Privacy notice

jobtool collects roles from Swiss company career pages and scores them against your skills. This page says what the tool stores about you, why it stores it, who else can see it, and how to have it removed.

What is stored

Only what an account needs to work:

You can share your CV while setting up your scores, by pasting the text or picking a PDF. It is read in memory to suggest your skills and is never stored: only the skills you confirm are saved. Beyond that the tool has nowhere to put a phone number, a postal address or a date of birth, and never asks for them.

Why it is stored

Your email address and password exist so you can sign in and recover the account. Your decisions, notes, skills and preferences are the product itself: your board is built from them. Your activity history is what the streak counts. Your plan and Stripe identifier exist so the tool knows whether premium is active.

Where it lives

The database is Neon Postgres in Frankfurt. The app itself, pages and API together, runs as one Railway service in the Netherlands. Both are in the EU. The server sees the network address your browser connects from, as any web server does. Traffic is encrypted end to end.

Who else can see it

Besides the hosting above, three outside services can be involved, and each one is used only if the operator has configured it. On a local install, none of them are.

Cookies, fonts and tracking

The browser extension

There is an optional Chrome extension, LinkedIn → Jobtool. It works only on LinkedIn job pages, and only for you:

How long it is kept

Your account data is kept until you delete the account. Sign-in sessions expire after 30 days, and changing your password ends every other session at once. Password-reset and verification links expire after 30 minutes.

Getting a copy

Open Account, find My data, and use Download JSON. The file holds your profile, every triage decision, your preferences, your skill ratings and your activity history. It leaves out your password, your session records and your tokens.

Deleting your data

You can delete everything yourself, at any time, without asking anyone.

This runs immediately. It removes your account, your triage decisions and notes, your skill ratings, your preferences, your activity history and milestones, your sessions and your pending links. There is no waiting period, and nothing is held back in the live database. The database does keep a rolling recovery window of about six hours, so a backup taken just before you deleted still contains your rows until that window passes.

If you have a premium subscription, it is cancelled at Stripe first. If Stripe cannot be reached at that moment, nothing is deleted and you are asked to try again shortly, so an account is never removed while its billing is still running.

Two things stay behind, on purpose. Roles are shared, so the scraped listings themselves remain for other people. And a record of each payment event is kept for accounting: it holds Stripe's own identifiers and nothing that names you.

If you cannot sign in, write to the contact email address in the responsible-party block at the top of this page and ask for your account to be deleted. Send the request from the address you registered with, so it can be matched to the account. Deletion does not require you to be able to sign in.