Privacy Policy
Effective: August 23, 2026
This policy explains how JobWillow collects, uses, and shares your information when you use jobwillow.com and related services. We wrote it in plain English wherever we could.
1. Who we are
JobWillow is a two-sided hiring marketplace built for college students and local employers, launching in Knoxville, Tennessee. We operate jobwillow.com.
Contact: privacy@jobwillow.com
2. Information we collect
Account information
- Your name, email address, and password (stored as a one-way hash)
- Your date of birth, if you register as a candidate or set up an account from an administrator invitation. We use it to confirm you are at least 18 at account creation (a requirement under our Terms of Service). Employers and researchers are not asked for one. It is stored on your account, treated as sensitive personal information, and is not shown on your candidate or employer profile.
- For employers: company name, location, industry, website, and the first name, last name, work email, and phone number of an internal contact person at the company.
- Two-factor authentication is available on every account. If you enroll, we store an encrypted TOTP secret and one-time recovery codes (hashed).
Candidate profile information
- University, major, and (optionally) graduation year and GPA
- Work authorization status
- Skills selected from our curated vocabulary, plus any custom skills you type yourself on a tailored resume profile
- Phone number, LinkedIn URL, and an optional contact email to display on your resume
- Your school affiliation for reporting purposes, which we derive only from your verified school email domain to place you in your school’s cohort for the aggregate reporting described in Section 4. The university you type on your profile is display-only and never places you in a cohort; without a verified domain match you are not counted in any school’s reporting.
- Resume content (work experience, projects, clubs, volunteering, writing samples), avatar, and resume PDF uploads. When you upload a resume PDF, we parse it on our own servers to suggest fields (skills, education, contact info) for you to confirm. The parsing is in-process and the PDF contents are not sent to any third party for parsing.
- Demographic information (optional, voluntary, used only in aggregate; see Section 5)
Graduate outcome survey (optional)
- Candidates may fill out a short first-destination survey about where they landed after graduating: outcome (for example, employed full-time or part-time, continuing education, military service, still seeking, or not seeking), employer name, job title, start date, self-reported salary, location, and graduating year.
- The survey is voluntary and you can update your response at any time. Employers never see it. Your school sees only the privacy-protected aggregate statistics described in Section 4. Your response is included in your data export and removed with your account.
Employer profile information
- Company logo, description, and industry
- Posted listings, custom questions, scorecard templates, talent pools
- Contact details (name, email, phone) for the hiring manager and recruiter listed on a posting, which may describe teammates other than the account holder
Researcher profile information
- Academic title, department, institution, a short bio, a description of your research, and links to your publications. Candidates see this profile when viewing your research listings.
Employer-submitted intern testimonials
- Employers may publish testimonials on their profile that include intern names, role titles, the season or dates of the internship, an optional photo, and a quoted description of the experience. This content is submitted by the employer and is not verified by JobWillow. Testimonial sections are labeled “Shared by the employer” so candidates understand the source.
- If you are named or pictured in a testimonial on JobWillow, even if you do not have a JobWillow account, you can request removal by emailing privacy@jobwillow.com. We will remove the testimonial promptly and without requiring you to explain why. We do not arbitrate factual disputes between you and the employer about what was said; the removal path is unconditional.
Application and messaging data
- Which listings you applied to and their status over time
- Messages exchanged between candidates and employers
- Interview scheduling, scorecard data, notes an employer’s interviewers write about an interview, and offer terms
- If an employer initiates a background check through the platform, we store the status the employer records (pending, in progress, completed), which provider was selected, an optional short note the employer may type (up to 500 characters), and the employer’s own case number at that provider, all visible to that employer’s team. We do not run the check itself and do not receive the underlying report, and the platform does not record a pass/fail adjudication. See §12 of the Terms of Service.
Reports and enforcement records
- If you report a listing, an application question, a testimonial, or a conversation, we store the report, its reason, and any comment you add, along with our resolution notes and any reply we send you. We also keep records of moderation actions taken on accounts (for example, a suspension and its reason) and an audit log of administrative actions. Moderation records and the administrative audit log are retained for platform safety even after accounts are deleted. Reports you filed are deleted with your account, except conversation reports, which are kept without your identity.
