Legal

Privacy Policy

Last updated: July 2026

1. What We Collect

When you sign up, we collect your name, email, and whatever profile info you choose to add (like your GitHub link or bio). We also store basic usage data — which pages you visit, how long you stay — so we can figure out what's broken and fix it.

2. How We Use It

Your data runs this platform. We use it to log you in, assign you to projects, send notifications, and let your teammates find you in the workspace. We don't sell your data to anyone. We don't share it with third parties for marketing. Full stop.

3. Passwords & Auth

Your password is hashed with bcrypt before it touches the database. We also issue JWT tokens that expire every 15 minutes with refresh token rotation. If you log out, the refresh token gets invalidated server-side. That said — use a strong password. "Password123" isn't gonna cut it.

4. Cookies

We set a CSRF token cookie for security. It's not used for tracking. If you're on production, it's flagged Secure. In dev, it's plain HTTP. Either way, no third-party cookies, no ad trackers, no analytics spyware.

5. Data Retention

We keep your account data until you delete it. Leave requests older than 30 days are auto-purged. If you want your account nuked entirely, reach out and we'll do it within a reasonable timeframe.

6. Third Parties

We use Supabase (PostgreSQL) for the database. That's about it. If we add anything else in the future, we'll update this page.

7. Contact

Questions? Complaints? Curious about a specific data point? Email us at hello@careerstack.dev. We'll actually read it.