jobCerno
Back to jobCerno

Privacy Policy

Last updated July 25, 2026

jobCerno is in private beta. This document describes what the software actually does with your data, but it has not been reviewed by a lawyer — treat it as a plain-language description rather than legal advice.

jobCerno is a job search engine. This policy describes exactly what data it collects, where that data goes, and what it never touches. It is written from the software’s actual behaviour rather than from a template, so where something is unusual — good or bad — it is stated plainly.

The short version

  • There is no analytics, no tracking, and no advertising cookies. None.
  • Your resume is read in your browser and never uploaded to us.
  • Your password is never sent anywhere to be checked against breach lists.
  • We never store your IP address in readable form.
  • We do not sell your data, and there is nobody to sell it to.

What we store about you

Your account. Your email address, and either a hashed password (scrypt, with a random per-account salt — the password itself is never stored) or an opaque Google account identifier if you sign in with Google. When you use Google, we request only your email address: not your name, photo, contacts, or anything else.

Your saved jobs. The listings you bookmark, stored with a copy of the listing so it stays readable even after the employer takes it down.

Sign-in security records. A hashed session token, and for email codes, the email address, a hashed code, and a hashed IP.

Beta access requests. If you ask for access, the email address and any note you write.

What we never store: your resume, your chat conversations, your search history, or your IP address in raw form.

Your resume never leaves your browser

When you attach a PDF resume, it is opened and read entirely on your own device. There is no upload endpoint, and no copy is kept on our servers. Closing the tab discards it.

The one exception, stated precisely: if you use the chat, we send up to 40 extracted skill keywords to our AI provider so it can tailor its questions and results. Those keywords are matched against the vocabulary of real job listings — they are terms like “registered nurse” or “curriculum design”, not raw text from your document, and never your name, address, or employment history.

IP addresses

We use your IP address to rate-limit abuse, and we store it only as a keyed cryptographic hash — never in readable form. Being precise about what that does and doesn’t buy you: the hash is pseudonymous, not anonymous. We cannot read an address back out of it, but the same address always produces the same hash, so requests from one address can be correlated with each other.

If you let the app guess your location, that is derived from network information already attached to your request by our host and returned straight to your browser. It is not stored, and no third party is contacted.

Passwords

New passwords are checked against public breach databases so you don’t reuse a compromised one. Your password is not sent to do this. Your browser hashes it locally and sends only the first five characters of that hash; the comparison finishes on your device. Neither we nor the breach-list service ever sees the password or the full hash.

No tracking

There are no analytics packages, no tracking pixels, no session recording, no advertising identifiers, and no third-party scripts of any kind. The only script the app loads besides its own is the one that applies your chosen colour theme before the page paints. A strict Content-Security-Policy blocks third-party scripts even if one were introduced by mistake.

Cookies and browser storage

Four cookies, all first-party, all strictly functional, none readable by JavaScript: your sign-in session, proof that you entered the beta password, and two short-lived cookies protecting the Google sign-in handshake. There are no advertising or analytics cookies.

Your browser also stores your theme choice, whether the sidebar is collapsed, a flag noting you have an account, and your saved searches. Saved searches stay on your device and are never sent to us.

Who else sees your data

We rely on these services, and this is what each one receives:

  • Anthropic and Groq — your chat messages and the resume keywords described above, to generate replies and rank roles.
  • Google (Gemini) — a short written summary of the kind of work you said you want, used to find semantically similar listings.
  • Google (Sign-In) — only if you choose to sign in with Google.
  • Resend — your email address and verification codes, and beta access requests including any note you wrote.
  • Neon — the database host for everything listed above.
  • Vercel — application hosting, including standard server request logs.
  • OpenStreetMap (Nominatim) and Zippopotam — a place name or ZIP code you typed, in order to turn it into coordinates. These requests are relayed through our servers, so your IP address is not exposed to them.

Job listings are collected from public job boards and employer career sites. Those requests contain no information about you.

Two things worth knowing

Company logos. Employer logos are loaded from Google’s public favicon service directly by your browser. That means Google can see your IP address and which employer’s logo is being displayed. We are calling this out because it is the one place the app does not shield you from a third party.

Voice mode. Speaking to the assistant uses your browser’s built-in speech recognition. In Chrome and Edge, that sends audio to the browser vendor for transcription. We never receive or store audio — only the resulting text, as if you had typed it.

How long we keep things

Account data and saved jobs are kept until you ask us to delete them. Sessions expire after 30 days. Email verification codes expire after 10 minutes, and their records are cleared out by routine daily maintenance. Rate-limiting records are discarded after two days.

Your choices

Email [CONTACT EMAIL] to get a copy of your data, correct it, or delete your account. Deleting your account removes your saved jobs and sign-in records. You can clear browser-stored data (theme, saved searches) at any time through your browser settings.

jobCerno is aimed at people looking for work in the United States and is not directed at children under 13.

Changes and contact

If this policy changes materially while you have an account, we will tell you by email. For anything else, contact [LEGAL ENTITY NAME] at [CONTACT EMAIL].