- Accounts you block are stored so the block can be enforced.
References you provide
- Candidates may add references to their profile. For each reference we collect the name, email, phone (optional), title, organization, and relationship that the candidate enters.
- We send each reference a confirmation email so they can confirm (or decline) being listed. Unconfirmed references are automatically deleted after a fixed retention window.
- When a candidate submits an application, a snapshot of their confirmed references is attached to that application so the employer can contact them. Subsequent edits to the live reference do not change the snapshot already attached to a prior application.
- If you have been listed as a reference and want your record removed, email privacy@jobwillow.com. We will remove it without requiring a reason. Removal erases your name, email address, phone number, title and organization from the live reference record and from the snapshot attached to every application the candidate has already submitted. The fact that the candidate listed a reference remains in the employer’s hiring record, without your details.
Business contacts and relationship records
- JobWillow keeps internal records about the people we work with while building the platform: employer and university contacts, advisors, investors, and other professional contacts, whether or not they have a JobWillow account. A record can include a name, role and organization, email address and phone number, a LinkedIn URL, how we met or who introduced us, and notes about our interactions.
- JobWillow staff may connect their own JobWillow work mailbox and contacts (Microsoft 365) to help maintain these records. That connection is metadata-only: the mail permission we use cannot read message bodies, and we record only the correspondent, subject line, direction, time, and the provider’s internal message identifier (used to avoid duplicate records), and only for people already in our records. Subject lines can be excluded per connection, and correspondents who are not already in our records are not stored at all.
- Partner universities can keep their own employer-outreach records in a CRM we host: the name, title, email, phone, and interaction notes of employer representatives they work with. If an invitation email is ever sent to such a contact through the platform, it will include a working unsubscribe, and opted-out addresses are kept on a suppression list solely to honor the opt-out.
- These records are internal tools: they are not shown to platform users and are used only for partnership, sales, and operations work. If you believe you are in these records and want to be removed, email privacy@jobwillow.com and we will remove you promptly, without requiring a reason.
Connected calendar and video accounts
- Employers (and, where applicable, candidates) can connect a Google, Microsoft, or Zoom account to schedule interviews.
- When you connect an account, we store the OAuth access and refresh tokens issued by the provider and the provider account identifier. The permissions we request cover calendar events and free or busy times on the account you connect (for Google, calendar events and free or busy; for Microsoft, calendar read and write plus online meetings; for Zoom, creating and removing meeting rooms). For a scheduling connection we do not request access to your email, your files, or your contacts; the only staff-side exception is described under Business contacts and relationship records above.
- We use those tokens to push interview events to your calendar, create or remove meeting rooms tied to a specific interview, and read free or busy times to suggest interview slots. If you open the calendar view inside JobWillow, we also fetch the events already on your connected calendar for the date range you are looking at, so your interviews appear alongside the rest of your schedule. That fetch returns the title, start and end time, all-day flag, and location of those events. We show them back to you only, we do not store them on our servers, and we do not use them for any other purpose. Through a scheduling connection we do not read your email, your files, or your contacts.
- You can disconnect a provider at any time from your account settings. We delete the stored tokens on disconnect.
Location data
- We collect the city and (for candidates) hometown you pick on your profile from a built-in list of US cities. We convert those cities into approximate coordinates (latitude and longitude) on our own servers, without sending them to any third party, to power proximity search and the Discover Talent map. We do not collect precise device location.
- When the map view loads in your browser, your browser fetches tiles directly from Mapbox, which means Mapbox sees your IP address as part of that request. A few free-text location fields (such as the first-destination survey) also fetch typing suggestions in your browser directly from Mapbox, which sees the text you type and your IP address. The map library additionally sends anonymous usage-telemetry events to Mapbox from your browser while the map is open. We do not share your account information with Mapbox.
