Privacy Policy
Last updated: July 2026
1. What We Collect
When you sign up, we collect your name, email, and whatever profile info you choose to add (like your GitHub link or bio). We also store basic usage data — which pages you visit, how long you stay — so we can figure out what's broken and fix it.
2. How We Use It
Your data runs this platform. We use it to log you in, assign you to projects, send notifications, and let your teammates find you in the workspace. We don't sell your data to anyone. We don't share it with third parties for marketing. Full stop.
3. Passwords & Auth
Your password is hashed with bcrypt before it touches the database. We also issue JWT tokens that expire every 15 minutes with refresh token rotation. If you log out, the refresh token gets invalidated server-side. That said — use a strong password. "Password123" isn't gonna cut it.
4. Cookies
We set a CSRF token cookie for security. It's not used for tracking. If you're on production, it's flagged Secure. In dev, it's plain HTTP. Either way, no third-party cookies, no ad trackers, no analytics spyware.
5. Data Retention
We keep your account data until you delete it. Leave requests older than 30 days are auto-purged. If you want your account nuked entirely, reach out and we'll do it within a reasonable timeframe.
6. Third Parties
We use Supabase (PostgreSQL) for the database. That's about it. If we add anything else in the future, we'll update this page.
7. Contact
Questions? Complaints? Curious about a specific data point? Email us at hello@careerstack.dev. We'll actually read it.