Privacy Policy
Last updated: 1 June 2026
Draft notice. This policy is a working draft and not legal advice. Bracketed values such as [ENTITY NAME] and [JURISDICTION] are placeholders to be completed and reviewed by qualified counsel before this service is offered to the public.
1. Who we are
GeMigJobb ("the Service", "we", "us") is operated by [ENTITY NAME], [ENTITY ADDRESS], [JURISDICTION]. We are the data controller for the personal data described in this policy. You can reach us about privacy matters at [SUPPORT EMAIL].
The Service helps you discover and triage job postings from the Swedish public job bank (Platsbanken / Arbetsförmedlingen) using semantic search and AI assistance.
2. Scope
This policy covers the GeMigJobb web application and its browser extension. It explains what personal data we process, why, on what legal basis, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).
3. Data we process
Account data. Your display name, email address, and authentication credentials (passwords are stored only as salted hashes; we never see them in plain text). You can sign in with a password or with a one-time magic link sent to your email. We send account emails (address verification, password reset, and magic-link sign-in) through our email provider (Resend).
Your job-search activity. Custom attribute schemas you define, attribute enrichment results, swipe decisions, notes, archived and applied jobs, agent search and chat sessions, your uploaded CV, and your preferences. This data is private to your account.
Profile and CV content. When you use CV-based features, the text of your CV and any profile information you provide are processed to generate embeddings and AI assessments. This may include personal data about you that you choose to supply.
Billing data. When you purchase a pass, our payment processor (Stripe) handles your card details directly. We never receive or store full card numbers. We retain a record of the purchase, the pass tier, validity window, and the resulting entitlement.
Usage and metering data. We log AI usage (model, token counts, and computed cost) to enforce per-pass allowances and rate limits, and we keep audit records of sensitive actions for security and accountability.
Analytics data. If you consent, we collect product-analytics events and a masked session replay (see Section 7).
Browser extension data. The extension assists with autofilling job applications. If you report an autofill problem, we receive a structured report of the form fields involved. Field values are garbled into same-length random characters before they leave your browser, encrypted at rest, and deleted after 14 days (see Section 6).
4. Job postings and AI processing
Shared job content. Job postings, their embeddings, machine translations, and AI summaries are built once at ingestion and shared across all users. They are platform content, not tied to your account.
Managed AI inference. We send prompts and job text to third-party model providers (OpenAI and Groq) to power embeddings, translation, summaries, attribute enrichment, agent search, agent chat, and CV analysis. These providers act as our sub-processors. You do not supply your own API keys; we operate the inference on managed accounts. We do not permit these providers to use your inputs to train their models, except as governed by our agreements with them.
Best-effort PII redaction. Job ads written by other people often contain personal data (recruiter names, phone numbers, personal emails, links). We redact this at ingestion, before anything is stored: we drop recruiter and contact-person details, keep only the application email that some ads require, and run a language model plus regular expressions to strip names, emails, phone numbers, and URLs from free-text fields. This redaction is best-effort. It is automated and may miss some personal data or remove some non-personal text. If you spot personal data that should not be there, contact us at [SUPPORT EMAIL] and we will remove it.
5. Why we process your data, and our legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide your account and core features | Performance of a contract (Art. 6(1)(b)) |
| Process payments and grant pass access | Performance of a contract (Art. 6(1)(b)) |
| Secure the Service, prevent abuse, enforce quotas, keep audit logs | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and masked session replay | Consent (Art. 6(1)(a)) |
| Comply with legal and tax obligations | Legal obligation (Art. 6(1)(c)) |
You can withdraw analytics consent at any time without affecting the lawfulness of processing before withdrawal.
6. How long we keep data
| Data | Retention (proposed default) |
|---|---|
| Account and your job-search activity | Until you delete your account, then purged on request |
| Usage and billing logs | Approximately 24 months |
| Audit logs | Approximately 12 months |
| Session replays | Approximately 1 month |
| Autofill problem reports (garbled, encrypted) | 14 days |
These retention periods are proposed defaults and may be adjusted before launch. When you delete your account, we cascade-delete your personal data and purge it on request, except where we must retain limited records to meet a legal obligation (for example, accounting records tied to a purchase).
7. Analytics and session replay
If you accept the cookie-consent banner, we use PostHog (hosted in the EU) to collect product-analytics events and a masked session replay. Replay masks the text of job-ad regions and any field that may contain personal data, so that ad content and sensitive inputs do not enter a recording. Nothing is collected until you click Accept, and you can decline. We use the data to understand how features are used and to improve the product.
8. Sub-processors
We rely on the following sub-processors to run the Service. They process personal data only on our instructions.
| Sub-processor | Purpose |
|---|---|
| OpenAI | AI inference |
| Groq | AI inference |
| Stripe | Payment processing |
| Resend | Transactional email |
| PostHog (EU) | Analytics and masked session replay (consent-based) |
| Turso | Database hosting (EU) |
| Vercel | Application hosting and serverless compute |
9. International transfers
We host data in the EU where practical (for example, our database and analytics are EU-hosted). Some sub-processors, in particular AI providers, may process data outside the EU/EEA. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent. You can:
- Export a copy of your data from the Account page.
- Delete your account, which erases your personal data, from the Account page.
- Withdraw analytics consent at any time.
To exercise any other right, contact us at [SUPPORT EMAIL]. You also have the right to lodge a complaint with your supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
11. Security
We use industry-standard measures including encryption in transit, hashed passwords, encryption at rest for sensitive autofill reports, and access controls that isolate each account's private data. No system is perfectly secure, but we work to protect your data and to notify you and the relevant authority of a breach where required.
12. Children
The Service is not directed at children under 16, and we do not knowingly collect their personal data.
13. Changes to this policy
We may update this policy as the Service evolves. We will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.
14. Contact
Questions about this policy or your data can be sent to [SUPPORT EMAIL], or by post to [ENTITY NAME], [ENTITY ADDRESS], [JURISDICTION].