Job Elf (jobelf.com) is a site where people looking for work build a profile from their résumé, and employers search for, message and hire them. Job Elf is run by Job Elf Technologies, Corp., a Florida corporation ("Job Elf", "we", "us").
This policy explains what we collect, why, who can see it, who helps us process it, how long we keep it, and what you can do about it. It's part of our Terms of Service.
Questions or requests: use our contact form and choose Privacy request, or email service@jobelf.com.
The short version
- Candidates control who sees their profile. A Public profile shows anyone your first name and last initial ("Michael R."), approved photos, intro video, summary, city, job titles with dates (but not company names), and skills. Signed-in employers see more. Only set-up employers can open your résumé or message you.
- Your email address is never shown to employers or other users. Messages stay on Job Elf.
- We don't sell your information or share it for advertising. We don't show ads or use advertising trackers. We count visits with Google Analytics, which sets two cookies of its own; Google's advertising features are turned off. Browsing without an account sets no other cookies.
- A few service providers help us run Job Elf, for example to store and play intro videos, to estimate your city for the search box or to read your résumé with AI. They're listed in section 5.
- You can download your data and delete your account in your account settings.
- Job Elf is only for people 18 and older.
1. What we collect
1.1 When you visit Job Elf
- No sign-in cookies for visitors. Looking around without an account sets no Job Elf cookies of our own, only the two Google Analytics cookies described below. See our Cookie Preferences page.
- Server logs. Like every website, our server records each request: your IP address, browser type, the page you asked for, the page you came from, and the time. We use these logs to keep the site running and secure.
- Visit statistics (Google Analytics). When you aren't signed in, your browser tells Google Analytics which page you viewed, the site you came from, and a few things you did on the page, such as scrolling, searching or clicking a link to another website, along with your browser type, device, screen size, language and IP address, which Google uses to estimate your country and city. Google Analytics stores a random ID in two cookies on your device (
_gaand_ga_followed by our property code, kept for up to 400 days) so it can tell new visits from return visits. Google's advertising features and Google signals are turned off, so it isn't linked to your Google account or used for advertising. Before anything is sent, we remove the parts of the page address that aren't needed (we keep search words, the place you searched and campaign tags), and we never use it on pages whose address holds a private code, such as password reset or share links. It doesn't run once you're signed in. Google keeps this data for us for up to 14 months. - Your area, for the search box. The search box may start with your city ("Near Tampa, FL"). To do this, our server sends your IP address to GeoJS, a location service, which replies with an approximate city. We keep that answer for up to 24 hours, filed under a scrambled (hashed) form of your IP address, so we don't have to ask again. We don't attach it to you or your account. Your device's precise location is used only if you choose "Use my location" and your browser asks your permission; we turn it into the nearest city and keep neither. You can change or clear the place at any time.
- Product analytics, kept by us. Your browser tells us about a few actions, such as starting a search, viewing a candidate card, playing an intro video or clicking an employer's "apply on our site" link. We record the action, the profile, job or search words involved, and the time. If you have a session (you're signed in or partway through signing up), we also record your account and a scrambled code made from your session. This stays in our own database.
- Profile views. When someone opens a candidate's profile, we count the view. For signed-in visitors we record which account viewed it. For guests we record a scrambled code made from the IP address and browser together with a secret key, never the IP address itself, so each visitor is counted once a day.
- Display preferences. If you change the text size or other display preferences, your browser remembers them. They never reach us.
1.2 When you create an account
- Your name, email address and password (stored only as a secure, one-way hash).
- If you sign in with Google, we receive and keep your Google account ID, name and email address. We don't receive your Google password, and we don't ask for your contacts, files or anything else.
- Whether you're a candidate or an employer, when you agreed to our Terms and this policy (including confirming you're 18 or older), when you confirmed your email, and when you last signed in.
- If you turn them on: two-factor authentication details (stored encrypted) and passkeys (we keep only the public part of the key; the private part stays on your device).
- Sign-in codes. When you sign in on a new device, and every 30 days, we send you a one-time code: by text for employers, by email for candidates. We keep a scrambled (hashed) copy of the code until it's used or expires after 10 minutes. When you choose "Remember this device", we record that browser (a scrambled version of a random code in its cookie, plus its IP address and browser type) for 30 days.
- Your email notification choices.
