Privacy Policy

Last updated: August 9, 2026

1. About JobFunnel

JobFunnel ("we", "us", or "our") is a job search management platform for tech professionals. This Privacy Policy explains how we collect, use, and protect your information when you use our web application at jobfunnel.eu and our Chrome browser extension ("JobFunnel Extension").

2. Data Controller

JobFunnel is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR). We are currently operating as an early-stage product (MVP) without a registered company entity yet; a registered legal name and address will be added here once formed. In the meantime, you can reach us for any data protection matter at admin@jobfunnel.eu.

3. Information We Collect

Web Application

  • Email address (used for authentication via magic link)
  • Profile information you provide: name, role, years of experience, target countries
  • Job application data you enter: company, job title, stage, salary, notes
  • Interview stories you create (STAR format content)
  • CV file uploads (stored securely in Supabase Storage)

AI-Assisted Features

  • When you use cover letter generation or CV parsing, the relevant CV text, job description, and job/company details are sent to our AI provider (Anthropic) to produce the result — see Third-Party Services below

Chrome Extension

  • Job posting data scraped from job board pages you visit (LinkedIn, Indeed, StepStone, Glassdoor, Xing) — only when you actively click "Save to Pipeline"
  • An authentication token stored locally in your browser's extension storage (chrome.storage.local) to connect the extension to your JobFunnel account
  • A local cache of saved job URLs to detect duplicates

4. How We Use Your Information

  • To provide and operate the JobFunnel service (legal basis: performance of a contract)
  • To display your job search pipeline, analytics, and insights (contract)
  • To send transactional emails (magic links, weekly summaries) via Resend (contract)
  • To calculate funnel conversion metrics for your personal dashboard (contract)
  • To generate cover letters and parse CV content using AI, when you request it (contract / your explicit request)
  • To measure which advertising campaigns bring people to JobFunnel, and to understand how the product is used (consent — only if you accept cookies, and never by default)

We do not sell your data. We do not use your job search content — your applications, notes, stories, or CVs — for advertising, and we do not build advertising profiles about you.

We do measure advertising, and only with your consent. If you accept cookies, a conversion event is sent to Google Ads when you sign up or subscribe. That event contains a value, a currency, and an opaque transaction identifier — a one-way hash, deliberately not your user ID — and nothing else. No name, no email address, and no job search content is ever sent. We do not enable Google's “enhanced conversions” feature, so your email address is never shared with Google in any form, hashed or otherwise.

One clarification we would rather state plainly than let you discover. The Google click identifier that tells us which ad you came from arrives in the page address. Our own servers never transmit it anywhere — we store it in our database and use it only to count which campaigns brought people to JobFunnel. But Google's own tag reads it from that address and sends Google a signal containing it as soon as the page loads, before you have answered the cookie banner. Until you accept, that signal stores nothing on your device and reads nothing from it: it tells Google a page was viewed, and that consent had not been given.

5. Data Storage and Security

All data is stored in Supabase (EU region). Row-Level Security (RLS) ensures your data is only accessible by your authenticated account. Authentication tokens are short-lived (1-hour access tokens) and never exposed to third parties.

Extension data stored in chrome.storage.local stays on your device and is never transmitted to third parties.

6. Chrome Extension Permissions

The JobFunnel Chrome Extension requests the following permissions:

  • activeTab / tabs — to read the URL of the current tab and detect supported job boards
  • storage — to save your authentication token and saved job cache locally on your device
  • Host permissions (LinkedIn, Indeed, StepStone, Glassdoor, Xing) — to scrape job details (title, company, location, salary) from job listing pages when you request it
  • Host permission (job-funnel-lime.vercel.app) — to silently retrieve your authentication token from the app when you are logged in

The extension only reads job data when you actively open the extension popup on a job page. It does not run in the background or track your browsing history.

