Jobtiv Privacy Policy

Version 1.0

Last updated: [INSERT PUBLICATION DATE]


1. Who we are

Jobtiv is operated by JOBTIV LTD, a company registered in England and Wales with company number 17092844, whose registered office is at 124-128 City Road, London, EC1V 2NX, United Kingdom.

In this policy, "Jobtiv", "we", "us" and "our" mean JOBTIV LTD. "You" and "your" mean the person using our website and services at jobtiv.ai (the "Service").

JOBTIV LTD is the controller of the personal information described in this policy. That means we decide why and how it is used, and we are responsible to you and to the regulator for it.

How to contact us about privacy. Email support@jobtiv.ai, or write to us at the registered office above. If your message is about your personal information, please put "Data request" in the subject line so it reaches the right person quickly.

We are registered with the Information Commissioner's Office, the UK data protection regulator, under registration number ZC240569.


2. What this policy covers

This policy explains what personal information we collect when you use Jobtiv, why we collect it, who we share it with, how long we keep it, and what rights you have.

It applies to everyone who uses the Service, including people who use it before creating an account, and to people who have never used Jobtiv but whose information we hold. If that is you, section 4.5 is written for you.

Two other documents sit alongside this one:

  • Our Cookie Notice explains the cookies and similar technologies we use and how you control them.
  • Our Sub-processor List names the companies that handle personal information for us, whether they do so on our instructions or as controllers in their own right, says what each one does, what it can see, where it is, and what safeguard applies to information we send outside the United Kingdom.

If you are in the United States, section 17 sets out additional rights and disclosures. If you have entered health related information into the Service and you live in Washington, Nevada or Connecticut, our separate Consumer Health Data Privacy Policy also applies.

Where we offer the Service. Jobtiv is offered to users in the United Kingdom and the United States. We do not market the Service in the European Economic Area and have not appointed a representative under Article 27 of the EU GDPR. If we start offering Jobtiv to people in the European Economic Area, we will appoint a representative there, name them here, and update this policy before we do it.


3. The short version

We built Jobtiv to help you find work. To do that we hold the most detailed document most people ever write about themselves, which is their CV.

  • Your CV, your cover letters, your application notes and your salary figures are stored on our servers and are visible to you.
  • Most of our tools work by sending some of that content to an artificial intelligence provider. Section 7 names every provider and says exactly what each one sees.
  • We do not sell your personal information. We do not run advertising and we do not use advertising cookies or advertising networks.
  • We do not send your CV, your scores or anything else about you to employers or recruiters. Nothing you do on Jobtiv is shared with a company you are applying to unless you send it to them yourself.
  • You can download everything we hold on your account and you can delete your account, both from Settings. Sections 11 and 13 explain what deletion does and does not reach.

The rest of this policy is the detail. Please read it.


4. The information we collect

4.1 Information you give us

Account information. Your email address, and your password if you set one. If you sign in with Google, we receive your email address and basic profile information from Google. Optionally, a display name.

Your age, but not your date of birth. When you create an account we ask for your date of birth so we can check that you are 18 or over. We check it and then keep only two things: the answer to that question, and the date you told us. The date of birth itself is never written to our database.

Your phone number, if phone verification is switched on. Phone verification is switched off at the moment. If we switch it on, we will require it before you can use the Service rather than offering it as an option, and we will tell you before we do. Where it is on, we send the number to Twilio to deliver a verification code and we store the number on your profile.

Your CV. This is the core of the Service. It commonly contains your full name, home or city address, telephone number, email address, employment history, education, qualifications, skills, projects, publications and anything else you choose to write. You can type it in, paste it, upload a PDF or Word file, or import a LinkedIn data export.

Job descriptions that you paste or upload, when you score your CV against a role, generate a cover letter, translate a job description or record an application.

Cover letters and your writing voice profile. The letters you generate and edit, and a profile of your writing style derived from a sample you provide.

Salary and offer information. In the Salary Negotiator: your role, location, employer, current and offered salary, bonus, equity, benefits and any notes you add. Your offer figures are stored encrypted in our database. The negotiation scripts we generate from them are stored in the ordinary way.

Application tracker content. Companies, roles, locations, salary text, interview dates, contacts you add, and your own free text notes about a company or an interview.

Portfolio content. Projects, biography, links, images and screenshots you upload for a portfolio page, and any password or access key you set for it.

Practice and assessment content. Your answers in aptitude and case practice, your STAR stories, your progress through the study material, and your scores in the Arcade practice games. Arcade scores appear on an internal leaderboard visible to our staff, not to other users.

Voice recordings. Where a feature lets you dictate rather than type, we send the recording to an artificial intelligence provider to be turned into text. Our code does not write the recording to our database or to our file storage, so we do not hold a copy of it after the text comes back. The provider's own retention applies to what we sent it, and section 7.2 explains that.

Resignation letters and the details you give to produce them, including your employer, role, notice period and the letter body.

Feedback you send us. If you use the feedback form, we store what you wrote, the page you were on and your account reference, and we email it to ourselves.

Waitlist entries. If you register interest in a feature that is not yet available, we store the feature, any note you leave and your account reference.

Anything else you type. Several tools take free text. Whatever you write in them is stored.

4.2 Information we collect automatically

Guest identity, and the draft behind it. If you start using Jobtiv before creating an account, we set a signed cookie called jobtiv_guest_id containing a random identifier, and we store the same identifier in your browser's local storage. We set it the first time you create or edit something, not when you land on the site. The cookie lasts 30 days and is cleared when you sign in or sign out.

The draft itself is a different thing from the cookie, and we should be plain about it. When you type or upload a CV as a guest, that CV is stored on our servers against the guest identifier, not against an account. It commonly contains your name and your contact details. If you never create an account, we keep that draft for 30 days from the day you started it and then delete it. The clock runs from when the draft was created rather than when you last edited it, because the cookie that identifies you as its owner also lasts 30 days and does not extend. Keeping the draft longer than the cookie would mean holding a CV we could no longer return to you. Until then, it is real personal information about you and we hold it.

If you have used Jobtiv as a guest and you want to know what we hold, or want it deleted before then, email support@jobtiv.ai and quote the value of jobtiv_guest_id from your browser, or ask us and we will explain how to find it. That identifier is the only way we can find your draft, because there is no name or email on our side to search by. If you cannot give it to us, tell us as much as you can and we will do what we reasonably can, but we may not be able to locate the record.