Usage data
- Pages visited, listings viewed, searches performed
- Login timestamps and session info
- Browser, device, and IP address
- Clicks on JobWillow short links that schools share through their own channels. We log the time of the click, the referring page, and a truncated, hashed form of the network the click came from (used only to avoid double-counting; it cannot identify you or follow you across links), and we report aggregate click counts to the sponsoring school. This applies to anyone who clicks such a link, with or without a JobWillow account.
Cookies and similar technology
- Essential cookies only. We use a session cookie to keep you logged in and a short-lived state cookie to protect the flow that connects a calendar or video account against cross-site request forgery. The session cookie cannot be disabled without breaking login; the state cookie cannot be disabled without breaking account connections.
- We do not use analytics, advertising, retargeting, or other third-party tracking cookies. We do not run cross-site behavioral profiling. If we ever add non-essential cookies, we will update this policy and, where consent is required, ask before setting them.
3. How we use your information
- Operate the marketplace: matching, search, messaging, scheduling
- Enforce platform rules: weekly application caps, response deadlines, employer approval
- Send transactional emails: account verification, application status, deadline alerts, interview confirmations
- Improve the product using aggregate usage patterns
- Provide your school with aggregate, privacy-protected reporting about its student cohort (see Section 4)
- Detect and prevent fraud, abuse, and policy violations
- Comply with legal obligations
We do not sell your personal information.
Legal bases for processing
Where applicable law requires us to identify a legal basis for processing your information, we rely on one or more of the following:
- Performance of a contract: to provide the services you signed up for (operating your account, processing your applications, delivering messages).
- Legitimate interests: to operate, secure, and improve the platform, prevent fraud, and enforce platform rules, where these interests are not overridden by your rights.
- Legal obligation: to comply with applicable laws and respond to lawful requests.
- Consent: where you have provided it for optional data collection or sharing (for example, demographic data for EEO reporting, the per-application consent to share academic details that applying to a research listing requires, or marketing emails).
4. Who we share it with
Other users on the platform
- Your candidate profile is visible to approved employers when you apply to their listings, when you appear in candidate search, or when you accept an interest signal.
- Employer profiles and listings are visible to candidates browsing.
- Messages and application data are visible to the specific candidate and employer involved. JobWillow staff can additionally read a conversation a participant has reported; that access requires an existing report and is logged.
- University research listings are posted by faculty researchers. Applying to a research listing requires your per-application consent to share your academic details (GPA, majors and minors, graduation year) and your resume with the faculty poster; you cannot submit that application without consenting, and the consent covers only that application. Without live consent, those fields are withheld from the poster.
Service providers we use
- Supabase: database hosting (PostgreSQL) and file storage (S3-compatible) for resumes, avatars, company logos, writing samples, and offer-letter PDFs.
- Vercel: frontend hosting (jobwillow.com).
- Render: API hosting (api.jobwillow.com).
- Cloudflare: CDN, DDoS protection, and proxy in front of the API. Cloudflare sees request IP addresses and metadata as part of routing traffic.
- Resend: transactional email delivery (verification, application status, deadlines, references, 2FA, password reset).
- Mapbox: map rendering for the Discover Talent view, plus in-browser typing suggestions on a few free-text location fields (such as the first-destination survey). Profile city and hometown are picked from a built-in list and are not sent to Mapbox.
- Google: when an employer or candidate connects a Google account, we use the Google Calendar API to create interview events on the connected calendar, to read free or busy times, and to list the events in the date range you are viewing inside JobWillow so they can be shown back to you.
- Microsoft: when a Microsoft account is connected, we use Microsoft Graph to create interview events in Outlook and meeting links in Microsoft Teams, to read free or busy times, and to list the events in the date range you are viewing inside JobWillow so they can be shown back to you. JobWillow staff may also connect JobWillow’s own work mailboxes through Microsoft Graph for the internal relationship records described in Section 2; that use is metadata-only and cannot read message bodies.
- Zoom: when a Zoom account is connected, we use the Zoom API to create and remove interview meeting rooms on the connected account.
- Sentry: error monitoring (when enabled). DSNs are currently unset, so Sentry does not receive data today.