7. Third-Party Services

  • Supabase — database and authentication (privacy policy)
  • Vercel — hosting and deployment, and Vercel Analytics for aggregate, cookieless page-view and performance measurement (privacy policy)
  • Resend — transactional email delivery (privacy policy)
  • Anthropic — AI processing for cover letter generation and CV parsing (privacy policy)
  • Google Ads — advertising measurement and conversion tracking. The Google tag loads for every visitor, but starts in a fully denied state: until you accept it stores nothing on your device and reads nothing from it. It does still tell Google that the page was viewed, that consent was not given, and — if you arrived from an ad — the click identifier and address you arrived on (privacy policy)
  • PostHog — product analytics, EU-hosted (privacy policy)

Some of these providers may process data outside the European Economic Area (EEA), including in the United States. Where this happens, we rely on appropriate safeguards such as Standard Contractual Clauses to ensure your data remains protected to EU standards.

8. Cookies and Tracking

We use a small number of first-party cookies. The strictly necessary ones — the cookie that keeps you signed in — are always set, because the app cannot work without them. Advertising and measurement cookies are stored only after you accept them in the cookie banner.

Before you decide, and if you decline, our product analytics runs in memory only: we can see how a single visit moves through the site, but nothing is written to your device and nothing identifies you again on a later visit.

If you withdraw consent, we delete the cookies we set on this site — including the analytics identifier and the advertising cookies. Google also sets cookies on its own domains (google.com, doubleclick.net, googleadservices.com) that no website can delete on your behalf; withdrawing tells Google to stop using them for advertising, and you can remove them yourself through your browser's cookie settings or Google's own ad settings.

These are the cookies we set ourselves:

  • jf_attr — 90 days — records how you arrived (the Google click identifier and campaign parameters, plus the page you landed on) so we can tell which campaigns bring us people who find JobFunnel useful. It is written only after you accept cookies.
  • jf_consent — 365 days if you accept, 180 days if you reject — remembers your cookie choice so we do not ask you again.
  • ph_phc_…_posthog — 365 days — set by PostHog, our EU-hosted product analytics, to recognise the same browser across visits so we can tell a returning user from a new one. Written only after you accept, and deleted if you withdraw.

Rejecting is as easy as accepting — both are ordinary buttons of the same size and weight, and neither is styled as the answer we would prefer. If you reject, Google advertising cookies are never loaded and no click or campaign data is stored.

You can at any time. If you withdraw a previous acceptance, the jf_attr cookie and everything in it are deleted immediately — withdrawing stops collection and removes what was already collected in your browser.

We do not use cookies for cross-site behavioural profiling, and we do not sell personal data.

9. Data Retention and Deletion

Your data is retained as long as your account is active. You can delete your account and all associated data at any time from Settings. Upon deletion, your personal data is permanently removed from our database within 30 days, with the one exception below.

Withdrawal records. If you exercise your right of withdrawal from a paid subscription, we keep a record of that declaration: your name, the email address you declared from, the date, and what was cancelled. We keep it for 6 years from the date of the declaration, and it survives deletion of your account.

We are not able to erase it on request. That is not a choice we make about your data: we are required to be able to show that we honoured a withdrawal we were legally obliged to honour, so this record falls under the exceptions to the right to erasure in Article 17(3)(b) and 17(3)(e) GDPR. The lawful basis for holding it is Article 6(1)(c), a legal obligation, together with Article 6(1)(b), performance of a contract. It is not based on consent, so there is nothing to withdraw. We keep the minimum needed to prove the declaration happened, and nothing else.

10. Your Rights (GDPR)

As a user based in the European Union, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate personal data
  • Request deletion of your personal data ("right to be forgotten"), subject to the withdrawal-record exception described in section 9
  • Data portability — export your data in machine-readable format
  • Withdraw consent at any time
  • Lodge a complaint with your national data protection supervisory authority — for the Netherlands, this is the Autoriteit Persoonsgegevens

To exercise any of these rights, contact us at admin@jobfunnel.eu

11. Children's Privacy

JobFunnel is not directed at, and is not intended for use by, anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via email or an in-app notice. Continued use of JobFunnel after changes take effect constitutes acceptance of the updated policy.

13. Contact

Questions about this Privacy Policy? admin@jobfunnel.eu

Related policies: Terms & Conditions · Refund Policy