Technical information from your requests. Your IP address, the pages and features you use, your browser and device type, and the time of each request. We use these to keep the Service running, to apply usage limits and to detect and stop abuse.

Product analytics in your browser. If you consent to analytics cookies, we record which features you open and how far you get through a task, and we send those events to PostHog. They are linked to your account identifier once you sign in, so they are not anonymous.

Analytics events carry the shape of what you did, not what you wrote: lengths, counts, categories, yes or no flags, and identifiers. No text you have typed is sent to PostHog. Web addresses are reduced to the path with a short list of permitted marketing and funnel parameters, so nothing put into a query string can reach analytics by accident. Where an IP address is needed to detect abuse, it is hashed before it is stored. An automated check in our build fails if anyone reintroduces a free text property, so this is enforced rather than merely intended. Our PostHog account is on their European Union cloud and analytics events are kept for 30 days.

Product analytics on our servers. Separately, our own servers record a small number of events about whether a request or a background job succeeded. Those never touch your device, so the cookie choice does not reach them. They carry an account identifier and no document text, and we keep them for 90 days.

Error reports. When something breaks, we send a report to Sentry, whose servers are in Germany. Section 12 explains what is stripped out of those reports before they leave our servers.

Error reporting runs from your first visit, before you have made any cookie choice, because a fault in the first few seconds of a page is exactly the kind we most need to see, including a fault in the cookie banner itself. A report carries the type of error, the code path and an anonymous identifier. It does not carry your documents, and our basis for it is our legitimate interests in a working service. You can object.

4.3 Information from other sources

From Google, if you sign in with a Google account.

From Stripe, when you buy a subscription: your subscription status, plan and billing period. We do not receive or store your card number.

From company and job data providers. When you use Find Recruiters, Course Finder or the market and salary features, we send a company name, a domain, a role or a search term to Apollo, Hunter, Serper, Adzuna, Jooble, Brandfetch, Logo.dev, YouTube and Udemy, and we receive information back. We search these sources for organisations, not for named individuals. Where a result nonetheless contains a named person, section 4.5 explains what we do with it.

4.4 What you have to give us, and what happens if you do not

You have to give us an email address to have an account, because it is how we sign you in and how we contact you. Without it we cannot provide the Service.

Everything else is your choice. A display name, the content of your CV, your cover letters, your salary figures, your notes and your tracker content are all optional. If you leave something out, the tool that depends on it will not work as well, or will not work at all. Nothing else happens.

You do not have to give the sensitive information permission in section 5.1. If you do not, the artificial intelligence features listed in section 7.1 are switched off for you and everything else works as normal.

You do not have to accept analytics cookies. If you refuse, the Service works exactly as it does if you accept.

4.5 If you are not a Jobtiv user and we hold information about you

Some of the information we hold is about people who have never used Jobtiv. This section is for you.

How this happens. There are two routes. When a Jobtiv user searches for recruiters, researches a company or looks at job market data, we send a company name, a domain or a search term to Apollo, Hunter, Adzuna, Jooble or Serper, and the results those companies return sometimes contain a named person, most often a recruiter named in a job advertisement. Separately, Jobtiv users write documents, and a CV or an application record often names a referee, a former manager or an interview contact.

What we hold. From a data supplier, typically a first name, an abbreviated surname, a job title and an employer, held in a cache keyed to the company's web domain and shared between our users. We do not store an email address or a telephone number for you. From a document a user wrote, whatever that user chose to write, which is usually a name, a role and how they know you. We do not build a profile of you, we do not use your information to make any assessment of you, and we never contact you ourselves. If a Jobtiv user writes to you, they send that message themselves from their own email account.

Where it came from. Either from one of the companies named above, each of which publishes its own privacy notice, or from a Jobtiv user who wrote it into a document. Where it came from a data supplier, that supplier collected it from public sources, from its own contributor network or from other data providers, and it is responsible for having done so lawfully.

Why we hold it and on what basis. So that our user can contact you about a job, and so that the document our user wrote is complete. Our lawful basis is our legitimate interests in providing a job search service, and the legitimate interests of our users in applying for work. We have assessed the balance between those interests and your rights, and you can ask us for a summary of that assessment.

How long. Recruiter lookup results are held for up to 30 days in the shared cache and then expire automatically. Cached drafts of outreach messages are held for 90 days. Company research results are held for 105 days. Information a user wrote into a document is held until the user deletes it or deletes their account.

Why you are reading this here rather than getting an email from us. The law says we should normally tell you directly that we hold information about you. We cannot: we do not hold an email address or a telephone number for you, by design, so there is no way for us to write to you without first collecting more information about you than we already have. Where that is the position, the law allows us to publish the information instead, which is what this section is. We have written down our reasoning and you can ask us for it.

Who sees it. The Jobtiv user who ran the search or wrote the document, and the companies listed in our Sub-processor List.

Your rights. You have the same rights as our users. You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, and object to us holding it at all. Because we hold it on the basis of legitimate interests, if you object we will stop unless we can show compelling grounds that override your rights, and in practice we expect to stop. Email support@jobtiv.ai with "Third party data request" in the subject line and tell us your name and, if you can, the company or the domain you are associated with. The shared cache is organised by company domain, so that is usually enough for us to find and remove you, and we can block your details from being cached again. If you want your details removed from a document a Jobtiv user wrote, tell us and we will contact that user and remove them.

Complaints. You can complain to us using the process in section 13.5, and to the Information Commissioner's Office at any time.


5. Sensitive information

5.1 Special category information

Some information is given extra protection by law. It is information that reveals your racial or ethnic origin, your political opinions, your religious or philosophical beliefs, your trade union membership, your genetic or biometric data, your health, your sex life or your sexual orientation.

We do not ask for any of it. There is no field anywhere in Jobtiv for your health, your ethnicity, your religion, your disability, your sexuality, your political views or your union membership.

CVs do not always cooperate with that. A CV may name a religious employer, a trade union role, an LGBT+ society, a disability charity, a health condition explaining a career gap, or a country of origin. If you write it, we store it, and our tools read it as part of the document.