- Stripe: payment processing for paid employer plans. Stripe is not yet wired into the live product; this entry is forward-looking for when paid plans become active.
These providers process your data on our behalf under their own terms and security commitments.
Aggregated, non-identifying data
We may publish aggregate hiring trends (for example, a “Knoxville Hiring Index”) using anonymized data that cannot identify any individual user.
On individual employer profiles and listings we also surface privacy-protected aggregates of past hires: for example, the median GPA, typical graduation year, most common majors, and median profile depth (projects, experiences, clubs) among candidates the employer has hired. These aggregates are governed by hard floors designed to prevent any single past hire from being identifiable:
- The panel is hidden entirely unless the relevant scope has at least five past hires. Below that threshold no aggregate is shown.
- Any specific value (for example, a particular major) is shown only when it appears in at least five of the past hires. Less frequent values are dropped before display.
- GPA statistics are omitted whenever fewer than half of past hires have a GPA on their profile, so a small sample with sparse data does not produce a misleading median.
- We never display the identity, profile, photo, or any other distinguishing detail of any specific past hire in these aggregates.
Your school (aggregate reporting)
If your verified email domain matches a partner school, you are counted in that school’s cohort, and career-services staff at the school see aggregate, privacy-protected statistics about the cohort: engagement (for example, how many students are active or applying), hiring outcomes including typical pay among captured offers, graduate outcome survey results, and click counts on links the school shared. These aggregates are governed by hard floors, in the same spirit as the past-hires aggregates above:
- Statistics are suppressed below a floor of five and guarded against tease-apart comparisons between differently filtered views, so no number can be traced to one student.
- Your school never sees your name, your profile, your application history, or any other individual record through these dashboards. If we ever offer schools an identified placement export, we will update this policy first, and it will require a signed data-sharing agreement.
Legal disclosures
We may disclose information when required by law, in response to valid legal process, or to protect rights, safety, or property.
5. EEO and demographic data
Demographic information (race, gender, veteran status, disability status) is optional and voluntary. It is used only in aggregate reporting protected by k-anonymity: we never display demographic breakdowns for groups smaller than five respondents. Individual employers never see your demographic information attached to your identity.
6. How long we keep your data
- Active accounts: as long as your account is active
- Deactivated accounts: retained for a reasonable period to allow restoration and to satisfy legal obligations, then deleted or anonymized
- Application records: may be retained for audit and legal-compliance purposes even after account deletion
7. Your rights
You can:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your account. Candidates can do this directly from account settings; employers, researchers, and school administrators can request deletion by emailing privacy@jobwillow.com. Deletion cascades to your profile and your application history, subject to limited retention for legal or fraud-prevention purposes.
- Export your data as a JSON file from Settings → Privacy → Export my data (candidates), Settings → Export my data (employers), or Settings → Account in the school portal (school administrators). Researchers can request an export at privacy@jobwillow.com. The export includes your account, profile, applications or listings, messages you have sent, and other records we hold about you.
- Opt out of non-essential marketing emails (transactional emails about your applications cannot be disabled while your account is active)
- Withdraw consent for optional data collection, including demographic data
We honor the Global Privacy Control (GPC) signal where it applies to a JobWillow data flow. JobWillow does not currently run analytics, advertising, retargeting, or sale-of-data pipelines, so the GPC signal has nothing to opt out of today; the handler is in place so that the moment any of those launch, GPC-on visitors will be excluded from them.
Depending on where you live (for example, California or the EU), additional rights may apply under CCPA, GDPR, or similar laws. Contact privacy@jobwillow.com to exercise any of these rights. We aim to respond to verifiable requests within 30 days, or as required by applicable law.
California residents (CCPA / CPRA)
If you are a California resident, you have the following additional rights with respect to personal information we collect:
- Right to know: the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to delete: request deletion of personal information we have collected, subject to legal exceptions.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out of sale or sharing: we do not sell or share your personal information for cross-context behavioral advertising. There is nothing to opt out of.
- Right to limit use of sensitive personal information: we only use sensitive personal information (such as EEO demographics) for the purposes you consented to.
