find your role first.

Policy

Privacy

This is a public preview. Checkout is off. Honestly, the site still processes some information the moment you load it, so this page has to say what that is.

Operator: Yashanth sai Tatineni, currently in the United States. A monitored support email will be published after a domain is registered. Don't send resumes, identity documents, payment cards, or a full API key.

What we process

Hosting providers see network and request data: IP address, path, time, and device headers. The app hashes the IP for rate limits. A hash isn't anonymous. Search parameters are processed to answer the request. We don't keep a free-text search history in an account table. Provider logs may still record query strings.

If you join the waitlist, we store your name and email so we can tell you when checkout opens. After you join, the site shows you jobs first seen in the last hour. We don't have a mailer yet, so those listings land on the page rather than in your inbox.

If you create an account, we store an account ID, key hashes and prefixes, subscription status, paid-access dates, usage totals, and the source job IDs already delivered to you. Raw keys pass through authentication and sit in a browser session cookie. The database stores hashes, not the full key.

Public job metadata lives in a separate store from account records. Billing providers will process payment and contact details only after checkout is turned on. We don't store full card numbers in the Find your role first database.

Who sees it

Cloudflare serves the frontend and proxies API and MCP traffic. Railway runs the backend and database. We use that data to authenticate, return jobs, meter usage, stop abuse, and answer support. Your own AI client receives the jobs you request and applies its own policies. Opening an employer link sends you to a different site.

The reviewed frontend has no advertising or analytics scripts. Live responses include Cloudflare Network Error Logging headers, which can report failed network requests to Cloudflare.

Cookies

jf_session authenticates the browser account. It lasts up to 30 days and uses SameSite=Strict. jf_checkout binds checkout to the originating browser for one day and uses SameSite=Lax, so the payment provider can return you here. Both are HttpOnly. They're Secure on HTTPS. Logout clears the session cookie. Blocking them breaks the browser account flow. API clients use a bearer header instead.

How long it stays

Change records and old closed jobs are kept about 90 days. Job-delivery ledgers stay for about three to four months. Rate-limit buckets can drop after five minutes. Account records and checkout references currently have no automatic deletion clock. Backups and provider logs may last longer than the app tables.

To ask for access, correction, or deletion, wait for the published support address. We'll verify ownership without asking for the full key. Some records may have to stay for a legal reason. Account deletion isn't a self-serve button yet. If you write before that inbox exists, keep the message to the account you control, skip the full API key, and we'll answer once a monitored address is attached to the chosen domain.

That's the list.

Effective 9 September 2026. This notice describes current preview processing. It isn't a GDPR or CCPA compliance claim.