Our position is:

  • We ask you not to include information about your health, your ethnicity, your religion, your disability, your sexuality, your political opinions or your trade union membership in anything you put into Jobtiv. Nothing about that request makes it a breach of our Terms of Service if your CV contains it. Most CVs do.
  • We do not draw conclusions from it. We do not read your documents to work out anything about your health, your ethnicity, your beliefs or any other protected characteristic, we build no profile of you from them, and nothing you write changes how the Service treats you.
  • We still ask your permission, because we cannot separate it out. If your CV names a religious employer or a union role, that information is in the document, and it goes wherever the document goes. So before the first time you use a feature that sends one of your documents to an artificial intelligence provider, we ask you separately. The box is not pre ticked. The request names the kinds of information it covers, which are your health, your racial or ethnic origin, your religious or philosophical beliefs, your political opinions, your trade union membership, your sex life or sexual orientation, and your genetic or biometric data. It also names the provider the feature uses. Our condition for that processing is your explicit consent under Article 9(2)(a) of the UK GDPR.
  • You can withdraw that permission at any time, in one step, in Settings, then Privacy, then Sensitive information. Withdrawing it is as easy as giving it and costs you nothing. Withdrawing does not make anything we did beforehand unlawful.
  • What happens if you say no, or change your mind. We stop sending your documents to artificial intelligence providers. You keep the CV builder, the editor, the exports, the Application Tracker and the Salary Negotiator calculators, and everything you have already made. CV scoring, cover letter generation and the other tools listed in section 7.1 stop working until you turn the permission back on. Your documents stay exactly where they are. We do not delete anything and we do not ask you to edit anything. They are yours, and you can delete any of them at any time. We tell you what will stop working at the point you switch the permission off, before it takes effect.

5.1A What our tools actually do with it

We do not ask for this information, we do not use it to build a profile of you, and we do not use it to decide anything about you.

An artificial intelligence model asked to improve your CV reads the whole document, including anything sensitive you have written in it, and its answer may reflect what it read. That is why we ask for your explicit permission rather than treating this as ordinary information. We instruct our models not to comment on or draw conclusions from protected characteristics. We check this when we change a prompt, and if you find a model that does it, tell us and we will fix it.

5.2 Criminal offence information

The same applies to information about criminal offences, allegations, investigations, proceedings, or the absence of a conviction, which the law reads broadly. We do not ask for it. Where you choose to include it, for example because a role requires disclosure or you are applying under a rehabilitation scheme, our lawful basis is the performance of our contract with you, and our additional condition is your consent under paragraph 29 of Schedule 1 to the Data Protection Act 2018. That consent is part of the same separate permission described in section 5.1 and you withdraw it the same way.

We also process this kind of information in one other situation, which is when we investigate a report that something published through Jobtiv is unlawful. Section 6 sets out our basis and condition for that, and we hold an appropriate policy document covering it.


6. Why we use your information, and our lawful bases

Under the UK GDPR we must have a lawful basis for everything we do with your personal information. This table sets out what we do and why we are allowed to do it.

What we doInformation usedLawful basis
Create and run your account, sign you in, keep you signed inEmail, password, session, display namePerformance of a contract with you (Article 6(1)(b))
Store, format, edit and export your CV and other documentsCV, job descriptions, cover letters, tracker content, offers, portfolio, practice answersPerformance of a contract with you. We draw no conclusion from any special category information a document happens to contain, so no Article 9 condition is engaged by holding it. See section 5.1
Run the artificial intelligence features you ask forWhatever the feature needs, as set out in section 7Performance of a contract with you. Where a document contains special category information, our additional condition is your explicit consent. See section 5.1
Keep a draft CV for you before you have an accountGuest identifier, draft CVOur legitimate interests, and yours, in not losing work you have started before you decide whether to sign up. We set the identifier at the moment you first create or edit something, not when you arrive
Take payment, manage your subscription and issue receiptsEmail, subscription status, planPerformance of a contract with you
Keep our accounting and tax recordsTransaction recordsCompliance with a legal obligation
Verify your phone number, where that feature is switched onPhone numberOur legitimate interests in keeping accounts secure and preventing abuse
Send you service messages, such as sign-in links, security alerts, receipts and notices about changes to these termsEmail addressPerformance of a contract with you. Where we have to tell you about a personal data breach, our basis is compliance with a legal obligation under Article 34 of the UK GDPR
Send you marketing email, if we start sending it. We do not send any at the momentEmail addressYour consent, which we ask for with an unticked box when you create your account and which you can change at any time in Settings under Notifications. Every message would carry an unsubscribe link that works without signing in, and our postal address
Apply usage limits, detect abuse, prevent fraud and keep the Service secureIP address, account identifier, request metadata, security and abuse logsOur legitimate interests in protecting the Service and our users, and in the security of our network and information systems
Diagnose faults, and record whether a request or a background job succeededError reports as described in section 12, server side events carrying an account identifierOur legitimate interests in a working product. You can object
Understand which features are used, and improve the ServiceProduct analytics events sent from your browserYour consent, given through our cookie banner. If you do not consent, we do not set anything in your browser and we do not send browser events
Learn from patterns in what works, where you have opted inAnonymised metadata about a generated message or a saved course, with no reference to youYour consent, given in the tool. You can withdraw it at any time and we will stop
Improve how we match what you type to a real company. When you search for an employer and pick one from the results, we keep the words you typed and the company you chose, so the next person searching for the same thing finds it fasterThe search term and the company chosen. Not linked to you and not part of your account. A search term is whatever you typed into the company box, so if you type a person's name that is what we keep. If nothing matched what you typed, we keep the words on their own with a count of how often they come upOur legitimate interests in a product that works better the more it is used. Nothing identifying you is kept. A pairing that several different people have confirmed we keep, because by that point it is a fact about the company rather than about anyone. A pairing only one person ever made, and a search term where nothing matched, we delete after twelve months. If you ask us to remove a particular search term we can find it and delete it, because the record is keyed on the words themselves
Assess reports of illegal or prohibited content, remove content, suspend or close accounts, and report content to the police or another authority where the law requires itThe reported content, the account behind it, and our record of what we didOur legitimate interests, and those of others, in keeping the Service lawful and safe, and our legal obligations under the Online Safety Act 2023. See the note below the table
Hold and return information about people who are not our users, such as a recruiter named in a job advertisement or a referee named in a CVName, job title, employer, business contact details, the source documentOur legitimate interests, and our users' legitimate interests, in operating a job search service. See section 4.5
Handle your data protection requests and complaintsWhatever is needed to answer youCompliance with a legal obligation
Establish, exercise or defend legal claimsWhatever is relevantOur legitimate interests in defending ourselves. See the note below the table

The conditions we rely on for sensitive and criminal offence information. Where we process special category information because you have chosen to include it, our condition is your explicit consent under Article 9(2)(a) of the UK GDPR, and for criminal offence information it is your consent under paragraph 29 of Schedule 1 to the Data Protection Act 2018. Where we process either kind of information in order to investigate a report that something on Jobtiv is unlawful, our conditions are the substantial public interest in preventing or detecting unlawful acts and in safeguarding children and individuals at risk, under paragraphs 10 and 18 of Schedule 1, extended to criminal offence information by paragraph 36. Where we process it to bring or defend a legal claim, our conditions are Article 9(2)(f) and paragraph 33 of Schedule 1. We keep an appropriate policy document covering the processing that requires one, and we will send you a copy on request. Our lawful basis under Article 6 in each case is the one given in the table.