- Security records. While you're signed in, our session records include your IP address and browser. We also keep short-lived counters (for example, the number of sign-in attempts from one network) to stop abuse.
1.3 Candidates
- Your résumé (PDF or Word file), the text we extract from it, and the structured profile we build from it. Files are kept in private storage. Every version you apply to your profile is kept until you delete your account; drafts you discard are deleted.
- Your profile: headline, summary, city, state and ZIP code (we turn the ZIP code into an approximate map point so employers can search by distance), work experience (titles, companies, dates and descriptions), education, skills, certifications, languages, the kind of work you want, remote or on-site preference, availability, salary expectations, your visibility setting, and whether your profile can appear in AI-assisted searches.
- Photos. We remove the hidden information photos carry, including GPS location, before anyone sees them, and make smaller copies for the site.
- Your intro video (15 to 60 seconds) and the transcript you type for it, which we also turn into captions. Your video is stored and played by our video host, Bunny (section 5), which turns it into the copies used for playback and doesn't keep your original file. Any background you choose while recording (a blur, a plain backdrop or your own picture) is added on your device, so we only ever receive the finished video.
- Your activity: jobs you save or apply to and any note you send with an application, interviews you're invited to and your replies, companies you block, share links you create (and how often each is opened), saved searches and job alerts, and your recent searches.
We don't ask for your date of birth, Social Security number or other government ID, street address, marital or family status, or protected characteristics such as race, religion, sex, age or disability, and we never show them. A résumé can contain anything you put in it, though, so please leave out anything you wouldn't want an employer to see.
1.4 Employers and company teams
- Your employer profile: your name, job title, team role and hiring needs.
- Your mobile number (or numbers), when texted sign-in codes are turned on. We use them only to text you sign-in codes, never for marketing, and we never show them to anyone.
- Your company: name, website, industry, size, location, tagline and description, logo, workplace photos and videos, and anything you send us to verify it. To verify a company automatically, we compare your email address's domain with its website.
- Your hiring activity: job postings, applicants and their status, private notes and scorecards on applicants, interviews you schedule (including meeting links, locations and notes), saved candidates and talent lists, message templates, saved searches and alerts, recent searches, AI-assisted searches (your request, location and filters, and the suggestions shown), and the candidate profiles you view.
- Team invitations: the email address and role of people you invite.
- Payments, when paid features are turned on: what you bought and when, credits and unlocks, and your billing email. Our payment provider handles your card, and tells us only the card type and last four digits.
Candidates can see which companies viewed their profile. The candidate dashboard shows the names of companies whose employers looked at the profile in the last 30 days. It never shows which person at the company looked.
1.5 Messages
Employers and candidates can message each other on Job Elf. We store the messages, when they were sent and when they were read. Your email address isn't shared with the other person unless you choose to share it in a message.
1.6 When you contact us
When you use the contact form, we keep your name, email address, the topic, your message, the page you came from (the address only, without search terms or security codes), your browser type, a scrambled code made from your IP address (not the address itself, so we can spot abuse) and, if you were signed in, a link to your account. A copy is emailed to our team's inbox, which is hosted by our email provider. We keep our replies and internal notes with your message.
1.7 Employer early-interest form
If you register interest as an employer before launch, we keep your name, business email, company, where you're hiring, the roles you're hiring for, whether you agreed to occasional product news, where you heard about us, and a scrambled code made from your IP address.
1.8 Reports and moderation
If you report a profile, photo, video, job, company or message, we keep the report, the reason and any details you give. We keep a log of what our team does in response (for example approving a photo, pausing a profile, suspending an account or opening a reported conversation) and why.
2. Why we use it
- To run Job Elf: create and secure your account, build your profile from your résumé, show profiles and jobs, run search, deliver messages, applications and interview invitations, and send the emails you asked for.
- To match people and jobs: search ranking uses experience, titles, skills, location, recency, availability and profile completeness. We never rank candidates on their photos, videos, names or any protected characteristic.
- To keep people safe: our team reviews every photo and video, and every company logo, photo and video, before it appears; reviews job postings from companies we haven't verified; verifies companies; handles reports; and blocks spam, scraping and abuse.
- To improve Job Elf: we look at our own analytics (for example, how many searches lead to a profile view) to decide what to build next.
- To answer you when you contact us.
- To meet legal obligations, enforce our Terms, and protect the rights and safety of our users, Job Elf and others.
