Privacy policy

NoBoards is designed so you can inspect live roles and test compatibility preferences before creating an account.

Service operator

NoBoards is operated by the service operator identified with this deployment. Privacy questions and requests may be sent to [email protected].

Information we process

When you create an account, we store your name, email address, authentication records and active sessions. If you use Google sign-in, Google supplies the basic account information required to sign you in. Compatibility choices used on the public preview stay in your browser unless you deliberately save them to your account. You may name and save separate compatibility searches; these contain normalized filter criteria, not your reusable application-answer profile. To show roles found since your previous visit, we store only the catalog timestamps observed for your current and previous visit sessions. You may optionally save a separate application-answer profile with contact details, current location, employer and title, profile links, named work-authorization regions, timing or compensation wording, referral source and custom question-and-answer pairs. If you use the opportunity queue, we store role identifiers and the stages you choose. If you create an alert, we also store its compatibility criteria, delivery state and queued role identifiers.

How we use it

We use account information to provide and secure the private workspace, maintain sessions, prevent abuse, verify email ownership, recover account passwords and deliver compatible-role alerts you request. If you save an application-answer profile, fixed matching rules compare it with application questions already collected from public job sources and show copy-ready suggestions for your review; no language model is called for this matching. Resend processes verification, password-reset and alert emails when mail delivery is enabled. We use job and interaction data to operate, debug and improve the service. We do not sell personal information.

Billing and payments

If you start a paid subscription, Stripe processes the billing contact and payment information needed to complete Checkout, manage renewal and handle billing support. NoBoards stores Stripe customer, subscription and checkout identifiers, subscription and payment status, and the product access attached to your account. We do not receive or store full card details, and we do not retain raw Stripe webhook payloads.

Job-source data and external links

Role information and application questions come from employers, applicant tracking systems and public job sources. Opening an original posting takes you to a third-party site with its own privacy practices. NoBoards does not automatically fill or submit external application forms, and saved answers are not sent to an employer or job platform by the suggestion feature.

Alert choices and recovery safety

When you explicitly enable or disable compatible-role alerts, we keep a restore-safety marker in a separate ledger that ordinary backups do not overwrite. It contains a one-way fingerprint of your immutable account identifier, the enabled or disabled choice, a monotonic decision version and timestamps; it contains no email address, raw account identifier, unsubscribe token, alert criteria, role identifier or mail-provider payload. Unsubscribing records disabled, explicitly re-enabling records enabled, and deleting the account records disabled before its live alert state is removed. We use this marker only to stop recovery from reversing your latest alert choice, and retain it only as long as an older backup, replica or other recovery copy that could contain the corresponding alert state can exist.

Retention and security

Account data is kept while your account is active and for a limited period afterward when required for security, legal or operational reasons. Opportunity stages remain until you remove them or delete the account. Alert email payloads are redacted when delivery finishes, and readable terminal job-interest history is removed after 90 days. We retain only keyed, non-readable event fingerprints to prevent duplicate alerts; deleting the account removes those fingerprints along with its live sign-in, saved compatibility preferences and named searches, catalog-visit timestamps, opportunity queue, alert subscription and queued alert candidates. After deletion, one-way fingerprints of the former Stripe account, Checkout and subscription identifiers are retained only as long as operationally necessary to stop delayed provider events from recreating access or an account; these tombstones contain neither the raw Stripe identifiers nor billing contact or card information. A separate recovery ledger retains a one-way fingerprint of the deleted account's immutable internal identifier and the deletion time for at least as long as an older recovery copy could contain that account. It contains no email address, raw account identifier, Stripe identifier or provider payload and is used only to prevent a restore from recreating deleted account and product data. Restricted operational backups may contain earlier account state until their configured retention period expires; they are used only for recovery, and the recovery process automatically checks the deletion ledger before a restore commits. We use access controls, signed sessions and encrypted transport in production, but no internet service can guarantee absolute security.

Your choices

You may browse public roles without an account. Every alert email includes an unsubscribe action, and you can pause an alert or permanently delete your account from the private workspace. You may also request access or correction by contacting [email protected].

Changes

We may update this policy as the product changes. Material changes will be identified by a new effective date.

Effective 31 July 2026