Where we rely on legitimate interests, we have carried out and recorded a balancing assessment, and you can ask us for a summary of it.

We do not train artificial intelligence models on your content. We do not use your CV, your documents or your conversations to build, train, fine tune or improve any model of our own. Where we choose a provider, we choose one that commits not to train on what we send it, and section 7 sets out what each one has committed to.

Two limits on that. One of our providers, OpenRouter, is a routing service that passes content to a further company. We have configured our account to route only to companies that do not train on submitted content, but OpenRouter's own documentation says that setting governs routing and not every upstream company's own policy. Separately, some of the companies that provide our infrastructure use artificial intelligence providers of their own, listed on their own sub-processor pages. We check those pages when we review this policy and when a vendor tells us something has changed, and we record what we find in our Sub-processor List.


7. Artificial intelligence: what we send, and to whom

Most of what makes Jobtiv useful is done by artificial intelligence models operated by other companies. We do not run our own models. To use those features, your content leaves our servers.

You are entitled to know exactly what goes where, so this section is specific.

7.1 What each tool sends

ToolWhat is sentProvider
CV import and PDF parsingThe text of your CV. On our third parsing route, the entire PDF fileGoogle Gemini; LlamaParse (LlamaIndex) on the third route
Setup assistance and Studio Magic WriteYour CV content and the section you are editingGoogle Gemini, with OpenAI as a fallback
CV scoring reviewYour CV and, where you score against a role, the job descriptionOpenRouter
Cover Letter GeneratorExtracts from your CV, the full job description, the company name and your voice sampleAnthropic, or OpenRouter as a fallback
Salary Negotiator scriptsYour role, employer, location and your salary and offer figuresAnthropic, or OpenRouter as a fallback
Career Path MapYour work history and skills, and your target roleOpenRouter
Networking MessagesYour headline, selected bullets and skills, and the target company and roleGoogle Gemini, with OpenAI as a fallback
Find Recruiters outreach draftsThe company, the role and your relevant experienceAnthropic, with OpenAI as a fallback
STAR Answer BuilderThe story you wroteAnthropic
Job Description TranslatorThe job description. Not your CVAnthropic
Course FinderYour role and skill gapsGoogle Gemini, with OpenAI and Anthropic as fallbacks
Portfolio Builder assistanceYour portfolio copy and project descriptionsAnthropic, then OpenAI, then Google Gemini
Resignation LetterYour employer, role, notice period and the letter contentAnthropic
Case and aptitude practiceYour answers and the generated case textOpenRouter, which routes to an Anthropic model
Application Tracker smart pasteA job advert or screenshot you paste in and ask us to readAnthropic, with OpenAI as a fallback
Voice dictationThe audio you recordGoogle Gemini, with OpenAI as a fallback
PDF downloadYour rendered CV, sent to a headless browser to be printedBrowserless

OpenRouter is a routing service. It passes your content to a model operated by a further company. If you would prefer your content not to go through a routing service, do not use the CV scoring review, the Career Path Map, the cover letter editor, case and aptitude practice, or Salary Negotiator scripts.

7.2 What providers may do with it

Where we have a signed data processing contract with a provider, that contract makes the provider our processor. It may then only use your content to give us the answer we asked for, and not for its own purposes. Three of the companies in this section do not yet have a signed contract with us: OpenRouter, Browserless and LlamaIndex. Our Sub-processor List says so plainly, says what we are doing about it, and tells you which features are affected so you can avoid them if you would rather.

  • Anthropic commits contractually not to train its models on customer content.
  • OpenAI states that content sent through its interface for developers is not used to train its models unless we opt in, which we have not.
  • Google. We use Google's paid developer interface. Google processes content sent to it under its data processing addendum, as our processor, and does not use it to improve its own products or services.
  • LlamaParse states that uploaded documents are used only to return the parsed result and never for model training.
  • OpenRouter does not store prompts or responses unless logging is switched on, which we have not switched on. We have also switched off the account setting that would allow requests to be routed to model providers that train on what is sent to them.

Providers keep some content for short periods so they can detect abuse of their own systems. Those periods are set by them, not by us. On our accounts, Anthropic's retention is set to 30 days and OpenAI's request logging is switched off. Providers also reserve the right to keep content that their own systems flag for review for longer than their standard period, and we cannot reach into a provider's abuse monitoring records to delete something. That is the honest limit of what we can promise.

Once your content has been sent to a provider, deleting your Jobtiv account removes it from our systems and stops us sending anything further. It does not retrieve copies held by a provider under its own abuse monitoring retention.

7.3 If you would rather not

Every artificial intelligence feature is something you choose to use. You can build, edit, store, score against our own non-AI checks and download your CV, record and manage applications in the Application Tracker, and use the Salary Negotiator calculators without any of your content going to an artificial intelligence provider. Some individual actions inside those tools do use artificial intelligence, for example pasting a job advert or a screenshot and asking us to fill in the details for you. Those are things you choose to do, and we label them.


8. Scores, and decisions about you

Jobtiv produces a score for your CV, scores for aptitude and case practice, and suggestions in the Career Path Map. These are automated. They are generated by software and, in some cases, by an artificial intelligence model.

Three things about them:

1. They are for you. A score is shown to the person whose CV it is. We do not give scores, CVs, practice results or any other assessment of you to employers, recruiters, agencies or anyone else, and we do not sell or license our scoring to anyone who screens candidates. This is a commitment, not just a current practice. If we ever change it, we will tell you in advance and this policy will change first. 2. They do not decide anything. No score changes what you can do on Jobtiv, what you pay, or what we do for you. Nobody is refused anything because of a score. 3. They can be wrong. They are a prompt to think, not a verdict on your career.

