Privacy notice
Last updated 2026-09-10.
jobtool collects roles from Swiss company career pages and scores them against your skills. This page says what the tool stores about you, why it stores it, who else can see it, and how to have it removed.
- Legal name
- Federico D'Ignazio
- Address
- Waldeggweg 4A, 8302 Kloten, Switzerland
- Contact email
- federico@dignazio.ch
What is stored
Only what an account needs to work:
- Your account. The email address you signed up with, the name you chose for the tool to greet you by, whether that email has been verified, when the account was created, and whether you are on the free or the premium plan.
- Your password, never in readable form. It is kept as a salted PBKDF2-SHA256 hash with 240,000 rounds.
- Your sign-in sessions. Only a SHA-256 fingerprint of the session token is stored, so a copy of the database cannot be used to sign in as you. The same is true of password-reset and email-verification links.
- Your triage decisions. Pursue, Stretch or Skip on each role, the reason for a Stretch, your own notes, the application status, and the date you applied.
- Your skill ratings. The level you gave yourself for each skill.
- Your preferences. The roles you are interested in, blocked keywords, favourite companies and boards, the countries you are searching in, your profile language, your weekly target, and your auto-triage instructions.
- Your activity history. The pipeline changes that build your streak, and the milestones you have earned.
- Your subscription, if you take one. Your plan and the customer identifier Stripe gives you. No card details ever reach jobtool.
You can share your CV while setting up your scores, by pasting the text or picking a PDF. It is read in memory to suggest your skills and is never stored: only the skills you confirm are saved. Beyond that the tool has nowhere to put a phone number, a postal address or a date of birth, and never asks for them.
Why it is stored
Your email address and password exist so you can sign in and recover the account. Your decisions, notes, skills and preferences are the product itself: your board is built from them. Your activity history is what the streak counts. Your plan and Stripe identifier exist so the tool knows whether premium is active.
Where it lives
The database is Neon Postgres in Frankfurt. The app itself, pages and API together, runs as one Railway service in the Netherlands. Both are in the EU. The server sees the network address your browser connects from, as any web server does. Traffic is encrypted end to end.
Who else can see it
Besides the hosting above, three outside services can be involved, and each one is used only if the operator has configured it. On a local install, none of them are.
- Stripe handles payment, if you subscribe. Checkout and the billing portal are pages hosted by Stripe. Stripe receives your account identifier, the price you chose, and your email address the first time you check out. Your card details go to Stripe and never to jobtool.
- Resend delivers account email, if it is configured. It receives the recipient address and the message. The only messages sent are the password-reset link, the email-verification link, and a notice to an address someone tried to move an account onto.
- Anthropic runs premium auto-triage, if you turn it on. For each role it receives the title, the company, the location, your match score, and the first 4,000 characters of the role description. Your email address, your name and your account identifier are never part of that request.
Cookies, fonts and tracking
- One cookie. It is called
jt_session, it holds your sign-in session, it cannot be read by scripts, and it lasts 30 days. It is removed when you sign out and when you delete your account. There is no other cookie. - Two small settings stay in your browser and are never sent anywhere: your choice of day or dark theme, and one scrape option.
- No advertising, no tracking pixels, no analytics. There is none of it in the app. A content security policy allows the browser to talk to jobtool's own server and to Google Fonts, and to nothing else.
- Google Fonts. The app loads two typefaces from Google's servers. That is not tracking code, but fetching them does show your IP address and browser version to Google.
- Failed sign-ins. Your network address is counted in memory for 15 minutes to slow down repeated failed attempts. It is not written to the database, and it is forgotten when the server restarts.
The browser extension
There is an optional Chrome extension, LinkedIn → Jobtool. It works only on LinkedIn job pages, and only for you:
- What it reads. The job posting you are viewing on LinkedIn: title, company, location and description. It reads nothing else on LinkedIn and nothing on any other site.
- Where that goes. To the jobtool you picked in the extension window: this shared cloud app, or a jobtool app on your own computer. The posting is sent there to be scored against your board, and it is stored only when you press Save.
- How it knows who you are. When saving to the cloud, the extension
reads jobtool's own
jt_sessionsign-in cookie described above and sends it along, so the job lands under your account. It never reads cookies from LinkedIn or any other site, and signing out of jobtool disconnects the extension too. - What stays in your browser. Your choice of destination and a short-lived cache of recent scores. They are never sent anywhere.
- No tracking. The extension does not record your browsing and sends nothing to anyone except jobtool itself. There is no analytics code in it.
How long it is kept
Your account data is kept until you delete the account. Sign-in sessions expire after 30 days, and changing your password ends every other session at once. Password-reset and verification links expire after 30 minutes.
Getting a copy
Open Account, find My data, and use Download JSON. The file holds your profile, every triage decision, your preferences, your skill ratings and your activity history. It leaves out your password, your session records and your tokens.
Deleting your data
You can delete everything yourself, at any time, without asking anyone.
- Open Account.
- Go to Delete account.
- Type DELETE in the box.
- Press Delete account.
This runs immediately. It removes your account, your triage decisions and notes, your skill ratings, your preferences, your activity history and milestones, your sessions and your pending links. There is no waiting period, and nothing is held back in the live database. The database does keep a rolling recovery window of about six hours, so a backup taken just before you deleted still contains your rows until that window passes.
If you have a premium subscription, it is cancelled at Stripe first. If Stripe cannot be reached at that moment, nothing is deleted and you are asked to try again shortly, so an account is never removed while its billing is still running.
Two things stay behind, on purpose. Roles are shared, so the scraped listings themselves remain for other people. And a record of each payment event is kept for accounting: it holds Stripe's own identifiers and nothing that names you.
If you cannot sign in, write to the contact email address in the responsible-party block at the top of this page and ask for your account to be deleted. Send the request from the address you registered with, so it can be matched to the account. Deletion does not require you to be able to sign in.