Legal
Privacy Policy
Last updated: 4 September 2026
This policy explains how JustAJob (“we”, “us”, “our”) collects, uses, shares and protects personal data when you use justajob.net and our services (the “Service”), and the rights available under the UK GDPR and the Data Protection Act 2018.
1. Who we are
JustAJob provides the Service and is responsible for the personal data described in this policy. For privacy questions or requests, email support@justajob.net.
2. Personal data we collect
Depending on the features you use, we collect the following:
- Account and authentication data. Your name, email address, password hash, email-verification status, single-use verification or password-reset tokens, and session identifiers. We do not store your password in readable form.
- Job activity. Jobs you save or track, application status and dates, and saved searches or alerts including keywords, location, region and frequency.
- CV and career content. CV text you upload, paste or save, and job adverts, application questions, target roles and other text you provide to career tools.
- AI feature data. Inputs and generated results for CV analysis, job matching, cover letters, application answers, LinkedIn profile optimisation, public-profile drafting and mock interviews. Mock-interview sessions store the target role, optional job context, questions, your answers, scores and feedback. We also keep usage counters and any account-level allowance adjustment used to operate fair-use limits.
- Public-profile data. If you create a shareable profile, we store its URL slug, name, headline, summary, skills, highlights, optional contact text and any saved CV you choose to offer as a public PDF. Profiles start as drafts and become public only when you publish them.
- Enquiries, feedback and reports. Employer enquiries include the company, contact name, work email, signed-in account email, role or careers link, message, status and any related payment reference. Feedback and support messages may include your account details, reply email and message. Job reports may contain listing details, your reason and details, and an optional reporter email.
- Payments. If paid services are offered, we store subscription status and identifiers needed to manage billing. Stripe handles card and payment details; we do not receive or store your full card number.
- Technical, security and analytics data. IP address and basic request data used for security, rate-limiting and abuse prevention; an approximate region inferred from network or content-delivery headers; and, when enabled, cookie-free visit and page-view measurements from Cloudflare Web Analytics. Our own traffic ledger contains aggregate daily counts rather than user profiles.
- Cookies and browser storage. Essential and functional cookies, on-device preferences and short-lived, account-scoped tab storage. Our Cookie Policy lists each item, its purpose and retention.
3. How and why we use personal data
We use personal data for the purposes and lawful bases below:
- Account and requested services. We create and secure accounts, provide job tracking, alerts, stored CVs, career tools, mock interviews and profiles, and manage subscriptions because this is necessary to perform our contract with you or take steps at your request before entering one.
- Employer enquiries and listings. We assess enquiries, verify the sender, communicate about a listing, issue payment requests and administer agreed listings to take pre-contract steps or perform a contract, and for our legitimate interests in operating a trustworthy job board and preventing scams.
- Service communications. We send verification and reset emails, alerts you request, billing notices and replies needed to provide the Service under our contract. We handle feedback and support correspondence for our legitimate interests in supporting users and improving the Service.
- Security and measurement. We rate-limit requests, investigate abuse, protect accounts and measure aggregate site performance for our legitimate interests in keeping the Service secure, reliable and useful.
- Legal and financial administration. We process records where necessary to comply with legal obligations and to establish, exercise or defend legal claims.
Some information is required to provide a feature. For example, we cannot create an account without an email address, generate tailored feedback without the text to analyse, or answer an employer enquiry without contact details. Optional fields are marked as such.
4. Sensitive information
CVs, interview answers, LinkedIn text and free-text messages can reveal special-category data such as health, ethnicity, religion, political views, trade-union membership or sexual orientation. Our career tools do not need this information. Please remove it before uploading, saving or sending content to an AI feature, and do not provide criminal-offence information. We do not use career content to infer sensitive characteristics or make decisions about your employment.
If you accidentally include sensitive information, remove it from your saved content where possible or contact support@justajob.net for help with a deletion request.
5. AI features
AI-assisted CV, application, LinkedIn, public-profile and mock-interview features send the text needed for the request to the configured provider, OpenAI or Anthropic. Inputs are length-limited. We do not use submitted content to train our own models. Under the providers’ standard commercial API terms, API inputs and outputs are not used to train their models by default; they may retain content for a limited period for safety, abuse prevention or legal compliance. Provider terms and any enhanced retention controls can change, so contact us if you need details of the configuration applying to your request.
Some generated results are kept only in short-lived storage in your browser. We store your five most recent completed mock interviews, automatically replacing older ones, and keep any public-profile draft you save until account deletion. AI output is assistive, may be inaccurate, and does not make hiring or other decisions with legal or similarly significant effects about you.