Because we do not use these scores to make decisions about you, the rules in Articles 22A to 22D of the UK GDPR on solely automated significant decisions do not apply to them. We nonetheless give you the protections those rules describe: we tell you when an output is automated, you can tell us if you think a score is wrong, you can ask a person at Jobtiv to look at it, and you can ask us to explain it. Email support@jobtiv.ai.

Where we suspend or close an account under section 17 of our Terms of Service, a person at Jobtiv makes that decision. It is never made by software alone.


9. Who we share your information with

We do not sell your personal information. We do not share it with anyone for their own marketing. We do not disclose it to employers or recruiters.

We share it in six situations.

With companies that provide our infrastructure and features. These companies act on our instructions. Where we have a signed data processing contract in place, that contract requires them to keep your information secure, to use it only to provide their service to us, and to delete or return it when we ask. Our Sub-processor List names them, says what they do, what they see, where they are, whether a signed contract is in place, and what transfer safeguard applies. Where a contract is not yet signed, we say so.

With Stripe, for payment. Stripe processes your payment and, for parts of what it does, acts as a controller in its own right, because it has its own legal duties around fraud and financial regulation. Stripe receives your email address and an account reference. It does not receive your CV or any of your documents. Stripe's own privacy policy governs the parts of its processing where it is a controller.

With our own staff, in limited circumstances. Jobtiv is run by a very small team. We can look at an account's content when we need to: to answer a support request, to investigate a fault you have reported, or to look into suspected abuse. Access is restricted to a named list of accounts. Our internal tools that read another person's account or documents record who opened it and when, and we keep that record for 90 days. We are extending that to cover every such tool automatically rather than by a list somebody maintains, and we would rather tell you that than imply it is already everywhere. Tools that only flip a feature switch or show totals across all accounts do not read anyone's file. We do not browse accounts out of curiosity, and if we ever have employees, doing so will be a disciplinary matter.

With people you choose to share with. If you publish a portfolio page, create a share link for your CV, a tracker board, a learning plan, a negotiation summary or a resignation letter, or send a message you have drafted, then whatever you have shared goes to whoever you send it to or whoever has the link. Section 7 of our Terms of Service explains how those links work and how long they last. This is publication by you, not disclosure by us: you choose whether to publish, what to publish and, for a portfolio, what web address it sits at. Where you choose to publish information about yourself that falls into the special categories described in section 5, you are making it public yourself, and that is the basis on which we then host it.

Where the law requires it, or to protect people. We will disclose information if we are required to by law, a court, or a regulator with the power to compel it. We will also disclose it where we reasonably believe it is necessary to investigate a crime, to enforce our Terms of Service, or to protect the safety of any person. We will tell you when this happens unless we are legally prevented from doing so.

If our business changes hands. If Jobtiv is sold, merged or reorganised, your information may transfer to the buyer as part of the business. A buyer takes on the same obligations to you under data protection law that we have, and we will require, as a term of any sale, that it continues to handle your information in line with this policy unless and until it gives you notice of a change and, where the law requires it, asks for your consent. We will tell you that a transfer has happened, and we will tell you beforehand where we are able to. Some transactions are confidential until they complete. You can delete your account at any time, before or after.


10. Sending information outside the United Kingdom

Your documents are stored in the United Kingdom and the code that reads them runs here too. Our database is in London and our server code is set to run in London. When you score a CV, generate a letter or build a negotiation script, that work happens in the United Kingdom before anything is sent to the artificial intelligence providers named in section 7.

One part of our code cannot be placed in a single country, and we should say what it is. Before a request reaches the code that does the work, a small routing layer runs on our host's worldwide network, close to wherever you are. That is how the host is built and we cannot confine it to London. It reads the web address you asked for, the ordinary headers your browser sends, your sign-in cookie, the identifier we use to keep a guest draft, and, where you are opening a portfolio protected by a key, that key.

It does not read the contents of any request. No CV, no cover letter, no note and no salary figure passes through it. Two features that draw the preview image shown when a portfolio is shared also run on that network, and those do handle portfolio content.

Separately, several of the companies we work with are United States companies whose own staff can reach their systems from outside the United Kingdom, wherever those systems physically sit.

So some of your personal information does leave the United Kingdom. The most significant of those transfers are the artificial intelligence providers in section 7.

When we do that, we rely on one of the following, and our Sub-processor List records which applies to each company:

  • UK adequacy regulations. Some of the companies we work with are in the European Economic Area or in Switzerland, which the United Kingdom has decided provide an adequate level of protection. No further safeguard is needed for information we send to them.
  • The UK Extension to the EU-US Data Privacy Framework, where the company is certified under it, the certification is active, and it covers the type of information we send. We check and date each certification.
  • The International Data Transfer Addendum to the EU Standard Contractual Clauses, or the International Data Transfer Agreement, both issued by the Information Commissioner. Where we rely on either of these, the law requires us to assess whether the protection the safeguard provides would be materially lower than the protection United Kingdom law gives you. We carry out that assessment, which the legislation calls the data protection test, before we start sending information, and we review it.

Some of the companies in Part B of our Sub-processor List decide for themselves what they do with the small amount of information we send them, such as a company name or a search term. Where those companies are outside the United Kingdom, we rely on the same routes above, and the Sub-processor List says which.

Where we rely on the UK Extension to send information to a company in the United States, and that information may contain special category or criminal offence information, we tell that company in writing that it must treat what we send as sensitive. That is a requirement of the Framework and we do it in the contract. Where we rely on the Addendum or the Agreement instead, the same protection comes from the clauses themselves.

The transfers to look at hardest are the ones that carry the whole of your document out of the United Kingdom: the artificial intelligence providers named in section 7.1, and LlamaParse, which reads a PDF you upload when our own parser cannot. Browserless, which renders your CV into a PDF when you download it, used to belong on this list and no longer does: we use its London endpoint, so that rendering happens here. Our Sub-processor List records where each company stands.

You can ask us for a copy of the safeguards we rely on for any particular company by emailing support@jobtiv.ai.


11. How long we keep your information

The short answer is that we keep the things you create until you delete them or you delete your account, and we delete operational records on a schedule.

