GiveMeTheJob privacy

Privacy

Last updated: 30 September 2026

You can use the basic workspace without an account. In that case, your profile stays in this browser. Information is sent to another service only when a feature you choose needs it.

Purposes and legal bases

  • Career profile, drafts and CV compositions: we use information you enter or import to create, edit, save and retrieve your career profile and CVs. Local-only information stays in your browser; if you sign in, profile and CV data can be synced to Supabase. Legal basis: GDPR Article 6(1)(b), to provide the service you request or take steps at your request before providing it.
  • CV import: the PDF is read in your browser. Extracted text and layout are checked for personal details and the remaining content is sent to OpenRouter to structure the CV. The original PDF is not sent. Detection is automated and may miss personal details. Legal basis: GDPR Article 6(1)(b), to provide the import feature you request.
  • Job analysis: when you submit a job link or text, our server may fetch the public job page. The job description and relevant project descriptions and skills from your profile are sent to OpenRouter to produce a match. The job site receives a request from our hosting provider and may process its request metadata under its own terms. Job matching is an assistive recommendation about relevance, not an automated hiring decision. Legal basis: GDPR Article 6(1)(b), to provide the analysis you request.
  • Sign-in: Supabase and Google process account and authentication data, such as your email address, name and profile image, so you can sign in and sync your data. Legal basis: GDPR Article 6(1)(b), to provide account access and synchronisation.
  • Security and service operation: hosting and authentication providers process request and diagnostic information to deliver the site, prevent abuse and troubleshoot faults. Legal basis: GDPR Article 6(1)(f), our legitimate interest in keeping the service secure and operational. You may object to processing based on legitimate interests.
  • Product analytics: only after you give consent, PostHog receives the limited product events described below. Legal basis: GDPR Article 6(1)(a), your consent. You can withdraw it at any time using the controls on this page; this does not affect the core service.

Who is responsible?

The data controller is Minh Trung Nguyen, an individual operating GiveMeTheJob.

For privacy questions or requests to exercise your rights, contact trungdavid969@gmail.com.

What information can be processed?

  • Career information that you enter or import, such as your name, contact details, work history, projects, skills, education, languages and profile photo.
  • CV compositions, selected projects, job descriptions and job links that you choose to save or analyse.
  • Account information supplied through Google sign-in, such as your email address, name and profile image, plus authentication session data.
  • Service and security information such as request paths, timestamps, browser and device details, authentication events and diagnostic logs. Providers may also process network information such as your IP address to deliver their services.

Where is your data stored?

Without an account, your profile, drafts and saved CV compositions are kept in this browser's local storage until you remove them, use the product's delete or start-over controls, or clear the site's storage. The original PDF is read in the browser and is not stored by the server as part of the import flow.

When you sign in with Google, your career profile and saved CV compositions can be synchronised to Supabase. Access is protected by account ownership rules. Deleting your account removes the connected profile record and the account deletion flow clears local copies. Backup copies may remain for the periods described below.

Processors and transfers outside the EU/EEA

The services below process information on behalf of GiveMeTheJob or provide authentication. Their subprocessor lists and privacy terms can change over time.

  • Vercel, Inc. (United States) hosts the site, serves static content through its global network and runs server functions. Vercel's default region for new Node.js functions is Washington, D.C., unless the project region is changed. Vercel may process data in the United States and other countries. See Vercel's data processing terms and runtime log retention.
  • Supabase provides authentication and stores synced account profiles and CVs. This project's database is hosted in Europe. Supabase and its subprocessors may process some information elsewhere to provide the service. See Supabase regions and subprocessors.
  • OpenRouter, Inc. (United States) routes redacted CV text and job-matching data to an eligible model provider. Requests require zero retention and deny data collection at the model provider, and provider fallbacks are disabled. The selected model provider may be in the United States or another country; EU-only routing is not configured. See OpenRouter's privacy policy and model provider information.
  • If you submit a job link, the linked job site receives a request from our hosting provider so the public page can be read. That site is not a processor for GiveMeTheJob and handles the request under its own terms. Do not submit private links or links containing information you do not want to share.
  • PostHog, Inc. receives consent-gated product analytics. The default analytics endpoint is PostHog's EU host, but the deployment can be configured to use another host. PostHog's DPA allows processing outside the EEA, including in the United States, by PostHog and its subprocessors under the transfer safeguards that apply to the service. See PostHog's subprocessor list, DPA and event retention API.
  • Google provides Google sign-in and supplies account identity information. Google may process that information under its own privacy terms and in countries outside the EU/EEA. See Google's privacy policy.
  • For transfers outside the EU/EEA, a provider may rely on an adequacy decision, such as the EU–US Data Privacy Framework where the recipient is certified, or on Standard Contractual Clauses and any additional safeguards required by the applicable provider agreement. The exact recipient and transfer route for AI requests can depend on the selected model provider.

Analytics and cookies

No product analytics are sent before you consent. If you allow analytics, the site sends five manually configured product events to PostHog: profile_started, profile_ready, job_analysis_completed, cv_created and pdf_downloaded. It also sends a page_view event when a page opens or the client-side route changes. These events use a temporary browser identifier and may include technical metadata such as browser details, the current page path, referrer and network information. They are pseudonymous, not anonymous. The site does not intentionally attach CV text, job text, your name, email address or account ID to these events. Automatic capture, page-leave events and session recording are disabled. The SDK keeps its analytics identifier in memory; your analytics choice is stored in this browser's local storage.

Necessary Supabase session cookies may be used when you sign in. Local storage is also used for workspace data and to remember your analytics choice. There are no advertising cookies or cross-site advertising trackers.

How long do we keep information?

  • Browser data remains until you remove it, use the product's delete or start-over controls, or clear the site's storage.
  • Supabase account data remains until you delete the account. Backups and authentication logs are retained under the active Supabase project configuration and provider policy; see Supabase's backup policy and log documentation.
  • Vercel retains runtime logs for the period that applies to the current account and project configuration. The period is determined by Vercel's active settings and service terms; see Vercel's runtime log retention.
  • OpenRouter requests require zero retention and deny data collection at the selected model provider, and provider fallbacks are disabled. OpenRouter's own privacy policy does not give one fixed retention period for all account, usage and operational data; it says such information is retained as reasonably necessary for business, legal and compliance purposes.
  • PostHog retains events for the window set by the active organization's plan. The retention window is plan-based and can be read through the PostHog project settings or API; it is not set by this application.

Your rights

Depending on the circumstances, you may have the right to request access, correction, deletion, restriction or portability of your personal data. You may object to processing based on legitimate interests and withdraw consent to analytics at any time. You can delete your account from the account menu. For requests the self-service controls do not cover, contact trungdavid969@gmail.com. You can also complain to the Swedish Authority for Privacy Protection (IMY) at imy.se.