01Who we are and what this covers
JobFrog is a recruiting platform. It has two kinds of users: candidates, who create a free profile to find work, and organizations (staffing agencies and in-house talent teams), whose staff use a private workspace to recruit. This policy covers jobfrog.dev, the application (app.jobfrog.dev, each organization's workspace address and custom domains), our API and MCP server, and the emails we send.
Who is responsible for your information depends on which record we mean. That split is the most important thing on this page, so it has its own section below: Your profile versus an organization's records.
02Your profile versus an organization's records
Your JobFrog profile belongs to you
When you sign up as a candidate you get one JobFrog network profile. You control it: you edit it, choose whether recruiters can discover it, can download everything in it, and can delete it. For this profile JobFrog is the controller (the party responsible for it under privacy law).
Organizations control their own candidate records
Each organization keeps its own, separate record of the people it works with, in a workspace no other organization can see. It may create that record itself (for example from a resume you sent them, their existing applicant tracking system, or an application to one of their roles), or attach your JobFrog profile to it when you accept an invite, apply, or they add you from the network with your opt-in. For these records the organization is the controller and JobFrog processes the data on its behalf, under our agreement with them. Questions or requests about an organization's record should go to that organization; if you send them to us, we'll pass them on.
When your account is linked to an organization's record, changes you make to your own profile flow into their copy, except fields they have locked. Organizations see your public profile when they find you through the network; they never see your email or phone number unless you share them or work with them directly.
03What we collect
From candidates
- Account
- Name, email address, a password (stored only as a hash) or your Google or Microsoft sign-in, and whether your email is verified.
- Profile
- Phone, location, headline, summary, skills, work history, education, certifications, profile links (LinkedIn, GitHub, portfolio), work authorization, work-mode and employment-type preferences, desired rate or salary, current compensation if you or a recruiter add it, and availability.
- Resumes and documents
- Files you upload (PDF, Word, text, or your own LinkedIn "Save to PDF" export), the text and structured data extracted from them, resumes and cover letters generated for you, and ATS readability scores.
- Applications
- Jobs you apply to or track, recruiter submissions and their stages, interviews, and placements.
- Identity verification
- If you choose to verify, Stripe Identity checks your ID document and a selfie. Stripe keeps the images; we store only the outcome (verified or not, checks performed, failure codes) and a reference.
- Messages
- Email and portal messages between you and an organization's recruiters, and notes a recruiter records about you.
From organizations and their staff
- Staff accounts
- Name, email, role in each organization, password hash or Google or Microsoft sign-in.
- Workspace data
- Clients, contacts, requisitions, candidates, pipeline, rates and fees, placements, timesheets and invoices, autonomy settings, and the organization's name, brand color, domains and postal address.
- Connected mailbox and calendar
- If a staff member connects Google Workspace or Microsoft 365, recruiting email with known candidates and contacts, and calendar events JobFrog schedules. See Mailbox and calendar access.
- Integrations
- Credentials for systems the organization connects (for example JobDiva or another ATS), encrypted at rest, and the records synced from them.
Collected automatically
- Sign-in sessions, including the IP address and browser user agent recorded with each session.
- An activity log of meaningful changes (a profile edit, a submission, an email sent) and a staff access log: when a team member opens a candidate's profile or document, at most once per person per candidate per hour.
- Records of AI agent runs (what ran, the model, token counts and cost) so organizations can see and audit automated work.
Job postings
The public job board is built from employers' own public job boards and job-listing APIs (such as Greenhouse, Lever, Ashby, Workday and SmartRecruiters) and public aggregators. Postings are about jobs, not people, though a posting can include a hiring contact's name or email when the employer published it. We never scrape LinkedIn or Indeed.
04How we use it
- To run your profile and the job board: matching you to roles, scoring how applicant tracking systems read your resume, and tracking applications.
- To run each organization's workspace on its instructions: sourcing, matching, outreach, submissions, interviews, placements and billing, and syncing with the systems it already uses.
- To send the email the product needs: sign-in links, verification, invites, and notifications.
- To keep JobFrog secure: authentication, tenant isolation, abuse prevention, audit logs, and debugging.
- To meet legal obligations, such as honoring unsubscribes and responding to lawful requests.
We don't sell personal information, share it for cross-context behavioral advertising, or show ads. We don't use candidate or mailbox data to train AI models.
05AI and automated processing
JobFrog uses AI for work that needs judgment. The main provider is Anthropic (Claude models) through its commercial API. We send it only what a task needs, for example:
- Resumes you or a recruiter upload, to extract your profile (PDFs are sent as documents; Word files as text).
- Your profile and a job description, to explain a match or produce a tailored, ATS-ready resume.
- A reply from a candidate or contact, to classify it (interested, not interested, scheduling, unsubscribe) and draft a response.
- Questions staff ask the workspace assistant, with the workspace data needed to answer them.
Anthropic processes these requests to return a result and does not use them to train its models under its commercial terms. An organization can instead point JobFrog at a model it hosts itself, in which case that data goes to the organization's own model server.
Optional third-party resume parsers
A candidate can choose to see how commercial resume parsers read their resume. When a deployment has them enabled and you select one (Textkernel, Affinda or RChilli), your resume is sent to that vendor for parsing and the result is used only to compute your score.