11.1 Kept until you delete it

We do not put a time limit on the following, because it is your working material:

Your profile, your CVs, your cover letters and voice profile, your applications, notes and tracker settings, your negotiation sessions and encrypted offer details, your portfolios and projects, your career journal and watchlist, your aptitude sessions and answers, your study progress, your custom dictionary, your feedback, and your subscription record.

If you stop using Jobtiv and never come back, this material stays until you delete your account. You can delete individual documents at any time, and there are separate controls to delete all your cover letter data and to clear the Application Tracker.

11.2 Deleted on a schedule

WhatHow long
Public CV share snapshots90 days from creation. The link stops working at 90 days whether or not the record has been swept
Resignation letter share links48 hours. The link stops working at 48 hours, and the record is deleted by a nightly job
Negotiation summary share links7 days. The link stops working at 7 days whether or not the record has been swept
Learning plan and course share links30 days. The link stops working at 30 days whether or not the record has been swept
A link you create to share your application tracker boardIt does not expire on its own. It stays live until you switch it off, create a replacement, which switches the old one off, or delete your account, which deletes it. While it is live, anyone holding the link can see the board
Guest identity cookie30 days
A CV drafted by a visitor who never creates an account30 days from the day it was created
Our internal record of a guest draft that was never claimed90 days. It holds the draft's reference and no contact details
Sign-in session cookie7 days
Portfolio password cookie24 hours
Recruiter lookup results, cached so the same search does not have to be run twiceUp to 30 days
Cached drafts of recruiter outreach messages90 days
Parsed CV cache, so the same file does not need parsing twice. It is held against your account7 days in our short term cache. 14 days in our database, after which a nightly job deletes it
Cached result of a CV scoring review or analysis, held against your account so the same document does not have to be scored twice7 days
Working copy of a CV held while a PDF is being producedUp to 30 minutes, deleted by a timer. Thirty minutes is how long a failed export needs to finish retrying, so a shorter figure would mean the retry failing for want of the file it was working on
Records of artificial intelligence calls, tool usage events, server side analytics and generated message text90 days
Our hosting provider's record of requests to the site: the web address asked for, the time, and technical details of the request. It holds no document content30 days. We keep this rather than the shorter default because if something goes wrong we need enough history to find out what, and a one day window would often be gone before anyone had looked
Company research cache105 days
The words you type into the company box. Where you picked a company, the pairing. Where nothing matched, the words with a countA pairing several people have confirmed, kept. A pairing only one person made, and words where nothing matched, 12 months. The same words also sit in a queue we use to decide which companies to add next, on the same periods
Our record that an account deletion ran6 years, so we can show we did what we said. It holds the date, the steps, the outcome and counts, never the content of what was deleted
Our record that you downloaded a copy of your dataUntil you delete your account, at which point it is deleted with everything else linked to the account
A minimal record of a security or abuse incident: type, date, and a one way hash of the email address2 years
Accounting and tax records6 years from the end of the financial year, as required by the Companies Act 2006 and by HMRC

Deleting your account does not reach everything. Section 13.4 sets out exactly what survives and why, and it is worth reading before you delete rather than afterwards.


12. How we protect your information

We are a small company and we do not pretend to be a bank. Here is what we do.

  • Access control in the database. Row level security is switched on for every table that holds your information, with one documented exception which is a lookup cache of company names holding no personal information at all. A direct query made with your sign-in credentials reaches only your rows, and a number of our tables are locked so that no direct query reaches them at all. Our own server code holds a privileged database credential, because it has to write records you cannot write yourself, and it restricts every read and write to your account identifier in code rather than relying on the database to do it. Both layers are reviewed and access to the privileged credential is limited.
  • Encryption. Traffic to and from the Service is encrypted in transit. Data is encrypted at rest by our database provider. Your salary and offer figures are additionally encrypted in the database with a separate key, so they are not readable even to someone who could read the table. The negotiation scripts generated from them are stored in the ordinary way, protected by the same access controls as the rest of your account but not separately encrypted.
  • Error reports are stripped before they leave us. When something breaks, the report we send to Sentry keeps only the type of error, the code path, and an anonymous account identifier. We remove the request body, the headers, the cookies and the query string. We remove the content of breadcrumbs. We replace the value of any field whose name looks like a salary, an offer, a CV, a token, a password, a cover letter or a negotiation, and we cut any string longer than 240 characters. We have an automated test covering this and we run it on every change.
  • Rate limits and abuse controls on every route that costs money or could be abused.
  • Payment card details never reach us. Stripe collects them on its own systems.

No service is perfectly secure. If there is a breach that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner without undue delay and, where we can, within 72 hours of becoming aware of it. If we cannot manage 72 hours we will say why when we report. If the risk to you is high we will tell you directly and without undue delay. If you are in the United States, we will notify you and the relevant authorities in line with the law of the state you live in.

If you find a security problem, please tell us at support@jobtiv.ai. We will not take action against anyone who reports a genuine vulnerability to us in good faith and gives us a reasonable chance to fix it.


13. Your rights

If you are in the United Kingdom, the UK GDPR gives you the following rights. We do not charge for exercising them.

You can stop our marketing emails at any time, for any reason or none. This is an absolute right. You do not have to give a reason, we cannot refuse, and there is no exception to it. Click unsubscribe in any message, switch it off in Settings, then Notifications, or email support@jobtiv.ai. We will stop.

13.1 What you can ask for

A copy of your information. You can download a machine readable copy of your account at any time: go to Settings and choose Download a copy of my data. You can do this three times an hour. The file contains your profile, your subscription plan and status, all your CVs, your cover letters, your tracker applications, notes, contacts and status history, your negotiation sessions including the decrypted offer figures and script text, your portfolios and projects with any password removed, and your live share links.

The file lists what it does not include, which is: cost and usage logs, internal processing logs, analytics events, hash keyed caches, admin and abuse records, public CV share snapshots, copies held by Stripe, PDFs we generated for you, and aptitude, recruiter lookup and networking records.

If you want the conclusions our software has drawn about you, including your aptitude scores, your recruiter lookup results and your networking records, ask us and we will send them. Some United States state laws give you a right to those, and we give them to everyone who asks.

