Cookie Policy
Last updated: 2026-08-31
Functional cookies (required)
sb-* cookies from Supabase Auth keep you signed in. Without them the service can't function.
Cookieless analytics (always on, no cookies)
Before you choose anything, we measure the site with privacy-first, cookieless analytics (PostHog EU, Frankfurt). It sets no cookies, stores nothing on your device, and creates no persistent identifier, so it cannot recognise you across sessions or sites. We use it only in aggregate, to see which pages are visited and where visitors get stuck, and the client IP is discarded. Because it stores nothing on your device, it needs no consent under PECR, and session replay is never part of it.
Enhanced analytics (opt-in)
When you opt in, we switch analytics to a persistent mode that recognises returning visitors and turns on session replay, using two processors. Neither sets an advertising ID, tracks you across other sites, or resells any data. (Marketing cookies, below, are a separate opt-in and do involve an advertising network — they are off unless you turn them on.)
- PostHog EU (Frankfurt): persistent product events, funnels, retention and sampled session replay. Cookies set on the PostHog EU domain.
- Microsoft Clarity: anonymised heatmaps and session replays so we can fix usability issues. Form inputs, CV body and interview transcripts are masked client-side before they ever leave your browser. Cookies set on
clarity.ms.
Marketing cookies (opt-in)
Only set if you explicitly opt in via the cookie banner. These measure whether an advertising campaign actually brought someone to us. Unlike everything above, this involves advertising networks, and it is the one tier that is off by default and stays off unless you choose it.
- TikTok Pixel: tells us that a visitor arrived from a TikTok ad and later signed up, so we can tell which campaigns are worth running. Cookies set on
tiktok.com. TikTok uses this data for its own purposes as well as ours, which makes us joint controllers rather than TikTok being our processor — see the privacy policy for what that means for your rights. - Meta Pixel (Facebook and Instagram ads): the same thing for Meta campaigns. Cookies set on
facebook.com. Meta likewise uses what it receives for its own purposes as well as ours, so we are joint controllers there too.
Where they run. Both pixels load on our advertising entry pages only — the home page, campaign landing pages, pricing, the free ATS checker, and the blog. It is deliberately absent from three places:
- Anywhere you are signed in. Your CV, your applications, your job searches and your profile are never in scope.
- Our visa and sponsorship pages. A page address alone can reveal that someone is researching immigration sponsorship, and that is not something we will hand to an ad network.
- Shared scan results, shared CVs, and your own scan result page. These carry a private link, and a pixel would send that link onward.
Changing your mind. Turning marketing cookies off in Settings Data & privacy stops collection immediately, without needing a page reload.
Managing your preferences
You can change your cookie preferences at any time via Settings Data & privacy.