find your role first.

Policy

Privacy

Honestly, the site processes some information the moment you load it, and more if you subscribe. This page says what that is.

Contact support@findyourrolefirst.click for account or privacy requests. Please don't send resumes, identity documents, payment cards, or full API keys.

What we process

Hosting providers see network and request data: IP address, path, time, and device headers. The app hashes the IP for rate limits. A hash isn't anonymous. Search parameters are processed to answer the request. We don't keep a free-text search history in an account table. Provider logs may still record query strings.

We previously collected names, emails, and countries for a waitlist. New signups are closed. Earlier messages included an unsubscribe link, which still works. Existing records remain until we set and publish a deletion schedule.

If you create an account, we store your checkout email, an account ID, agent-key hashes and prefixes, browser-session token hashes, subscription status, paid-access dates, usage totals, and the source job IDs already delivered to you. Agent keys pass through API authentication. A separate token in an HttpOnly cookie signs in your browser; the database stores only its hash. We can send a short-lived, single-use sign-in link to your checkout email. The link token is stored as a hash, and the email never contains an agent key. Signing in doesn't replace your agent keys.

For the first-month offer and referrals we also store your referral code, which account referred yours (if any), whether and when a referred account paid, a normalized form of your email so the offer is used once per person, the single-use discount code issued to your account, and any referral refunds. Someone who referred you can see a count of their referrals that paid, never who you are.

Public job metadata lives in a separate store from account records. The billing provider processes payment and contact details when you subscribe. We don't store full card numbers in the Find your role first database.

Who sees it

Cloudflare serves the frontend and proxies API and MCP traffic. Railway runs the backend and database. Resend sends account access links. If you sign in with Google, Clerk handles that sign-in and tells us your Clerk user ID and the email address on your Google account; we store those two things and nothing else from it, and Clerk's own script runs only on the account page. We use that data to authenticate, return jobs, meter usage, stop abuse, send those emails, and answer support. Your own AI client receives the jobs you request and applies its own policies. Opening an employer link sends you to a different site. Company logos load from Logo.dev, so your browser asks Logo.dev for each logo by company name; that request carries your IP address and browser details, as any image request does, and nothing about your account.

The site has no advertising scripts. Cloudflare Web Analytics counts page views on our public pages: it sets no cookies and doesn't identify you, and it records the page, the referring site, your country, and your device and browser type. Live responses include Cloudflare Network Error Logging headers, which can report failed network requests to Cloudflare.

Cookies

jf_session authenticates the browser account. It lasts up to 30 days and uses SameSite=Strict. jf_checkout binds checkout to the originating browser for one day and uses SameSite=Lax, so the payment provider can return you here. Both are HttpOnly. jf_ref holds a referral code from a link you opened, for up to 30 days, so the sign-in that follows can credit whoever shared it; it uses SameSite=Lax and carries no access. They're Secure on HTTPS. Logout clears the session cookie. Blocking them breaks the browser account flow. API clients use a bearer header instead.

How long it stays

Change records and old closed jobs are kept about 90 days. Job-delivery ledgers stay for about three to four months. Rate-limit buckets can drop after five minutes. Access links expire after 15 minutes and are removed by the cleanup job after another day. Account records and claimed checkout references currently have no automatic deletion clock. Backups and provider logs may last longer than the app tables.

For access, correction, or deletion requests, email support@findyourrolefirst.click. We'll verify ownership without asking for the full key. Some records may have to stay for a legal reason. Account deletion isn't a self-serve button yet.

That's the list.

Effective 29 September 2026. This notice describes current processing. It isn't a GDPR or CCPA compliance claim.