Privacy policy
Last updated 3 August 2026
WorkSynapse helps you find jobs and explains why each one fits. Doing that means processing a CV, which is some of the most sensitive information you will ever hand to a website. This page says exactly what happens to it.
We apply this policy to everyone, wherever they live. The GDPR is the baseline for the whole product rather than a European add-on, because splitting the rules by region would mean building two products and giving some people the worse one.
What we hold
- Your account: an email address, and the identifier of the Google or GitHub account if you signed in with one. There are no passwords: we never store one, so we can never leak one.
- Documents you upload: the CV file itself, in EU-region object storage.
- Your profile: the skills, seniority, locations, languages and preferences extracted from that CV or typed by you. Every extracted field is editable, including our inferences. If we got something wrong, you correct it rather than argue with it.
- What you do here: the jobs you saved or dismissed, and the searches that produced them, so the feed can improve.
- A security trail: sign-ins, uploads and document scans. IP addresses in that trail are stored hashed, never in the clear.
- One free allowance per person: to keep the free plan to one allowance per person, we keep one-way hashes of your email address, your sign-in identity, your phone number and your CV file for up to a year, and of your network address for thirty days. None of them can be turned back into the original, and they decide nothing but whether a second account gets a second free allowance.
What we refuse to hold
Age, gender, ethnicity, nationality, religion, disability, and marital or family status are never extracted, never stored, and never used to rank anything. Nor are the fields that stand in for them: a graduation year implies an age, a name implies an ethnicity, a postcode implies an income. Names and photographs are stripped from a CV before it is turned into the vector used for matching.
Why we are allowed to
Running your account, reading your CV into a profile, and producing matches are all necessary to provide the service you asked for. Job-alert emails are separate and happen only if you ask for them, and you can stop them in one click without affecting anything else. We do not sell your data, we do not share it with employers unless you apply, and we do not track you across other websites.
Automated decisions
WorkSynapse ranks and explains opportunities. It never rejects you, never removes you from an employer’s consideration, and never scores you in a way that decides anything on its own. A human always chooses whether to apply. Every recommendation shows its reasons, and each reason points at the sentence in your CV or in the job ad it came from. When we cannot point at a sentence, we drop the claim rather than dress it up.
Who else processes it
Storage and the database are EU-region. Some processing runs on providers outside the EU: Anthropic reads CV and job text to extract structured fields and to write explanations, and Voyage AI turns text into the vectors used for matching. Email is sent through Resend. Those providers act on our instructions and are not permitted to use your data for their own purposes or to train models on it.
How long we keep it
- Uploaded CV files: 24 months after your last activity.
- Your profile: until you change or delete it.
- Application logs: 90 days.
- Security and audit records: 12 months.
- Dismissed jobs: 12 months.
Those are scheduled jobs, not intentions.
Your rights, as buttons rather than requests
- See it: your profile page shows everything stored about you, including the fields we inferred.
- Take it: one request exports your account as a single JSON document.
- Correct it: every field is editable.
- Delete it: deleting your account removes the database recordsand the CV files in storage. What survives is the security trail, with your identifier removed from it, plus one line recording that the erasure happened.
- Object: you can switch off personalisation, and the feed returns to its unpersonalised order. That stops a use of your history; it does not delete the history, which is what deletion is for.
None of these are an email queue. If something does not work, or you want to raise a complaint, write to [email protected]. You also have the right to complain to your local data protection authority.
Cookies
Only the ones that make signing in work: a session cookie and a CSRF token. There is no advertising cookie and no cross-site tracking, which is why there is no consent banner in your way. If that ever changes, the banner comes first, and refusing will be exactly as easy as accepting.
Where the jobs come from
Postings are collected from company career pages and the applicant tracking systems they publish through, always via public interfaces those systems provide, and every posting links back to the original. See the application terms for what that means when you apply.