Privacy
Score This Job scores a job posting against your resume. To do that we keep your resume on file — encrypted, readable only by this service, and deletable by you at any moment.
Last updated 10 September 2026
The short version
Your resume is encrypted at rest
It is stored so you can score with one click instead of uploading it every time. The encryption key lives outside the database, so a stolen copy of the database is unreadable on its own.
Nobody can see what you searched
We do keep the job postings themselves, so we can tell you when one has been re-listed for months. What we never record is who looked at what — postings carry no link to any person.
No tracking, no ads
No analytics, no advertising, no third-party trackers, no tracking cookies. There is nothing to opt out of.
We never read your LinkedIn
No part of this product accesses your LinkedIn profile. If you want that data here, you export it from LinkedIn yourself and upload the file.
Who is responsible
Score This Job is operated by Code 418 (trading as Aardvark Hosting), a sole proprietorship registered in the Netherlands, KvK 68957157. It is the data controller for everything described here.
For anything on this page, including a request about your data, write to info@aardvark-hosting.nl. A postal address is available on request.
What we store
The complete list. If something is not here, we do not have it.
| What | Why | Legal basis |
|---|---|---|
| Your email address, and your name if the sign-in provider gives us one | To have an account at all, and to send sign-in links | Performance of a contract |
| Which sign-in method you used and the opaque user id that provider gave us | To recognise you next time you sign in | Performance of a contract |
| Your resume, encrypted — the text itself, plus a label, how you added it, its length and a one-way fingerprint | So a posting can be scored against it without you uploading it again, on any device you sign in from | Your explicit consent (Art. 9(2)(a)), given before the first upload and withdrawable by deleting your resumes |
| Job postings we have seen, and when we saw them — the employer's own public advertisement, its text, and its re-listing history. Never attached to a person. | So we can tell you a role has been re-listed five times since January, which is the difference between guessing a job is a ghost and knowing it | Legitimate interest (Art. 6(1)(f)) — public employer advertisements, held to warn job seekers about listings that are not real |
| One row per score: the number, the band, how many requirements matched, whether the score used your CV, the ghost-job reading of the listing, and when | To count your monthly usage against your plan, and for aggregate product statistics | Performance of a contract for usage counting; legitimate interest (Art. 6(1)(f)) for aggregate statistics |
| Your plan and its status | To know what you are entitled to | Performance of a contract |
| Hashed, single-use sign-in tokens | To make email sign-in links work once and then expire | Performance of a contract |
| Aggregate per-day counts by job site, outcome and extension version — no personal data | To see whether the extension can still read a job site, so a redesign that breaks it shows up as a spike instead of silence | Legitimate interest (Art. 6(1)(f)) — keeping the extension working |
The fingerprint is a SHA-256 hash of your resume text. It is one-way: it lets us tell two resumes apart without holding either. Nothing about you can be recovered from it.
What we deliberately do not store
Any link between you and a job
We keep job postings, but never who looked at one. There is no column anywhere joining a person to a listing, so we cannot tell which jobs you have been reading — and neither can anyone who takes our database.
This holds even though the browser extension reports the postings it opens. Those reports carry an identifier for the install, minted without signing in and never joined to your account. It exists so one misbehaving install can be throttled, and it is not enough to say whose install it is. You can switch reporting off in the extension, which deletes that identifier too. The extension also reports, per job site, whether it could read the page — the site's name, "read" or "unreadable", and the extension's version. Those reports are counted per day and kept without the install identifier, the page address or anything on the page. The same switch turns them off.
Anything from your LinkedIn profile
Signing in with LinkedIn returns your name and email address. It does not return work history, and we do not ask for it.
Anything from your Google Drive
If you use the Drive picker, we can access only the single file you choose, read in your browser. We cannot see anything else in your Drive.
Resumes routinely contain things the law treats as sensitive — health, nationality, union membership, religion, a photograph. We designed the product not to hold that data rather than to hold it carefully, because not having it is the only guarantee that survives a mistake on our side.
One consequence worth being plain about: because your resume is processed in memory when you score a posting, it passes through our server even though it is never written down. If your resume contains something you would rather no service ever processed, remove it from the copy you upload.
Cookies
Two, both strictly necessary, neither used for tracking:
stj_session— keeps you signed in. Expires after 30 days.stj_oauth— holds the one-time security values that protect a sign-in round trip. Expires after 10 minutes.
There is no analytics cookie, no advertising cookie, and no third-party cookie. That is why this site does not show you a cookie banner: under the ePrivacy rules, strictly necessary cookies do not need consent, and we do not set any other kind.
Who else is involved
We use as few third parties as the product allows. These are all of them.
| Who | What they do | What they see |
|---|---|---|
| Sign-in, and the Drive file picker if you use it | That you signed in to us; the file you pick | |
| Sign-in | That you signed in to us | |
| Scaleway (France) | Sends sign-in emails | Your email address and the message |
| Cloudflare | Serves the site and protects it from abuse | Request metadata, including your IP address |
| netcup (Germany) | Hosts the application and its database | Nothing beyond what is listed above as stored |
None of them receive your resume or the postings you score. Servers and data are in the European Union. Google, LinkedIn and Cloudflare are US companies operating under the EU-US Data Privacy Framework; contacting them is unavoidable if you choose to sign in with Google or LinkedIn, and Cloudflare sits in front of every request.
How long we keep it
- Your account, your resumes and your plan — until you delete them. A resume you remove is gone immediately; deleting your account takes everything with it.
- Score records — 13 months, which covers the monthly allowance and a year-on-year comparison, then deleted.
- Job postings — kept as long as they are useful evidence, because a re-listing history is only worth anything over time. They contain no personal data of yours; if a posting names a recruiter, that is the employer's own published text.
- Sign-in tokens — deleted a day after they expire. They are unusable from the moment they are used or 15 minutes after they are issued, whichever is first.
- Extraction counts — aggregate per-day counts by job site, outcome and extension version; no personal data; kept 13 months, then deleted.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, delete it, take it elsewhere, restrict what we do with it, or object to it. Two of those do not need a request at all:
Get a copy, now
Download everything we hold as a JSON file, including your resumes in full. Straight from your account, no request, no waiting.
Delete it, now
Your account page deletes the account and everything attached to it immediately. There is no grace period and no soft delete.
For anything else, email info@aardvark-hosting.nl. We answer within 30 days, usually far sooner. If you are not satisfied, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority where you live.
Children
Score This Job is for people looking for work and is not directed at children under 16. We do not knowingly hold their data. If you believe a child has an account here, email us and we will delete it.
Changes
If this policy changes in a way that affects what we collect or why, we will email account holders before it takes effect rather than quietly changing the date at the top.

