Menu

Privacy

This page says what Ajuma stores, why it is stored, and who can see it. It covers the public job board and the signed-in product.

What we store

  • Your account. Your email address and your name. A phone number and a profile photo if you add them. A password, kept hashed, if you set one.
  • Your profile, if you make one. It is optional: a headline, a summary, your location, years of experience, whether you are open to remote work, skills, and links you choose to add such as a portfolio or LinkedIn page.
  • A link to your CV. You supply the link and we store the link, not a copy of the document. When you apply, the link as it stood at that moment is attached to that application, so replacing your CV later does not change what an employer already reviewed.
  • Your applications. Which roles you applied to, any cover letter you wrote, the status of each application and every status change, and the note an employer writes when they decide.
  • Messages. Messages between you and an employer about an application, and interview times arranged through the product.
  • Saved jobs, followed companies and notifications. The jobs you save, the companies you follow, and the notices the product shows you when you are signed in, with whether you have read them.
  • Sign-in sessions. A record of each session: when it started, when it runs out, and whether it has been ended, so a session can be revoked. The record does not include your IP address or which browser you used.
  • Support reports. What you send through the support form, the email address you give or your account's address if you are signed in, what the report is about, and the replies on it.
  • An audit log. Changes made through the product are written to an append-only record of who made them, what changed and when: creating an account, signing in, editing a profile, applying, moving an application, sending a message, and staff actions such as approving a company or suspending an account. For a message the record says one was sent, never what it said. Nothing in the product edits or deletes a row in that log.

Email we send you

One kind of email: a six-digit code when you sign up, to confirm the address is yours. We keep the code hashed, with the address it went to and when. It expires ten minutes after it is sent and stops working once used. So that nobody can fill a stranger's inbox, we send at most three codes to one inbox in an hour and five in a day.

Everything else the product tells you, such as an application moving forward, appears as a notification when you are signed in. It is not emailed.

Who can see it

  • When you apply, the employer for that role sees your name, your CV link, your cover letter and your profile. They do not see your applications to anyone else.
  • Jobs you save and companies you follow are yours alone. Employers are not told you looked.
  • Our staff can see accounts, companies and postings in order to review and support them. Those actions go into the audit log.
  • Your profile is not published on the public board. Job and company pages are public and indexed by search engines; your application is not.

Who else handles it

  • Google Cloud runs the site and holds its database, in the United States. Its request logs record the IP address and browser of each visit to the site.
  • The Lumin mail service sends the signup code. It receives your email address and the code, and keeps a record of each email it sends. It delivers through Resend, an email delivery provider, which receives them too.

Cookies

We set cookies to keep you signed in. That is what they are for. Today the site runs no advertising or analytics trackers.

Your data, and getting it back or removed

You can edit your account and profile at any time while signed in. To ask for a copy of your data, or for your account to be removed, send a request through support. There is no button for either yet, so a person handles each request by hand.

Removing an account removes its profile and its applications, and with each application the conversation about it, so the employer loses those messages too. Support reports and audit log entries are kept, and both include the email address they were made with.

Who is responsible for your data

Controller
[Placeholder: the legal entity responsible, to be confirmed]
Address
[Placeholder: its registered address, to be confirmed]
Privacy contact
[Placeholder: a contact for privacy questions, to be confirmed]. Until then, use support.

Changes to this page

If what we store changes, this page changes at the same time, and we say on it what changed.