People stay in charge
AI suggestions don't decide who gets hired. Anything JobFrog does in the outside world on an organization's behalf (sending an email, submitting a candidate to a client) follows that organization's autonomy policy, which can require a person to approve each action. Generated resumes are checked against your profile so they never add facts you didn't provide, and resume scores from simulated applicant tracking systems are labeled as emulations.
06Mailbox and calendar access
Only an organization's staff connect a mailbox and calendar. If you're a candidate and sign in with Google or Microsoft, JobFrog uses the sign-in to identify you (name, email, profile picture) and never syncs, reads or sends from your mailbox or calendar: those features run only for staff accounts. When a staff member connects Google Workspace, JobFrog asks for:
- Sign-in (openid, email, profile)
- Identifies the staff member and their mailbox address.
- Gmail (gmail.modify)
- Reads recent mail to find conversations with the organization's known candidates and contacts, and sends email that the staff member or an approved automation writes, from their own mailbox so replies thread normally. JobFrog does not delete mail.
- Google Calendar (calendar.events)
- Creates and updates the interview and meeting events JobFrog schedules, and keeps them in sync.
Only recruiting mail is kept. On each sync JobFrog looks at the sender and recipients of new messages (the first sync looks back 14 days). A message is stored only if a participant is a candidate or contact in that staff member's organization; every other message is read for its headers, discarded, and nothing about it is kept. Stored messages (subject, body, sender, recipients, time) become part of the organization's candidate or contact record. Google tokens are encrypted at rest, and staff can disconnect at any time from their settings or their Google or Microsoft account.
Microsoft 365. Staff can connect an Outlook mailbox and calendar instead. JobFrog asks Microsoft Graph for sign-in (openid, email, profile, User.Read), offline_access to stay connected, Mail.ReadWrite and Mail.Send to find recruiting conversations and send from the staff member's mailbox, and Calendars.ReadWrite for the events it schedules. The same rules apply: only mail with the organization's known candidates and contacts is kept, tokens are encrypted, and nothing is deleted.
Google API Services: Limited Use disclosure
JobFrog's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data from Gmail and Google Calendar:
- is used only to provide and improve the user-facing recruiting features described above, in the connected user's own organization;
- is transferred to others only as needed to provide those features (for example, to Anthropic to classify a candidate's reply, and to our hosting and database providers), to comply with law, for security, or as part of a merger or acquisition with notice;
- is never used for advertising, never sold, and never used to build user profiles for unrelated purposes;
- is never used to develop, improve or train generalized AI or machine-learning models; and
- is not read by people, except with the user's affirmative permission for specific messages, where needed for security (such as investigating abuse), to comply with law, or when the data has been aggregated and anonymized for internal operations.
07Recruiting email and unsubscribing
Organizations use JobFrog to email candidates and client contacts. Every recruiting email includes the organization's name and postal address and a one-click unsubscribe link. Unsubscribing stops that organization from emailing that address through JobFrog, across all of its records for you, and doesn't affect other organizations. JobFrog refuses to send to anyone marked do-not-contact, and an organization can't send recruiting email until it has a postal address on file.
10How long we keep it
- Your JobFrog profile stays until you delete your account. Deleting it removes your login, resumes and generated documents, conversations on your profile and your application tracker, strips your personal details from the profile, and marks it do-not-contact so you aren't emailed again.
- An organization's records are kept as long as the organization chooses, under its agreement with us. Its admins can export or erase a candidate's record at any time. When a record is erased, placements and invoices it appears on are kept as financial records but no longer identify the person.
- Mail that isn't recruiting mail is never stored. Stored recruiting messages follow the record they belong to.
- Sessions expire after 14 days. Activity and access logs follow the record they describe; when a candidate is erased, their name is removed from them.
- Backups held by our database provider expire on its rolling schedule, after which deleted data is gone from them too.
11Your choices and rights
From your candidate portal you can, at any time:
- See and correct your profile (fields an organization locked on its own record can only be changed by that organization).
- Download your data as a JSON file from Settings.
- Delete your account from Settings.
- Control discovery: choose whether recruiters can find your profile on the network, and see and end your connection with an organization.
- Unsubscribe from any organization's recruiting email using the link in the email.
Depending on where you live (for example the EU, UK, or US states such as California), you may also have the right to object to or restrict processing, to data portability, and to appeal a decision about your request. For an organization's record of you, contact that organization, which can export or erase it from its workspace; we'll help it respond. For anything else, email privacy@jobfrog.dev. We won't treat you differently for exercising these rights, and we may need to verify your identity first. You can also complain to your local data protection authority.
12Security and where data is stored
Data is encrypted in transit. OAuth tokens and integration credentials are also encrypted at rest with AES-256-GCM. Each organization's data is kept in its own tenant: staff only reach an organization's records with a membership in it, API keys are bound to one organization, and database row-level security limits read-only tools to a single organization. No system is perfectly secure; if a breach affects your information we'll notify you and the relevant authorities as the law requires.
JobFrog is operated from and hosted in the United States. If you use it from elsewhere, your information is transferred to and processed in the US, with safeguards such as standard contractual clauses where required.
13Children
JobFrog is for people looking for work and is not directed at children. Don't create a profile if you are under 16.
14Changes to this policy
We'll update this page when our practices change and revise the date at the top. If a change is significant, we'll tell you by email or in the product before it takes effect.
15Contact
Questions or requests: privacy@jobfrog.dev. If you're a candidate, the quickest way to see, download or delete your data is your candidate portal. Read our Terms of Service for the rules of using JobFrog.