CV, sent once and not retained by us. No email address or account ID is sent in either case | US (EU–US Data Privacy Framework) |
| Langfuse (Langfuse GmbH) | LLM observability — records each LLM call (prompt, model, tokens, cost, latency) for quality + cost monitoring | Only the public job- / company-description calls, and that classifier is currently switched off — so in practice Langfuse receives nothing today. CV calls are excluded in code and never reach Langfuse | EU (Frankfurt) |
| Cloudflare | DNS, email forwarding, edge security | DNS queries, IP-level traffic patterns | Global |
Sub-processors used by these providers are listed in their respective privacy policies, linked from their public sites. In particular, Langfuse uses ClickHouse Cloud (managed ClickHouse, EU region) as its trace-storage sub-processor.
8. International data transfers
JobEmbed's primary data store is in the EU. Langfuse and its ClickHouse sub-processor host in the EU (Frankfurt). Some processors (OpenAI, Google, parts of LemonSqueezy, Cloudflare) operate in the United States or have global infrastructure. Transfers outside the EEA rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where the provider has executed them with us; and / or
- Adequacy decisions where applicable to the destination country.
You can request a copy of the safeguards in place for any specific provider by emailing privacy@jobembed.co.
9. Data retention
| Data | Retained for |
|---|---|
| Account, search profiles, saved jobs | Until you delete your account |
| Work history you entered or we read from your CV | Until you delete it, or until you delete your account — whichever comes first |
| The uploaded CV file itself | Not retained at all. It is read in memory during the upload request and never written anywhere |
| Billing records (invoices) | Invoices are issued and kept for 10 years by our Merchant of Record, as tax law in Serbia and the EU requires. The billing rows in our own database (customer ID, subscription status) are deleted together with your account |
| Sign-in session records (IP address, user-agent) | Kept while the session record exists. We do not currently expire them on a fixed schedule, and some records on our system are older than 30 days |
| Backups | 30 days rolling window |
| Email deliverability status (e.g. bounced flag) | Until you re-verify or delete the account |
| Profile picture | Until you replace or remove it. Deleting your account removes the database record but does not currently delete the stored image file — email privacy@jobembed.co and we will delete it |
| Waiting-list email and the role you typed | Until we send you a launch invitation, or until you ask us to remove it — whichever comes first |
Account deletion triggers cascading removal across search profiles, work-history entries, saved-job records, pipeline-run rows, and authentication identities. Two things it does not currently reach: a profile picture you uploaded, which we delete on request, and invoices held by the Merchant of Record, which tax law requires to be kept and which you can ask either of us for.
An empty cv_documents storage bucket remains from an earlier design of the CV feature. It holds no files, and no policy grants anyone permission to write to it.
10. Your rights
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar laws, you have the following rights over your personal data:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure ("right to be forgotten") — delete your data; in JobEmbed you can do this yourself from the settings page.
- Restriction of processing — pause specific uses of your data.
- Data portability — receive your data in a machine-readable format. There is no self-service export yet; email us and we will produce it.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — for activities based on consent (e.g. optional product email), withdraw it at any time.
- Lodge a complaint with a supervisory authority (in Serbia: Повереник за информације од јавног значаја и заштиту података о личности; in the EU: your national data-protection authority).
If you joined the waiting list but never created an account, you can still ask us to delete your entry — email privacy@jobembed.co. You do not need an account to ask.
To exercise any of these rights, email privacy@jobembed.co with enough detail for us to identify your account. We respond within 30 days, or sooner where the law requires.
11. Children
JobEmbed is for adults. We do not knowingly collect data from anyone under 16. If you believe a minor has signed up, email us and we will remove the account.
12. Cookies and local storage
JobEmbed uses the bare minimum of cookies and local storage:
- Authentication cookies set by Supabase to keep you signed in. Essential for the service ("strictly necessary" cookies under ePrivacy Article 5(3)); they are not subject to the consent banner and cannot be opted out without signing out.
jobembed_consent_v1inlocalStoragerecords that you have seen the transparency banner. The single stored value is"acknowledged". No personal data is stored alongside this flag. Clearing your browser's localStorage (or using private browsing) will make the banner appear again the next time you visit a public page; it is not shown inside the signed-in dashboard.auth_last_methodinlocalStorageremembers how you last signed in, so the sign-in page can put that option first. If you signed in with an email and password, your email address is stored in it, on your own device, for 30 days. It is never sent to us as part of this record — your browser already sends it when you sign in — and clearing your browser storage removes it.- Preference cookies:
NEXT_LOCALEandlang(which language to show you),theme(light or dark), andsidebar_state(whether the dashboard sidebar is collapsed). All first-party, none personal, none used for tracking — they only remember display choices.NEXT_LOCALEis set on your very first visit, before you sign in, so the site can serve your language. - No advertising cookies, no cross-site tracking, no fingerprinting libraries.
There is no analytics script on the site at all — not a cookieless one, not a self-hosted one, none. Nothing counts your pageviews. The banner is therefore a transparency notice about the authentication cookie rather than a consent prompt.
If JobEmbed introduces tracking cookies in a future release (v2), a new jobembed_consent_v2 banner will offer Accept / Reject choices, and a Manage cookie preferences link will be added to the site footer so you can change your selection at any time.
13. Security
- All traffic to and from jobembed.co is encrypted with TLS.
- Database access is restricted by Supabase Row-Level Security so each user only sees their own data. Those policies are covered by an automated cross-tenant test suite that runs on every change.
- Passwords are hashed via Supabase Auth (industry-standard bcrypt-class function); we never see your plaintext password.
- We never see or store your card details: they are entered on the payment provider's own hosted checkout. Our database has no field for card data — the provider's notifications tell us only your subscription status and customer ID.
- We don't claim to be unhackable. If you suspect a security issue, email privacy@jobembed.co; we'll respond and, where required, notify the supervisory authority within 72 hours per Article 33.
14. Changes to this notice
When we make material changes, we update the Effective date at the top and notify active account holders by email at least 30 days before the change takes effect (unless the change is required immediately by law). Minor edits — typos, clarifications, additional examples — update the Last updated date only.
A history of past versions is available on request.
15. Contact
For any question or request about this Privacy Policy or your personal data:
privacy@jobembed.co
Postal address (for formal correspondence): Roman Kliukin / JobEmbed, Kraljice Natalije 42, stan 5A, 11000 Beograd, Serbia.