Who we are
getremotejobs (the “Service,” “we,” “our,” or “us”) is a remote-only job platform. We ingest public job listings from company career pages and remote-job aggregators, and we match them to candidates who upload resumes. This policy describes how we handle personal data when you use the Service.
What we collect
We collect the minimum needed to run the product. Specifically:
- Account data: email, password hash, and optional display name when you create an account.
- Resume data: if you upload a resume, we store the original file plus the structured summary we extract from it (skills, experience, education, seniority, desired titles).
- Preferences: saved searches, job bookmarks, application tracker entries, recruiter-visibility settings.
- Usage data: pages visited, features used, error events. We use this to keep the product working, not to build advertising profiles.
- Recruiter workspace data: if you are on the recruiter tier, we store the candidates, pipelines, notes, and outreach you create inside your workspace.
We do not sell your personal data. We do not share it with data brokers. We do not serve third-party advertising on our product surfaces.
How we use it
We use the data you give us for these purposes:
- To match your resume against public remote job listings and rank them in your personal view.
- To deliver email or Slack alerts when jobs matching your saved searches appear.
- To let you track your own applications.
- To make your profile discoverable to recruiters only when you explicitly turn that setting on. It is off by default.
- To operate the Service — authentication, security, fraud prevention, debugging, and customer support.
AI processing
We use AI to parse resumes and to rank job matches. Two things worth knowing:
- Resume parsing runs once per upload and extracts a structured summary — the content you see in your profile.
- Matching is done via vector embeddings generated from your resume and from each job description. We compute similarity server-side; we do not send your resume content to third parties for purposes unrelated to the match computation you requested.
- We do not use your resume content to train models we offer to third parties. We do not sell embeddings.
Your rights
Regardless of where you live, you can:
- Access the personal data we hold about you from your profile page.
- Correct any inaccuracies — the structured resume editor lets you directly edit every extracted field.
- Delete your resume, your account, or both. Deletion is immediate and cascades to derived data (embeddings, match scores, profile views). Recruiter workspaces that have already sourced your profile retain the snapshot they copied; this is visible to you in your “who viewed me” log.
- Export your data in a portable JSON format.
- Opt out of recruiter discovery at any time. This is a simple toggle on your profile page; the effect is immediate.
If you are in the EU, UK, or EEA, you have additional rights under GDPR (including the right to object to processing, the right to data portability, and the right to lodge a complaint with a supervisory authority). If you are in California, you have rights under the CCPA/CPRA, including the right to know and the right to delete.
Retention
We keep personal data only as long as needed for the purposes described above:
- Account data: for the life of your account, plus a 30-day grace period after deletion.
- Resume and embeddings: until you delete your resume, or until your account is deleted, whichever comes first.
- Usage logs: up to 90 days.
- Audit logs (security-significant events): up to 2 years.
Security
We use encryption in transit (TLS) and at rest, scoped access controls, row-level security in our database, and quarterly vulnerability reviews. We maintain a security.txt at /.well-known/security.txt. If you believe you have found a security issue, please let us know — details in Trust & security.
International transfers
We operate primarily from the United States. If you access the Service from outside the US, the data you provide will be transferred to and processed in the US, where data protection laws may differ from those of your home country. When required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
Children
The Service is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. Material changes will be announced in-app and via email to signed-in users at least 30 days before they take effect. The “Last updated” date at the top of this page always reflects the most recent revision.
Contact
Email [email protected] for any privacy-related question, request, or complaint. We acknowledge requests within 7 days and respond substantively within 30 days.