Privacy
This page describes the data behavior in the current Joobzi beta. It doesn't describe future advertising, payments or integrations.
Private job and resume text
When you run a tool, the job or resume text is sent to Joobzi's private API. It is encrypted for temporary server-side processing. It isn't published in a result URL, sitemap, advertisement or public page.
The current workflow marks pasted text as ephemeral. The default maximum retention is two hours. A completed check wipes the ciphertext, initialization vector and authentication tag. Most failed checks do the same immediately.
A paused check can retain encrypted input so the operation can be handled safely. An abandoned input becomes eligible for the stale-input sweep after 15 minutes and is also covered by the two-hour expiry. A time-bound legal hold can block deletion.
After a cryptographic wipe, a restricted database row can retain the input type, content hash, byte size, retention purpose and deletion timestamps. Joobzi also stores structured analysis data such as the decision, evidence, uncertainty and corrections. It doesn't store that structured result on a public page.
Anonymous sessions
Joobzi creates a signed, HTTP-only session cookie when a private tool or session endpoint is used. The cookie uses SameSite=Lax and a site-wide path. Its default lifetime is 30 days.
The server stores an anonymous identifier, session timestamps, consent version, rate-limit records and tool records. Network information is reduced to a derived rate-limit key rather than stored as raw private input.
Entitlement-only accounts
If free accounts are enabled, Joobzi stores a normalized handle, a salted passphrase hash, account and session records, and analysis allowance records. It doesn't store the passphrase itself.
These accounts exist for quota continuity. There is no email address, email recovery, marketing signup, saved upload library or paid subscription.
Internal events and measurement
Joobzi keeps a first-party event ledger for operations, privacy controls, product quality and tool state. Approved event payloads can include a route, event name, consent state, timestamps, byte size or a hashed anonymous identifier.
Raw job text, resume text, email addresses, private results, ciphertext, secrets and content hashes are forbidden from event payloads. The current cleanup default removes stale event rows after 30 days.
Umami, GlitchTip, AdSense and other third-party analytics or advertising integrations are disabled for this beta.
Data uses that are disabled
Joobzi doesn't use uploads, paid AI, public job ingestion, email capture, advertising, affiliate tracking, payments or employer workflows in the current beta.
Private session data is blocked from public pages, sitemaps, ads, affiliates and public structured data.
Deletion and its limits
Private text is wiped as described above. Account deletion removes credentials and entitlement data, revokes active account sessions and marks the account deleted.
A deleted account leaves a tombstone with its status and deletion time. Access-controlled audit records can also remain. Legal holds can delay deletion. Deleting an account doesn't by itself delete the separate anonymous session.
The code can revoke and delete anonymous-session data, including linked private inputs, analyses, consent records and event payloads. There is no approved public control or contact route for that request yet. This is a launch blocker.
Policy status and changes
This beta notice was last reviewed on 19 July 2026. It must be updated if Joobzi's data behavior changes.
The operator identity, privacy contact, legal basis, regulator details and approved launch regions are not final. Production traffic stays blocked until those facts are approved.