6. Who receives personal data
We do not sell personal data or share it for third-party advertising. We use providers to operate the Service, subject to their roles and contractual terms:
- Hosting, database, security and analytics — Neon and Cloudflare.
- Email — Resend, for account and service messages, alerts, feedback and enquiry notifications.
- Payments — Stripe, which processes payment information under its own privacy terms and provides us with billing and subscription records.
- AI processing — OpenAI or Anthropic, as described in section 5.
- Job search providers — providers such as Adzuna, Reed, Jooble, JSearch and Careerjet, and services used to retrieve public career-site listings. Search parameters such as keywords and location may be sent from our server, but we do not send your account identity with them.
Content you deliberately publish on a public profile can be viewed, copied or indexed by anyone, including search engines. If you provide a public CV download, visitors can retain copies after you unpublish the page. Information agreed for a job listing may also be published on the board. We may disclose information where required by law or where necessary to protect legal rights, users or the public.
7. International transfers
Some providers process data outside the UK, including in the United States or European Economic Area. Where UK personal data is transferred internationally, the transfer must be covered by an applicable UK adequacy regulation or appropriate contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum. Contact us if you would like more information about the safeguard relevant to a provider.
8. Retention
- Pending accounts and authentication. Verification and reset links expire after 30 minutes. Never-verified sign-ups are scheduled for deletion after 48 hours. Sessions expire after seven days without activity and always within 30 days of sign-in.
- Account content. Account details, applications, CVs, saved searches, public-profile drafts and subscription records remain while the account is active unless you delete or replace them sooner. We keep the five most recent completed interviews and remove older ones as new sessions are saved. Unpublishing a profile removes public access but does not delete its draft.
- AI and security counters. Short-window rate-limit records are pruned after their operational window; daily and monthly AI usage records are generally pruned within about 60 days. A manually granted allowance remains until removed or account deletion.
- Enquiries, feedback and reports. Employer enquiries remain in the admin queue until an authorised administrator deletes them. Support and feedback messages remain in our email system for as long as needed to respond, maintain a useful support history or handle a dispute. Job-report records may remain after account deletion, but the reporter email is anonymised by the account-deletion flow.
- Billing and legal records. We and Stripe retain transaction, tax and dispute records for the periods required by law and legitimate financial administration.
Under standard API settings, OpenAI and Anthropic may retain AI inputs and outputs for up to 30 days, subject to exceptions in their terms. When a record is no longer needed, we delete or anonymise it unless a legal obligation or live claim requires longer retention.
9. Your rights and account controls
Depending on the circumstances, UK data-protection law gives you rights to:
- request access to personal data and information about how it is used;
- correct inaccurate or incomplete data;
- request erasure or restriction;
- object to processing based on legitimate interests;
- receive certain data in a portable format;
- withdraw consent where consent is the lawful basis; and
- challenge qualifying solely automated decisions.
Download my data provides a structured JSON export of application-database records associated with your account ID or verified email. It covers your account, applications, stored CVs, saved searches, subscription record, AI usage and allowance, mock-interview history and answers, public profile, job reports, employer enquiries and any delegated administrative permissions. Password hashes, session identifiers and authentication tokens are excluded for security. Support and feedback correspondence is held in our email system, so contact support@justajob.net if you need a formal access request covering those messages or want to exercise another right. Short-lived drafts, results and preferences stored only in your browser are not available to the export endpoint; use Clear device data in your account to remove them.
Delete account removes the account and user-ID-linked applications, CVs, searches, subscriptions, sessions, AI usage and allowances, interview history and public profile. It also removes authentication tokens and anonymises the reporter email on job reports. It does not automatically erase employer enquiries or support and feedback emails associated only by email address, or records independently held by providers such as Stripe. Ask us to review those records as part of an erasure request; legal, billing, fraud-prevention or dispute records may need to be retained.
If you are unhappy with our response, you can complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address the issue first.
10. Security
Measures include HTTPS, one-way password hashing, email verification, purpose-limited and expiring reset tokens, hashed server-side session identifiers, httpOnly secure session cookies, rate-limiting, bot protection and role-based administrative access. No system can guarantee absolute security; please use a unique password and tell us promptly if you suspect unauthorised account use.
11. Children
The Service is intended for people aged 16 and over and is not directed at children. We do not knowingly collect data from children under 16. Contact us if you believe a child has provided personal data.
12. Other websites
Applying for a role usually takes you to an employer or job-board website with its own terms and privacy practices. We do not control those sites, so review their notices before providing personal data.
13. Changes
We may update this policy as the Service or legal requirements change. We will update the “Last updated” date and, where a change materially affects how we use personal data, provide an appropriate additional notice.
14. Contact
For privacy questions or rights requests, email support@justajob.net.