- Right to non-discrimination: we will not deny you service, charge you a different price, or provide a different quality of service because you exercised your CCPA rights.
You may also use an authorized agent to exercise these rights on your behalf. We will require reasonable verification of the agent’s authority and your identity.
8. Children's privacy
JobWillow is for users 18 and older. Candidate registration requires a date of birth and will not complete for anyone under 18; employers and researchers confirm their age by accepting our Terms of Service. We do not knowingly collect personal information from minors. If we learn that we have, we will delete it.
9. Security
- All data is encrypted in transit (HTTPS / TLS)
- Passwords are stored using one-way cryptographic hashing (bcrypt)
- Two-factor authentication is available on every account
- Access to production systems is limited and audited
No system is completely secure. We encourage you to use a unique, strong password and enable two-factor authentication.
Security incidents
If we discover a security incident that affects your personal information, we will notify affected users without unreasonable delay and in accordance with applicable law. State and federal laws may require specific notification timelines, methods, and content; we will follow those requirements. You can report suspected security issues to security@jobwillow.com.
10. International transfers
JobWillow is operated from the United States. Some of our service providers may process data in other jurisdictions. If you access JobWillow from outside the United States, you consent to the transfer of your information to the United States for processing.
11. Changes to this policy
We may update this policy from time to time. When we make a material change, we post the updated policy with a new effective date and describe the change in the list below. Your continued use of JobWillow after the new effective date indicates acceptance of the updated policy. For significant changes we may also notify you by email or in the product, but the posted policy and its effective date are the authoritative record.
Recent material changes
- August 23, 2026: Disclosed three processing activities that were live but missing from this policy: the aggregate reporting partner schools receive about their own student cohort, including how the cohort is derived from a verified email domain and the click counting on school short links (§2, §3, §4); the optional graduate outcome survey and the fields it collects, including self-reported salary (§2); and the internal business-contact and relationship records JobWillow and partner universities keep, including planned metadata-only staff mailbox connections, with an unconditional removal path (§2). Added a category for researcher profiles (§2), the consent gate on academic details for research listings (§3, §4), staff review of reported conversations (§2, §4), and fields that were collected but unlisted: candidate phone, LinkedIn URL, alternate resume email, custom skills, hiring-manager and recruiter contacts on listings, interviewer notes, and the background-check case number (§2). Narrowed the email-files-contacts statement to the scheduling connection it describes (§2), corrected the description of the second essential cookie (§2), disclosed the map library’s telemetry beacon (§2), and stated the export and deletion paths for every role (§7). Also changed what this section itself promises, to match practice: the authoritative record of a change is the posted policy, its effective date, and this list.
- August 4, 2026: Corrected the background-check description (§2). The platform stopped recording “clear” and “flagged” adjudications in May 2026, but this policy still listed them; it also did not mention the optional short note an employer may type. Both are now described accurately. Also stated exactly what removal does for someone listed as a reference (§2): their contact details are erased from the live record and from the snapshot attached to applications already submitted.
- May 31, 2026: Added new disclosures covering references that candidates submit (§2), resume parsing (§2), connected calendar and video accounts via Google, Microsoft, and Zoom (§2 and §4), location data sent to Mapbox (§2 and §4), date of birth captured at signup to confirm age (§2), and an expanded service provider list adding Cloudflare, Mapbox, Google, Microsoft, and Zoom and correcting the file-storage provider to Supabase Storage (§4). Also clarified that JobWillow uses only essential cookies (session and sign-in CSRF protection) and does not use functional, analytics, advertising, or third-party tracking cookies (§2). Added a self-service data export at Settings → Privacy → Export my data for candidates and Settings → Export my data for employers, and documented our Global Privacy Control (GPC) handler (§7).
- May 18, 2026: Added handling for employer-submitted intern testimonials (§2) and described the privacy guards on per-employer aggregate hiring data shown on listings (§4).
12. Contact
Questions, requests, or concerns about your privacy:
- Email: privacy@jobwillow.com
- JobWillow, Knoxville, TN