Point your AI agent at freehire and let it find you a job.

Get the CLI →

// legal

Privacy Policy

Last updated: September 16, 2026

freehire (freehire.me) is a free, open-source IT job aggregator. This policy explains what data we collect, why, and who we share it with. We collect only what the product needs to work, and we never sell your data.

What we collect

  • Account data. When you register, we store your email address and — for password sign-in — a salted bcrypt hash of your password (never the plaintext). If you sign in with Google, GitHub, or LinkedIn, we store your verified email and a provider identifier so we can recognise you next time; we do not keep the provider's access tokens. Connecting Gmail or Google Calendar is a separate, opt-in step that does store a token — see “Gmail and Google Calendar”.
  • Job activity. If you save, view, apply to, or track a job, we store that interaction (the job, timestamps, application stage, and any notes you add) so we can show you your pipeline.
  • CV / résumé. If you upload a CV for skill matching or AI match analysis, we store the file and the text we extract from it. Running an AI match analysis sends the relevant parts of your CV, together with the job posting, to our language-model provider (see “Third-party services”).
  • API keys. If you create a personal API key, we store only a SHA-256 hash of it. The key itself is shown once at creation and is unrecoverable afterwards.
  • Technical data. Standard request logs (IP address, user agent, timestamps) and, where you allow it, product-analytics cookies (see “Cookies”). We do not sell your data or build advertising profiles.

How we use it

We use your data to run the service: authenticate you, remember your saved and tracked jobs, match jobs to your CV, deliver any digests you subscribe to, and keep the platform secure and working. We do not sell your personal data or use it for third-party advertising.

Cookies

When you sign in, we set a single HttpOnly, SameSite=Lax session cookie holding a signed token. It is strictly necessary for keeping you logged in and cannot be read by JavaScript. Logging out clears it. This cookie is always set and needs no consent.

For product analytics we use Google Analytics and PostHog, which set their own cookies and, in PostHog's case, may record a session replay with all inputs masked. These are non-essential. If you visit from the EU, EEA, or UK, they load only after you accept them in the cookie banner — reject and nothing loads. You can change your choice at any time via “Cookie settings” in the footer.

Job listings

The jobs we display are aggregated from public company career boards and other public sources. We normalise and deduplicate them; we do not own this content, and a role closes in our catalogue once it disappears from its original source.

Third-party services

We rely on a small set of processors to run freehire:

  • A language-model provider — processes CV and job text to produce AI match analysis, only when you request it; and, if you have connected Gmail, classifies the hiring mail our own keyword vocabulary could not place (see “Gmail and Google Calendar”). It processes this text to answer that one request and is contractually barred from training on it.
  • Product analytics (Google Analytics, PostHog) — measure aggregate usage to improve the product; loaded only with your consent where required (see “Cookies”). PostHog runs on its EU instance.
  • Error monitoring (Sentry) — captures application errors to keep the service reliable; configured without personal-data capture.
  • OAuth providers (Google, GitHub, LinkedIn) — only if you choose to sign in with them, to verify your identity and email.
  • ChatGPT Actions — if you connect freehire to a custom GPT, ChatGPT sends your search and tracking requests (authenticated with your API key) to our API. Your use of ChatGPT is also governed by OpenAI's own privacy policy.

Browser extension

The freehire Chrome extension puts a job-application agent in a side panel next to whatever page you are on. It does nothing until you sign in from the panel.

  • Session token. Signing in stores your freehire session token in chrome.storage.local, scoped to your browser profile. Nothing else is stored there.
  • Page content. While the panel is open and only in service of what you asked for, it can read the current page's URL, title, and visible text (capped at 5,000 characters), or the fields of a job-application form you asked it to fill. This is sent to freehire.me — the only host the extension talks to — and kept in that conversation's transcript, which you can read and delete from your account. A read is always named in the panel, and browser-internal pages, other extensions' pages, and local files are never read.
  • Profile data for Autofill. Filling an application form sends the relevant fields from your freehire profile (name, email, phone, CV fields) to the page; you review and submit yourself.

We do not sell this data, and we do not use it for anything unrelated to running the extension's job-application agent, in line with the Chrome Web Store's limited-use requirements.

Gmail and Google Calendar

This section applies only if you use the Inbox feature and connect a Google account to it. It is off by default, it is separate from signing in with Google, and nothing below happens for anyone who has not connected one. You can disconnect at any time from your account settings, or revoke the grant directly in your Google account permissions.

  • What we read (gmail.readonly). We do not read your whole mailbox. Each sync runs a search for hiring-shaped mail only — messages from recognised applicant-tracking systems, or carrying application and interview wording — and skips mail you sent yourself. We store the matching messages (sender, subject, date, body) so your application inbox and pipeline stages work. Nothing else in your mailbox is fetched, and we never send mail on your behalf.
  • Your calendar (calendar.readonly, and calendar.events only if you are a mentor taking bookings). Read access shows your interviews alongside your applications. The mentor write scope creates the event and Meet link for a session someone books with you — we create nothing else and delete nothing.
  • Automated processing. To decide which application a message belongs to and what stage it signals, we first try a fixed keyword vocabulary that runs entirely on our own servers. Only when that cannot decide do we send the sender, the subject, and the first 4,000 characters of the body to our language-model provider (see “Third-party services”). No human at freehire reads your mail, except where you explicitly ask us to look at a specific message for support, or where we are legally required to.
  • Your Google token. The refresh token that lets us sync is encrypted at rest with AES-256 and is never shown to you or to anyone else. Disconnecting revokes it with Google and deletes the messages we synced from that account.

freehire's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, we do not use it for advertising or to build advertising profiles, we do not use it to train or improve any generalised machine-learning model, and we do not transfer it to anyone except the processors named in this policy and only to provide the Inbox feature you asked for.

CV link tracking

You can turn on link tracking for a single CV. It is off for every CV unless you switch it on, and switching it on for one CV does not affect any other.

When it is on, the links in that CV's PDF point at freehire and forward to the real destination. Following one records the time, the browser and operating system family, the device type, and the host — not the full address — of the page the visitor came from. It also records a keyed hash of the visitor's IP address and browser identity, so that repeat visits can be told from separate people. We do not store the IP address itself, and the hash is keyed with a secret so it cannot be turned back into an address.

These records are deleted after 180 days, and immediately if you delete the CV. Your own clicks are marked as yours and left out of the counts. A recorded open means the link was fetched; company mail systems follow links automatically, so it is not proof that a person read your CV.

Retention

We keep account and activity data for as long as your account exists. When you delete your account, we delete or anonymise your personal data, except where we must keep it to comply with the law. Request logs are retained for a limited period for security and debugging.

Your rights

You can access, correct, export, or delete your personal data at any time — most of it directly from your account settings, or by contacting us. You can also revoke API keys and unlink sign-in providers. If you are in the EU/EEA or UK, you have the rights granted by the GDPR, including the right to lodge a complaint with a supervisory authority.

Contact

Questions or requests about your data? Reach us at hello@freehire.me, on Telegram, or via GitHub. As an open-source project, our data handling follows what the source code actually does.

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available