You also have the right to ask us in writing what we hold, why we hold it, who we share it with and how long we keep it. We will respond within one month. If your request is complex or you have made several, we may extend that by up to two further months, and we will tell you within the first month if we do. If we need to confirm who you are, or to ask what you are looking for, the clock pauses while we wait for your answer. We search for your information in a way that is reasonable and proportionate, which is the standard the law sets.

Correction. You can edit your CV and almost everything else directly in the product. If something is wrong and you cannot fix it yourself, tell us and we will.

Deletion. See 13.3 and 13.4.

Restriction. You can ask us to stop using your information while we look into a complaint about its accuracy or our use of it.

Objection. Where we rely on legitimate interests, you can object and we will stop unless we can show compelling grounds that override your rights.

Portability. The download described above is your portable copy. If you want it sent directly to another service, ask us and we will do it where it is technically possible.

Withdrawing consent. Where we rely on consent, you can withdraw it at any time. That does not affect anything we did before you withdrew it.

13.2 How to make a request

Email support@jobtiv.ai with "Data request" in the subject line, or write to the registered office. Tell us what you want. We may need to check you are who you say you are, which usually means confirming from the email address on the account.

13.3 Deleting your account

Go to Settings, then Danger zone, then Delete my account.

When you do that, in this order, we:

1. Delete your stored CVs. 2. Delete the files keyed to your account in our file storage: portfolio screenshots, PDF exports and any practice audio. 3. Delete your generated networking messages and the event records that would otherwise hold their text. We keep a minimal record of any security or abuse incident on your account: the type of incident, the date, and a one way hash of your email address. We keep it because we are entitled to defend the Service against someone who closes an account and opens another, and because we could not otherwise apply section 17 of our Terms of Service fairly. It holds nothing you wrote and it cannot be read back into an email address. 4. Cancel any active paid subscription, so you are not billed again. 5. Ask our analytics provider to delete the person record for your account. 6. Delete your sign-in account, which removes your email address, your password and your authentication details. 7. Write a record that the deletion ran, holding the date, the steps and their outcome, but none of your content.

If any of steps 1 to 4 fails, we stop and do not delete your sign-in account, so nothing is left orphaned and you are never left paying for an account we have closed. If step 5 fails, we still close your account and we tell you that the analytics deletion is outstanding. Email us and we will complete it by hand.

Almost everything else in our database is set to delete automatically when your sign-in account goes. That covers your profile, applications and notes, tracker settings and share links, cover letters and their outcomes, negotiation sessions and offer details, remaining coach records, portfolios and projects, your career journal and watchlist, aptitude sessions, your subscription record, your export log and your custom dictionary.

Your browser is signed out and the Jobtiv data held in that browser's local storage is cleared. Other browsers and devices you have used keep their local copies until you clear them.

13.4 What deletion does not reach

This is the part most privacy policies leave out. We are telling you because it matters.

What staysWhy
Public CV share links you createdThese snapshots are stored without an account reference, so we cannot find yours to delete them. The link stops working 90 days after it was created. If you have created a share link and you want it gone before you delete your account, delete the link first.
Your Stripe customer record and invoicesWe are required to keep records of payments for accounting and tax. We cancel the subscription. We do not delete the payment record
Analytics events recorded against a shared server identifierOur request to delete your analytics person record covers events tagged with your account identifier. A small number of server side events are recorded against a shared identifier with your account in a property, and those are not picked up by that request
Shared caches that hold no reference to youSome results are cached so the same work is not repeated: company research, recruiter lookups by company domain, and exact matches of a generated piece of text. These are keyed by what was asked for rather than by who asked, and they carry no account reference, so there is nothing in them to find and delete. They expire on the schedule in section 11.2. The caches that hold your own documents, including the parsed CV and the scoring review, are held against your account and are deleted when you delete it
Job description fingerprints and anonymous market outcomesThese have no account reference by design and cannot be traced back to you
Error reportsThese hold no content, only an anonymous identifier and a code path. There is no per person deletion route for them. We stop sending anything about you once your account is gone
Records held by our artificial intelligence providersAs explained in section 7.2. Providers keep short term abuse monitoring records under their own policies
Phone verification records at Twilio, if you verified a phoneWe do not store a reference we could use to ask Twilio to delete a specific record. Twilio's own retention applies, and is normally about 30 days
Emails we have already sent youOur email provider keeps a delivery log
Anonymised operational records, such as practice game scores, parser usage and cost recordsYour account reference is removed. What is left is a number and a timestamp
BackupsOur backups are encrypted and are overwritten on a rolling cycle. A copy of a deleted record may remain in a backup until that cycle completes. We do not restore a backup in order to bring deleted data back
A minimal record that a security or abuse incident happenedThe type, the date and a one way hash of your email address. Section 13.3 explains why. It holds nothing you wrote

If you want us to go further on any of these, email us and we will do what we can and tell you honestly what we cannot.

13.5 Complaining

If you are not happy with how we have handled your personal information, tell us. Email support@jobtiv.ai with "Data protection complaint" in the subject line, or write to us at the registered office. You can also raise it with any member of our team by any means you like, in any form, and we will treat it as a complaint. We are building an online form and will link it here when it is ready.

We will acknowledge your complaint within 30 days of receiving it. We will look into it properly and tell you the outcome without undue delay.

You do not have to complain to us first, and there is no waiting period. You can complain to the Information Commissioner's Office at any time:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Telephone 0303 123 1113 ico.org.uk/make-a-complaint


14. Children

Jobtiv is for adults. You must be 18 or over to use it. We ask for your date of birth when you create an account and check it, and we keep only whether you are over 18 and the date you told us, not the date of birth itself. It is a self declared answer and we do not verify it against a document. We do not knowingly collect personal information from anyone under 18.

If you believe someone under 18 has created an account, email support@jobtiv.ai and we will close it and delete the information.

We are aware that a service about finding work may attract people who are 16 or 17, and that a line in our terms is not on its own enough to establish that they are not using it. We do not design for them, market to them, or build features intended to appeal to them. We keep this under review against what our own figures show, and if under 18s are in fact likely to be using Jobtiv we will treat it as a service likely to be accessed by children and put the additional protections that requires in place.


15. Cookies and similar technologies

We use a small number of cookies and browser storage entries. Some are essential and some are not. Our Cookie Notice lists every one of them, explains what it does and how long it lasts, and tells you how to change your choices.

We do not use advertising cookies. We do not use advertising networks. We do not track you across other websites.