3. What other people can see
| Who | What they can see |
|---|---|
| Anyone, including search engines (Public profiles only) | First name and last initial ("Michael R."), approved photos, intro video with its captions and transcript, headline, summary, city and state, job titles with their dates and durations (no company names or descriptions), degree and subject with graduation year (no school names), languages and skills. |
| Signed-in employers | The above, plus company names (unless you hide your current employer), job descriptions, school names and certifications. |
| Employers who have confirmed their email, finished setting up, and whose team role allows it | The above, plus your résumé file (including any contact details in it), and they can message you or invite you to apply or interview. When paid features are turned on, a company may also need an application from you, an existing conversation, a plan or an unlock before it sees your full name and résumé. |
| A company you apply to | Your profile and résumé, even if your profile is Private or Hidden, until you withdraw the application. |
| Anyone with a share link you create | Whatever you chose for that link. By default: your photo, intro video, summary, location, experience (including company names and dates), skills and languages. You can also include education, certifications, your full last name and your original résumé. You can turn a link off at any time. Share links aren't listed by search engines unless you choose that. |
| Nobody else | Your email address, account settings, salary expectations, exact ZIP code and map point, saved jobs and searches, blocked companies, and your messages (only the people in a conversation see it). |
Your visibility setting:
- Public: appears in search results, and search engines can list it (Public profiles are in our sitemap).
- Private: not in search results or the sitemap. Signed-in employers who have the link can still open it.
- Hidden: employers can't open it at all, except companies you've applied to.
Job postings and company pages are public. Anyone can see live job postings, and we mark them up so search engines such as Google can show them in job search. A company's page is public once the company is verified or has a live job.
Example profiles. Job Elf shows some clearly labeled example profiles of made-up people. They aren't real candidates and can't be contacted.
Our team. Job Elf staff with admin access can see account and profile information to run and moderate the service. Staff read private messages only when a conversation or message has been reported, and each time they open one it's recorded in our audit log. Every admin account requires two-factor authentication.
Résumés, photos and videos are never at a permanent public web address: each time someone opens one, we check they're allowed to see it. A résumé is then sent through Job Elf itself, a photo loads through a private link that expires within minutes, and a video plays through a link that works only on Job Elf and expires after a few hours.
4. AI and automated processing
- Reading your résumé. When AI résumé reading is turned on, the full text we extract from your résumé (which can include your name and contact details) is sent to Anthropic's Claude to split it into experience, education, skills and so on. The file itself isn't sent. Nothing goes live until you review it, and you can edit or delete anything. When AI reading is off, a parser on our own server does this instead.
- AI-assisted search for employers. When an employer describes who they're looking for, we send their request and a limited summary of matching profiles to Anthropic's Claude, which suggests candidates and explains why. The summary includes headline, skills, job titles with years, short descriptions, degree and subject, certifications, languages, work preferences, city and state, and availability. We remove names, email addresses, phone numbers, links, company names and exact dates, and we never send photos, videos, ZIP codes, salary expectations or your résumé file. You can keep your profile out of AI-assisted search by turning off that option in your profile preferences.
- Writing help. When someone asks for it, Anthropic's Claude suggests wording. No message is sent and nothing is saved or published until a person reads the suggestion and chooses to use it.
- Candidates can ask for clearer wording for their summary or the description of a role, a résumé drafted from their answers in the résumé builder, or a script for their intro video. We send only what that needs: the text and answers you ask about, your job titles, and for an intro script your headline, summary and skills. We never send your name (we fill it in afterwards), contact details, salary expectations or résumé file, and we leave out company and school names unless you typed them into that text yourself. Your profile doesn't change until you apply a suggestion and save it, and you can restore the earlier wording.
- Employers can ask for drafts of job posts, messages, interview notes and search criteria. We send the employer's own words, the job and the company's details. For a message to a candidate we also send that candidate's headline, skills, recent job titles, years of experience, work preferences, area and availability, but only when the candidate lets AI search suggest them to employers, and never their name (we add names afterwards), contact details, photos, videos, messages or salary expectations.
- Automatic checks on photos and videos. When you upload a photo or video, we send it to Anthropic's Claude to check that it isn't inappropriate (for example nudity, violence, hate symbols or a scam) before anyone else sees it. For a video we send still frames taken from it and the transcript you typed, not its sound. If the check finds it inappropriate, it's turned down straight away and we tell you why. If it can't decide, or can't run, a member of our team looks at it instead. Our team can see every decision, and you can ask us to take another look through our contact form.
