Privacy Policy

Last updated August 9, 2026 · Placeholder - see note below

1. Who we are

Jobamine is operated by Sunmintz, an individual-operated project based in India (not yet a registered company). Contact: admin@jobamine.com.

2. What we collect

Account information (name, email, profile photo), the career/resume content you add to your Data Vault, application/interview tracking data you enter, interview questions you add to your Questions Vault, and basic usage/audit data (login sessions, for security purposes).

3. Legal basis for processing

Your account, career, and operational data is processed on the basis of contract necessity - it's the product, and we can't provide Jobamine without it. Community sharing, and any future marketing communications, are processed on the basis of your explicit, opt-in consent, captured item by item. Security and audit data is processed on the basis of our legitimate interest in keeping the Service and your account secure.

4. How we use your data

Primarily to provide the Jobamine product to you - storing your career data, generating resumes, tracking your pipeline, and processing billing for paid plans. We do not sell or share your identifiable personal data. The one exception is questions you explicitly share to the Community feed, described below - your Questions Vault itself always stays private to you unless you take that action.

5. Community sharing

Sharing a question or an Experience & Advice post to the Community feed is an explicit, item-by-item action you take from your Questions Vault or the Community feed itself - it never happens automatically or in bulk. Everything you share is reviewed by an admin before it goes live, and it is attributed to you: your display name is shown next to it once published, so other members can see it's a real, user-contributed item rather than one Jobamine created. There is no anonymous sharing option. Optionally, your personal tags on a shared question can also be included at share time. Shared content may be used to improve Jobamine or offered as a separate feature or product in the future.

6. Your responsibility for shared content

You are solely responsible for making sure anything you share to the Community feed is yours to share. We have no way to verify whether a question or experience is covered by an NDA, confidentiality agreement, or employer policy, and admin review is a basic content check, not a legal clearance. Generic behavioral/interview-style questions and experiences are typically low-risk; take-home assignments, case studies, and proprietary technical problems can carry real legal risk to share - that judgment call is yours to make. We do not guarantee anonymity for shared content, since your name is shown alongside it, and accept no liability for what you choose to share.

7. Admin support access

Authorized administrators can access account data, including logging in as a user to see exactly what they see, strictly for debugging a reported issue, providing support, or reviewing a potential policy violation. Every such access - including the module viewed or the start and end of a session logged in as you - is recorded. During this kind of access, certain contact details (phone number, LinkedIn/GitHub links, and the email shown on your account settings) are masked from the admin's view; the resume and application content itself remains visible, since seeing that content is the reason for the access. This access is never used for marketing, is never sold, and is not part of routine account review.

8. Who we share it with

Supabase (database and authentication hosting), Razorpay and its payment processing partners (subscription billing only - payment details never touch our own servers), and Google (if you choose Google sign-in). No other third parties. These providers act as data processors under their own standard data processing terms. We do not sell your personal data and do not share it for cross-context behavioral advertising.

9. International data transfers

If you are located in the EEA, UK, or another jurisdiction with data-transfer restrictions, your data may be processed in the United States, the European Union, India, or other countries where our service providers operate. We take reasonable steps to ensure appropriate safeguards apply to any such transfer. We do not currently have a significant EU/UK user base and have not yet appointed an EU representative under GDPR Article 27; we will do so before actively marketing to or onboarding EU/UK users at scale.

10. Your rights

Delete your account and all associated data immediately and without contacting support, at any time, from Profile → Data & Account → Delete Account. Depending on your jurisdiction, you may also have the right to access, correct, port (request a copy of), object to, or restrict our processing of your personal data, and to lodge a complaint with your local data protection authority. To exercise any of these rights, email admin@jobamine.com - we will respond within 30 days.

11. Data retention

We retain your data for as long as your account is active. Deleting your account removes your data immediately from primary systems; any residual copies in routine backups are purged as part of normal backup rotation, typically within 30 days.

12. Security

Your data is protected by row-level access controls scoping every record to your account. Passwords are never stored in plaintext (handled entirely by Supabase Auth). We're continuing to harden this over time.

Jobamine is currently an MVP (minimum viable product) under active, ongoing development, and substantial parts of the codebase are built using AI-assisted ("vibe coding") development workflows with human review, rather than the level of formal security audit, third-party penetration testing, or certification (e.g. SOC 2, ISO 27001) typical of a mature commercial product. Security measures described in this Policy are implemented on a reasonable, good-faith, best-efforts basis given that stage - they are not, and must not be read as, a guarantee that data loss, unauthorized access, a data breach, or a data leak cannot occur. No method of transmission or storage is 100% secure, and this is especially true of software at Jobamine's current stage of development. See the Terms of Service §7 and §9 for how this limits our liability.

13. Breach notification

In the event of a data breach affecting your personal data, we will make reasonable, good-faith efforts to notify affected users and any required regulator without undue delay, consistent with applicable law - for example, within 72 hours to the supervisory authority where GDPR applies. This commitment to notify is separate from, and does not itself create, any liability, guarantee, or warranty regarding the occurrence, cause, or prevention of a breach - see Terms of Service §7 and §9.

14. Children

Jobamine is not directed at, and we do not knowingly collect data from, individuals under the age of 18.

15. Changes to this policy

We will notify you of material changes via the in-app consent flow, which requires active re-acceptance before continued use.

16. Contact

Questions about this policy - Email us

This page is a placeholder and has not been reviewed by a lawyer. It should be reviewed and formalized before any public/full rollout.