// legal

Privacy Policy

Last updated: August 12, 2026

HireAll (freehire.me) is a free, open-source IT job aggregator. This policy explains what data we collect, why, and who we share it with. We collect only what the product needs to work, and we never sell your data.

What we collect

  • Account data. When you register, we store your email address and — for password sign-in — a salted bcrypt hash of your password (never the plaintext). If you sign in with Google, GitHub, or LinkedIn, we store your verified email and a provider identifier so we can recognise you next time; we do not keep the provider's access tokens.
  • Job activity. If you save, view, apply to, or track a job, we store that interaction (the job, timestamps, application stage, and any notes you add) so we can show you your pipeline.
  • CV / résumé. If you upload a CV for skill matching or AI match analysis, we store the file and the text we extract from it. Running an AI match analysis sends the relevant parts of your CV, together with the job posting, to our language-model provider (see “Third-party services”).
  • API keys. If you create a personal API key, we store only a SHA-256 hash of it. The key itself is shown once at creation and is unrecoverable afterwards.
  • Technical data. Standard request logs (IP address, user agent, timestamps) and, where you allow it, product-analytics cookies (see “Cookies”). We do not sell your data or build advertising profiles.

How we use it

We use your data to run the service: authenticate you, remember your saved and tracked jobs, match jobs to your CV, deliver any digests you subscribe to, and keep the platform secure and working. We do not sell your personal data or use it for third-party advertising.

Cookies

When you sign in, we set a single HttpOnly, SameSite=Lax session cookie holding a signed token. It is strictly necessary for keeping you logged in and cannot be read by JavaScript. Logging out clears it. This cookie is always set and needs no consent.

For product analytics we use Google Analytics and PostHog, which set their own cookies and, in PostHog's case, may record a session replay with all inputs masked. These are non-essential. If you visit from the EU, EEA, or UK, they load only after you accept them in the cookie banner — reject and nothing loads. You can change your choice at any time via “Cookie settings” in the footer.

Job listings

The jobs we display are aggregated from public company career boards and other public sources. We normalise and deduplicate them; we do not own this content, and a role closes in our catalogue once it disappears from its original source.

Third-party services

We rely on a small set of processors to run HireAll:

  • A language-model provider — processes CV and job text to produce AI match analysis, only when you request it.
  • Product analytics (Google Analytics, PostHog) — measure aggregate usage to improve the product; loaded only with your consent where required (see “Cookies”). PostHog runs on its EU instance.
  • Error monitoring (Sentry) — captures application errors to keep the service reliable; configured without personal-data capture.
  • OAuth providers (Google, GitHub, LinkedIn) — only if you choose to sign in with them, to verify your identity and email.
  • ChatGPT Actions — if you connect HireAll to a custom GPT, ChatGPT sends your search and tracking requests (authenticated with your API key) to our API. Your use of ChatGPT is also governed by OpenAI's own privacy policy.

Browser extension

The HireAll Chrome extension puts a job-application agent in a side panel next to whatever page you are on. It does nothing until you sign in from the panel.

  • Session token. Signing in stores your HireAll session token in chrome.storage.local, scoped to your browser profile. Nothing else is stored there.
  • Page content. While the panel is open and only in service of what you asked for, it can read the current page's URL, title, and visible text (capped at 5,000 characters), or the fields of a job-application form you asked it to fill. This is sent to freehire.me — the only host the extension talks to — and kept in that conversation's transcript, which you can read and delete from your account. A read is always named in the panel, and browser-internal pages, other extensions' pages, and local files are never read.
  • Profile data for Autofill. Filling an application form sends the relevant fields from your HireAll profile (name, email, phone, CV fields) to the page; you review and submit yourself.

We do not sell this data, and we do not use it for anything unrelated to running the extension's job-application agent, in line with the Chrome Web Store's limited-use requirements.

CV link tracking

You can turn on link tracking for a single CV. It is off for every CV unless you switch it on, and switching it on for one CV does not affect any other.

When it is on, the links in that CV's PDF point at HireAll and forward to the real destination. Following one records the time, the browser and operating system family, the device type, and the host — not the full address — of the page the visitor came from. It also records a keyed hash of the visitor's IP address and browser identity, so that repeat visits can be told from separate people. We do not store the IP address itself, and the hash is keyed with a secret so it cannot be turned back into an address.

These records are deleted after 180 days, and immediately if you delete the CV. Your own clicks are marked as yours and left out of the counts. A recorded open means the link was fetched; company mail systems follow links automatically, so it is not proof that a person read your CV.

Retention

We keep account and activity data for as long as your account exists. When you delete your account, we delete or anonymise your personal data, except where we must keep it to comply with the law. Request logs are retained for a limited period for security and debugging.

Your rights

You can access, correct, export, or delete your personal data at any time — most of it directly from your account settings, or by contacting us. You can also revoke API keys and unlink sign-in providers. If you are in the EU/EEA or UK, you have the rights granted by the GDPR, including the right to lodge a complaint with a supervisory authority.

Contact

Questions or requests about your data? Reach us at hello@freehire.me, on Telegram, or via GitHub. As an open-source project, our data handling follows what the source code actually does.

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of HireAll is available