- Checks on AI output. We discard suggestions that aren't backed by something in the candidate's own profile, and we flag requests that mention protected characteristics. Suggestions are shown to the employer as suggestions, not decisions.
- No automated decisions about you. Search ranking and suggestions are automated, but employers, not Job Elf, decide whom to contact, interview or hire. Apart from the automatic check on photos and videos described above, which our team reviews whenever you ask, Job Elf doesn't use AI to moderate content; our team does that.
Under Anthropic's commercial terms, it may use the data we send only to provide its service to us, not to train its models.
5. Who helps us run Job Elf
We use a small number of service providers. They may use your information only to provide their service to us. Some are used only when that feature is turned on.
| Provider | What they do | What they receive |
|---|---|---|
| Our hosting provider (United States) | Hosts the server that runs Job Elf, our database and our files | Everything stored on Job Elf |
| Bunny (BunnyWay d.o.o., Slovenia) | Stores, converts and delivers intro videos and company videos, from Germany and the United States; stores photos, résumé files and company logos in the United States | The videos you record or upload, your photos and résumé files, and company logos and photos; when someone watches a video, their IP address and browser details |
| GeoJS | Estimates a visitor's city from their IP address for the search box | Your IP address |
| Anthropic (Claude), when AI features are turned on | Reads résumé text; suggests candidates in AI-assisted search; suggests wording when someone asks for writing help; checks uploaded photos and videos (section 4) | The résumé text, the limited summaries, requests and text described in section 4, and the photos you upload, still frames from videos and their transcripts |
| Google Analytics (Google LLC, United States) | Counts visits to Job Elf's pages for visitors who aren't signed in, using its own cookies (section 1.1) | The page address (trimmed), the page you came from, what you did on the page, your browser, device and IP address, and the random ID in its cookies |
| Google, only if you choose to sign in with it | Confirms who you are | Google learns that you signed in to Job Elf; we receive your account ID, name and email address |
| Stripe, when paid features are turned on | Processes payments | Your company name, billing email and payment details |
| Twilio (United States), when texted sign-in codes are turned on | Delivers the sign-in codes we text to employers | Your mobile number and the text itself, and whether it was delivered |
| Twilio SendGrid (United States) | Delivers the emails Job Elf sends | Your email address and name, the email itself, and whether it was delivered, bounced or marked as spam |
| Our email provider | Hosts our team's inbox | Messages you send us through the contact form, and our replies |
We send account and notification emails through Twilio SendGrid, and they pass through your own email provider when they're delivered. We've turned off SendGrid's open and click tracking for our emails, so it doesn't record whether you open them or which links you click.
We don't sell your personal information, "share" it for targeted advertising, or give it to data brokers. We don't use advertising networks. Google Analytics runs with Google's advertising features and Google signals turned off.
We may also disclose information if the law requires it; to protect anyone's safety, rights or property, including Job Elf's; to investigate fraud, abuse or violations of our Terms; or as part of a merger, acquisition or sale of all or part of our business, in which case we'll tell you before your information becomes subject to a different privacy policy.
6. Cookies and similar technology
We use only the cookies needed for the site to work: a session cookie and a security cookie once you sign in, sign up or use a form, a "keep me signed in" cookie if you choose it or continue with Google, and a cookie that remembers a browser where you entered a sign-in code. When you aren't signed in, Google Analytics also sets two cookies to count visits (section 1.1). We don't use advertising cookies, and there's no cookie banner; you can block or delete cookies in your browser, or install Google's opt-out add-on. Our Cookie Preferences page lists each cookie, how long it lasts, and the little we keep in your browser's storage.
7. Emails we send
- Account emails, which always arrive: confirming your email address, sign-in codes, password resets, team invitations, data downloads, and notices about your account (for example, a decision on a job posting or on your company's verification).
- Notifications you control in your email notification settings: new messages, invitations to apply, interview updates, application updates, new applicants, a weekly summary of profile views, new results for saved searches, and reminders to finish your profile. They also appear in your notifications on Job Elf.
- Replies from our team when you contact us.
- Product news, only if you agreed to it on the employer early-interest form. Reply to any of these emails, or contact us, to stop them.
