Privacy Policy
Placem collects the minimum needed to provide job-search tools and keeps personal workspace data private.
Effective date:
The short version
- Browsing public jobs does not require an account.
- Placem does not sell personal data or use behavioral advertising.
- Profiles, bookmarks, saved searches, and application tracking are private.
- Professional links are stored only when supplied and are never crawled.
- Users can edit, export, unsubscribe, delete, or request deletion of their data.
Information Placem processes
- Public browsing: ordinary request information such as IP address, browser details, requested URL, and timestamps may be processed by hosting infrastructure for delivery, reliability, and security.
- Account: the OAuth provider, provider account identifier, email address, display name, image, and database-backed session information. Placem never receives your GitHub or Google password.
- Private workspace: bookmarks, saved-search filters and cadence, application stages and notes, job shares, and professional profile fields and preferences you choose to provide.
- Notifications: recipient address, saved-search results, delivery window, and delivery status needed to send and safely retry requested digests.
- Public job data: postings retrieved from company career sites. This describes employers and roles, not Placem users.
How information is used
Information is used to authenticate users, provide private job-search tools, return relevant search results, send notifications users request, prevent duplicate deliveries, protect the service, diagnose failures, and respond to support or privacy requests.
Job-seeking status is explicitly chosen by the user. Placem does not infer it from browsing behavior, and a status of not looking prevents future profile-matching notifications.
Security and privacy safeguards
- TLS protects traffic; Azure PostgreSQL provides encryption at rest.
- The production database is reached through a private network endpoint and has no standing public firewall allowlist.
- The application uses a restricted database role without schema or role-management privileges.
- Every user-owned query uses the server-derived session user identifier, never a client-supplied owner identifier.
- Security headers include a strict Content Security Policy, HSTS, and protections against framing and content-type confusion.
- Employer-provided HTML is sanitized before it is rendered.
- Profile fields, professional links, resume contents, and job-seeking status are excluded from application logs and operator dashboards.
No service can promise absolute security. Please report a concern through the Contact page.
Service providers and external sites
Placem uses Azure for application hosting, database storage, and transactional email; GitHub or Google for optional OAuth sign-in; and Cloudflare routing for messages sent to the public contact address. These providers process only the information needed for their role.
Clicking an application link sends you to the employer's site, whose privacy practices apply there. Placem does not receive the application you submit.
Retention and user controls
Account and workspace information is retained while needed to provide the feature or until it is removed. Signing out revokes the database session. Profile fields can be edited, cleared, downloaded as JSON, or deleted from the profile page. Saved searches and bookmarks have their own removal controls, and every digest includes management or unsubscribe controls.
To request access, correction, a broader export, or account deletion, email contact@getplacem.app. Verified account-deletion requests remove the account and its user-owned records through database cascade rules.
Changes to this policy
This page will be updated when collection or processing materially changes. The effective date above identifies the current version.