Privacy Policy
Last updated: 15 July 2026 · Applies to jobctl.app and app.jobctl.app
1. What we collect
- Account: your email address (used for magic-link sign-in only).
- Application data you provide: companies, roles, statuses, salaries, notes, interview details, attached CV/cover-letter files, company analyses, and match assessments — entered by you in the dashboard or written by an AI agent you connected via MCP/API using your token or OAuth grant.
- Technical: standard server logs (IP address, timestamps, request paths) for security and abuse prevention, retained for up to 30 days.
We do not collect analytics, advertising identifiers, or the content of your conversations with AI assistants — an agent only sends jobctl the specific tool calls it makes.
2. How we use it
- To provide the service: store and display your job-application pipeline.
- To authenticate you (magic-link emails, session cookies, API tokens, OAuth tokens).
- To protect the service (rate limiting, abuse detection via server logs).
No profiling, no advertising, no sale of personal data, and no use of your data to train machine-learning models.
3. Storage & security
Data is stored in a PostgreSQL database hosted on Amazon Web Services in eu-central-1 (Frankfurt, Germany), encrypted in transit (TLS) and at rest. Authentication secrets (tokens, codes) are stored only as SHA-256 hashes. OAuth access is scoped to your account and revocable in Settings → API tokens.
4. Third parties
- Amazon Web Services — hosting and database (EU region).
- Resend — delivers magic-link sign-in emails (your email address only).
- GitHub Pages — serves this static website (jobctl.app); no account data touches it.
We share data with no one else. No third party receives your application data.
5. Data retention & deletion
- Your data is kept for as long as your account exists.
- Export: download everything as JSON anytime (Settings → Export).
- Delete: deleting your account (Settings) permanently and irreversibly removes all your data — applications, files, analyses, events, tokens — in line with GDPR Art. 17.
- Server logs rotate within 30 days.
6. Your rights (GDPR)
You have the right to access, rectify, export, and erase your personal data, and to object to or restrict processing. Most of these are self-service in the app; for anything else, email us.
7. Contact
Data controller: Dmytro Rybka, Germany.
Email: dmytro@rybka.me
8. Changes
If this policy changes materially, the "Last updated" date above changes and the current version is always published at jobctl.app/privacy.