Privacy Policy
Last updated: 5 September 2026
Who we are
Job360 (“we”, “us”) operates the job-search service at job360.uk. We are the data controller for the personal data described here. To contact us about anything in this policy, email privacy@job360.uk.
What we collect
- Account data — your email address and a password. Passwords are stored only as an argon2id hash; we cannot read them. If you sign in by magic link, no password is stored at all.
- Profile data you upload — the text of your CV (PDF/DOCX), an optional LinkedIn profile PDF, an optional GitHub username, your job preferences, and your timezone.
- Job and application data — every job you (or your connected AI agent) bring in by pasting the ad or a link, plus your applications: a timeline of events, every version of your tailored CV and cover letter, any fit notes you or your agent recorded, contacts you add for a role (name, role, email, notes), and receipts of what you submitted.
- Technical data — request logs, error traces, and (only if you accept the analytics banner) product-usage analytics.
Why we process it (lawful basis)
- Contract — storing the jobs and applications you bring, generating tailored documents you request, serving your own connected AI agent’s requests, and operating your account.
- Consent — product analytics (PostHog) only run after you accept the cookie banner; declining or not answering means no analytics event is ever sent.
- Legitimate interest — keeping the service secure and fixing errors (Sentry).
We do not sell your data. We do not show ads. We do not use your data to train AI models.
AI processing — read this part
When you upload a CV or LinkedIn PDF, or generate a tailored CV or cover letter, the text is sent to the AI providers listed below to be parsed or drafted. This is core to how Job360 works — without it, we cannot build your profile or draft a tailored document. We use these providers’ business APIs, which contractually do not use your content to train their models. Your original files and the extracted profile stay on our servers; the AI providers process text transiently.
Who we share data with (subprocessors)
We share data only with the service providers below, only for the purposes stated, and never for their own marketing.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| OpenAI | CV parsing and tailored-document generation (primary AI provider) | Text extracted from your CV / LinkedIn PDF; job descriptions | USA |
| Google (Gemini), Groq, Cerebras | CV parsing (fallback AI providers, used only if the primary fails) | Text extracted from your CV / LinkedIn PDF | USA |
| Railway | Application hosting and database | All service data (encrypted in transit and at rest) | EU/USA |
| Resend | Transactional email (login links, email verification, password reset) | Your email address and message content | USA |
| Cloudflare R2 | Nightly encrypted database backups (kept as the newest 30) | Ciphertext only — backups are encrypted (AES-256) before upload; Cloudflare never sees readable data | Global (Cloudflare network) |
| PostHog (EU) | Product analytics (which features are used) | Usage events and pseudonymous identifiers | EU |
| Sentry | Error monitoring | Error traces and request metadata (request bodies are scrubbed) | EU/USA |
| GitHub | Fetching your public repositories, if you link a GitHub username | The GitHub username you provide | USA |
Where a provider is outside the UK, transfers rely on that provider’s standard contractual clauses / UK addendum. We will update this list before adding any new subprocessor.
How long we keep it
- Your account, jobs, and application data are kept until you delete your account — Job360 has no automatic deletion of your content.
- Security tokens expire automatically and are not renewable: magic sign-in links after 15 minutes, an AI agent’s OAuth access token after 1 hour (its refresh token after 30 days).
- Encrypted database backups run nightly and only the newest 30 are kept; older ones are deleted automatically. A deleted account ages out of backups within that same window.
How we protect it
All traffic is encrypted in transit (HTTPS/HSTS). Passwords are argon2id-hashed — we cannot read them. Your AI agent’s connection tokens (personal API tokens and OAuth tokens) are stored only as a hash, never in plain text, so we cannot recover or read them either. Database backups are encrypted (AES-256) before they leave our infrastructure, so the backup-storage provider only ever holds ciphertext.
Your rights
Under UK GDPR you can access, correct, export, or delete your personal data, object to processing, and withdraw consent. Deleting your account (Settings → Account → Delete) erases your per-user data immediately — this is our built-in Article 17 (“right to erasure”) mechanism. For anything else, email privacy@job360.uk and we will respond within one month. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
Changes to this policy
If we make material changes, we post them here and update the date at the top — this page is the single source of truth for what changed and when.