8. How long we keep information
| Information | How long |
|---|---|
| Your account, profile, photos and intro video | Until you remove them or delete your account |
| Photos and videos our automatic check turned down | 30 days, so our team can review the decision, then deleted |
| Résumé files | Every version you apply is kept until you delete your account |
| Messages | While the conversation exists (see section 9) |
| Recent searches | Your last 20; anything older than 90 days is deleted automatically |
| Job postings | They stop showing after 30 days unless renewed, and stay in the company's account |
| Data downloads | The download link works for 24 hours, and the file is deleted after 7 days |
| Your area for the search box | Up to 24 hours, not linked to you |
| Sessions | 2 hours without activity (up to 400 days with "keep me signed in") |
| Password reset links | 60 minutes |
| Sign-in codes | 10 minutes, or until used |
| Remembered browsers for sign-in codes | 30 days |
| Your mobile numbers (employers) | Until you remove them or delete your account |
| Server logs | About 5 weeks |
| Backups | 14 days |
| Analytics, profile-view counts, contact-form messages, early-interest sign-ups, reports, AI-assisted search records and our moderation audit log | As long as we need them to run, improve and protect Job Elf. When you delete your account, they're no longer linked to it; contact-form messages keep the name and email address you wrote with |
We may keep information longer if the law requires it, or if we need it to resolve a dispute, enforce our Terms or investigate abuse.
9. Your choices and rights
In your account settings you can:
- edit or remove anything on your profile, change its visibility, and hide your current employer's name;
- remove photos and your intro video, replace your résumé, and turn share links off;
- keep your profile out of AI-assisted search;
- choose which notification emails you get;
- download a copy of your data; and
- delete your account.
When you delete your account, it's deleted straight away. We remove your account and profile, your résumés, photos, intro videos and data downloads, your notifications, applications, saved jobs and candidates, saved searches, share links and the talent lists you own. Some things remain:
- messages you sent stay in the other person's inbox, shown as from a deleted account; a company's job postings, notes and records stay with the company;
- records of profile views, analytics, AI-assisted search records, reports you made, and our moderation log stay, no longer linked to your account;
- messages you sent us through the contact form stay, because they may be the request itself; and
- copies in backups remain until those backups are replaced, within 14 days.
You can also ask us to tell you what information we have about you, correct it, delete it, or send you a copy, including anything the download in your settings doesn't cover (for example interviews, scorecards or AI-assisted search records). Use the contact form and choose Privacy request, or email service@jobelf.com. To protect you, we'll check that the request comes from you, for example by asking you to write in while signed in or by replying to your account's email address. If you live in a state with a privacy law that gives you more rights (such as California, Colorado, Connecticut, Virginia, Texas or Oregon), we'll honor them, and if we turn down your request you can ask us to reconsider by replying to our answer. An authorized agent may make a request for you with your signed permission. We won't treat you differently for making a request.
Because we don't sell or share personal information for advertising, there's nothing to opt out of, but we treat a browser's Global Privacy Control signal as an opt-out request anyway.
10. Security
We protect your information with encrypted connections (HTTPS), private storage for files, permission checks every time a résumé, photo or video is opened, secure password storage, sign-in codes on new devices, optional two-factor authentication and passkeys, required two-factor authentication for our admin team, limits on repeated attempts, and an audit log of our team's actions. No system is perfectly secure, so we can't guarantee that your information will never be accessed without permission. If a breach affects you, we'll tell you as the law requires.
11. Children
Job Elf is only for people 18 and older, and we don't knowingly collect information from anyone younger. If you believe someone under 18 has created an account, tell us using our contact form and we'll delete it.
12. Where information is stored
Job Elf is run from the United States, and your information is stored and processed in the United States, except that our video host also keeps intro and company videos in Germany (in the European Union) alongside the copy in the United States. Job Elf is offered for use in the United States; if you use it from somewhere else, your information will be transferred to and processed in the United States.
13. Changes to this policy
If we change this policy in a way that matters, we'll tell you by email or with a notice on Job Elf before the change takes effect. The date at the top shows when it last changed.
14. Contact us
Job Elf Technologies, Corp. Use our contact form (choose Privacy request for anything about your data), or email service@jobelf.com.
Effective October 4, 2026. Questions? Send us a message from our contact page.