16. Changes to this policy

We will update this policy when what we do changes. The date at the top always shows the current version.

If a change is significant, we will tell you by email or with a notice in the product before it takes effect, and where the change means we would be using your information for something materially different, we will ask for your consent.

We keep previous versions and will send you one on request.


17. If you are in the United States

Jobtiv is a UK company, and everything above applies to you. This section adds the rights and disclosures that United States law requires. It is written to the standard set by the state privacy statutes generally, not only to the ones that apply to a company of our size today.

17.1 What we collect, in the categories US law uses

CategoryDo we collect itExamples
IdentifiersYesName, email, postal address in a CV, phone, IP address, account identifier
Customer records informationYesName, address, telephone number, employment
Protected classification characteristicsOnly if you put them in your documentsSee section 5
Commercial informationYesSubscription plan, purchase history
Internet and network activityYesPages and features used, request logs
Geolocation dataYes, coarse onlyWe work out a country or region from your IP address, for security and for tax. We do not collect device location, and we do not collect precise geolocation as United States state law defines it
Audio, visual or similar informationYesImages you upload to a portfolio, and any voice recording you make in a feature that offers dictation
Professional or employment related informationYesThis is the core of the Service
Education informationYesWhatever is in your CV
InferencesYesCV scores, aptitude scores, suggested career paths
Sensitive personal informationYes, in two waysYour account password and sign-in credentials, which we hold for every account. And, only if you put it in your documents, information such as your immigration or work authorisation status, racial or ethnic origin, religious beliefs, union membership or health
Biometric informationNo

We collect all of it for the purposes in section 6 and we keep it for the periods in section 11.

17.2 We do not sell or share your personal information

We do not sell your personal information and we do not share it for cross context behavioural advertising. We do not run advertising of any kind. Some state laws define a "sale" widely enough to include an exchange of information for something other than money. We have looked at that: we pay the companies in our Sub-processor List, they do not pay us, none of them gives us anything in return for your information, and we do not contribute your information to anyone's database. We have not sold or shared the personal information of any consumer, including any consumer under 16, at any time since Jobtiv launched.

Because of that, we do not display a "Do Not Sell or Share My Personal Information" link. It would be misleading to offer an opt out of something we do not do.

We use sensitive personal information only to provide the service you asked for, to sign you in, and for security and fraud prevention. Those are purposes state law permits without an opt out, and we do not use sensitive personal information to infer characteristics about you. Because of that, we do not display a "Limit the Use of My Sensitive Personal Information" link.

We do not use your personal information to train large language models, our own or anyone else's, and section 6 sets out the two limits on what we can promise about the companies we send content to.

17.2A Sensitive information and your consent

Some of the information a CV or a document can contain is treated as sensitive under state law. That includes your racial or ethnic origin, your religious beliefs, your citizenship or immigration or work authorisation status, your physical or mental health condition or diagnosis, your sexual orientation or your status as transgender or nonbinary, your union membership, and government issued identifiers.

We do not ask for any of it, and there is no field anywhere in Jobtiv for it. But documents contain what people write in them.

We ask for your permission before we process it. The permission we ask for, what it covers, how you withdraw it and what happens when you do are set out in section 5.1. It is offered to every user, wherever you live, it is not bundled into anything else, and the box is not pre ticked.

We use sensitive information only to store the document you wrote it in and to run the tool you asked us to run. We do not use it to profile you, to advertise to you, to train any model, or to make any decision about you.

17.3 Your rights

Depending on where you live, you may have the right to:

  • Confirm whether we process your personal information and access it. That includes the conclusions our software has drawn from what you gave us, such as your CV score, your aptitude scores and the suggested paths in the Career Path Map, and it includes a list of the specific companies we have disclosed your personal information to, not just the kinds of company. If your state gives you the right to that list, ask us and you will get names.
  • Correct inaccurate personal information.
  • Delete personal information we hold about you.
  • Obtain a copy in a portable and readily usable format.
  • Opt out of the sale of personal information, of targeted advertising, and of profiling in support of decisions that produce legal or similarly significant effects. We do none of these things, so there is nothing to opt out of.
  • Not be discriminated against for exercising any of these rights. We will not deny you the Service, charge you a different price, or give you a worse product because you made a request.

17.4 How to exercise them, and how to appeal

Email support@jobtiv.ai with "Privacy request" in the subject line, or use the same Settings controls described in section 13, which are open to everyone.

We will respond within 45 days. If we need more time we will tell you within that period and take up to a further 45 days. State law lets us charge for a third or subsequent request in any 12 month period, or for a request that is plainly excessive or repetitive. We do not intend to charge anyone, and if we ever did we would tell you the amount before doing any work.

If we refuse your request, you can appeal. Reply to our decision or email support@jobtiv.ai with "Privacy appeal" in the subject line. We will decide the appeal within 60 days and write to you with our reasons. If we refuse the appeal, you may complain to the Attorney General of your state. We will give you the link when we write to you.

Authorised agents. You may use an authorised agent. We will ask for written proof that you gave them permission, and we may ask you to confirm it directly.

17.5 Notice for California residents

The CCPA thresholds do not currently apply to us. We offer California residents the rights above in any event. Requests to know cover the 12 months before the request. You may ask us for information going back further, to 1 January 2022, and we will provide it unless doing so would be impossible or involve disproportionate effort, in which case we will tell you so and explain why.

17.6 Health related information

If you type information about your physical or mental health into a document or a conversation, and you live in Washington, Nevada or Connecticut, that is treated as consumer health data under the law of your state. Our separate Consumer Health Data Privacy Policy, linked from our homepage, explains what we do with it and what rights you have. We do not sell consumer health data and we never will.

17.7 Contact for US privacy matters

support@jobtiv.ai, or JOBTIV LTD, 124-128 City Road, London, EC1V 2NX, United Kingdom. We have no United States establishment. That does not affect your rights or our obligations to you.


18. Questions

Email support@jobtiv.ai.


JOBTIV LTD, registered in England and Wales, company number 17092844. Registered office: 124-128 City Road, London, EC1V 2NX.


The other documents

These five documents work together, and each is a page on this site.

  • Terms of Service
  • Cookie Notice
  • Sub-processor and Recipient List
  • Consumer Health Data Privacy Policy

If any of these links does not work, tell us at support@jobtiv.ai and we will fix it. A legal page that does not load is a problem whatever it says.